Questions with verified Answers (Latest Update 2026)
UPDATE!!
Smurf Attack
An attack that broadcasts a ping request to computers yet changes
the address so that all responses are sent to the victim.
Reflection Email Attack
- Send thousands of emails to legitimate mail server
- uses illegitimate email
-source email is victim
Botnet
◦ Master sends commands to compromised zombie
◦ Zombies attack victim
◦ Victim only sees attacks from zombie
3. Espionage
Business Intelligence (legal), open
source intelligence (osint),
industrial espionage (apple car)
state-sponsored espionage
,insider
Employee or contractor that enters a trusted relationship with an
organization.
◦ Trust means that by entering a work relationship, the insiders
agree to the rules and obligations that come with the role
◦ This relationship of trust does not, and should not, include
alleged dishonest, unethical or illegal activity.
◦ The insider must obey laws and hold to ethical practices,
despite the trusted relationship.
Whistleblower
An insider that reports wrongdoing (generally not for personal
gain).
◦ It is unlawful for an employer to retaliate against you for
making a "protected disclosure." A disclosure is protected
only if it meets two criteria:
1 The disclosure based on a reasonable belief that
wrongdoing has occurred.
2 The disclosure must also be made to a person or entity
that is authorized to receive it
(news media and sensitive data not included)
,Open Source Intelligence
Property / tax record (name, city, home
address) Voting Registration (name, city,
political party)
Genealogy Records (mother's maiden
name) Obituaries (siblings and children,
time of funerals) Criminal Records
Traffic Camera Information
Open source intelligence commercial info
Surfing habits
Purchases
Interests and relationships
Internet of Things (IoT)
Forces of Nature
Quality information systems organizations create disaster recovery
and business continuity plans in advance of disruptive events.
Employees
____ simultaneously represent an organization's most valuable
resource...and its greatest risk.
, 5: Human Error or Failure
System misconfiguration;
Poor patch management;
Connecting personally owned or unknown devices to the
organization's network
Oversharing - ex: sysadmin discussing problems
online Sharing passwords
Poor password selection
Leaving computers unattended and
unlocked Lost devices;
Opening an unsafe URL or attachment
Accidental deletion
Sending secure information to an incorrect email address
Business Email Compromise (BEC)
6: Information Extortion
Steals/encrypts information and demands compensation for its
return or to not disclose it