Security+ Final week

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/108

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:28 PM on 7/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

109 Terms

1
New cards

Encrypting confidential data for a recipient uses which key?

The recipient’s public key. Only their private key can decrypt it.

2
New cards

What does the recipient use to decrypt data encrypted with their public key?

Their private key.

3
New cards

Digital signature: which key signs and which verifies?

Sender’s private key signs; sender’s public key verifies.

4
New cards

What provides confidentiality: hashing or encryption?

Encryption. It is reversible with the correct key.

5
New cards

What provides one-way integrity checking?

Hashing

6
New cards

Two parties establish a shared secret. What process is this?

Key exchange, commonly Diffie–Hellman.

7
New cards

Symmetric encryption

Same shared key encrypts and decrypts; fast; used for bulk data.

8
New cards

Asymmetric encryption

Public/private key pair; slower; used for key exchange, signatures and limited encryption.

9
New cards

What mathematical property underpins RSA?

A trapdoor function. Easy one way, difficult to reverse without secret information.

10
New cards

Encryption algorithm

Mathematical procedure that transforms plaintext into ciphertext.

11
New cards

Hash function

Produces a fixed-length, one-way digest for integrity.

12
New cards

Full-disk encryption

Encrypts the complete physical drive, including OS and files.

13
New cards

Volume encryption

Encrypts one logical volume, partition or virtual drive.

14
New cards

File-level encryption

Encrypts selected files or folders.

15
New cards

Data in transit: primary protection

Encryption, normally TLS or another secure tunnel.

16
New cards

TPM

Trusted Platform Module

Motherboard-integrated hardware storing keys and platform measurements.

17
New cards

HSM

Hardware Security Module

Dedicated hardware device for securely generating and managing cryptographic keys.

18
New cards

Root of trust

Foundation that is inherently trusted and supports the chain of trust.

19
New cards

Risk appetite

Broad amount and type of risk an organisation is willing to pursue or accept.

20
New cards

Risk tolerance

Specific acceptable variation or exposure before action is required.

21
New cards

Risk threshold

Point at which risk becomes unacceptable or triggers action.

22
New cards

Risk owner

Person or department responsible for managing a specific risk.

23
New cards

Risk register

Central record of identified risks, impacts, owners and responses.

24
New cards

Likelihood

Qualitative assessment of how likely a risk is to occur.

25
New cards

ARO

Annual Rate of Occurrence

Expected incidents per year.

26
New cards

SLE formula

Single Loss Expectancy

Asset value × Exposure factor.

27
New cards

ALE formula

SLE × ARO.

28
New cards

SLE $15,000 and ARO 0.1: ALE?

$1,500.

29
New cards

Due diligence

Investigation performed before selecting or entering an arrangement.

30
New cards

Due care

Ongoing reasonable actions taken to protect assets and meet obligations.

31
New cards

Internal audit

Organisation examines its own controls and processes.

32
New cards

Independent third-party audit

External, objective assessment of controls.

33
New cards

Attestation

Formal affirmation that a statement or report is accurate and complete.

34
New cards

TCO

Total Cost of Ownership

Total lifecycle cost: purchase, operation, maintenance, support and retirement.

35
New cards

CAPEX

Capital Expeniture

Initial capital purchase expenditure.

36
New cards

ROI

Return on Investment

Benefit or return compared with the investment cost.

37
New cards

DAC

Discretionary Access Control

Owner decides who can access the resource.

38
New cards

MAC

Mandatory Access Control

Central authority uses classifications and labels; users cannot alter permissions.

39
New cards

RBAC

Role-Based Access Control

Permissions assigned according to job role.

40
New cards

ABAC

Attribute-Access Control

Access based on attributes such as user, device, location, time and resource.

41
New cards

802.1X

Port-based network access control; authenticates before wired or wireless access.

42
New cards

NAC

Network Access Control

Assesses identity/device posture and allows, restricts or quarantines network access.

43
New cards

BYOD

Bring Your Own Device

Employee owns and uses the device.

44
New cards

COPE

Corperate owned, Personally Enabled

Company owns the device but permits personal use.

45
New cards

COBO

Corporate owned, Business only

Company-owned and restricted to business use.

46
New cards

CYOD

Choose Your Own Device

User chooses from an approved list of company-supported devices.

47
New cards

Default credential management

Replace factory-set usernames and passwords before deployment.

48
New cards

Data controller

Determines why and how personal data is processed.

49
New cards

Data processor

Processes personal data on behalf of the controller.

50
New cards

Data custodian

Handles operational storage, protection and maintenance of data.

