Computer Security Exam 1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/147

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:22 PM on 10/3/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

148 Terms

1
New cards

Confidentiality

Only authorized people can read or see the data

2
New cards

Integrity

Data is not altered without detection or authorization

3
New cards

Availability

Systems and data are accessible when needed

4
New cards

CIA triad

Confidentiality Integrity and Availability - the three core security goals

5
New cards

Asset

Anything of value that must be protected such as data servers or reputation

6
New cards

Threat

A potential cause of harm such as an attacker malware insider or natural disaster

7
New cards

Vulnerability

A weakness that a threat can exploit such as unpatched software or a weak password

8
New cards

Risk

The chance a threat exploits a vulnerability to harm an asset

9
New cards

Type 1 hypervisor

Runs directly on hardware (bare metal) such as ESXi or Hyper-V

10
New cards

Type 2 hypervisor

Runs on top of a host OS such as VirtualBox or VMware Workstation

11
New cards

Symmetric encryption

One shared secret key encrypts and decrypts - fast and used for bulk data

12
New cards

Asymmetric encryption

Public/private key pair - public encrypts or verifies and private decrypts or signs - slow

13
New cards

Key distribution problem

The main weakness of symmetric encryption - how to share the key safely

14
New cards

Hybrid encryption

Asymmetric exchanges a symmetric key and then symmetric encrypts the data - used in TLS and PGP

15
New cards

Plaintext

Original readable data before encryption

16
New cards

Ciphertext

Unreadable encrypted output

17
New cards

Salt

Random non-secret value added to a password before hashing - defeats rainbow tables and is stored with the hash

18
New cards

IV or nonce

Random value so the same plaintext encrypts to different ciphertext each time - not secret

19
New cards

Encoding

Reversible format conversion with no key and no security such as Base64

20
New cards

Base64

Encoding that turns binary data into printable text so it can be stored or sent safely - not encryption

21
New cards

Hashing

One-way function that turns any input into a fixed-size digest

22
New cards

AES

Secure symmetric block cipher - the current standard

23
New cards

DES

Old symmetric cipher with a 56-bit key - insecure and should not be used

24
New cards

3DES

DES applied three times - deprecated

25
New cards

ECB mode

Encrypts identical blocks to identical ciphertext and leaks patterns - should not be used

26
New cards

GCM mode

Secure AES mode that provides encryption plus integrity (authenticated encryption)

27
New cards

CBC mode

AES mode that chains blocks using an IV

28
New cards

PBKDF2

Key derivation function that turns a password plus salt plus many iterations into a strong key - slow on purpose

29
New cards

PBKDF2 vs AES

PBKDF2 creates the key from a password and AES uses that key to encrypt the data

30
New cards

KDF

Key derivation function - derives a cryptographic key from a password or secret

31
New cards

bcrypt / scrypt / Argon2

Slow salted password hashing algorithms for storing passwords

32
New cards

RSA

Asymmetric algorithm based on factoring large primes - use 2048 bits or more

33
New cards

ECC

Elliptic curve cryptography - asymmetric with smaller keys at the same strength

34
New cards

Diffie-Hellman

Key exchange that lets two parties agree on a shared secret over an insecure channel

35
New cards

SHA-256

Secure hash function producing a 256-bit digest

36
New cards

MD5 and SHA-1

Broken hash functions with known collisions - should not be used

37
New cards

Collision

Two different inputs producing the same hash

38
New cards

Rainbow table

Precomputed table of hashes to passwords - defeated by salts

39
New cards

Dictionary attack

Hashing common words and passwords to find a matching hash

40
New cards

Brute force attack

Trying every possible key or password

41
New cards

Avalanche effect

A tiny input change completely changes the hash output

42
New cards

HMAC

Hash combined with a secret key to provide integrity and authenticity

43
New cards

Digital signature

Hash of a message encrypted with the sender's private key - provides authenticity integrity and non-repudiation

44
New cards

Creating a signature

Hash the message then sign the hash with the sender's private key

45
New cards

Verifying a signature

Hash the message and check it against the signature using the sender's public key

46
New cards

Non-repudiation

The sender cannot deny sending the message

47
New cards

Password manager design

Master password plus salt through PBKDF2 makes an AES key that encrypts the vault - stored Base64-encoded

