topic 6 cyber security Flashcards

1
Q

define cyber security

A

the process and practice and technology designed to protect networks, computers, programs, and data from attack, damage or unauthorized access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

define social engineering

A

The art of manipulating people to give up confidential information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

define malicious code

A

the term used to refer to a variety of forms of hostile or intrusive software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what are methods of social engineering?

A
  • blagging
  • phishing
  • shouldering
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what is blagging?

A

Targets an individual to persuade them to give up sensitive information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what is phishing?

A

Can be done by email/ text, disguised to look like it’s from a reputable source, targets a large group of people hoping some would respond, , often contains a link directing u to a fake website

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what is shouldering?

A

looking over someone else’s shoulder seeing their usernames, passwords, PIN etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

how can you prevent methods of social engineering?

A

Education – spreading knowledge and awareness of security risks etc.

Verify the caller identity

Do not use email links, properly find main web address and login securely to c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is the biggest risk of a computer virus?

A

One the biggest risks of viruses is a day 0 attack. A day 0 is when it is on release and this is when nobody really knows what it is, so nobody has a fix for it right away. You have to try and prevent the virus from coming in AND you have to fix it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what are examples of malicious code?

A
  • computer virus
  • trojan
  • spyware
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what is a computer virus?

A

Can spread when executed, attached to another program or file,executed by clicking onto the host/ infected program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is a trojan?

A

Poses as having a useful purpose/ a legitimate program. User id tricked into executing the Trojan, when the program is executed the Trojan activates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is spyware?

A

Gathers information about person/ organisation activity without their knowledge. Send information back to originator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

how can you prevent malicious code?

A

-education on how you can stop getting spyware

-when installing new programs download the correct versions

-don’t use copied code

-use an antivirus software

-cover up your camera

-password managers, this is an antispyware tool as key loggers cant detect your password as you aren’t typing it in it saves it for you

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

how can you reduce the risk of getting a virus?

A

-download files from correct places, not those that are sent to you

-education, tell people not to click on links

-get files from reputable sources

-get antivirus software to detect viruses on your computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

how can you prevent a trojan?

A

-education, do not open suspicious file endings those especially that are code files

-use antivirus software, really it is antimalware software

-don’t open emails from people you don’t trust

17
Q

what are the methods to detect and prevent cyber security threats?

A
  • biometric measures
  • password systems
  • CAPTCHA systems
  • email confirmation
  • automatic software updates
18
Q

what is penetration testing?

A

When you hire someone to test your cyber security measures.

19
Q

what are the 2 types of penetration testing?

A
  • internal penetration testing
  • external penetration testing
20
Q

what is internal penetration testing?

A

when the tester has knowledge of the security and structure of a network. E.g. if an employee decides to test the security of the network. This simulates someone trying to hack the network.

21
Q

what is external penetration testing?

A

when somebody doesn’t know the structure so they look for vulnerabilities in the network. Companies pay for this to be done to give them the ability to see where they might be vulnerable.