The technique for discovering what's running on a system. correct answers Service Discovery
OR Fingerprinting
Method of entering secured area without authorization. correct answers Tailgating
Hidden method used to gain access to computer system. Sometimes used by software developers.
correct answers Backdoors
Security principle that states that data should be modified only by authorized individuals. correct
answers Integrity
Claiming someone has given you permission. correct answers Authority
Malware capable of stealing typed credentials. correct answers Keylogger
Malicious code that is triggered by specific event or condition. correct answers Logic Bomb
Hacktivists are known for employing this type of attack. correct answers Denial of Service (DoS)
Failure to shred documents leaves them vulnerable to this type of attack. correct answers
Dumpster Diving
Research activity that involves running specific queries. correct answers Google hacking
Implementing security controls at various levels. correct answers Defense in Depth OR Layered
Security
, Convincing Burger King employee's to break their windows is an example of. correct answers
Intimidation
Attacker's ability to obtain, modify, and diversify access. correct answers Advanced Persistent
Threat
Explain the CIA Triad, each of its properties, and how satisfying each secures information.
correct answers Confidentiality - information should only be known to certain people.
Integrity - data is stored and transferred as intended and that any modification is authorized.
Availability - information is accessible to those authorized to view or modify it.
List and describe the categories and types of security controls correct answers Technical -
controls implemented in OSes, software, and security appliances. (Firewall, Anti-virus)
Operational - controls that depend on a person for implementation.
Managerial - controls that give oversight of the system. (Risk identification)
Preventative - physically or logically restricts unauthorized access.
Detective - may not prevent or deter access, but it will identify and record any attempted or
successful intrusion. Operates during an attack.
Corrective - responds to and fixes an incident and may also prevent its reoccurrence. Operates
after an attack.