What is a cyber threat?
A person, group, event, or condition that could harm information or systems.
Study 2 Threats and Attacks with 12 free online flashcards. Review key terms, definitions, and concepts with this interactive flashcard deck.
What is a cyber threat?
A person, group, event, or condition that could harm information or systems.
What makes an event a cyber attack?
An attempt to exploit a weakness to gain access, steal or alter information, disrupt services, or cause damage.
What commonly motivates cybercriminals?
They seek financial gain, for example through fraud, stolen data, or ransomware.
Why can insiders pose a security threat?
Insiders have trusted access and may cause harm by deliberately misusing it or through error or deception.
What three factors help assess an adversarial threat?
Consider the actor’s capability, intent, and targeting rather than relying only on the actor’s label.
How does MITRE ATT&CK distinguish tactics, techniques, and procedures?
Tactics describe the goal, techniques describe the method, and procedures describe a specific implementation.
What is a supply-chain compromise?
It abuses a trusted supplier, service, or software update to reach downstream organizations.
What is the goal of a denial-of-service attack?
It overwhelms or disrupts a service so legitimate users cannot use it.
How can a worm spread differently from a virus?
A worm spreads between systems, often without requiring a user to run an infected file.
What defines a Trojan?
A Trojan appears legitimate or useful but performs hidden malicious actions.
What is double extortion in ransomware attacks?
Ransomware blocks access to data or systems, commonly by encrypting files, and demands payment. Double extortion also threatens to publish stolen data.
What does social engineering exploit?
It exploits trust, urgency, authority, curiosity, or fear to influence someone’s actions.