A+ Security Basics

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/100

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:13 AM on 9/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

101 Terms

1
New cards

Barricades / Bollards

Metal or concrete barriers that prevent physical access, particularly by vehicles.

2
New cards

Access Control Vestibule

A secured entry area with multiple doors designed so access through one door affects the locking of the others.

3
New cards

What is a Badge Reader?

What kind of tech does it use?

Grants physical access using an access card, commonly through magnetic stripe, RFID, or NFC.

4
New cards

Video Surveillance

Monitoring and recording areas to detect motion, objects, faces, license plates, and other activity.

5
New cards

Circuit-Based Alarm

An alarm triggered when an electrical circuit detects a change- such as a broken wire or tripped sensor.

6
New cards

Motion-Detection Alarm

An alarm triggered when a sensor detects unexpected movement.

7
New cards

Duress Alarm

An alarm manually activated by a person during an emergency.

8
New cards

Common Types of Door Locks

Conventional, deadbolt, electronic, token-based, and biometric.

9
New cards

Mantrap

Two interlocking doors where the first must close and lock before the second opens.

10
New cards

Equipment Lock

A physical lock used to prevent unauthorized access to critical hardware.

11
New cards

Guards and Access Lists

Guards verify identities and use authorized-access/visitor lists to control entry.

12
New cards

Privacy Filter Screen

Prevents people viewing a screen from an angle from easily seeing its contents.

13
New cards

Key Fob

A device used to gain access to secured areas, often replacing a traditional key.

14
New cards

Smart Card

A card containing an embedded chip used for authentication and access control.

15
New cards

Mobile Digital Key

A digital credential stored on a smartphone that replaces a physical key.

16
New cards

Biometrics

Authentication based on physical or behavioral characteristics such as fingerprints, face, retina, handprint, or voice.

17
New cards

Physical Security Purpose of Lighting

Improves visibility and makes surveillance cameras more effective.

18
New cards

Magnetometer

A metal detector.

19
New cards

Hardware Token

A physical authentication device used to prove possession, such as a USB security key or code-generating token.

20
New cards

Principle of Least Privilege

Give users only the minimum rights and permissions necessary to perform their assigned tasks.

21
New cards

Zero Trust

A security model in which users, devices, and processes are not automatically trusted and must be authenticated/verified.

22
New cards

ACL (Access Control List)

A list that permits or denies access to computing resources based on defined criteria.

It is the exact form of the rules that AD DS generates and applies to security groups.

23
New cards

What are ACL criteria options for network devices?

  • Source IP

  • Destination IP

  • TCP/UDP ports

  • ICMP.


24
New cards

ACL vs. Firewall

An ACL allows/denies traffic using defined rules at a specific point; a firewall provides broader traffic inspection and control.

25
New cards

MFA (Multi-Factor Authentication)

Authentication using two or more different authentication factors.

26
New cards

Authentication Factor: Something You Know

An authentication factor such as a password or PIN.

27
New cards

Authentication Factor: Something You Have

An authentication factor such as a phone, smart card, or hardware token.

28
New cards

Authentication Factor: Something You Are

A biometric factor such as fingerprint, face, or retina.

29
New cards

Authentication Factor: Somewhere You Are

Authentication based on location.

30
New cards

If you authenticate with two passwords, is that MFA?

No; both represent the same factor (something you know).

31
New cards

What is Authentication via Email?

Using an associated email address as part of identity verification, registration, or account recovery/modification.

32
New cards

What is Authentication via text/SMS?

Sending an authentication code to a predefined phone number through SMS.

33
New cards

Weakness of SMS Authentication

Phone numbers/messages can be compromised, reassigned, spoofed, or intercepted.

34
New cards

Voice-Call Authentication

Delivering an authentication token/code through a phone call instead of SMS.

35
New cards

Authentication App

A mobile application that generates authentication tokens/codes.

36
New cards

OTP (One-Time Password)

A one-time password/code valid for only one authentication attempt or session.

37
New cards

TOTP (Time-Based OTP)

A time-based OTP that changes at fixed intervals, commonly every 30 seconds.

38
New cards

OTP vs. TOTP

OTP is the broader one-time-password concept; TOTP is an OTP generated based on time synchronization.

39
New cards

SAML (Security Assertion Markup Language)

An open standard used to provide SSO to internet/cloud applications through an identity provider.

40
New cards

SSO (Single Sign-On)

Allows a user to access multiple applications using one set of credentials/login.

41
New cards

SAML and SSO Relationship

SAML can be used to implement SSO between applications and an identity provider.

