1/100
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Barricades / Bollards
Metal or concrete barriers that prevent physical access, particularly by vehicles.
Access Control Vestibule
A secured entry area with multiple doors designed so access through one door affects the locking of the others.
What is a Badge Reader?
What kind of tech does it use?
Grants physical access using an access card, commonly through magnetic stripe, RFID, or NFC.
Video Surveillance
Monitoring and recording areas to detect motion, objects, faces, license plates, and other activity.
Circuit-Based Alarm
An alarm triggered when an electrical circuit detects a change- such as a broken wire or tripped sensor.
Motion-Detection Alarm
An alarm triggered when a sensor detects unexpected movement.
Duress Alarm
An alarm manually activated by a person during an emergency.
Common Types of Door Locks
Conventional, deadbolt, electronic, token-based, and biometric.
Mantrap
Two interlocking doors where the first must close and lock before the second opens.
Equipment Lock
A physical lock used to prevent unauthorized access to critical hardware.
Guards and Access Lists
Guards verify identities and use authorized-access/visitor lists to control entry.
Privacy Filter Screen
Prevents people viewing a screen from an angle from easily seeing its contents.
Key Fob
A device used to gain access to secured areas, often replacing a traditional key.
Smart Card
A card containing an embedded chip used for authentication and access control.
Mobile Digital Key
A digital credential stored on a smartphone that replaces a physical key.
Biometrics
Authentication based on physical or behavioral characteristics such as fingerprints, face, retina, handprint, or voice.
Physical Security Purpose of Lighting
Improves visibility and makes surveillance cameras more effective.
Magnetometer
A metal detector.
Hardware Token
A physical authentication device used to prove possession, such as a USB security key or code-generating token.
Principle of Least Privilege
Give users only the minimum rights and permissions necessary to perform their assigned tasks.
Zero Trust
A security model in which users, devices, and processes are not automatically trusted and must be authenticated/verified.
ACL (Access Control List)
A list that permits or denies access to computing resources based on defined criteria.
It is the exact form of the rules that AD DS generates and applies to security groups.
What are ACL criteria options for network devices?
Source IP
Destination IP
TCP/UDP ports
ICMP.
ACL vs. Firewall
An ACL allows/denies traffic using defined rules at a specific point; a firewall provides broader traffic inspection and control.
MFA (Multi-Factor Authentication)
Authentication using two or more different authentication factors.
Authentication Factor: Something You Know
An authentication factor such as a password or PIN.
Authentication Factor: Something You Have
An authentication factor such as a phone, smart card, or hardware token.
Authentication Factor: Something You Are
A biometric factor such as fingerprint, face, or retina.
Authentication Factor: Somewhere You Are
Authentication based on location.
If you authenticate with two passwords, is that MFA?
No; both represent the same factor (something you know).
What is Authentication via Email?
Using an associated email address as part of identity verification, registration, or account recovery/modification.
What is Authentication via text/SMS?
Sending an authentication code to a predefined phone number through SMS.
Weakness of SMS Authentication
Phone numbers/messages can be compromised, reassigned, spoofed, or intercepted.
Voice-Call Authentication
Delivering an authentication token/code through a phone call instead of SMS.
Authentication App
A mobile application that generates authentication tokens/codes.
OTP (One-Time Password)
A one-time password/code valid for only one authentication attempt or session.
TOTP (Time-Based OTP)
A time-based OTP that changes at fixed intervals, commonly every 30 seconds.
OTP vs. TOTP
OTP is the broader one-time-password concept; TOTP is an OTP generated based on time synchronization.
SAML (Security Assertion Markup Language)
An open standard used to provide SSO to internet/cloud applications through an identity provider.
SSO (Single Sign-On)
Allows a user to access multiple applications using one set of credentials/login.
SAML and SSO Relationship
SAML can be used to implement SSO between applications and an identity provider.
Just-in-Time (JIT) Access
Privileged access granted temporarily when needed and revoked afterward.
Purpose of JIT Access
Reduces the amount of time an account has elevated privileges.
PAM (Privileged Access Management)
The specific strategy of designing how elevated administrative access is granted to systems.
Subset of IAM, not for all users.
Capabilities of PAM
Centralized password management, automated privileged access, tracking, and auditing.
MDM (Mobile Device Management)
Centralized organizational management of mobile devices and their policies.
COPE vs. BYOD
COPE = company-owned devices; BYOD = user-owned devices used for work.
What is an MDM Control Scope?
The specific boundaries, users, or device groups that a given MDM policy applies to.
DLP (Data Loss Prevention)
Policies/technologies designed to prevent sensitive data from being lost or accessed by unauthorized parties.
Who relies more on DLP strategies- individual users or large enterprises / ISPs?
