Week 1: Computer & Network Security Study Guide

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/78

flashcard set

Earn XP

Description and Tags

Comprehensive vocabulary flashcards covering concepts, architectures, threat categories, attack responses, security services and mechanisms, standards organizations, penetration testing roles, models, certifications, and frameworks from Week 1 of Computer & Network Security.

Last updated 9:43 PM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

79 Terms

1
New cards

Cybersecurity

The collection of tools, policies, security concepts, security safeguards, guidelines, risk management approaches, actions, training, best practices, assurance, and technologies that can be used to protect the cyberspace environment and organization and users’ assets.

2
New cards

Information Security

Preservation of confidentiality, integrity, and availability of information.

3
New cards

Network Security

Protection of networks and their service; prevent unauthorized modification, destruction or disclosure; provide assurance that networks perform their critical functions correctly.

4
New cards

CIA Triad

Confidentiality, integrity, and availability.

5
New cards

Confidentiality (data confidentiality)

Assures that private or confidential information is not made available or disclosed to unauthorized individuals.

6
New cards

Privacy

Assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.

7
New cards

Data Integrity

Assures that data and programs are changed only in a specified and authorized manner.

8
New cards

System Integrity

Assures that a system performs its intended function in an unimpaired manner, free from deliberate or inadvertent unauthorized manipulation of the system.

9
New cards

Availability

Assures that systems work promptly and service is not denied to authorized users.

10
New cards

Authenticity

Property of being genuine and being able to be verified and trusted.

11
New cards

Accountability

The security goal that generates the requirement for actions of an entity to be traced uniquely to that entity.

12
New cards

OSI Security Architecture — Security attack

Any action that compromises the security of information owned by an organization.

13
New cards

OSI Security Architecture — Security mechanism

A process (or a device incorporating such a process) that is designed to detect, prevent, or recover from a security attack.

14
New cards

OSI Security Architecture — Security service

A processing or communication service that enhances the security of the data processing systems and the information transfers of an organization.

15
New cards

Security services vs. mechanisms

Security services are intended to counter security attacks, and they make use of one or more security mechanisms to provide the service.

16
New cards

Threat

A potential for violation of security, which exists when there is a circumstance, capability, action, or event that could breach security and cause harm.

17
New cards

Attack

An assault on system security that derives from an intelligent threat; a deliberate attempt to evade security services and violate the security policy of a system.

18
New cards

Passive attack

Attempts to learn or make use of information from the system; does not affect system resources.

19
New cards

Active attack

Alters system resources and affects their operation; involves modification of a data stream or creating a false data stream.

20
New cards

Release of message contents

A passive attack in which the contents of a telephone conversation, an e-mail, or a file may be accessed by unauthorized people.

21
New cards

Traffic analysis

A passive attack in which opponents observe the pattern of messages even if content is hidden by encryption, including communicating hosts and frequency and length of messages.

22
New cards

Why passive attacks are difficult to detect

They do not involve any alteration of the data; message traffic is sent and received in an apparently normal fashion.

23
New cards

Passive attack defense emphasis

Emphasis is on prevention rather than detection.

24
New cards

Masquerade

Takes place when one entity pretends to be a different entity.

25
New cards

Replay

Involves the passive capture of a data unit and subsequent retransmission to produce an unauthorized effect.

26
New cards

Data modification attack

Some portion of a legitimate message is altered, or messages are delayed or reordered to produce an unauthorized effect.

27
New cards

Denial of Service (DoS)

Prevents or inhibits the normal use or management of communications facilities.

28
New cards

Active attack response

Difficult to prevent due to variety of potential vulnerabilities; dealt with by detection followed by recovery.

29
New cards

Authentication security service

Concerned with assuring that a communication is authentic.

30
New cards

Peer entity authentication

Provides for the corroboration of the identity of a peer entity in an association.

31
New cards

Data origin authentication

Provides for the corroboration of the source of a data unit. It does not provide protection against the duplication or modification of data units.

32
New cards

Access control security service

The ability to limit and control the access to host systems and applications via communications links.

33
New cards

Data confidentiality service

The protection of transmitted data from passive attacks.

34
New cards

Traffic-flow confidentiality

Requires that an attacker not be able to observe the source and destination, frequency, length, or other characteristics of the traffic on a communications facility.

35
New cards

Connection-oriented integrity service

Assures that messages are received as sent with no duplication, insertion, modification, reordering, or replays.

36
New cards

Connectionless integrity service

Generally provides protection against message modification only in a larger context.

37
New cards

Nonrepudiation

Prevents either sender or receiver from denying a transmitted message.

38
New cards

Availability security service

Protects a system to ensure its availability; addresses the security concerns raised by denial-of-service attacks.

39
New cards

Reversible cryptographic mechanism

An encryption algorithm that allows data to be encrypted and subsequently decrypted.

