Font size
WorksheetsSAQ practice
Total questions: 150
Worksheet time: 1hrs 18mins
Introduction & Hacker Culture: What was the original meaning of the term “hacker”?
(a)
Introduction & Hacker Culture: Why is early hacker culture associated with fantasy imagery?
(a)
Introduction & Hacker Culture: How does Sun Tzu’s philosophy apply to cybersecurity?
(a)
Cybersecurity Domains: What is a cybersecurity “domain”?
(a)
Cybersecurity Domains: Which of the following are data‑rich cyber domains?
(a)
Growth of the Cyber World: What is the main cybersecurity challenge created by IoT devices?
(a)
Growth of the Cyber World: What does GIS technology allow organizations to do?
Encrypt all emails by default
Map and track environmental and geographical data in real time
Block unauthorized access to mobile apps
Simulate malware outbreaks
Types of Cyber Criminals: Who are “script kiddies”?
Highly trained penetration testers
Low‑skilled attackers who use pre‑made tools or scripts
Senior system administrators
Ethical hackers with certifications
Types of Cyber Criminals: What is the key difference between white‑hat and black‑hat hackers?
White‑hat hackers only use open‑source tools
White‑hat hackers have authorization; black‑hat hackers do not and act illegally
Black‑hat hackers never target networks
White‑hat hackers work remotely while black‑hat hackers work on‑site
Types of Cyber Criminals: What motivates hacktivists?
Quarterly sales goals
Political or social causes
Personal curiosity only
Compliance audits
Cyber Criminal Motivations: Today, what is the primary motivator for most cybercrimes?
Entertainment
Financial gain
Academic research
Reputation among peers only
Cyber Criminal Motivations: Why is stolen medical data valuable to attackers?
It is easy to delete without detection
It contains long‑lasting, sensitive information that can be used for fraud or blackmail
It is always encrypted and useless
Hospitals pay attackers to store records
Becoming a Cybersecurity Specialist: Why is cybersecurity considered a high‑demand field?
There is a global shortage of skilled professionals and increasing digital threats
Most jobs require only entry‑level skills
Cybersecurity work is seasonal
Digital threats are declining
Defense Strategies: What is the purpose of a honeypot?
To store backups securely
To attract attackers and gather intelligence on attack methods
To block all external traffic
To accelerate software development
Defense Strategies: What international standard helps organizations manage cybersecurity?
PCI DSS
ISO 27000 series
IEEE 802.11
HTML5
Threats & Vulnerabilities: Define “threat” in cybersecurity.
A patch that fixes a bug
A potential cause of an unwanted incident, such as an attack
A scheduled maintenance window
A secure communication channel
Threats & Vulnerabilities: Define “vulnerability”.
A security training program
A weakness that can be exploited by a threat actor
A type of antivirus software
A legislative requirement
Personal Data Risks: Give one example each of sensitive data from education, employment, and finance.
Education: grades; Employment: performance evaluations; Finance: bank statements
Education: class schedules; Employment: office layout; Finance: cafeteria menu
Education: campus map; Employment: parking passes; Finance: ATM locations
Education: event flyers; Employment: holiday calendar; Finance: billboard ads
Internet Service Threats: What is DNS spoofing?
Blocking domain names to reduce traffic
Manipulating DNS data to redirect users to malicious sites
Encrypting DNS queries to improve privacy
Creating new top‑level domains
Internet Service Threats: What is packet sniffing used for?
Capturing data packets to steal information such as passwords
Repairing damaged network cables
Generating encryption keys
Allocating IP addresses automatically
Industrial & SCADA Threats: Why are SCADA systems vulnerable to cyberattacks?
They run only on battery power
They were originally designed without cybersecurity in mind and are now connected to IT networks
They use overly complex passwords
They do not control physical processes
Industrial & SCADA Threats: Name a famous cyberattack involving SCADA systems.
WannaCry
Stuxnet
Heartbleed
Conficker
Cybersecurity & Society: What is one challenge governments face in cybersecurity?
Balancing national security needs with citizen privacy rights
Eliminating all malware worldwide
Funding only private companies
Restricting internet access to universities
Internal vs External Threats: Why are internal threats often more dangerous than external threats?
