AP® Cybersecurity Unit 4 flashcardsSecuring Devices
40 cards · about 10 minutes for the whole deck
Flashcard drill
Space flips the card, arrow keys move, and keys 1 to 4 rate how well you knew it.
- Position
- 1 / 40
- Due
- 40
- Mastered
- 0 / 40
This card: New
Flip the card before you rate it.
Server computer
A computer that provides services, like DNS or file sharing, to other computers. Enterprise servers usually have more power and storage than a PC.
Topic 4.1: Device Vulnerabilities and Attacks
Handheld computer
A battery-powered device smaller than a PC, like a tablet, smartphone or smart watch. Also called a mobile computer.
Topic 4.1: Device Vulnerabilities and Attacks
Embedded computer
A computer built into a machine, like a car, insulin pump or water pump. Usually slow, cheap and low on storage.
Topic 4.1: Device Vulnerabilities and Attacks
Internet of Things (IoT)
Everyday devices with embedded computers that connect to networks, like thermostats, coffee makers and washing machines.
Topic 4.1: Device Vulnerabilities and Attacks
Virus
Malware that runs only when a user opens or runs an infected file.
Topic 4.1: Device Vulnerabilities and Attacks
Worm
Malware that spreads from one computer to another on its own, with no human action needed.
Topic 4.1: Device Vulnerabilities and Attacks
Trojan
Malware hidden inside software that seems harmless. A remote access trojan (RAT) also gives the attacker remote control of the system.
Topic 4.1: Device Vulnerabilities and Attacks
Ransomware
Malware that encrypts a device's files and demands payment, usually by a deadline, for the key to unlock them.
Topic 4.1: Device Vulnerabilities and Attacks
Spyware
Malware that tracks what a user does on a computer and sends that information back to the attacker.
Topic 4.1: Device Vulnerabilities and Attacks
Logic bomb
Malware that waits until certain conditions are met, like a date or a specific operating system version, before it acts.
Topic 4.1: Device Vulnerabilities and Attacks
Rootkit
Sophisticated malware that gets into the operating system, can control almost everything, and hides itself from detection.
Topic 4.1: Device Vulnerabilities and Attacks
Fileless malware
Malicious code that lives in memory (RAM) and uses legitimate programs already on the device, instead of being stored as files.
Topic 4.1: Device Vulnerabilities and Attacks
BIOS or UEFI password
A password on a computer's startup firmware. Without one, an attacker can boot their own system from a drive and change user accounts.
Topic 4.1: Device Vulnerabilities and Attacks
Autorun
A setting that runs a program automatically when a drive is plugged in. If it's on, a malware-loaded drive can infect the device.
Topic 4.1: Device Vulnerabilities and Attacks
Cryptographic hash function
An algorithm that turns data of any length into a fixed-length output called a hash or digest. The same input always gives the same hash.
Topic 4.2: Authentication
Collision
When two different inputs give the same hash. With infinite inputs and a fixed number of outputs, collisions must exist.
Topic 4.2: Authentication
Pre-image resistance
A hash property: given a hash, it's infeasible to figure out the input that made it.
Topic 4.2: Authentication
Deprecated hash function
A hash function no longer used in secure settings because collisions can be forced efficiently. MD5 and SHA-1 are examples.
Topic 4.2: Authentication
Salt
A few random bits, unique to each user, hashed together with a password. Two users with the same password then get different hashes.
Topic 4.2: Authentication
Offline password attack
Guessing passwords against a stolen password database on the attacker's own computer. It skips lockouts and can't be detected.
Topic 4.2: Authentication
Password spraying
Trying one common password against many different user accounts.
Topic 4.2: Authentication
Credential stuffing
Trying default logins (like a router's factory admin password) or stolen username-password pairs to get into devices and services.
Topic 4.2: Authentication
Brute force attack
An offline attack that tests every possible password until one's hash matches the stolen hash.
Topic 4.2: Authentication
Dictionary attack
An offline attack that hashes each password in a list of common passwords and compares it to the stolen hash.
Topic 4.2: Authentication
Rainbow table
A precomputed table of possible passwords and their hashes, sorted by hash so a stolen hash can be looked up fast. Salting defeats it.
Topic 4.2: Authentication
Authentication factors
Something you know (password, PIN), have (card, phone, token), are (fingerprint, retina) or somewhere you are (location).
Topic 4.2: Authentication
Account lockout
A login setting that locks an account after a set number of wrong passwords, often 3–5, to stop online guessing.
Topic 4.2: Authentication
Password history
A login setting that stores a user's previous password hashes, often the last 5–10, so old passwords can't be reused.
Topic 4.2: Authentication
Maximum password age
A login setting that makes users change passwords after a set time, often 90 or 120 days. Some national standards advise against forced changes.
Topic 4.2: Authentication
Password complexity
A login setting that makes a new password include uppercase letters, lowercase letters, digits and special characters.
Topic 4.2: Authentication
Acceptable use policy
Rules for what users may, may not or must do on company devices, such as banning gaming sites or requiring software updates.
Topic 4.3: Protecting Devices
Software installation policy
Rules about which software users may install, including a list of approved programs and a way to request new ones.
Topic 4.3: Protecting Devices
Anti-malware software
Software that scans files against a database of malware signatures and quarantines and removes matches.
Topic 4.3: Protecting Devices
Patch
A small update from a vendor that fixes a vulnerability. Staying updated stops attackers from using known flaws.
Topic 4.3: Protecting Devices
Host-based firewall
Firewall software on a single device that allows or denies traffic in and out of it, using ordered rules where the first match wins.
Topic 4.3: Protecting Devices
Authentication (auth) log
A log that records every attempted login on a system. It reveals password attacks.
Topic 4.4: Detecting Attacks on Devices
Host-based IoC
Evidence found in logs and settings: unusual new or changed files, unexpected processes, unauthorized setting changes or software installs.
Topic 4.4: Detecting Attacks on Devices
File-based IoC
Evidence found in files, usually executables: a hash that matches known malware, or file names and paths linked to malware.
Topic 4.4: Detecting Attacks on Devices
Behavior-based IoC
Evidence of suspicious actions in logs: many failed logins, odd login times or places, and attempts to reach sensitive data or raise privileges.
Topic 4.4: Detecting Attacks on Devices
Endpoint detection and response (EDR)
A third-party service that watches all of an organization's devices with one central alert platform. Thorough but expensive.
Topic 4.4: Detecting Attacks on Devices