Chapter 4
- Describe business email compromise in your own words.
Business email compromise is a type of malicious email message that does not have a payload but instead tries to deceive the recipient into acting against their own interests. (Section: The most important threat vector)
- What is the concept of least privilege? What is need to know? How are they the same and how do they differ?
The concept of least privilege refers to the idea that people should be given the minimum permissions necessary to accomplish their job function. Need to know states information should only be shared with those who need to know it. The primary difference between the two is that the concept of least privilege refers to access, while need to know refers to information sharing. (Section: Time- honored best practices that could stop most breaches)
- What are the three factors of authentication?
Something you know, something you are, and something you have. (Section...