Insiders already have legitimate access to systems and data
External attackers have more resources
Insiders cannot be monitored
External threats never use social engineering
Internal vs External Threats: Give one example of how an internal user can unintentionally cause a breach.
Plugging in an infected USB device
Using a company‑approved password manager
Reading the employee handbook
Attending security awareness training
Mobile & BYOD Risks: Why does BYOD increase security risk?
Organizations have less control over security updates and configurations on personal devices
BYOD guarantees devices are more secure
It limits network connectivity
It eliminates the need for authentication
IoT & Big Data Challenges: What are the “3Vs” of Big Data?
Volume, Velocity, Variety
Vision, Value, Validity
Virtualization, Versioning, Verification
Vulnerability, Visibility, Variance
IoT & Big Data Challenges: Why is Big Data attractive to cybercriminals?
It contains massive amounts of valuable and sensitive information
It is too small to analyze
It is stored only on paper
It never includes personal records
Advanced Cyber Weapons: What is an Advanced Persistent Threat (APT)?
A single short‑term malware infection
A long‑term, stealthy attack where intruders gain continuous access
A hardware malfunction
A network backup process
Advanced Cyber Weapons: What is a selective attack?
An attack that activates only when specific target criteria are met
An attack that randomly targets any device
An attack limited to wireless networks
An attack that only uses phishing emails
Identity & Access: What is a major risk of federated identity systems?
Users must remember more passwords
A compromise of the identity provider can grant widespread access across multiple services
It prevents single sign‑on
It makes auditing impossible
What is the main purpose of the Cybersecurity Cube?
To provide a framework for applying cybersecurity principles across systems and networks
To replace all existing cybersecurity tools with a single platform
To measure network speed and latency
To create backup copies of organizational data
Who developed the Cybersecurity Cube?
John McCumber
Bruce Schneier
Whitfield Diffie
Ron Rivest
Which set lists the three dimensions of the Cybersecurity Cube?
CIA Triad; States of Data; Security Safeguards
Confidentiality; Privacy; Availability
Hardware; Software; People
Threats; Vulnerabilities; Risks
What is confidentiality?
Protection of data from unauthorized access
Ability of a system to remain accessible during failures
Verification that data has not been altered
Tracking and recording user actions
Which method is commonly used to ensure confidentiality?
Encryption
Packet sniffing
Load balancing
Data deduplication
Which are the three types of sensitive information?
Personal, business, classified
Public, archived, compressed
Static, dynamic, streaming
Numeric, textual, graphical
What does authentication verify?
A user's identity
Network uptime
File ownership rights
Data compression ratio
Which is an example of authentication evidence?
Password
Clear-text email
Public Wi‑Fi hotspot
Unencrypted USB drive
What does authorization determine?
What a user is allowed to do on a system
Whether a user is online
How fast a network transmits data
How data is compressed
In the AAA model, what is the purpose of accounting?
To track and record user activity
To encrypt stored passwords
To block malicious traffic
To validate network routes
Which statement best distinguishes confidentiality from privacy?
Confidentiality is the duty to protect data; privacy is the correct use of personal data
Confidentiality is about uptime; privacy is about backups
Confidentiality is user training; privacy is access control
Confidentiality is encryption; privacy is hashing
What does integrity ensure?
That data is accurate, complete, and not tampered with
That data is available to all users at all times
That data is stored redundantly
That data is compressed efficiently
What is hashing used for?
Verifying data integrity by creating a digital fingerprint
Encrypting data so only authorized users can read it
Compressing files to reduce size
Balancing traffic across multiple servers
Which is an example of a hashing algorithm?
SHA-256
AES-256
RSA-2048
TLS 1.3
What is availability?
Ensuring that data and services are accessible to authorized users when needed
Ensuring data remains confidential from unauthorized users
Ensuring data is accurate and unaltered
Ensuring traffic is encrypted end-to-end
What does “Five Nines” uptime represent?
99.999% availability
99.9% availability
95% availability
90% availability
Which list correctly names the three states of data?
Data at rest, data in transit, data in process
Structured data, semi-structured data, unstructured data
Hot data, warm data, cold data
Primary data, secondary data, tertiary data
What is data at rest?
Stored data on devices or servers
Data currently being transmitted over a network
Data being computed by applications
Data cached in memory only
Which is a challenge associated with data at rest?
