Terminology Flashcards

1
Q

Rainbow Table

A

contains hashes of common passwords to speed up brute force attacks. Defeated by salting the hashes differently for each user on a system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

https://haveibeenpwned.com

A

website to see if your password has been stolen by email address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

skimming

A

stealing credit card information usually by adding hardware to a legitimate reader

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

evasion attacks

A

Cause an AI to misunderstand something like SPAM by changing your pattern

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

poisoning the training data

A

modify an AI’s training data to confuse it or cause it to act incorrectly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

downgrade attack

A

A cryptographic attack where the attacker exploits the need for backward compatibility to force a computer system to abandon the use of encrypted messages in favor of plaintext messages (Prof Messer considers this a downgrade attack even if the encryption version is moved to something insecure rather than completely plaintext)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

risk register

A

A risk register is a document showing the results of risk assessments in a comprehensible format. The register may resemble the heat map risk matrix shown earlier with columns for impact and likelihood ratings, date of identification, description, countermeasures, owner/route for escalation, and status. Risk registers are also commonly depicted as scatterplot graphs, where impact and likelihood are each an axis, and the plot point is associated with a legend that includes more information about the nature of the plotted risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

data owner

A

role with ultimate responsibility for maintaining confidentiality, integrity and availability of info asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

data steward

A

responsible for data quality, i.e. for ensuring data is labeled and identified with appropriate metadata and that data is collected and stored in a format and with values that comply with applicable laws and regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

data custodian

A

manages the system on which the data is stored; enforces access control, encryption and backup/recovery measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Data Privacy Officer (DPO)

A

responsible for oversight of any personally identifiable information (PII) assets managed by the company. The privacy officer ensures that the processing, disclosure, and retention of PII complies with legal and regulatory frameworks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Data controller

A

responsible for determining why and how data is stored, collected, and used and for ensuring that these purposes and means are lawful. The data controller has ultimate responsibility for privacy breaches, and is not permitted to transfer that responsibility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Data processor

A

engaged by the data controller to assist with technical collection, storage, or analysis tasks. A data processor follows the instructions of a data controller with regard to collection or processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

dns sinkhole

A

Temporary DNS record that redirects malicious traffic to a controlled IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

hping

A

Open-source spoofing tool that provides a penetration tester with the ability to craft network packets to exploit vulnerable firewalls and IDSs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

tcpreplay

A

tcpreplay takes previously captured traffic that has been saved to a .pcap file and replays it though a network interface (linux.die.net/man/1/tcpreplay).