Description should include, but not be limited to
- authentication (e.g., password attacks, biometrics attacks)
- social engineering, including phishing and other scams
- web application attacks such as injection attacks and scripting attacks
- exploitation of operating system and application software vulnerabilities
- viruses, worms, and Trojan horses
- brute-force attacks
- privacy invasion tools (e.g., spyware, malware, ransomware, cookies, adware, popups)
- spam
- denial of service attacks
- acts of terrorism and how they present a threat
- pandemics and how they present a threat
- natural disasters and an evaluation of such threats in the recent past
- accidents or technical failures
- the potential for accidents and failures is often reached when infrastructure is pushed past its intended life
- unintentional failures.
Teacher Resource: Cyber Basics: Module E: Hacking, Virginia Cyber Range