Vulnerable endpoints
Packet sniffing
Weak routing protocols
Excessive bandwidth
What is data in transit?
Data being moved across a network or between devices
Data stored on backup tapes
Data processed by an application
Data archived for long-term retention
Which is a major threat to data in transit?
Eavesdropping or packet sniffing
Disk fragmentation
Power over Ethernet failure
Excessive logging
Which security measure protects data in transit?
Encryption (e.g., VPN)
Defragmentation
Load shedding
Open mail relay
What is data in process?
Data being input, computed, or output by applications
Data archived for compliance
Data stored only on removable media
Data queued for printing
Which is a threat to data in process?
Malicious code
Cable attenuation
Dust accumulation
Low screen resolution
Which are the three main categories of cybersecurity safeguards?
Technology, cloud, and human safeguards
Physical, chemical, and biological safeguards
Hardware, software, and firmware safeguards
Policies, audits, and fines
Which is an example of a technology safeguard?
Firewall
Spreadsheet template
Inkjet printer
Public bulletin board
What is SaaS?
Software as a Service—applications hosted by cloud providers
Security as a Standard—government cybersecurity rules
Storage as a System—on‑premises tape libraries
Service and Support—help desk procedures
What is the purpose of cybersecurity training?
To educate users on safe practices and reduce human-related risks
To increase network bandwidth
To eliminate all software vulnerabilities
To enforce legal penalties on attackers
What is an Acceptable Use Policy (AUP)?
A policy defining appropriate and inappropriate use of company systems and networks
A policy that sets hardware warranty terms
A policy that lists public holidays for staff
A policy for printer ink management
What is the purpose of standards in cybersecurity?
To ensure consistency by defining specific rules and configurations
To reduce the need for backups
To prevent any user errors from occurring
To guarantee 100% system uptime
What is the main difference between a virus and a worm?
A virus requires user action to spread; a worm self‑propagates without user action
A virus only targets servers; a worm only targets desktops
A virus is always benign; a worm is always malicious
A virus encrypts data; a worm compresses data
What is the difference between a virus and a worm?
A virus self-replicates without user action, while a worm needs user interaction to spread
A virus requires user action to spread, while a worm self-replicates and spreads automatically
A virus only infects mobile devices, while a worm only targets servers
A virus is harmless, while a worm always encrypts files
Why are Trojans considered dangerous?
They openly announce themselves to users to request permission
They disguise themselves as legitimate software and exploit user privileges to install malware or create backdoors
They only slow down internet speed temporarily
They are limited to sending spam emails
What is the purpose of ransomware?
To monitor user browsing habits
To encrypt or lock a user’s data and demand payment for its release
To improve system performance
To provide remote technical support
How does a rootkit help an attacker?
It optimizes the operating system for faster performance
It hides the attacker’s presence by modifying the operating system, allowing ongoing privileged access without detection
It automatically updates all security patches
It blocks all outbound network traffic
What is spear phishing?
A broad phishing campaign sent to random recipients
A highly targeted phishing attack aimed at specific individuals or organizations
A method of encrypting emails for security
A hardware-based attack on network switches
What is vishing?
Phishing conducted through voice calls or VoIP to trick victims into revealing information
Phishing conducted only via email
Malware that infects video files
A vulnerability in virtual machines
What type of attack involves redirecting a user to a fake website?
Smishing
Pharming
Keylogging
Drive-by download
How is a DoS attack different from a DDoS attack?
A DoS attack uses multiple compromised systems, while a DDoS uses one source
A DoS attack comes from one source, while a DDoS attack originates from multiple compromised systems
A DoS is legal, while a DDoS is illegal
A DoS only affects mobile networks, while a DDoS only affects wired networks
What is a man-in-the-middle attack?
An attack where malware deletes files on a local system
An attack where an unauthorized party intercepts and possibly alters communication between two legitimate parties
An attack that only targets wireless routers by flooding them with traffic
An attack that replaces a user’s keyboard with a malicious device
What is an evil twin?
A legitimate access point with enhanced security
A fake wireless access point set up to mimic a legitimate AP and lure users into connecting
A peer-to-peer connection used for file sharing
A backup device used to improve network redundancy
Name one way to detect or prevent ARP spoofing.
