Memory hook: Actor explains intent; evidence identifies the technique.
Must remember
Actors differ in funding, access and motivation: nation-state espionage, organized financial crime, hacktivism, malicious or careless insiders and opportunistic attackers. Shadow IT is unapproved technology that creates unmanaged exposure; it is not necessarily malicious.
Phishing targets messages; spear phishing targets a person/group; whaling targets senior staff. Smishing uses text messages and vishing voice calls. Pretexting invents a credible story, business email compromise abuses trusted payment workflows, and tailgating exploits physical access. Verify unusual requests through an independent channel, especially when voice or video could be synthesized.
| Indicator | Likely technique / useful response |
|---|---|
| Many passwords against one account | Brute force; rate limits and monitoring. |
| One common password across many users | Password spraying; MFA and password hygiene. |
| Known breached username/password pairs | Credential stuffing; revoke/resecure reused credentials. |
| Browser executes untrusted page content | XSS; contextual output encoding and safe frameworks. |
| Query structure changes through input | Injection; parameterized queries and validation. |
| Server fetches attacker-chosen internal URL | SSRF; destination controls and restricted credentials. |
| Local IP maps to an unexpected MAC | Possible ARP spoofing; inspect trusted bindings and switching controls. |
Ransomware denies access or extorts using stolen data; a worm self-propagates; a Trojan disguises malicious behavior; rootkits hide privileged persistence; spyware captures information. Fileless activity can use legitimate interpreters and memory rather than a conspicuous executable.
Race conditions exploit timing (including time-of-check/time-of-use); buffer overflows corrupt memory; insecure direct object references expose missing object-level authorization. Supply-chain compromise can enter through dependencies, build systems or updates. Downgrade attacks seek weaker protocols; replay reuses captured valid messages without breaking the cipher.
Treat a single indicator as a hypothesis. Correlate identity, endpoint, network and application evidence before concluding cause.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Suspicious urgent transfer request | Independently verify with established contacts. |
| Database query injection | Use parameterized queries; a WAF is supplementary. |
| Large distributed traffic flood | Use upstream capacity and DDoS protections as well as local controls. |
Traps
- A strong password does not prevent phishing of a live session.
- A vulnerability is a weakness; an exploit is a method of using it.
Active recall
1. Spraying versus brute force?
Spraying tries a small password set across many accounts; brute force tries many candidates against a target.
2. What prevents SQL input becoming query syntax?
Parameterized queries and appropriate safe data-access patterns.
3. Why is SSRF dangerous in a cloud application?
The server may reach internal services or credentials unavailable to the attacker directly.
4. Does a signed update prove the whole supply chain is uncompromised?
No. The signing system or authorized publisher can itself be compromised.
5. Why verify urgent requests by another channel?
The original account or communication channel may be controlled by an attacker.