Cybersecurity Threats and Mitigation Flashcards
7 cards from real ICT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Threats and Mitigation flashcards as text
An attacker intercepts and alters communication between two parties without their knowledge. What type of attack is this?
Answer: Man-in-the-Middle (MitM) attack
A Man-in-the-Middle attack occurs when an attacker secretly intercepts and potentially alters communications between two parties who believe they are communicating directly.
Which of the following best describes a botnet?
Answer: A collection of compromised computers controlled remotely by an attacker
A botnet is a network of malware-infected computers (bots) that an attacker controls remotely, often used for DDoS attacks, spam campaigns, or credential stuffing.
What security technique involves sending fake credentials to attacker infrastructure to detect and slow down credential-stuffing attacks?
Answer: Credential canaries / honey credentials
Honey credentials (credential canaries) are fake login pairs seeded into data sets; when an attacker uses them, the defender receives an alert that stolen credentials are being used.
A threat actor gains physical access to an office by following an authorized employee through a secured door. This is called what?
Answer: Tailgating (piggybacking)
Tailgating (or piggybacking) is a physical security attack where an unauthorized person follows an authorized individual through a secured entry point.
Which encryption protocol replaced the vulnerable WEP standard for securing Wi-Fi networks?
Answer: WPA/WPA2 replaced WEP
WPA (Wi-Fi Protected Access) and later WPA2 replaced the easily crackable WEP (Wired Equivalent Privacy) protocol; WPA3 is the current strongest standard.
What is the main risk of using the same password across multiple websites?
Answer: A breach on one site exposes all accounts using that password (credential stuffing)
Credential stuffing attacks use credentials stolen from one breached site to automatically test access on other sites, exploiting password reuse.
Which security concept ensures that no single person has complete control over a critical system or process?
Answer: Separation of duties
Separation of duties requires that critical tasks be divided among multiple people, reducing the risk of fraud, error, or insider threats from a single individual.