Skip to main content

Unit 2 · Topic 2.1

2.1 Cyber Foundations

This topic is the vocabulary the whole course runs on: the tactics social engineers use, the kinds of adversaries, the phases of an attack, how to assess and manage risk, and how security controls are sorted. Almost every later question asks you to apply one of these ideas, so learn them precisely.

Key terms

  • risk assessment
  • avoid, transfer, mitigate, accept
  • CIA triad
  • physical, technical and managerial controls
  • preventive, detective and corrective controls
  • defense in depth

Seven social engineering tactics

Social engineers use psychology to get a target to act. The course names seven tactics, and one message often uses several:

TacticWhat the attacker doesSounds like
PretextingInvents a believable reason to make contactHi, I'm from the IT help desk doing a mailbox upgrade
AuthorityPoses as someone with power over you, or relays orders from themThe principal needs this done before the board meeting
IntimidationStates bad consequences if you don't complyIgnore this and your account will be closed
ConsensusClaims everyone else is already doing it90% of your team has already confirmed
ScarcitySays something is in short supplyOnly 5 free upgrades left
FamiliarityPretends to be, or to know, someone close to youYour cousin Dana gave me your number
UrgencySets a deadline to avoid a bad outcomeRespond within one hour

Adversary types and attack phases

Attacks unfold in phases, though not every attack uses all six: (1) reconnaissance, gathering information, often from open source intelligence (OSINT), meaning freely available information; (2) initial access, getting a foothold, often through social engineering or weak or stolen credentials; (3) persistence, keeping access, often with malware like a remote access trojan (RAT) or rootkit that talks to the attacker over a command and control (C2) channel; (4) lateral movement, reaching other computers and accounts to gain higher privileges; (5) taking action, collecting data, sending it out (exfiltration), disrupting services or destroying data; (6) evading detection, deleting or editing logs and erasing planted files.

  • Script kiddies: low-skilled adversaries who use tools made by others without understanding them, often for money or bragging rights.
  • Hacktivists: attack to support a social, political or personal cause, believing the cause justifies breaking the law.
  • Insiders: people with legitimate credentials and access, like employees, which makes them especially dangerous. Greed or revenge can motivate them, and outsiders may recruit them.
  • Cyberterrorists: driven by politics or beliefs, they try to disrupt whole communities or nations, for example by attacking a power grid or water plant. They may act alone or for governments or criminal groups.
  • Transnational criminal organizations: profit-driven groups that mainly deploy ransomware and steal intellectual property to sell.

Assessing risk

You have a risk whenever some threat could use a vulnerability (a weakness) to harm an asset (anything valuable: money, intellectual property, data, digital infrastructure, physical property or reputation).

A risk assessment weighs two factors. Likelihood depends on how valuable the target looks to adversaries, how much skill the exploit takes (well-documented exploits are easier, so more people can use them) and how motivated and capable the likely adversaries are. Severity is the projected damage, usually measured in money, including reputational and operational harm.

Ratings can be quantitative (a number, like 7 on a 1–10 scale or a $25,000-a-year risk) or qualitative (a label, like low, medium, high or severe, or likely-high-impact). Good documentation lists each vulnerable asset and its value, the likely threats, the specific vulnerability and how it could be exploited, the severity and likelihood, and a final rating.

Managing risk

Organizations favor controls that are cost-effective (cheaper to install and maintain than the loss they're expected to prevent) and easy to run.

  • Avoid: stop the activity that creates the risk. Impossible if the activity is central to the organization's mission.
  • Transfer: shift the burden to someone else, like an insurance company, a government or consumers.
  • Mitigate: add security controls that lower the likelihood or the impact.
  • Accept: live with the residual risk, the risk left after avoiding, transferring and mitigating. Perfect security doesn't exist, so some risk is always accepted.

Security controls and defense in depth

Every control protects at least one part of the CIA triad: confidentiality (only authorized people can access data), integrity (data stays accurate and unaltered) or availability (data and services work when authorized people need them).

By type, controls are physical (locks, fences, cameras, bollards, guards), technical (firewalls, anti-malware, encryption) or managerial (policies and procedures, like password policies, access reviews and incident response plans). By function, they are preventive (stop an attack, like locks and encryption), detective (spot an attack, like cameras, an intrusion detection system or a SIEM) or corrective (fix the problem and restore service, like patching, repairing a broken card reader or an intrusion prevention system that stops an attack in progress).

Defense in depth means layering different controls across human, physical, network, device, application and data layers. Each threat meets the control best suited to it, and if an adversary gets past one layer, the next can still stop them or limit the damage.

Worked examples

Try each one yourself first, then open the solution.

  1. Example 1

    Naming the tactics in a message

    An email says: "This is Dean Patel's office. The dean needs every club advisor to confirm their login on the new portal today. Most advisors already have. Accounts not confirmed by 5 p.m. will be deactivated." Identify four social engineering tactics and the phrase that shows each.