51
New cards

Tap/monitor mode

Copies traffic for analysis without altering the traffic flow.

52
New cards

Inline mode

Device sits directly in the traffic path and can block or modify traffic.

53
New cards

IDS

Intrusion Detection System

Detects and alerts; normally does not block.

54
New cards

IPS

Intrusion Prevention System

Detects and actively blocks or rejects traffic.

55
New cards

HIDS/HIPS

Host-based detection/prevention on an endpoint.

56
New cards

What blocks unauthorised endpoint port activity and exfiltration?

HIPS

57
New cards

Signature-based detection weakness

May miss zero-day and unknown attacks.

58
New cards

Signature tuning

Reduces false positives caused by broad or unsuitable signatures.

59
New cards

Load balancer

Distributes traffic across servers for performance and availability.

60
New cards

WAF

Web Application Firewall

Protects web applications against attacks such as SQL injection and XSS.

61
New cards

Port 1433

Microsoft SQL Server.

62
New cards

Port 53

DNS

63
New cards

Port 21

FTP

64
New cards

Port 443

HTTPS

65
New cards

IP addresses plus port numbers correspond mainly to which OSI layer?

Layer 4, because ports are transport-layer identifiers.

66
New cards

Screened subnet/DMZ

Isolated zone separating public-facing services from the internal network.

67
New cards

WPA2-Personal authentication

Passphrase is used to derive the pairwise master key (PMK).

68
New cards

WPA3-Personal authentication

Uses SAE/Dragonfly, providing stronger protection against offline guessing.

69
New cards

TKIP

Temporal Key Integrity Protocol

Older per-packet keying protocol associated with WPA and legacy compatibility.

70
New cards

AES/CCMP

Advanced Encryption Standard

Counter Mode with Cipher Block Chaining Messaging Authentication Code Protocol

Stronger encryption used with WPA2 and later standards.

71
New cards

IaC

Infrastructure as Code

Infrastructure provisioned and managed using code or scripts.

72
New cards

Availability

Service remains accessible and operational.

73
New cards

Resilience

Ability to withstand disruption and recover quickly after failure.

74
New cards

Redundancy

Duplicate components remove single points of failure.

75
New cards

Scalability

Capacity can increase to support additional demand.

76
New cards

Failover

Switching operations to a standby system after failure.

77
New cards

RTOS security concern

Performance priorities may reduce protections such as buffer-overflow defences.

78
New cards

Shadow IT

Unapproved hardware, software or services used for convenience, usually without malicious intent.

79
New cards

Insider threat

Authorised insider intentionally or negligently abuses legitimate access.

80
New cards

Brute-force attack

Systematically tries many or all possible password combinations.

81
New cards

Dictionary attack

Tries words and candidate passwords from a prepared list.

82
New cards

Password spraying

Tries a small number of common passwords across many accounts.

83
New cards

Credential stuffing

Uses stolen username/password pairs against other services.

84
New cards

Credential replay

Reuses captured credentials or authentication material.

85
New cards

Replay attack

Captures and retransmits valid data, tokens or messages.

86
New cards

<script>, alert(), document.cookie

Code/script injection; commonly associated with XSS in web contexts.

87
New cards

CSRF

Cross-Site Request Forgery

Tricks an authenticated user’s browser into submitting an unwanted request.

88
New cards

Command injection

Executes operating-system commands through vulnerable input handling.

89
New cards

Directory traversal

Uses paths such as ../ to access files outside the intended directory.

90
New cards

Supply-chain attack

Compromises a trusted vendor, dependency, installer or service provider.

91
New cards

Watering-hole attack

Compromises a site frequently visited by the intended victims.

92
New cards

Typosquatting

Uses a misspelt or similar-looking domain to deceive users.

93
New cards

Cryptographic downgrade

Forces communication to use a weaker protocol or cipher.

94
New cards

Environmental variables in vulnerability management

Organisation-specific infrastructure, business and operational context affecting vulnerability risk.

95
New cards

Rescanning

Runs the vulnerability scan again to determine whether the finding remains.

96
New cards

Reviewing event logs

Examines system behaviour and evidence related to remediation or exploitation.

97
New cards

Patch management

Identifies, tests, deploys and verifies software or firmware security updates.

98
New cards

Baseline

Approved standard configuration used to identify deviation and configuration drift.

99
New cards

Log aggregation

Centralises logs to simplify correlation, investigation and compliance.

100
New cards

Archiving logs

Preserves historical evidence for later investigations, audits and analysis.