Skip to main content

AP® Cybersecurity Unit 1 flashcardsIntroduction to Security

35 cards · about 9 minutes for the whole deck

Flashcard drill

Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.

Position
1 / 35
Due
35
Mastered
0 / 35
Saved on this device · Sign in to sync

This card: New

Something wrong with this card?

What's wrong?

Please don't include personal details.

Flip the card before you rate it.

  • Social engineering

    Using psychological tricks to get someone to reveal information, open a harmful file or click a bad link. It often comes by email, text or social media, but it can happen in person too.

    Topic 1.1: Understanding Social Engineering

  • Phishing

    A social engineering message, usually an email, that pretends to come from someone trusted so you'll click a link, open a file or hand over information.

    Topic 1.1: Understanding Social Engineering

  • Elicitation

    Getting a target to reveal sensitive information, often through casual questions that seem harmless, like a fake survey asking for your pet's name.

    Topic 1.1: Understanding Social Engineering

  • Intimidation

    A tactic where the attacker threatens bad consequences if you don't do what they ask. It uses fear to push you into acting.

    Topic 1.1: Understanding Social Engineering

  • Urgency

    A tactic where the attacker gives you a reason to act right now, like a deadline. The rush keeps you from stopping to check whether the request is safe.

    Topic 1.1: Understanding Social Engineering

  • One-time password (OTP)

    A short code, often texted or shown in an app, that works for one login. If you give it to an attacker, they can sign in as you.

    Topic 1.1: Understanding Social Engineering

  • Challenge question

    A question a website uses to check your identity, like your first pet's name or birthdate. Details you share online can let attackers answer it.

    Topic 1.1: Understanding Social Engineering

  • Online password attack

    Trying common, patterned or stolen passwords on a real login page or device. Signs include many fast failures, odd-hour logins and unknown devices.

    Topic 1.2: Suspicious Website Logins

  • Common password pattern

    A habit attackers expect, like a word plus a two-digit year and a symbol at the end (Soccer17!), or a pet's name or birthday.

    Topic 1.2: Suspicious Website Logins

  • Targeted password list

    A custom dictionary of guesses an attacker builds from facts about you (pets, family names, birthdays) and feeds into an automated login tool.

    Topic 1.2: Suspicious Website Logins

  • Password manager

    An app that creates long, random passwords and stores them for you, so every account can have a different strong password.

    Topic 1.2: Suspicious Website Logins

  • Passphrase

    A long password made of several words. A long, unique passphrase is much harder to guess than a short password and easier to remember.

    Topic 1.2: Suspicious Website Logins

  • Multifactor authentication (MFA)

    Logging in with more than one kind of proof, such as a password plus a one-time code. A stolen password alone is no longer enough.

    Topic 1.2: Suspicious Website Logins

  • Low-skilled adversary

    An attacker who uses tools other people made, often bought online. Those tools exploit known vulnerabilities, so patching stops many of them.

    Topic 1.3: Best Practices for Public Networks

  • High-skilled adversary

    An attacker who can build or adapt their own tools and find brand-new flaws (zero-days) to get around defenses.

    Topic 1.3: Best Practices for Public Networks

  • Zero-day

    A vulnerability that hasn't been documented or patched yet. Defenders have had zero days to fix it.

    Topic 1.3: Best Practices for Public Networks

  • Adversary motivation

    Why an attacker acts: greed, recognition, a cause, revenge, politics or beliefs. Motive helps predict what they'll target.

    Topic 1.3: Best Practices for Public Networks

  • Service set identifier (SSID)

    The name of a Wi-Fi network. Always check that it matches the network you meant to join, letter for letter.

    Topic 1.3: Best Practices for Public Networks

  • Evil twin

    A fake Wi-Fi access point with the same or a similar name as a real one. People who join it send their traffic through the attacker.

    Topic 1.3: Best Practices for Public Networks

  • Jamming attack

    Flooding an area with a strong radio signal on the Wi-Fi's frequencies so no one can connect. It's a denial of service attack.

    Topic 1.3: Best Practices for Public Networks

  • War driving

    Driving or walking around a target to pick up its Wi-Fi beacons, learning the network type and where the signal leaks outside the building.

    Topic 1.3: Best Practices for Public Networks

  • HTTPS

    The encrypted version of the web's protocol. An eavesdropper on the same Wi-Fi, even on an evil twin, can't read HTTPS traffic.

    Topic 1.3: Best Practices for Public Networks

  • Virtual private network (VPN)

    A service that encrypts all your traffic to the VPN operator's system. It hides traffic from the local network, but the VPN provider can see it.

    Topic 1.3: Best Practices for Public Networks

  • Deepfake

    A fake video, image or voice of a real person made by AI from samples of them. Attackers use deepfakes to impersonate people on calls.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • Voice cloning

    Using AI and recordings of someone's voice to make it say anything. It's a bigger threat as more services use voice to verify identity.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • Large language model (LLM)

    An AI tool trained on huge amounts of text that writes fluent text. Attackers use LLMs to write convincing phishing in any language.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • Poisoned training data

    False information an attacker plants on websites so it ends up in an AI model's training data, making the AI repeat it.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • AI-powered reconnaissance

    Using AI tools to scan social media and public websites and gather facts about a target quickly.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • Shared secret

    A word or phrase known only to you and a close friend or relative. Asking for it checks that a caller is really who they claim to be.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • Prompt-based data extraction

    Writing prompts that trick an AI tool into revealing sensitive data from its training data or from what other users typed in.

    Topic 1.4: AI-Based Cybersecurity Attacks

  • AI threat detection

    AI trained to sort millions of logged events into likely attacks and harmless activity, much faster than people could.

    Topic 1.5: Leveraging AI in Cyber Defense

  • Automated response

    An AI tool that alerts the security team or takes a set corrective action, like isolating a device, as soon as it spots likely malicious activity.

    Topic 1.5: Leveraging AI in Cyber Defense

  • AI configuration review

    Using AI to check settings like firewall rules and access controls and suggest safer ones. A knowledgeable technician checks before anything changes.

    Topic 1.5: Leveraging AI in Cyber Defense

  • AI code review

    Using AI to scan application code for vulnerabilities and suggest fixes. A knowledgeable programmer reviews the fixes before they're used.

    Topic 1.5: Leveraging AI in Cyber Defense

  • Human review of AI output

    The rule that AI suggestions (firewall changes, code fixes, detection rules) are checked by an expert before they go live.

    Topic 1.5: Leveraging AI in Cyber Defense