    Show the solution
    1. Step 1: Authority: the message claims to come from the dean, someone with power over the advisors ("Dean Patel's office").
    2. Step 2: Consensus: "Most advisors already have" creates social pressure.
    3. Step 3: Urgency: "by 5 p.m." and "today" set a deadline.
    4. Step 4: Intimidation: "will be deactivated" states a negative consequence.
    5. Step 5: Pretexting also fits: the "new portal" is an invented reason for the contact. Any four correct tactics with matching evidence would answer the question.

    Answer: Authority ("Dean Patel's office"), consensus ("Most advisors already have"), urgency ("by 5 p.m." today) and intimidation ("will be deactivated"); pretexting (the new portal story) also fits.

  2. Example 2

    Choosing a risk strategy

    Harbor Bike Rentals keeps customers' scanned driver's licenses on an old laptop. The licenses aren't needed after a bike is returned. For each option, name the risk strategy: (a) delete the scans after each return and stop scanning; (b) buy cyber insurance; (c) encrypt the laptop's drive and lock it in a cabinet; (d) after doing (c), decide the remaining risk is acceptable.

    Show the solution
    1. Step 1: (a) Stopping the activity that creates the risk is avoidance. It works here because keeping scans isn't essential to renting bikes.
    2. Step 2: (b) Insurance shifts the financial burden to another company, which is transference.
    3. Step 3: (c) Adding controls (encryption and a lock) lowers the likelihood and impact, which is mitigation.
    4. Step 4: (d) Living with what's left after mitigation is acceptance of the residual risk.

    Answer: (a) avoid, (b) transfer, (c) mitigate, (d) accept the residual risk.

  3. Example 3

    Classifying controls

    Classify each control by type (physical, technical or managerial) and by function (preventive, detective or corrective): a door lock on the server room; a password policy requiring 15-character passwords; an intrusion detection system; installing a security patch.

    Show the solution
    1. Step 1: Door lock: it exists in physical space, so physical. It stops entry, so preventive.
    2. Step 2: Password policy: a written rule people follow, so managerial. Long passwords make guessing fail before anyone gets in, so preventive.
    3. Step 3: Intrusion detection system: software in the digital space, so technical. It spots attacks and alerts, so detective.
    4. Step 4: Security patch: applied to software, so technical. It fixes a known flaw, which the course classifies as corrective.

    Answer: Lock: physical, preventive. Password policy: managerial, preventive. IDS: technical, detective. Patch: technical, corrective.

Common mistakes

  • Mixing up consensus and scarcity. Consensus is "everyone else is doing it"; scarcity is "there isn't much left."
  • Calling buying insurance mitigation. Insurance doesn't make an attack less likely or less damaging; it transfers who pays, so it's transference.
  • Confusing a control's type with its function. "Physical, technical, managerial" is what it is; "preventive, detective, corrective" is what it does. A camera is physical and detective.
  • Treating risk as just likelihood. Risk combines likelihood and severity, so an unlikely attack on a very valuable asset can still be a high risk.

On the exam

  • Many questions give a short scenario and ask you to name a tactic, adversary type, attack phase, risk strategy or control category. Quote or point to the exact detail that proves your answer.
  • When asked why defense in depth is needed, say both parts: different threats need different controls, and if one control is bypassed, another can still stop or limit the attack.

Connected topics

Videos

  • AP Cybersecurity Topic 2.1.a - Cyber Foundations (Social Engineering) . Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Security Controls - CompTIA Security+ SY0-701 - 1.1

    Professor MesserWatch on YouTube (opens in a new tab)

  • What is the CIA Triad

    IBM TechnologyWatch on YouTube (opens in a new tab)

  • AP Cybersecurity Topic 2.1.g - Defense in Depth Explanations and MCQs!

    Dr_WuWatch on YouTube (opens in a new tab)

  • Risk Management Strategies - CompTIA Security+ SY0-701 - 5.2

    Professor MesserWatch on YouTube (opens in a new tab)

  • Threat Actors - CompTIA Security+ SY0-701 - 2.1

    Professor MesserWatch on YouTube (opens in a new tab)

Check yourself: 2.1 Cyber Foundations

4 questions on 2.1 Cyber Foundations. Pick an answer to see if you got it, and why.

From: Marcus Webb, Office of the CEO <m.webb@pinecrest-benefits.example.net>

To: All Pinecrest Credit Union Staff

Subject: Quick benefits survey

Hi team, the CEO asked me to make sure everyone fills out this year's benefits survey.

Only the first 20 employees to finish will receive a $50 gift card, and most of the people in your branch have already completed it.

Just sign in at the link below with your work email and password. Thanks!

A message reported to the security team at Pinecrest Credit Union, an invented organization

Question 1 of 4

Which sentence uses the tactic of scarcity?

Question 2 of 4

A coworker reads the message and says, "If most of our branch already did it, it must be legit." Which tactic in the message worked on this coworker?

Question 3 of 4

The message says the CEO asked Marcus to collect the surveys. Which tactic is this?

Question 4 of 4

A caller says he works for the company that inspects the office building's elevators and needs to confirm which days the security desk is unstaffed so he can schedule a visit. Which social engineering tactic is he mainly using?

0 of 4 answered