Threat vectors and attack surfaces Flashcards

SY0-701

1
Q

Threat vector

A

Means or path that an attacker can use to access networks or computers to deliver a malicious payload or carry out an unwanted action, ie how

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Attack surface

A

Encompasses all various points where an unauthorized user can try to enter data to extract data, ie where

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How to minimize

A

Restricting access, removing unnecessary software, disabling unused protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Messages

A

message based threat vectors delivered by email, sms, or other forms of IM, IE, phishing campaign

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Images

A

Imaged based threat vector involve embedding of malicious code inside an image file by the threat actor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Files

A

File based threat vector use malicious files to deliver cyber threats, ie, disguised as legit, can be transferred via email. Or downloaded game from file share

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

voice calls

A

Voice call threat vectors involve the use of voice calls to trick victims into revealing their sensitive info. May try to impersonate a bank or IRS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Removable devices

A

threat vectors delivered via USB or other removable devices. Baiting can be used by hackers leaving usb devices for victims who are unknowing, or social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Unsecure networks

A

threat vectors that lack appropriate security measures for protection, like wifi, bluetooth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Blueborne

A

exploit in bluetooth that can allow an attacker to take over devices or spread malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Bluesmack

A

Type of denial service attack that targets bt enabled devices by sending specifically crafted Logical Link Control and adaptation protocol packet which can cause device to crash or become inoperable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly