Across
- 2. When an attacker inserts malicious database commands into a website's input fields to access, change, or delete data.
- 4. A set of rules that defines how users are allowed to use an organisation's computer systems, networks, and internet access.
- 8. A simple encryption method where each letter in a message is shifted a fixed number of places through the alphabet.
- 10. A method of gaining unauthorised access by repeatedly trying different username and password combinations until the correct one is found.
- 14. A security method that requires two forms of identification, usually something you know (a password) and something you have (a code sent to a phone or generated by an app).
Down
- 1. A pre-set password provided by the manufacturer of a device or software, which should be changed to improve security.
- 3. An attack that floods a computer system or network with traffic, preventing legitimate users from accessing services.
- 5. A method of authentication that uses unique physical characteristics, such as fingerprints, facial recognition, or iris scans, to identify a user.
- 6. A collection of computers or devices infected with malware and controlled as a group, often to carry out attacks such as DDoS attacks.
- 7. An authorised attempt to test the security of a computer system by deliberately trying to find and exploit vulnerabilities.
- 9. Occurs when sensitive or confidential data is accessed, shared, or stolen by someone who is not authorised to see it.
- 11. Hardware or software that monitors and controls network traffic, blocking unauthorised access while allowing legitimate communications.
- 12. A secret combination of characters used to verify a user's identity and allow access to a computer system or account.
- 13. A type of DoS attack where multiple computers are used to flood a target system with traffic simultaneously.
