Page 5 of 6.
CVE vs CVSS: what's the difference?
CVE identifies a vulnerability; CVSS scores its severity. How MITRE's catalog and FIRST's 0-10 scoring system work together, decoded with a worked example.
Cyber Threat Intelligence (CTI), explained.
The four tiers of cyber threat intelligence, the intelligence cycle, STIX/TAXII sharing standards, and how CTI drives MITRE ATT&CK-mapped detection engineering.
Social engineering, explained.
Pretexting, phishing, vishing, smishing, baiting, and tailgating — the core social engineering techniques and the psychological principles behind them.
SIM swap attacks, explained.
How SIM swap and port-out fraud actually works, why phone numbers became a weak link in account recovery, and how to lock down a number against it.
How a VPN actually works, and what it doesn't hide.
How VPN tunneling actually works, what it hides from your ISP and local network, and why it does not make you anonymous — the provider can still see everything.
Stateful vs stateless firewalls, and NGFW explained.
Stateless packet filters judge each packet alone; stateful firewalls track connections in a state table; NGFWs add deep packet inspection — with a worked example.