Large enterprises / ISPs.
IAM (Identity and Access Management)
A framework for ensuring the right identities receive the right access at the right time.
Major IAM Functions
Providing and authenticating user identities, controlling access and permissions, and tracking activity for auditing.
AAA.
IAM vs. PAM
IAM manages identities/access broadly; PAM specifically manages privileged/admin access and is a subset of IAM.
PAM is not for all users, but IAM is.
What is a directory service?
A centralized database containing network objects and identity information.
AD DS is the Windows directory service.
Directory Service Objects
Computers, user accounts, file shares, printers, and groups.
What is Microsoft's Windows proprietary directory service?
Active Directory.
Microsoft Defender Antivirus
Windows' built-in antivirus/anti-malware software that continuously scans for malware and helps prevent/remove it.
Where to access settings of Microsoft Defender Antivirus
Windows Security → Virus & threat protection.
Importance of Antivirus Definition Updates
Antivirus needs current malware signatures/definitions to recognize newer threats.
Microsoft Defender Firewall
Windows' built-in firewall that filters network traffic according to firewall rules.
Port Security (Firewall)
Allowing or blocking network traffic based on ports/protocols.
Application Security (Firewall)
Permitting or blocking specific applications from communicating over the network.
Windows Firewall Network Profiles
Domain, Private, and Public.
Public Firewall Profile
Appropriate when connected to a public/untrusted network.
Private Firewall Profile
Appropriate on a trusted private network, such as a home network.
Domain Firewall Profile
Used when the computer is connected to an organizational domain network.
Local Account vs. Microsoft Account
A local account authenticates against one Windows computer; a Microsoft account is cloud-connected and synchronizes services/settings across devices.
What is the configuration path for managing Local Users and Groups?
Computer Management → Local Users and Groups.
Power User
A legacy Windows user type between standard user and administrator that has little modern usefulness.
Different options for logging into Windows?
Username/password, PIN, biometrics, and SSO.
Windows Hello
Windows authentication functionality that can use methods such as biometrics, PINs, and security keys.
NTFS (New Technology File System)
The standard Windows file system supporting features such as permissions, encryption, compression, and recoverability.
Windows Share
A method of making files/folders available to users over a network.
The four attributes a Windows File/Folder can have?
Read-only
System
Hidden
Archive
NTFS Permissions
Permissions controlling access to files/folders locally and over the network.
Share Permissions
Permissions controlling access to a shared folder over the network (does not apply to local access).
What is the rule for when NTFS and Share Permissions overlap?
When both are overlapping, Windows evaluates both sets of permission rules and applies the most restrictive of the two.
What happens if Allow permission and Deny permission overlap/conflict?
A Deny permission generally overrides an Allow permission.
Inherited Permissions
Permissions received from a parent folder/object.
Explicit Permissions
Permissions directly assigned to an Active Directory or group policy object.
Run as Administrator
Runs an application with elevated privileges when authorized.
UAC (User Account Control)
Windows feature that prevents unauthorized changes to the OS by asking for administrator credentials or approval.
BitLocker
Windows full-disk encryption that encrypts an entire drive/partition, including OS data.
What is BitLocker’s physical theft protection?
Data remains encrypted even if the physical drive is removed from the computer.
BitLocker To Go
BitLocker encryption for removable drives such as USB flash drives.
EFS (Encrypting File System)
Encrypts individual files/folders at the file-system level rather than an entire disk.
BitLocker vs. EFS
BitLocker encrypts an entire drive/partition; EFS encrypts individual files/folders.
Active Directory Domain Services (AD DS)
Microsoft's directory service for centrally organizing, authenticating, and managing domain objects.
What are managed objects in the Active Directory?
Users, computers, groups, and other organizational/network resources.
Domain (Active Directory)
A logical grouping of users, computers, and resources managed together.
Domain Controller
A server that hosts and maintains a copy of the Active Directory database.
What occurs when you add a Computer to a Domain?
It automatically adds the computer to the centrally managed domain environment.
OU (Organizational Unit)
A logical container used to hold users accounts, computers, and other OUs.
The OU is the group to which a group policy will be applied.
Active Directory Users and Computers (ADUC).
Tne tool to Manage AD Users, Computers, and Groups
Group Policy
Centralized management of Windows user and computer configurations.
Examples of things a Group Policy can enable/disable?
Items such as application settings, login scripts, network configurations, and security parameters.
GPO (Group Policy Object)
A collection of settings applied to users/computers through Group Policy.
Command to Force Group Policy Update
gpupdate /force
Login Script
A script/program/command configured to run automatically when a user logs in.
Folder Redirection
Redirecting Windows folders such as Desktop/Documents to a central network location while appearing normal to the user.