Please enable JavaScript to use CodeHS

Cyber Glossary

Flashcards

Course:

Module:

Lesson:

Search:

risk assessment General

The process of identifying, assessing and prioritizing potential risks for an organization or company.

vulnerability scan General

Designed and used to assess computers, networks or applications for known weaknesses.

packet sniffing General

The practice of gathering, collecting, and logging some or all packets that pass through a computer network.

race condition General

A situation when a device or system has two or more operations running at the same time that must be completed in proper sequence.

buffer overflow General

A situation when too much data is placed into a fixed-sized buffer that can cause data corruption.

integer overflow General

When a value higher than the maximum or lower than the minimum is used which can result in logic errors.

penetration test General

When a company hires a white hat hacker to assess the security of a system by finding and exploiting vulnerabilities.

passive reconnaissance General

Collecting information about a target without directly accessing the system (social media, news, website, etc).

active reconnaissance General

Collecting information about a target by actively engaging a system and analyzing responses (network and port scans).

initial exploitation General

When the tester is first able to gain access into the target system.

pivot General

Using a compromised trusted system to gain access to a target system within the same network.

escalation of privilege General

Using tools to gain higher levels of privilege.

black box pen test General

When the tester has no knowledge of the target system (simulates an external attack).

white box pen test General

When the tester has intimate knowledge of the target system (simulates an internal attack).

gray box pen test General

When the tester is limited knowledge of the target system.

qualitative risk assessment General

Risk assessment that gives a numerical (typically monetary) value to the impact of a threat occuring.

single loss expectancy (SLE) General

How much money could be lost at any one time which is determined by the formula: AV * EF + SLE

asset value (AV) General

How much an asset is worth.

exposure factor (EF) General

The amount of the asset that would be impacted (amount of time, % of data, etc) by a threat event.

annual loss expectancy General

How much can be expected to be lost in a year due to a single threat event which is determined by the formula: SLE * ARO = ALE

annual rate of occurrence (ARO) General

How often a threat event per year (typically determined by historical data).

qualitative risk assessment General

Risk assessment that defines an event’s level of risk in words rather than numbers which is determined by the potential level of impact and the likelihood of occurrence.

risk avoidance General

Risk response that removes the risk by avoiding the behavior completely.

risk transfer General

Risk response that shares the responsibility of the risk with someone else.

risk acceptance General

Risk response that accepts the risk as is.

risk mitigation General

Risk response that takes steps to avoid the risk or minimize the impact or likelihood.