1 / 13
CompTIA Security+ (SY0-601) Terminology
1.Phishing: A type of social engineering attack often used to steal
user data, including login credentials and credit card numbers.
2.Smishing: The act of committing text message fraud to try to lure
victims into revealing account information or installing malware.
3.Vishing: An electronic fraud tactic in which individuals are tricked
into revealing critical financial or personal information to unauthorized entities.
4.Spam: An unsolicited bulk messages sent to multiple recipients who
did not ask for them.
5.Spam over instant messaging (SPIM): Refers to unsolicited instant
messages.
6.Spear phishing: An email or electronic communications scam
targeted towards a specific individual, organization or business.
7.Dumpster diving: A technique used to retrieve information that could
be used to carry out an attack on a computer network. 1 / 4
2 / 13
8.Shoulder surfing: A direct observation techniques, such as looking
over some- one's shoulder, to get information.
9.Pharming: A form of online fraud involving malicious code and
fraudulent web- sites.
10.Tailgating: A physical security breach in which an unauthorized
person follows an authorized individual to enter a secured premise.
11.Eliciting information: A reporting format designed to elicit as much
informa- tion as possible about individuals involved in a group or network.
12.Whaling: A method used by cybercriminals to masquerade as a
senior player at an organization and directly target senior individuals, with the aim of stealing or gaining access to their computer systems for criminal purposes.
13.Prepending: A technique used to deprioritize a route in a netork.
14.Identity fraud: A crime in which an imposter obtains key pieces of
personally identifiable information (PII) to impersonate someone else.
15.Invoice scams: A fraudulent way of receiving money or by
prompting a victim to put their credentials into a fake login screen. 2 / 4
3 / 13
16.Credential harvesting: The process of gathering valid usernames,
pass- words, private emails, and email addresses through infrastructure breaches.
17.Reconnaissance: A term for testing for potential vulnerabilities in a
computer network. 3 / 4
4 / 13
18.Hoax: A message warning the recipients of a non-existent
computer virus threat.
19.Impersonation: A form of fraud in which attackers pose as a known
or trusted person to dupe an employee into transferring money to a fraudulent account, sharing sensitive information or revealing login credentials.
20.Watering hole attack: A targeted attack designed to compromise
users within a specific industry by infecting websites they typically visit and luring them to a malicious site.
21.Typosquatting: A form of cybersquatting which relies on mistakes
such as typos made by Internet users when inputting a website address into a web browser.
22.Pretexting: A form of social engineering in which an individual lies
to obtain privileged data.
23.Social media: A computer-based technology that allows the sharing
of ideas, thoughts, and information through the building of virtual networks.
24.Authority: The power to enforce rules or give orders.
- / 4