Cybersecurity Threats and Mitigation Flashcards
7 cards from real ICT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Threats and Mitigation flashcards as text
Which type of malware encrypts a victim's files and demands payment for the decryption key?
Answer: Ransomware
Ransomware encrypts the victim's data and extorts payment, typically in cryptocurrency, in exchange for the decryption key.
What is a zero-day vulnerability?
Answer: A vulnerability unknown to the software vendor with no patch available
A zero-day vulnerability is a security flaw that is unknown to the vendor, meaning there are zero days of protection since no patch exists yet.
A company receives an email appearing to be from their CEO requesting an urgent wire transfer. This is an example of what attack?
Answer: Business Email Compromise (BEC)
Business Email Compromise (BEC) involves impersonating executives or trusted parties via email to trick employees into transferring funds or sensitive data.
Which network security tool monitors traffic and generates alerts when suspicious activity is detected but does NOT block it?
Answer: Intrusion Detection System (IDS)
An IDS passively monitors network traffic and alerts administrators to suspicious activity, while an IPS actively blocks detected threats.
What is the primary purpose of network segmentation as a security control?
Answer: To limit lateral movement of attackers within a network
Network segmentation divides a network into zones so that if an attacker breaches one segment, they cannot freely move to other sensitive areas.
Which attack exploits trust relationships between websites to make authenticated users unknowingly submit malicious requests?
Answer: Cross-Site Request Forgery (CSRF)
CSRF tricks an authenticated user's browser into sending unauthorized requests to a site where they are already logged in, exploiting the site's trust in the user.
What does the principle of 'defense in depth' mean in cybersecurity?
Answer: Layering multiple security controls so that if one fails, others remain
Defense in depth employs multiple overlapping security layers so that a failure or bypass of one control does not result in a complete compromise.