2.1.C.3In the initial-access phase of an attack, adversaries establish a foothold on the target’s computer, often through social engineering or compromised or weak credentials.Learning objective: Describe the phases of a cyberattack.
2.1.C.6In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.Learning objective: Describe the phases of a cyberattack.
5.2.A.3Organizations often categorize data according to their sensitivity and prioritize a higher degree of security for more sensitive information.Learning objective: Explain how the state or classification of data impacts the type and degree of security applied to that data.
AP Networking alignment
1.3.A.2Information gathered from compromised accounts or exposed credentials can be used to commit fraud, make purchases, or apply for loans. Victims may experience credit score damage, financial debt, or long-term identity misuse.Learning objective: Identify the impacts of digital and physical attacks on individual devices.
1.4.B.1To prevent phishing-based account compromise, users should verify message sources and use caution before interacting with emails or messages, especially those requesting sensitive information. Users should: • verify the…Learning objective: Implement device- and account-level security practices to prevent phishing, credential compromise, and data loss.
4.1.A.3When confidentiality is compromised, systems are vulnerable to having sensitive data exposed or stolen. A breach of confidentiality can be identified by: • unauthorized access • network traffic showing exfiltration of…Learning objective: Identify evidence of compromised confidentiality, integrity, or availability.