2.1.C.5In the lateral-movement phase of an attack, adversaries try to escalate their privileges by accessing computers and user accounts with elevated permissions to services and data.Learning objective: Describe the phases of a cyberattack.
2.1.C.6In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.Learning objective: Describe the phases of a cyberattack.
4.3.C.2Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.Learning objective: Explain why keeping a device’s operating system and software updated makes it more secure.
AP Networking alignment
3.4.B.5Security controls to limit lateral movement or unintended communication between segments can include: • allowing only essential services, such as printing, to communicate across segments • deny-by-default firewall or access…Learning objective: Determine appropriate security controls to limit the impacts of common threats and vulnerabilities in a segmented LAN.
4.5.A.3Widespread data compromise, service outages, or loss of administrative control can occur when an adversary or malicious software moves laterally across a network. These impacts are more likely in segmented or large networks…Learning objective: Identify the impacts of common threats and vulnerabilities in a managed network.
4.6.B.4Applying and documenting software updates and patches reduces the risk of failure and reduces recovery time if an outage occurs.Learning objective: Identify ways to improve the reliability and availability of networked systems.