48
New cards

Shor's algorithm

Quantum algorithm that breaks RSA and ECC and Diffie-Hellman

49
New cards

Grover's algorithm

Quantum algorithm that halves effective symmetric key strength - AES-256 stays safe

50
New cards

Quantum vulnerable

Asymmetric cryptography is more vulnerable to quantum than symmetric

51
New cards

Post-quantum cryptography

New algorithms resistant to quantum attacks such as ML-KEM (Kyber)

52
New cards

Certificate Authority (CA)

Trusted organization that verifies identity and signs certificates

53
New cards

Root CA

Top of the trust chain - self-signed and preinstalled in the OS or browser trust store - kept offline

54
New cards

Intermediate CA

Signed by the root and signs server certificates - protects the root

55
New cards

Chain of trust

Server certificate to intermediate CA to root CA

56
New cards

Two functions of a certificate

Authenticate the server identity and distribute its public key

57
New cards

Let's Encrypt

Free automated nonprofit CA issuing 90-day domain-validated certificates via ACME/certbot

58
New cards

ACME

Protocol Let's Encrypt uses to automatically prove domain control and issue certificates

59
New cards

TLS

Protocol that secures HTTPS with confidentiality integrity and authentication

60
New cards

TLS asymmetric use

Handshake - authenticate the server and exchange or agree on keys

61
New cards

TLS symmetric use

Encrypting the actual data after the handshake

62
New cards

Session key

Temporary symmetric key used for one connection only

63
New cards

Forward secrecy

Past sessions stay safe even if the server's private key is stolen later - uses ephemeral DH (ECDHE)

64
New cards

ECDHE

Ephemeral elliptic curve Diffie-Hellman - new keys per session that give forward secrecy

65
New cards

TLS handshake goal

Authenticate the server and agree on a shared session key and cipher suite

66
New cards

ClientHello

First handshake message - supported versions and cipher suites and key share

67
New cards

ServerHello

Server picks the cipher suite and sends its key share and certificate

68
New cards

Certificate warning causes

Expired - hostname mismatch - self-signed - untrusted CA - revoked - or man-in-the-middle

69
New cards

TCP SYN flood

Many half-open connections exhaust the server - an availability attack - defended by SYN cookies

70
New cards

ARP spoofing

Fake ARP replies map the attacker's MAC to the gateway IP - enables man-in-the-middle on a LAN

71
New cards

DNS spoofing / cache poisoning

Fake DNS answers send users to the attacker's IP

72
New cards

IP spoofing

Forging the source IP address of packets

73
New cards

Man-in-the-middle

Attacker secretly intercepts and can alter traffic between two parties

74
New cards

DDoS

Distributed denial of service - many machines flood a target - an availability attack

75
New cards

IP

Network layer protocol for addressing and routing packets - connectionless and best effort

76
New cards

TCP

Transport layer protocol for reliable ordered connection-oriented delivery

77
New cards

UDP

Transport layer protocol that is connectionless and fast with no delivery guarantee

78
New cards

Three-way handshake

TCP setup - SYN then SYN-ACK then ACK

79
New cards

Port

Identifies the application or service on a host

80
New cards

Socket

IP address plus port number

81
New cards

Port 22

SSH

82
New cards

Port 25

SMTP (email)

83
New cards

Port 53

DNS

84
New cards

Port 80

HTTP

85
New cards

Port 443

HTTPS

86
New cards

Network zone

Group of systems with the same trust level separated by firewalls

87
New cards

DMZ

Zone for public-facing servers between the internet and the internal network

88
New cards

Firewall role in zones

Sits at zone boundaries and controls which traffic may cross - default deny

89
New cards

Packet filter firewall

Stateless - checks each packet's IP and port and protocol alone

90
New cards

Stateful firewall

Tracks connection state and allows return traffic for established connections

91
New cards

Application firewall / WAF

Inspects Layer 7 payload content

92
New cards

whois

Looks up domain registration info - registrar - name servers - dates

93
New cards

nmap

Scans networks for live hosts and open ports and services and OS

94
New cards

nmap -sS

SYN stealth scan

95
New cards

nmap -sV

Detects service versions

96
New cards

nmap -O

Detects the operating system

97
New cards

dig / nslookup

Query DNS records

98
New cards

DNS

Translates domain names into IP addresses

99
New cards

DNSSEC

Digitally signs DNS records so answers can be verified

100
New cards

DNS amplification

Small spoofed queries cause large responses sent to the victim