Use static ARP entries
Enable dynamic ARP inspection on network devices
Disable HTTPS in browsers
Switch to WEP encryption on Wi‑Fi
What is a replay attack?
An attack where captured messages are retransmitted to impersonate a user or bypass authentication
An attack that replaces software libraries with malicious versions
An attack that brute-forces passwords using dictionary lists
An attack that scans open ports on a server
What is the function of a backdoor?
It encrypts all user data automatically
It provides attackers unauthorized remote access to a system after initial compromise
It blocks malicious IP addresses by default
It updates antivirus signatures
What makes zero-day attacks particularly dangerous?
They only use outdated malware that is easily detected
They exploit unknown vulnerabilities for which no patches or fixes exist yet
They require physical access to the device
They are limited to social media platforms
What is a rogue access point?
An authorized access point installed by the network team
An unauthorized wireless access point installed without approval, often used for attacks
A device that only provides guest Wi‑Fi
A hardware firewall connected to the router
How can shoulder surfing be prevented?
By shielding screens
By using privacy filters
By being aware of surroundings when entering sensitive information
By sharing passwords with trusted colleagues
What is grayware?
Software that is clearly malicious and encrypts files
Software that is annoying or undesirable and may gather data, but is not clearly malicious
Software that is guaranteed safe and vetted by government agencies
Hardware drivers required for operating system updates
What is the goal of SEO poisoning?
To improve legitimate search rankings for educational websites
To manipulate search engine results to direct users to malicious websites
To block all pop-up advertisements by default
To encrypt search queries for privacy
Why is SMiShing effective?
Because users often trust SMS messages more and tend to click links without verifying the sender
Because SMS messages are always scanned by antivirus software
Because SMS links are blocked by all mobile carriers
Because SMS is only used for internal corporate communication
What is a browser hijacker?
A legitimate browser update that improves performance
Malware that modifies browser settings to redirect users to unsafe or advertising-heavy websites
A plug‑in that removes cookies for privacy
A tool used by administrators to enforce security policies
What is the main goal of cryptography?
To compress data for faster transmission
To protect information by ensuring confidentiality, integrity, authentication, and non‑repudiation
To increase computer graphics performance
To replace passwords with biometrics
What is plaintext?
Encrypted data that is unreadable without a decryption key
The original readable message before encryption
A random key generated during hashing
A message stored only in binary form
What is ciphertext?
Encrypted data that is unreadable without a decryption key
The original readable message before encryption
A public key used to verify signatures
A checksum appended to network packets
What is the difference between cryptography and cryptanalysis?
Cryptography creates secure codes; cryptanalysis attempts to break or defeat them
Cryptography stores passwords; cryptanalysis transmits messages
Cryptography hides images; cryptanalysis compresses files
Cryptography speeds networks; cryptanalysis slows them
Name two historical encryption methods.
Scytale
Caesar Cipher
Vigenère Cipher
Enigma
SHA-256
What is the main weakness of symmetric encryption?
Key distribution — both sender and receiver must share the same secret key
It cannot encrypt large files
It never supports authentication
It requires internet access
What kind of key does asymmetric encryption use for encryption?
The receiver’s public key
The sender’s private key
A shared session key
A one-time pad
What kind of key does asymmetric encryption use for decryption?
The receiver’s private key
The sender’s public key
A symmetric key
A hash value
Why is asymmetric encryption slower than symmetric encryption?
It uses complex mathematical operations and larger key sizes
It transmits data over longer distances
It requires multiple recipients
It relies on physical tokens
Give one example of a symmetric encryption algorithm.
AES
RSA
Diffie–Hellman
ECC
Give one example of an asymmetric encryption algorithm.
RSA
AES
DES
Blowfish
What is the purpose of hybrid cryptography?
To combine asymmetric encryption for secure key exchange with symmetric encryption for fast data transfer
To replace all symmetric ciphers with hashes
To hide messages inside images
To increase compression efficiency
What is steganography?
Hiding secret data inside other data such as an image, audio, or video file
Converting plaintext to ciphertext with a key
Detecting malicious network traffic
Erasing metadata from files
What does a block cipher do?
Encrypts data in fixed-sized blocks
Encrypts only headers of files
Encrypts data one bit at a time
Compresses data before encryption
What does a stream cipher do?
