4.2.A.5Password-based authentication services shouldn’t store passwords in plaintext, so that if an adversary gains access to the user:password directory they won’t immediately know the passwords for all users. Instead, user…Learning objective: Explain why hashes (also called hash outputs, checksums, message digests, or digests) are used to store passwords.
5.1.C.2High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.Learning objective: Assess and document risks from application and data vulnerabilities.
5.2.A.3Organizations often categorize data according to their sensitivity and prioritize a higher degree of security for more sensitive information.Learning objective: Explain how the state or classification of data impacts the type and degree of security applied to that data.
AP Networking alignment
1.3.A.2Information gathered from compromised accounts or exposed credentials can be used to commit fraud, make purchases, or apply for loans. Victims may experience credit score damage, financial debt, or long-term identity misuse.Learning objective: Identify the impacts of digital and physical attacks on individual devices.
1.4.B.4To prevent unauthorized account access through credential reuse or guessing, users should use strong, unique passwords for each account to prevent access if any single set of credentials is compromised.Learning objective: Implement device- and account-level security practices to prevent phishing, credential compromise, and data loss.
4.1.A.3When confidentiality is compromised, systems are vulnerable to having sensitive data exposed or stolen. A breach of confidentiality can be identified by: • unauthorized access • network traffic showing exfiltration of…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.