Skip to main content

AP® Cybersecurity Unit 2 flashcardsSecuring Spaces

40 cards · about 10 minutes for the whole deck

Flashcard drill

Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.

Position
1 / 40
Due
40
Mastered
0 / 40
Saved on this device · Sign in to sync

This card: New

Something wrong with this card?

What's wrong?

Please don't include personal details.

Flip the card before you rate it.

  • Pretexting

    Making up a believable reason to contact a target, like posing as an inspector who needs a schedule. The story makes the request seem normal.

    Topic 2.1: Cyber Foundations

  • Authority

    A social engineering tactic where the attacker poses as someone with power over you, like a boss, or claims to pass on that person's orders.

    Topic 2.1: Cyber Foundations

  • Consensus

    A tactic that creates social pressure by saying everyone else has already done what the attacker wants: "Everyone on your team already signed up."

    Topic 2.1: Cyber Foundations

  • Scarcity

    A tactic that makes something seem limited, like "only the first 20 people get a gift card," so you act before thinking.

    Topic 2.1: Cyber Foundations

  • Familiarity

    A tactic where the attacker pretends to be, or to know, someone close to you so you'll trust the request.

    Topic 2.1: Cyber Foundations

  • Script kiddie

    A low-skilled attacker who uses tools made by others without understanding how they work. Often driven by greed or wanting recognition.

    Topic 2.1: Cyber Foundations

  • Hacktivist

    An attacker driven by a social, political or personal cause who believes the goal justifies illegal hacking, like defacing a company's website.

    Topic 2.1: Cyber Foundations

  • Insider

    A threat from someone who already has legitimate credentials and access. Insiders may act out of greed or revenge or be recruited by outsiders.

    Topic 2.1: Cyber Foundations

  • Cyberterrorist

    An attacker driven by politics or beliefs who tries to disrupt whole communities or nations, such as by attacking a power grid or water plant.

    Topic 2.1: Cyber Foundations

  • Transnational criminal organization

    An organized crime group that seeks money, mainly by deploying ransomware and stealing intellectual property to sell.

    Topic 2.1: Cyber Foundations

  • Phases of a cyberattack

    Reconnaissance, initial access, persistence, lateral movement, taking action and evading detection. Not every attack uses all six.

    Topic 2.1: Cyber Foundations

  • Open source intelligence (OSINT)

    Freely available information, like websites and social media, that attackers gather during reconnaissance.

    Topic 2.1: Cyber Foundations

  • Persistence

    The attack phase where the adversary keeps access without breaking in again, often using a RAT or rootkit and a command and control (C2) channel.

    Topic 2.1: Cyber Foundations

  • Lateral movement

    The attack phase where the adversary moves to other computers and accounts with higher privileges to reach more data and services.

    Topic 2.1: Cyber Foundations

  • Risk

    What happens when a threat can exploit a vulnerability to compromise an asset. You assess it by its likelihood and its severity.

    Topic 2.1: Cyber Foundations

  • Asset

    Anything valuable to an organization: money, intellectual property, data, digital infrastructure, physical property or reputation.

    Topic 2.1: Cyber Foundations

  • Likelihood

    How probable an attack on a vulnerability is. It rises with the target's value, how easy the exploit is, and how motivated and skilled attackers are.

    Topic 2.1: Cyber Foundations

  • Quantitative vs. qualitative risk

    Quantitative risk uses numbers, like a 1–10 score or a $10,000 yearly loss. Qualitative risk uses labels, like low, medium, high and severe.

    Topic 2.1: Cyber Foundations

  • Risk avoidance

    Stopping the activity that creates the risk. It isn't possible when that activity is central to the organization's mission.

    Topic 2.1: Cyber Foundations

  • Risk transference

    Shifting the burden of a risk to someone else, such as an insurance company, a government or consumers.

    Topic 2.1: Cyber Foundations

  • Residual risk

    The risk left over after avoiding, transferring and mitigating. An organization accepts it, because perfect security is impossible.

    Topic 2.1: Cyber Foundations

  • Cost-effective control

    A control that costs less to install and maintain than the loss you'd expect from the attack it stops.

    Topic 2.1: Cyber Foundations

  • CIA triad

    Confidentiality (only authorized people see data), integrity (data stay accurate) and availability (data and services work when needed).

    Topic 2.1: Cyber Foundations

  • Control types

    Physical controls protect spaces (locks, fences). Technical controls protect digital systems (firewalls, encryption). Managerial controls are policies and procedures.

    Topic 2.1: Cyber Foundations

  • Control functions

    Preventive controls stop attacks (locks), detective controls spot them (cameras, IDS) and corrective controls fix damage (patching).

    Topic 2.1: Cyber Foundations

  • Defense in depth

    Layering several kinds of controls (human, physical, network, device, application, data) so one bypassed control isn't the end.

    Topic 2.1: Cyber Foundations

  • Piggybacking

    Using social engineering to get an authorized person to let you into a restricted area, like asking them to hold the door while you carry boxes.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Tailgating

    Slipping into a restricted area right behind an authorized person who doesn't notice you.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Shoulder surfing

    Watching someone, sometimes with a camera, as they type or view sensitive information so you can use it later.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Dumpster diving

    Searching a target's trash for useful information, like printed records, notes or account details.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Card cloning

    Copying an authorized user's access card so the attacker can get into everything that user can.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Keylogger

    Software or a small hardware device that records keystrokes and sends them to an attacker, who can pull out usernames and passwords.

    Topic 2.2: Physical Vulnerabilities and Attacks

  • Security awareness training

    Teaching employees to spot phishing, not to badge others into restricted areas and to prevent device theft.

    Topic 2.3: Protecting Physical Spaces

  • Workstation security policy

    Rules for protecting desks and devices: lock your screen, clear sensitive papers, use a privacy screen and plug into a surge protector or UPS.

    Topic 2.3: Protecting Physical Spaces

  • Uninterruptible power supply (UPS)

    A battery backup that keeps a device running during a power outage. Generators can power a whole building or critical devices.

    Topic 2.3: Protecting Physical Spaces

  • Access control vestibule

    A small entry space with two doors where only one person can pass at a time. It stops piggybacking and tailgating.

    Topic 2.3: Protecting Physical Spaces

  • Bollard

    A short, sturdy post that blocks vehicles from driving into a building or entrance. Fences, gates and bollards deter attackers.

    Topic 2.3: Protecting Physical Spaces

  • Motion sensor placement

    Put motion sensors where no one should normally be, like a server room. In busy areas they cause so many false alarms people stop trusting them.

    Topic 2.4: Detecting Physical Attacks

  • Stationary vs. patrolling guard

    Stationary guards protect one spot, best where traffic funnels in. Patrolling guards are hard to plan around and suit perimeters.

    Topic 2.4: Detecting Physical Attacks

  • Door-open time in badge logs

    Badge readers can record how long a door stays open. A door held open longer than normal can point to piggybacking or tailgating.

    Topic 2.4: Detecting Physical Attacks