Accounting - Answers The ability that provides tracking of events
Advanced Persistent Threat - Answers A class of attacks by state actors that use innovative attack
tools to silently extract data over an extended period
Asset - Answers An item that has value
Attack vector - Answers The pathway for an attack
Authentication - Answers Proof of genuineness
Authorization - Answers The act of providing permission or approval to technology resources
Availability - Answers Security actions that ensure that data is accessible to authorized users
Brokers - Answers An attacker who sells knowledge of a vulnerability to other attackers or
governments
Confidentiality - Answers Security actions that ensure that only authorized parties can view the
information
Cybercriminals - Answers An attacker whose goal is financial gain
Cybersecurity - Answers The tasks of protecting the integrity, confidentiality, and availability of
information on the devices that store, manipulate, and transmit the information through products,
people, and procedures
Cyberterrorism - Answers A politically motivated cyberattack designed to cause disruption and panic
Cyberterrorists - Answers An attacker whose motivation may be defined as ideological, or attacking
for the sake of principals and beliefs
General Data Protection Regulation - Answers A directive that requires companies that perform
business in the European Union to inform the EU's Information Commissioner's Office if they suffer a
breach involving the personal information of customers or employees
Gramm-Leach-Bliley Act - Answers A U.S. law that requires banks and financial institutions to alert
customers of their policies and practices in disclosing customer information
Hactivists - Answers An attacker who attacks for ideological reasons
Hacker - Answers An older term that referred to a person who used advanced computer skills to
attack computers
HIPAA - Answers A U.S. law designed to guard protected health information and implement policies
and procedures to safeguard it
Identity theft - Answers Stealing another person's personal information, such as Social Security
Number, and then using it to impersonate the victim, generally for financial gain
Insiders - Answers An employee, contractor, or business partner who is responsible for an attack
Integrity - Answers Security actions that ensure that the information is correct and no unauthorized
person or malicious software has altered the data
Payment Card Industry Data Security Standard - Answers A set of security standards that all U.S.
companies processing, storing, or transmitting credit card information must follow
Risk - Answers A situation that involves exposure to danger
Sarbanes-Oxley Act - Answers A U.S. law designed to fight corporate corruption
Script Kiddies - Answers Individual who lacks advanced knowledge of computers and networks and
uses downloaded automatic attack software
State Actors - Answers An attacker commissioned by the government
Threat - Answers A type of action that has the potential to cause harm
Threat Actor - Answers A term used to describe individuals or entities who are responsible for cyber
incidents against the technology equipment of enterprises and users
Threat Agent - Answers A person or element that has the power to carry out a threat
Threat Likelihood - Answers The probability that a threat will actually occur
Vulnerability - Answers A flaw or weakness that allows the threat agent to bypass security
Fair and Accurate Credit Transactions Act - Answers A law that contains rules regarding consumer
privacy
Hoax - Answers A false warning, often contained in an email claiming to come from the IT
department
Impersonation - Answers Masquerading as a real or fictitious character and then playing out the role
of that person to trick a victim in a social engineering attack
, Online Brute Force Attack - Answers An attack in which the same account is continuously attacked by
entering different passwords
Password - Answers A secret combination of letters, numbers, and/or characters known only by the
user
Password Crackers - Answers Sophisticated attacker software that is specifically designed to break
passwords
Password Spraying - Answers An attack in which one or a small number of commonly used passwords
is used to attempt to log in to several different user accounts
Phishing - Answers Sending an email claiming to be from a legitimate enterprise in an attempt to trick
the user into surrendering private information or taking action
Random Password Generator - Answers A feature in password management software to create long
and unique passwords
Social Engineering - Answers A means of using trickery to cause the victim to act in the attacker's
favor
Social Networking - Answers The use of Internet-based social media platforms that allow users to stay
connected with friends, family, and peers
Weak security update distribution - Answers Which of the following is not a reason why it is difficult
to defend against today's attackers?
a. Faster detection of vulnerabilities
b. Complexity of attack tools
c. Weak security update distribution
d. Greater sophistication of attacks
Distributed attacks - Answers Which of the following accounts for the greatest difficulty in preventing
attacks?
a. Availability and simplicity of attack tools
b. Delays in security updating
c. Distributed attacks
d. User confusion
It is the steps necessary to protect a person or property from harm - Answers In a general sense,
what is security?
a. It is only available on specialized computers
b. It is protection from only direct actions
c. It is the steps necessary to protect a person or property from harm
d. It is both an art and a science
Confidentiality - Answers Which of the following ensures that only authorized parties can view
information?
a. Confidentiality
b. Authorization
c. Integrity
d. Availability
The vulnerability they uncover was previously unknown and is unlikely to be patched quickly -
Answers Why can brokers command such a high price for what they sell?
a. Brokers are licensed professionals
b. The attack targets are always wealthy corporations
c. The vulnerability they uncover was previously unknown and is unlikely to be patched quickly
d. Brokers work in teams and all the members must be compensated
Purposes - Answers Which of the following is not a successive layer in which information security is
achieved?
a. Products
b. People
c. Policies and procedures
d. Purposes
APT - Answers What is a class of attacks by state actors that use innovative attack tools to silently
extract data over an extended period of time?
a. RPP
b. XLX
c. APT