1/53
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
SOP
Standard Operating Procedure (SOP)
Step-by-step instructions for completing a task
Ensures tasks comply with policy
Most IT procedures should be governed by SOPs
SLA
Service Level Agreements (SLA)
Defines the required level of service
Agreement between:
Internal departments
External third-party vendors
Specifies how service performance is measured
AUP
Acceptable Use Policy (AUP)
Defines what users are allowed to use services/resources for
Applies to employees or customers
Controls use of:
Computers and devices
Internet access
Telephone services
Network resources
NTFS
New Technology File System (NTFS)
Microsoft file system for Windows
Supports very large files and volumes
Key features:
Journaling → improves recovery after crashes/power loss
Snapshots → allows previous file versions/recovery
Security → permissions, ownership, auditing, quotas, encryption
POSIX support → some UNIX/Linux compatibility
Indexing → faster file searches
Dynamic disks → combine storage from multiple physical disks
Main drawback → limited support outside Windows
macOS: Can read but normally cannot write to NTFS
Linux: Can support NTFS to varying degrees
ReFS
Resilient File System (ReFS)
Newer Microsoft file system
Designed for large-scale and specialized storage
Key benefits:
Resiliency → detects and repairs corruption
High performance → optimized for large datasets/workloads
Scalability → supports extremely large amounts of data
NTFS remains more common for general Windows use
FAT32
Older File Allocation Table system
Maximum file size → 4 GB − 1 byte
Typically supports volumes up to 2 TB
Does not provide NTFS-level security or reliability features
Useful for:
Boot/system partitions
Removable drives
Memory cards
Devices using different operating systems
exFAT
Extended File Allocation Table
Designed for removable drives and flash media
Supports large volumes
Recommended maximum → 512 TB
Supports access permissions
Does not support encryption
XFS
Introduced in 1993
64-bit journaling file system
Designed for high performance and scalability
Default file system for Red Hat Enterprise Linux (RHEL)
Supported by other Linux distributions
NFS
Network File System (NFS)
Allows Linux to mount remote storage
Makes a remote file resource appear like a local file system
Useful for accessing files stored on another computer/system
APFS
Apple File System (APFS)
Apple's proprietary file system
Used by Mac computers
Supports:
Journaling
Snapshots
Permissions/ownership
Encryption
Robocopy
Heavy-duty backups, network transfers, full mirroring
Xcopy
Quick, basic file and folder copying
ipconfig
IP address
Subnet mask
Default gateway
ipconfig /all
DHCP information
DNS servers
MAC address
NetBIOS status
RTT
Round-Trip Time
tracert
Command-line tool used to trace the path packets take to a destination.
Helps identify routing problems.
Can use:
IP address
FQDN
tracert displays:
Hop number
Router/host interface
Response time in milliseconds (ms)
Pathping
Alternative to tracert
First traces the route, then pings each hop multiple times.
Measures:
Round-trip time (RTT)
Link latency
Packet loss at each hop
Useful for identifying where along the route latency or packet loss occurs.
Higher-Layer Network Troubleshooting
3 Main Areas of Failure
Security
Firewall may be blocking the connection.
Security software/hardware may be blocking traffic.
Incorrect proxy settings may prevent access.
Name Resolution (DNS)
DNS failure means you can connect using an IP address but not a hostname.
Example:
ping 8.8.8.8 → works
ping google.com → fails
Indicates a possible DNS/name-resolution problem.
Application / OS
The operating system or application providing the service may have failed.
If the server itself cannot be reached, the OS or network may be the problem.
If the server can be reached but a specific service cannot, the service process may have crashed.
nslookup
Command-line tool used to troubleshoot DNS.
Can be used:
Interactively
Directly from Command Prompt
netstat
netstat investigates open ports and network connections on the local computer.
Useful for checking:
File-sharing ports
Email ports
Client connections to a server
RDP
Remote Desktop Protocol
Windows uses RDP for Remote Desktop functionality.
Start Remote Desktop using:
Remote Desktop Connection
mstsc.exe
Connect using:
IP address
FQDN
VNC
Virtual Network Computing
VNC is an alternative to RDP for remote desktop access.
macOS Screen Sharing uses VNC.
VNC operates over TCP port 5900.
Security varies between VNC implementations.
Not all VNC versions support secure connections.
macOS Screen Sharing is encrypted.
NLA
Network Level Authentication
You can choose whether to:
Allow older RDP clients, or
Require clients that support NLA.
NLA authenticates the user before creating the desktop session.
This helps protect against Denial-of-Service (DoS) attacks.
WinRM
Windows Remote Management
Microsoft's implementation of the WS-Management protocol.
Allows systems to exchange and access management information remotely.
Included in current Windows versions.
Microsoft's implementation of the WS-Management protocol.
Allows systems to exchange and access management information remotely.
Included in current Windows versions.
RMM
Remote Monitoring & Management
Primarily designed for Managed Service Providers (MSPs).
