PM - Section 1.2 Attack Types Flashcards

1
Q

What is Phishing?

A

Social engineering + spoofing

Often delivered by spam, usually very well done.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Vishing?

A

Voice Phishing over the phone!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Spearing Phishing?

A

Focus in on specific people - CEO is whaling.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is tailgating?

A

Use someone else gain access into a locked area to gain access.

Or wearing a camouflage.
Sneak in smoking break.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How to stop tailgating?

A

Must identify everyone - visitors have a badge.
Scanning in must be one person at a time - air locks.
Train staff to ask about visitors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How to stop impersonation?

A

Never share PII.

Call numbers back and verify callers/emails.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is dumpster diving?

A

Sifting through trash for information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you protect against dumpster diving?

A

Shredding, locks, fence.

Check your own company’s trash and use for training.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is shoulder surfing?

A

Curious, competitive advantage, industrial espionage.

People use webcams, binos etc

Use privacy filters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are computer hoaxes?

A

A way to waste time and consume resources.

A hoax about a virus can take as much time as a real virus.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to prevent hoax attacks?

A

Check on:
hoax-slayer.net
snopes.com

Spam filters can help

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a watering hole attack?

A

When your network/work environment is secure the attackers go to favorite coffee/sandwich shop and attack that place. Infect the wifi there and gain access through the coffee shop.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is social engineering?

A
Tricking someone to get info, phone calls/emails.
Authority - police/CEO calling...
Intimidation - the payroll wont go out.
Scarcity - this must happen now
Familiarity - Trusting/friends
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a denial of service? DoS

A

Force a service to fail - a design failure or vulnerability.
Could even just be an overload.
Could be simple e.g. cut power.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a friendly DoS?

A

Unintentional DoS - Layer 2 loop without Spanning Tree on Switches.
Not enough bandwidth.
Water main break

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a DDoS?

A

Distributed Denial of Service - Botnets attack all at once for a coordinated attack.
DDoS attacks can be amplified

17
Q

What is a man-in-the-middle attack?

A

Interrupting traffic and watching.

18
Q

What is ARP poisoning?

A

AKA Spoofing!

Address Resolution Protocol has no security so you can update the ARP Cache.
Must be in the same local network.

Ettercap is a software to perform ARP poisoning.

19
Q

What is man-in-the-brower?

A

A proxy is created on the system, and all info is sent through the proxy.

The malware must be installed on the machine first.

20
Q

What is a buffer overflow?

A

Overwriting a buffer of memory. up to devs to stop it from happening.
Can open up access to the system and other variables.

21
Q

What is code injection?

A

Inject any code into an application. Many types - html, sql, xml, LDAP.

Good Applications can validate the incoming data.

22
Q

What is XSS?

A

Cross Site Scripting - Uses Javascript

Can have stored ones that live in a post on social networking site that gets activated when someone shared it.

23
Q

What is Cross Site request forgery attack?

A

XSRF or CSRF or Sea Surf