Social Engineering and Cyber Security Flashcards
1
Q
What is social engineering?
A
- A method of gaining informatin though human interactions and manipulation
2
Q
What are 4 types of social engineering? Describe each
A
- Pishing
> Sends fake emails, texts or phone calls pretending to be official/legit cooperations (e.g. a bank) in order to gain information (e.g. you account needs to be changed, please provide details) - Pharming
> Redirection of users to a fake website (usually though a similar looking DNS to the actual thing), which can get them to enter information - Blagging
> Creating a false scenario in which a person feels more incline to give information they would not normally hand over in ordinary circumstances - Shouldering
> Looking at someone’s information (e.g. password) without their consent or knowledge of it
3
Q
Name 5 tyoes of cyber security threats
A
- Spyware (software that can keylog information that someone enters on their computer e.g. bank account details)
- Adware (Not illegal, but can be harmful by redirecting you as aform of pharming of getting you to install malicious software, e.g. spyware withut you even knowing)
- Trojans (Disguise themselves as legit software or needed software, which could be installed and gain information and host of a computer network)
- Worms (self-replicating software that does not need to be connected to an existing program to operate; can
cause harm even by just consuming bandwidth) - Viruses (self-replicating software that makes files unreliable)
4
Q
What is the difference between white-box and black-box penetration testing?
A
White-box:
- The person infiltrating is usually an employee, who is given information prior to the penetration
Black-Box:
- Usually an outsider posing as a hacker, who has no prior information of the software, whos job is to see whether there are any gaps or vunerabilities
5
Q
What is CAPTCHA and what does it stand for?
A
- Completely Automated Public Turing Test to tell Computers and Humans Apart
- A random generate test, which spawns a pop up askng you to type what you see of select images
> This tests for motion rather than what you actual type