Attack types, threat actors, and vulnerability concepts tested on the Security+ exam, distinct from the core terminology deck.
45 cards · basic cards · AI-written, checked twice. Edit anything.
- What is pretexting in social engineering?
- Creating a fabricated scenario to trick someone into divulging information or performing an action.
- What is baiting in social engineering?
- Offering something enticing (like a USB drive or download) to prompt a target to take an action that compromises security.
- What is quid pro quo in social engineering?
- Offering a service or benefit in exchange for information or access.
- What is tailgating (or piggybacking) in physical security?
- Following an authorized person through a secure entrance without using credentials.
- What is dumpster diving?
- Searching through trash or discarded materials to find sensitive information.
- What is phishing?
- Sending fraudulent emails, messages, or websites to trick recipients into revealing sensitive information or clicking malicious links.
- What is spear phishing?
- A targeted phishing attack directed at a specific individual or organization using personalized information.
- What is whaling?
- A targeted phishing attack against high-level executives or decision-makers.
- What is vishing?
- Voice phishing, using phone calls to socially engineer someone into divulging information.
- What is smishing?
- SMS phishing, using text messages to trick targets into clicking malicious links or providing information.
- What is a Trojan (or Trojan horse)?
- Malware disguised as legitimate software that appears harmless but contains malicious code.
- What is ransomware?
- Malware that encrypts files or locks a system, demanding payment for decryption or restoration.
- What is a worm?
- Self-replicating malware that spreads across networks without requiring user interaction or a host program.
- What is a virus?
- Malware that requires a host program to execute and spreads by infecting other files or programs.
- What is a rootkit?
- Malware that gains root or administrator-level access to a system and hides its presence.