Tools of Defense Flashcards

1
Q

firewall

A

Hardware or software designed to block unauthorized network access while permitting authorized communications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

cloud computing

A

The practice of using remote servers on the Internet to store, manage, and process data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

security awareness training

A

Any training that raises the awareness of a user to potential threats, and how to avoid them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Kevin Mitnick

A

“World’s Most Wanted Hacker” in the 90s
“World’s Most Famous Hacker” today
successful Fortune 500 security consultant
part owner and the Chief Hacking Officer of KnowBe4
Kevin’s main contribution to KnowBe4 is his experience
KMSAT named after him

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

learning management system (LMS)

A

A system for the administration, documentation, tracking, reporting, and delivery of e-learning education courses or training programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

return on investment (ROI)

A

Measures the amount of return on an investment relative to the investor’s cost. For IT Security this is measured by “reduction in risk.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Shareable Content Object Reference Model (SCORM):

A

A technical standard that governs how online learning content and Learning Management Systems communicate with each other.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the Six Steps to Success SAT?

A

Step 1: Have a security policy, and have each employee read and sign it.

Step 2: Have all employees take mandatory SAT (online), with a clear deadline and reasons why they’re taking the training.

Step 3: Make SAT part of the onboarding process (the process of integrating new hires in a company).

Step 4: Regularly test employees to reinforce the SAT its application.

Step 5: Have employees who fail phishing tests meet privately with a supervisor or HR; reward employees with low failure rates.

Step 6: Send regular security hints and tips via email to all employees.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

7 reasons why an organization would outsource SAT

A
  1. reduce costs
  2. access to talent
  3. geographic reach and scalability
  4. compliance
  5. mitigate risk
  6. business focus
  7. leverage the cost of technology
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is defense in depth and what are its 6 layers?

A

A security discipline that refers to having layers of protection in an IT infrastructure.

  1. Policies, Procedures, and Awareness
  2. perimeter
  3. internal network
  4. host
  5. application
  6. data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

social engineering indicators (SEI)

A

A feature of KnowBe4’s simulated phishing campaigns that shows a user the red flags they missed when clicking on a link in a simulated phishing campaign.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Artificial Intelligence Driven Agent (AIDA)

A

A tool that uses artificial intelligence (AI) to automatically create integrated campaigns that send emails, text, and voicemail to an employee, simulating a multi-vector social engineering attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly