/
Tekrar 1-1
Save to my account
Sign up
Tekrar 1-1
View
Tekrar00.pdf Flashcards
Study
1
Question
What does the CIA triangle stand for in cybersecurity?
Answer
Confidentiality, Integrity, Availability
2
Question
What does confidentiality mean in cybersecurity?
Answer
Ensuring sensitive data is accessed only by authorized users, using encryption methods for privacy protection and to prevent sniffing attacks
3
Question
What does integrity mean in cybersecurity?
Answer
Ensuring data has not been changed, modified, or corrupted while in transit, using hashing techniques to prevent man-in-the-middle attacks
4
Question
What does availability mean in cybersecurity?
Answer
Ensuring data is available when needed, utilizing backups to maintain availability against DDoS attacks, for example
5
Question
What is a sniffing attack in cybersecurity?
Answer
Attackers capture data using tools like Wireshark to read it in clear text
6
Question
What is a man-in-the-middle attack in cybersecurity?
Answer
An attacker sits between devices to intercept and manipulate data
7
Question
What is the difference between DoS and DDoS attacks?
Answer
DoS disrupts services from a single attacker, while DDoS uses multiple computers to attack a single target, specifically targeting availability of services
8
Question
What is a DoS attack compared to in real-world terms?
Answer
It is like one person blocking the entrance to a store so others can't get in, disrupting the normal operations
9
Question
What is a DDoS attack compared to in real-world terms?
Answer
It is like a large group of people blocking the entrance to a store from different sides, making it impossible for anyone to enter, disrupting the normal operations
10
Question
What is encoding, encryption, and hashing in cybersecurity?
Answer
Encryption is a two-way function used to maintain confidentiality, with algorithms like RSA, AES, and 3DES. Common types of encryption are asymmetric, symmetric, and hybrid; asymmetric uses pair keys, symmetric uses a single key, and authorized users can decrypt data using public or private keys
11
Question
What is DDoS?
Answer
Distributed Denial of Service - like a large group of people blocking the entrance to a store from different sides making it impossible for anyone to enter.
12
Question
What is encryption?
Answer
Encryption is a two-way function used to maintain confidentiality. Some common encryption algorithms are RSA, AES, and 3DES. Common types of encryptions are Asymmetric, Symmetric, and Hybrid.
13
Question
What is encoding?
Answer
Encoding is a simple algorithm that transforms data into another format that can easily be reversed. It can be done by open-source intelligence tools like link sanitizer and cyberchef. Operations include Base64 and hex.
14
Question
What is hashing used for?
Answer
Hashing is a one-way algorithm used to validate the integrity of data. If the data has been compromised, the hashes are different, indicating a change in the data. Common hashing algorithms include MD5, SHA-1, and SHA-2. SHA-2 is preferred for its stronger security and longer hash values compared to MD5 and SHA-1.
15
Question
What is a digital signature?
Answer
A digital signature is a cryptographic technique used to verify the authenticity and integrity of digital documents or messages. It involves using a private key to create a unique digital signature that can be verified using a public key.
16
Question
What are some common Hashing algorithms mentioned in the text?
Answer
MD5, SHA-1, and SHA-2
17
Question
Why is SHA-2 considered the best choice among hashing algorithms mentioned?
Answer
SHA-2 offers stronger security and longer hash values compared to MD5 and SHA-1
18
Question
What is a hash collision and why is it a concern with MD5 and SHA-1?
Answer
A hash collision occurs when two different inputs produce the same output hash value. MD5 and SHA-1 have known vulnerabilities to hash collisions.
19
Question
What is a digital signature used for in cryptography?
Answer
A digital signature is used to verify the authenticity and integrity of digital documents or messages.
20
Question
Explain the process of a three-way handshake.
Answer
A three-way handshake is a process used to create a connection between a client and a server. It involves three steps: 1. The client sends a SYN packet to the server. 2. The server responds with a SYNACK packet. 3. The client sends an ACK packet to the server. Once these steps are completed, the connection is established.
21
Question
How are Encryption and Hashing different?
Answer
Encryption hides data in a non-humanly readable form and provides confidentiality, while hashing verifies data integrity. Encryption is a two-way function, and hashing is a one-way function.
22
Question
What are the differences between TCP and UDP protocols?
Answer
TCP is a connection-oriented protocol that ensures reliable and ordered delivery of data, while UDP is a connectionless protocol that offers faster transmission but does not guarantee delivery.
23
Question
What is a three-way handshake?
Answer
24
Question
Answer
A process used to establish a connection between a client and a server in three steps: SYN, SYNACK, and ACK.
25
Question
What is the main difference between TCP and UDP protocols?
Answer
26
Question
Answer
TCP is a connection-based protocol while UDP is connectionless.
27
Question
Why is UDP preferred for video conferences and live streams?
Answer
28
Question
Answer
Sometimes connection speed is more important than reliability, making UDP ideal for real-time communication.
29
Question
Name some examples of TCP flags.
Answer
30
Question
Answer
SYN, ACK, FIN, RST, PSH, URG.