Encrypts data one bit or byte at a time
Encrypts in fixed-size blocks
Stores keys on hardware tokens
Hashes messages for integrity
What are the four steps of access control?
Identification
Authentication
Authorization
Accountability
Confidentiality
Give one example of something you “are” used for authentication.
Biometrics like fingerprints, iris scan, or facial recognition
Passwords remembered by the user
Hardware tokens carried by the user
Security questions answered by the user
What type of access control is used in government or military (Secret/Top Secret labels)?
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
What access control model assigns permissions based on job roles?
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Lattice-Based Access Control
What is a common disadvantage of Discretionary Access Control (DAC)?
It is less secure because users can share or change permissions too freely
It never allows file sharing
It requires custom hardware
It cannot be implemented on operating systems
Give one example of a physical access control.
Locks
Passwords
Encryption
Firewall rules
Give one example of a logical access control.
Passwords
Locks
CCTV
Mantraps
Which encryption standard is commonly used for secure web browsing (HTTPS)?
RSA (for key exchange)
AES (for data encryption)
MD5 (for hashing only)
DES (legacy)
What is the purpose of an Access Control List (ACL)?
To define rules that specify which users or devices can access certain resources
To encrypt files using symmetric keys
To compress and archive logs
To assign IP addresses on a network
Why is AES preferred over DES today?
AES uses stronger keys and is more secure than the outdated DES
AES is older and easier to implement
AES avoids using any substitution boxes
AES requires no hardware acceleration
What is data masking?
Replacing sensitive data with a non-sensitive but realistic substitute to protect information
Encrypting data using a public key
Deleting sensitive data permanently
Storing sensitive data in a separate database
Name two reasons why organizations use data masking.
To reduce exposure of sensitive data
To protect data in development and testing environments
To increase network bandwidth
To comply with password reuse policies
List any two data masking techniques.
Substitution
Shuffling
Nulling-out
Mirroring
Watermarking
What is the main purpose of steganography?
To hide the existence of a secret message inside another file
To verify message integrity with hashes
To scramble data for compression
To assign user permissions
What is a stego object?
The output file after embedding hidden data
The unmodified cover file used for hiding
The cryptographic key used for encryption
The detector used to find hidden data
How many bits can typically be hidden in a single RGB pixel using LSB techniques?
Three bits (one per color channel)
One bit total
Six bits (two per channel)
Eight bits total
What is steganalysis?
The process of detecting hidden information inside a file
The process of encrypting a message with a key
The process of masking sensitive fields in a database
The process of compressing images for storage
Give one example of social steganography.
Posting a normal-looking status that secretly signals a meaning to a friend
Using a VPN to encrypt all internet traffic
Compressing files to reduce their size
Sharing a public encryption key on a website
Define cryptography.
The science of encoding and decoding information to ensure confidentiality, integrity, and authentication
The process of compressing data to save storage space
The practice of hiding messages only through imagery
A method of backing up files to protect against loss
What is the difference between plaintext and ciphertext?
Plaintext is readable data; ciphertext is encrypted data
Plaintext is compressed data; ciphertext is expanded data
Plaintext uses a private key; ciphertext uses a public key
Plaintext is binary; ciphertext is hexadecimal
What is a cipher?
An algorithm used to encrypt and decrypt data
A device for physically securing access
A protocol for routing network packets
A checksum used to verify file downloads
Name two classical (historical) ciphers.
Caesar Cipher and Vigenère Cipher
AES and RSA
Blowfish and Twofish
SHA-256 and SHA-512
What key characteristic defines symmetric encryption?
The same key is used for both encryption and decryption
It always uses public and private key pairs
It only encrypts fixed-size blocks
It cannot be implemented in software
Name one symmetric encryption algorithm.
AES
RSA
ECC
ElGamal
Give one disadvantage of symmetric encryption.
Key distribution is difficult because both parties need the same shared key
It cannot encrypt large files
It requires expensive hardware to run
It never achieves confidentiality
What is asymmetric encryption?
A method using two different keys—one public to encrypt and one private to decrypt
A technique that uses a single shared key for both encryption and decryption
A compression method that reduces redundancy
A hashing approach that produces a fixed-length digest
Name one asymmetric encryption algorithm.
RSA
AES
DES
Blowfish
State one advantage of asymmetric encryption.