MSPs provide IT support for multiple client organisations.
RMM tools can:
Separate/manage different client accounts.
Monitor systems remotely.
Record support activity.
Track/report billable support work.
WOL
Wake on LAN
Can remotely wake/start compatible machines.
May also support:
Firmware/BIOS configuration
Firmware updates
OS deployment
SPICE
Simple Protocol for Independent Computing Environments
Used for remote display and interaction with virtual machines (VMs).
Allows users/admins to monitor and interact with VMs remotely, including across the Internet.
Windows Event Viewer
Event Viewer is used to view and troubleshoot Windows system events and errors.
(eventvwr.msc)
System Information Tool
Provides a detailed overview of a Windows computer's hardware and software.
(msinfo32.exe)
Task Manager
Purpose: Monitors CPU, memory, disk, network, and running processes.
Performance tab: Provides detailed information about:
CPU
Memory (RAM)
Disk
Network
GPU
Performance Monitoring Tools
Provides more detailed monitoring than Task Manager.
Shows resource performance graphs and statistics.
Can track:
Processes and threads
Memory usage
Hard page faults per second
A continuous increase in certain statistics may indicate a performance problem.
(resmon.exe)
Performance Monitor
Provides real-time charts and long-term performance logging.
More detailed than Task Manager's Performance tab.
Helps identify system bottlenecks, such as:
Slow CPU
Slow disk
Network problems
Useful for determining which hardware or component may need upgrading.
(perfmon.exe)
System Configuration
Purpose: Controls settings that affect Windows startup and booting.
Main use: Diagnostic troubleshooting, not usually for permanent configuration changes.
Open it: Search System Configuration or run msconfig.exe
Windows Recovery Environment
Windows Recovery Environment (WinRE)
Used when Windows cannot boot normally.
Can be accessed through:
Recovery partition
Repair/recovery disk
Windows installation media
You may need to change the BIOS/UEFI boot priority to boot from recovery media.
Security Controls
Security controls are safeguards that reduce or prevent security risks.
Physical: Control access to physical locations.
Examples: Fences, doors, locks
Procedural: Security measures carried out by people.
Examples: Incident response, management oversight, security training
Logical: Digital/technical controls enforced by systems.
Examples: Authentication, antivirus, firewalls
CIA Triad
Confidentiality: Only authorized users can access sensitive information.
Integrity: Data remains accurate and trustworthy.
Availability: Systems and resources are accessible when needed.
Identity & Access Management
Identity & Access Management (IAM)
IAM ensures users have the right access to the right resources at the right time.
Identification: Identifies users, devices, and applications.
Authentication: Verifies who someone is.
Passwords
Biometrics
Multi-factor authentication (MFA)
Authorization: Determines what the user is allowed to do.
Access Control: Enforces those permissions and restrictions.
Access Control Lists
Access Control Lists (ACLs)
A permission determines what access an account has to a resource.
An ACL contains rules called Access Control Entries (ACEs).
Each ACE identifies a subject and its permitted actions.
Subjects can include:
Users
Computers
Services
Windows uses a unique Security Identifier (SID) for accounts.
Symmetric Encryption
Uses one secret key to both encrypt and decrypt data.
The key must remain secret.
If the key is stolen or lost, security can be compromised.
Main weakness: secure key distribution and storage.
Main advantage: very fast, making it ideal for large amounts of data.
Example: AES (Advanced Encryption Standard).
Asymmetric Encryption
Uses a key pair:
Public key: Can be shared openly.
Private key: Must remain secret.
The keys are mathematically linked.
Data encrypted with one key can only be reversed using the paired key.
Main advantage: secure communication without having to secretly distribute the public key.
The private key cannot be derived from the public key.
Cryptographic Hashing
Converts data of any size into a fixed-length hash value.
A cryptographic hash is one-way — the original data cannot practically be recovered from the hash.
Useful when the original data doesn't need to be retrieved.
Common use: secure password storage.
Common algorithms:
SHA-256
SHA-3
Just-in-Time (JIT) Access
Grants access only when it is needed.
Access is available for only as long as required.
Reduces the time an account has elevated access.
Supports the principle of least privilege.
Privileged Access Management (PAM)
Secures, controls, and monitors privileged accounts.
Important because compromised administrator accounts can cause major system damage.
Helps control and reduce unnecessary administrative access.
User Account Control (UAC)
Windows security feature that protects against malware and unauthorized privileged actions.
Implements least privilege by requiring explicit approval for elevated tasks.
A Security Shield icon indicates actions protected by UAC.
Security Assertions Markup Language
Security Assertions Markup Language (SAML)
Enables a form of SSO between an Identity Provider (IdP) and a Service Provider (SP).
Single Sign-On
Single Sign-On (SSO)
Authenticate once → Access multiple services.
Windows domain SSO commonly uses Kerberos + Active Directory.
Advantages:
Fewer passwords to manage.
Easier user experience.
Disadvantage:
If the account is compromised, multiple services may be compromised.