AP® Cybersecurity Unit 1 flashcardsIntroduction to Security
35 cards · about 9 minutes for the whole deck
Flashcard drill
Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.
- Position
- 1 / 35
- Due
- 35
- Mastered
- 0 / 35
This card: New
Flip the card before you rate it.
Social engineering
Using psychological tricks to get someone to reveal information, open a harmful file or click a bad link. It often comes by email, text or social media, but it can happen in person too.
Topic 1.1: Understanding Social Engineering
Phishing
A social engineering message, usually an email, that pretends to come from someone trusted so you'll click a link, open a file or hand over information.
Topic 1.1: Understanding Social Engineering
Elicitation
Getting a target to reveal sensitive information, often through casual questions that seem harmless, like a fake survey asking for your pet's name.
Topic 1.1: Understanding Social Engineering
Intimidation
A tactic where the attacker threatens bad consequences if you don't do what they ask. It uses fear to push you into acting.
Topic 1.1: Understanding Social Engineering
Urgency
A tactic where the attacker gives you a reason to act right now, like a deadline. The rush keeps you from stopping to check whether the request is safe.
Topic 1.1: Understanding Social Engineering
One-time password (OTP)
A short code, often texted or shown in an app, that works for one login. If you give it to an attacker, they can sign in as you.
Topic 1.1: Understanding Social Engineering
Challenge question
A question a website uses to check your identity, like your first pet's name or birthdate. Details you share online can let attackers answer it.
Topic 1.1: Understanding Social Engineering
Online password attack
Trying common, patterned or stolen passwords on a real login page or device. Signs include many fast failures, odd-hour logins and unknown devices.
Topic 1.2: Suspicious Website Logins
Common password pattern
A habit attackers expect, like a word plus a two-digit year and a symbol at the end (Soccer17!), or a pet's name or birthday.
Topic 1.2: Suspicious Website Logins
Targeted password list
A custom dictionary of guesses an attacker builds from facts about you (pets, family names, birthdays) and feeds into an automated login tool.
Topic 1.2: Suspicious Website Logins
Password manager
An app that creates long, random passwords and stores them for you, so every account can have a different strong password.
Topic 1.2: Suspicious Website Logins
Passphrase
A long password made of several words. A long, unique passphrase is much harder to guess than a short password and easier to remember.
Topic 1.2: Suspicious Website Logins
Multifactor authentication (MFA)
Logging in with more than one kind of proof, such as a password plus a one-time code. A stolen password alone is no longer enough.
Topic 1.2: Suspicious Website Logins
Low-skilled adversary
An attacker who uses tools other people made, often bought online. Those tools exploit known vulnerabilities, so patching stops many of them.
Topic 1.3: Best Practices for Public Networks
High-skilled adversary
An attacker who can build or adapt their own tools and find brand-new flaws (zero-days) to get around defenses.
Topic 1.3: Best Practices for Public Networks
Zero-day
A vulnerability that hasn't been documented or patched yet. Defenders have had zero days to fix it.
Topic 1.3: Best Practices for Public Networks
Adversary motivation
Why an attacker acts: greed, recognition, a cause, revenge, politics or beliefs. Motive helps predict what they'll target.
Topic 1.3: Best Practices for Public Networks
Service set identifier (SSID)
The name of a Wi-Fi network. Always check that it matches the network you meant to join, letter for letter.
Topic 1.3: Best Practices for Public Networks
Evil twin
A fake Wi-Fi access point with the same or a similar name as a real one. People who join it send their traffic through the attacker.
Topic 1.3: Best Practices for Public Networks
Jamming attack
Flooding an area with a strong radio signal on the Wi-Fi's frequencies so no one can connect. It's a denial of service attack.
Topic 1.3: Best Practices for Public Networks
War driving
Driving or walking around a target to pick up its Wi-Fi beacons, learning the network type and where the signal leaks outside the building.
Topic 1.3: Best Practices for Public Networks
HTTPS
The encrypted version of the web's protocol. An eavesdropper on the same Wi-Fi, even on an evil twin, can't read HTTPS traffic.
Topic 1.3: Best Practices for Public Networks
Virtual private network (VPN)
A service that encrypts all your traffic to the VPN operator's system. It hides traffic from the local network, but the VPN provider can see it.
Topic 1.3: Best Practices for Public Networks
Deepfake
A fake video, image or voice of a real person made by AI from samples of them. Attackers use deepfakes to impersonate people on calls.
Topic 1.4: AI-Based Cybersecurity Attacks
Voice cloning
Using AI and recordings of someone's voice to make it say anything. It's a bigger threat as more services use voice to verify identity.
Topic 1.4: AI-Based Cybersecurity Attacks
Large language model (LLM)
An AI tool trained on huge amounts of text that writes fluent text. Attackers use LLMs to write convincing phishing in any language.
Topic 1.4: AI-Based Cybersecurity Attacks
Poisoned training data
False information an attacker plants on websites so it ends up in an AI model's training data, making the AI repeat it.
Topic 1.4: AI-Based Cybersecurity Attacks
AI-powered reconnaissance
Using AI tools to scan social media and public websites and gather facts about a target quickly.
Topic 1.4: AI-Based Cybersecurity Attacks
Shared secret
A word or phrase known only to you and a close friend or relative. Asking for it checks that a caller is really who they claim to be.
Topic 1.4: AI-Based Cybersecurity Attacks
Prompt-based data extraction
Writing prompts that trick an AI tool into revealing sensitive data from its training data or from what other users typed in.
Topic 1.4: AI-Based Cybersecurity Attacks
AI threat detection
AI trained to sort millions of logged events into likely attacks and harmless activity, much faster than people could.
Topic 1.5: Leveraging AI in Cyber Defense
Automated response
An AI tool that alerts the security team or takes a set corrective action, like isolating a device, as soon as it spots likely malicious activity.
Topic 1.5: Leveraging AI in Cyber Defense
AI configuration review
Using AI to check settings like firewall rules and access controls and suggest safer ones. A knowledgeable technician checks before anything changes.
Topic 1.5: Leveraging AI in Cyber Defense
AI code review
Using AI to scan application code for vulnerabilities and suggest fixes. A knowledgeable programmer reviews the fixes before they're used.
Topic 1.5: Leveraging AI in Cyber Defense
Human review of AI output
The rule that AI suggestions (firewall changes, code fixes, detection rules) are checked by an expert before they go live.
Topic 1.5: Leveraging AI in Cyber Defense