It allows secure communication without having to share secret keys beforehand
It guarantees zero latency in data transfer
It prevents all forms of data tampering automatically
It requires no computational resources
Why do systems combine symmetric and asymmetric encryption?
To get the speed of symmetric encryption and the secure key exchange of asymmetric encryption
To avoid using any keys at all
To make data readable during transit
To eliminate authentication requirements
What is a block cipher?
A cipher that encrypts fixed-sized blocks of data
A cipher that encrypts one bit at a time
A method of hashing passwords
A protocol for establishing VPN tunnels
What is a stream cipher?
A cipher that encrypts data one bit or one byte at a time
A cipher that encrypts fixed-sized blocks of data
A compression algorithm
A key exchange protocol
What does a VPN do?
It creates an encrypted tunnel over the internet to protect data and hide the user’s IP address
It converts plaintext to ciphertext using public keys
It prevents files from being deleted
It scans systems for malware automatically
Give one common use of a VPN.
Secure browsing on public Wi‑Fi
Defragmenting a hard drive
Compressing multimedia files
Installing operating system updates
List the three categories of access controls.
Physical, Logical, Administrative
Mandatory, Discretionary, Role-Based
Preventive, Detective, Corrective
Public, Private, Hybrid
Give one example of a physical access control.
Locked doors
Password policies
Role assignments in an application
Firewall rules
What is logical access control?
Digital mechanisms that control access, such as passwords or biometrics
Physical barriers like fences
Organizational policies and procedures
Backup schedules for servers
Give an example of administrative access control.
Security policies, procedures, or background checks
Biometric fingerprint scanners
Smart locks on doors
Encryption of hard drives
What is Mandatory Access Control (MAC)?
A strict model where the system, not the user, controls access rights
A model where users assign permissions freely
A role-centric model that groups users by job function
A decentralized approach with no central authority
Which access control model assigns permissions based on job roles?
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Attribute-Based Access Control (ABAC)
Provide one example of rule-based access control.
Allowing access only during office hours or from specific IP addresses
Letting users decide permissions for their own files
Granting access solely by physical badge scans
Encrypting data with a symmetric key
What does data integrity ensure?
That data remains accurate, unchanged, and trustworthy
That data is always encrypted with AES
That data is stored only in the cloud
That data loads faster on networks
Name two methods used to ensure data integrity.
Hashing and digital signatures
Compression and deduplication
VPN tunneling and network address translation
Symmetric encryption and RAID mirroring
What is hashing?
A one-way function that converts data into a fixed-length value called a hash or digest
A reversible encryption method
A protocol for assigning IP addresses
A data compression technique
Why is hashing considered one-way?
Because it cannot be reversed to recover the original data
Because it only works on text files
Because it requires a pair of keys
Because it always produces different outputs
What is a collision in hashing?
When two different inputs produce the same hash value
When the same input yields different output lengths
When a hash matches its original plaintext
When hashing fails due to insufficient memory
Give an example of a hashing algorithm still considered secure.
SHA‑256
MD5
DES
RC4
Why is MD5 no longer recommended for security use?
It is vulnerable to collisions
It cannot run on modern CPUs
It uses too much memory
It only produces very long hashes
What is the purpose of hashing digital forensic images?
To prove the copy is identical to the original (fixity verification)
To encrypt the image for confidentiality
To compress the image to save storage
To remove sensitive information from the image
Why do systems store password hashes instead of plaintext passwords?
To prevent attackers who obtain the database from reading user passwords directly
To ensure passwords are always the same length
To allow users to share passwords safely
To make login processes faster
What happens when a user logs in to a system that uses hashing?
The entered password is hashed and compared with the stored hash
The entered password is encrypted and stored as plaintext
The stored hash is decrypted to reveal the original password
The system sends the password to the server without transformation
What is a dictionary attack?
An attack using a list of common passwords to find a matching hash
An attack that tries all possible character combinations
An attack that intercepts passwords during transmission
An attack that modifies the hashing algorithm
What is a brute-force attack?
Trying all possible combinations until the correct hash is found
Guessing passwords from a list of common phrases
Phishing users to obtain their passwords
Exploiting software vulnerabilities to bypass login
What is a salt?
A random string added to a password before hashing
A secret key used to sign a message
A checksum appended after encryption
A token used to start a session