40
New cards

Irreversible cryptographic mechanisms

Include hash algorithms and message authentication codes, which are used in digital signatures and authentication.

41
New cards

Data integrity mechanism

Mechanisms used to assure the integrity of a data unit or stream of data units.

42
New cards

Digital signature

Data appended to, or a cryptographic transformation of, a data unit that allows a recipient to prove the source and integrity of the data unit and protect against forgery.

43
New cards

Authentication exchange

A mechanism intended to ensure the identity of an entity by means of information exchange.

44
New cards

Traffic padding

The insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

45
New cards

Routing control

Enables selection of particular physically or logically secure routes for certain data and allows routing changes, especially when a breach of security is suspected.

46
New cards

Notarization

The use of a trusted third party to assure certain properties of a data exchange.

47
New cards

Access control mechanism

A variety of mechanisms that enforce access rights to resources.

48
New cards

NIST

a U.S. federal agency that deals with measurement science, standards, and technology.

49
New cards

Internet Society

A professional membership society that provides leadership in addressing issues that confront the future of the Internet.

50
New cards

RFC

Request for Comments; Internet standards and related specifications are published as RFCs.

51
New cards

ITU

International Telecommunication Union; an organization within the United Nations System in which governments and the private sector coordinate global telecom networks and services.

52
New cards

ISO

International Organization for Standardization; a nongovernmental organization that promotes development of standardization and related activities.

53
New cards

Penetration test

Attempt to break into a company’s network to find the weak links.

54
New cards

Vulnerability assessment

Tester attempts to enumerate all vulnerabilities found in an application or on a system.

55
New cards

Security test

Tester analyzes a company’s security policy and procedures and reports any vulnerabilities to management.

56
New cards

Hacker (U.S. DOJ definition)

A person who accesses a computer or network without the owner’s permission; the U.S. Department of Justice labels all illegal access as hacking.

57
New cards

Cracker

Breaks into systems to steal or destroy data.

58
New cards

Ethical hacker

Performs most of the same activities a hacker does, with the permission of the owner or company.

59
New cards

Penetration tester / security tester

An ethical hacker; hired by companies to perform penetration tests.

60
New cards

Script kiddies / packet monkeys

Inexperienced people who copy code or use tools created by knowledgeable programmers without understanding how they work.

61
New cards

Hacktivist

A person who hacks computer systems for political or social reasons.

62
New cards

Script

A set of instructions that runs in sequence to perform tasks on a computer system.

63
New cards

Penetration tester duties

Perform vulnerability, attack, and penetration assessments; discovery and scanning for open ports and services; apply appropriate exploits; document discoveries and report to the client.

64
New cards

White box model

Tester is told what network topology and technology the company is using; may be given a floor plan and permitted to interview IT personnel and employees.

65
New cards

Black box model

Tester is not given any diagrams or details about the technologies used; burden is on the tester to find details. Tests security personnel’s ability to detect an attack.

66
New cards

Gray box model

Hybrid of the white and black box models; company gives tester only partial information.

67
New cards

Acceptable Use Policy (ISP)

A section of the ISP contract to read; running scanning software that slows down network access or prevents users from accessing network components might create problems.

68
New cards

Legal precautions before security testing

Keep abreast of local laws, know what is allowed, read your ISP Acceptable Use Policy, and contact local law enforcement agencies before installing hacking tools where appropriate.

69
New cards

Illegal actions in security testing

Accessing a computer without permission; destroying data without permission; copying information without the owner’s permission; installing viruses on a network; denying users access to network resources.

70
New cards

Written contract

Using a contract is good business and may be useful in court; have an attorney read your contract before signing.

71
New cards

Skills needed to be a security tester

Knowledge of network and computer technology; ability to communicate with management and IT personnel; understanding of applicable laws; ability to apply necessary tools.

72
New cards

CompTIA Security+

A minimum certification for network security personnel, or equivalent knowledge; Network+ level knowledge is a prerequisite according to the slides.

73
New cards

CompTIA Network+

Network knowledge level listed as a prerequisite for Security+ in the slides.

74
New cards

CompTIA PenTest+

Advanced certification verifying skills in planning and scoping assessments, legal and compliance requirements, scanning, penetration testing, analysis, and reporting.

75
New cards

Offensive Security Certified Professional

Advanced certification requiring hands-on abilities; covers network and application exploits, writing scripts, and trying exploits on vulnerable systems.

76
New cards

Certified Ethical Hacker

EC-Council certification; the multiple-choice exam is based on 22 domains according to the slides.

77
New cards

Red team

People with varied skills who act as attackers and simulate real-world cyberattacks by performing penetration tests.

78
New cards

Blue team

Defenders who protect an organization’s infrastructure and data; roles include recovery, incident response, and log analysis.

79
New cards

Purple team

A hybrid cooperative approach involving red and blue teams.