Classic cybersecurity flashcards covering major threats, attacks, and basic defenses.
Malware
Any malicious software designed to damage, disrupt, or steal data from a system.
Ransomware
Malware that locks or encrypts files and demands payment to restore access.
Phishing
A fake message or website that tricks users into revealing passwords, money, or other sensitive data.
Spear Phishing
A targeted phishing attack aimed at a specific person or organization.
DDoS
A flood of traffic from many sources that overwhelms a service and makes it unavailable.
Botnet
A network of infected devices controlled by an attacker, often used for spam or DDoS attacks.
Brute-Force Attack
An attack that tries many password combinations until one works.
Insider Threat
A security risk caused by someone inside an organization, such as an employee or contractor.
Zero-Day Vulnerability
A software flaw that is unknown to the vendor or has no patch yet.
Multi-Factor Authentication (MFA)
A login method that requires two or more proof factors, such as a password plus a code.
Virus
A malicious program that attaches to a file or program and spreads when it runs.
Worm
A self-replicating program that spreads across networks without user action.
Trojan
A program that looks legitimate but secretly performs harmful actions.
Spyware
Software that secretly monitors activity and steals information.
Social engineering
Tricking people into revealing information or taking unsafe actions.
Password attack
An attempt to steal or guess a password to gain access.
Antivirus software
A tool that detects, blocks, and removes known malicious software.
Backups
Copies of data kept separately so files can be restored after loss or attack.
Firewall
A security control that filters network traffic based on rules.
User awareness training
Training that teaches people to spot threats and follow safe security habits.