Security+ SYO-601 Chapter 1

  1. process by which an attacker seeks to extract useful information from users by tricking them into helping the attacker.
    Social engineering
  2. assumes the character or appearance of someone else.
    Impersonation
  3. scavenge for useful information in the trash.
    Dumpster diving
  4. looking over someone’s shoulder to obtain information.
    Shoulder surfing
  5. digital junk mail.
    Spam
  6. SPAM over instant message.(IM)
    Spam over internet messaging (SPIM)
  7. acquire sensitive information by masquerading as a trustworthy entry via electronic communication (email).
    Phishing
  8. phishing email towards a specific individual.
    Spear phish
  9. phishing after high profile targets such as an executive within a company.
    Whaling
  10. voice phishing - use of fake caller ID to enter account details via the phone.
    Vishing
  11. SMS phishing via text message.
    Smishing
  12. redirects victims from a legitimate site to a bogus website using DNS cache poisoning.
    Pharming
  13. piggybacking or following closely behind someone who has authorized physical access in an environment.
    Tailgating
  14. prepend the subject line in email some sort of notification if the email is external.
    Prepending
  15. a person’s personal information is used without authorization to deceive or commit a crime.
    Identify fraud
  16. fake crafted invoices emailed for payment.
    Invoice scam
  17. common goal of phishing campaigns that involves capturing usernames and passwords.
    Credential harvesting -
  18. gather information about the personnel’s roles and responsibilities.
    Reconnaissance
  19. Presents a threat but the threat does not actually exists at face value.
    Hoax
  20. attacking a site that the a target frequently visits.
    Watering hole attack
  21. an attack against a vulnerability that is unknown to software and security vendors.
    Zero-day exploit
  22. AKA URL hijacking, is a simple method used frequently for benign purposes websites for misspelled URLs.
    Typo squatting
  23. to spread FUD on social media outlets
    Influence campaign
Author
buckyhead2000
ID
355858
Card Set
Security+ SYO-601 Chapter 1
Description
Updated