42
New cards

Just-in-Time (JIT) Access

Privileged access granted temporarily when needed and revoked afterward.

43
New cards

Purpose of JIT Access

Reduces the amount of time an account has elevated privileges.

44
New cards

PAM (Privileged Access Management)

The specific strategy of designing how elevated administrative access is granted to systems.

Subset of IAM, not for all users.

45
New cards

Capabilities of PAM

Centralized password management, automated privileged access, tracking, and auditing.

46
New cards

MDM (Mobile Device Management)

Centralized organizational management of mobile devices and their policies.

47
New cards

COPE vs. BYOD

COPE = company-owned devices; BYOD = user-owned devices used for work.

48
New cards

What is an MDM Control Scope?

The specific boundaries, users, or device groups that a given MDM policy applies to.

49
New cards

DLP (Data Loss Prevention)

Policies/technologies designed to prevent sensitive data from being lost or accessed by unauthorized parties.

50
New cards

Who relies more on DLP strategies- individual users or large enterprises / ISPs?

Large enterprises / ISPs.

51
New cards

IAM (Identity and Access Management)

A framework for ensuring the right identities receive the right access at the right time.

52
New cards

Major IAM Functions

Providing and authenticating user identities, controlling access and permissions, and tracking activity for auditing.

AAA.

53
New cards

IAM vs. PAM

IAM manages identities/access broadly; PAM specifically manages privileged/admin access and is a subset of IAM.

PAM is not for all users, but IAM is.

54
New cards

What is a directory service?

A centralized database containing network objects and identity information.

AD DS is the Windows directory service.

55
New cards

Directory Service Objects

Computers, user accounts, file shares, printers, and groups.

56
New cards

What is Microsoft's Windows proprietary directory service?

Active Directory.

57
New cards

Microsoft Defender Antivirus

Windows' built-in antivirus/anti-malware software that continuously scans for malware and helps prevent/remove it.

58
New cards

Where to access settings of Microsoft Defender Antivirus

Windows Security → Virus & threat protection.

59
New cards

Importance of Antivirus Definition Updates

Antivirus needs current malware signatures/definitions to recognize newer threats.

60
New cards

Microsoft Defender Firewall

Windows' built-in firewall that filters network traffic according to firewall rules.

61
New cards

Port Security (Firewall)

Allowing or blocking network traffic based on ports/protocols.

62
New cards

Application Security (Firewall)

Permitting or blocking specific applications from communicating over the network.

63
New cards

Windows Firewall Network Profiles

Domain, Private, and Public.

64
New cards

Public Firewall Profile

Appropriate when connected to a public/untrusted network.

65
New cards

Private Firewall Profile

Appropriate on a trusted private network, such as a home network.

66
New cards

Domain Firewall Profile

Used when the computer is connected to an organizational domain network.

67
New cards

Local Account vs. Microsoft Account

A local account authenticates against one Windows computer; a Microsoft account is cloud-connected and synchronizes services/settings across devices.

68
New cards

What is the configuration path for managing Local Users and Groups?

Computer Management → Local Users and Groups.

69
New cards

Power User

A legacy Windows user type between standard user and administrator that has little modern usefulness.

70
New cards

Different options for logging into Windows?

Username/password, PIN, biometrics, and SSO.

71
New cards

Windows Hello

Windows authentication functionality that can use methods such as biometrics, PINs, and security keys.

72
New cards

NTFS (New Technology File System)

The standard Windows file system supporting features such as permissions, encryption, compression, and recoverability.

73
New cards

Windows Share

A method of making files/folders available to users over a network.

74
New cards

The four attributes a Windows File/Folder can have?

  • Read-only

  • System

  • Hidden

  • Archive


75
New cards

NTFS Permissions

Permissions controlling access to files/folders locally and over the network.

76
New cards

Share Permissions

Permissions controlling access to a shared folder over the network (does not apply to local access).

77
New cards

What is the rule for when NTFS and Share Permissions overlap?

When both are overlapping, Windows evaluates both sets of permission rules and applies the most restrictive of the two.

78
New cards

What happens if Allow permission and Deny permission overlap/conflict?

A Deny permission generally overrides an Allow permission.

79
New cards

Inherited Permissions

Permissions received from a parent folder/object.

80
New cards

Explicit Permissions

Permissions directly assigned to an Active Directory or group policy object.

81
New cards

Run as Administrator

Runs an application with elevated privileges when authorized.

82
New cards

UAC (User Account Control)

Windows feature that prevents unauthorized changes to the OS by asking for administrator credentials or approval.

83
New cards

BitLocker

Windows full-disk encryption that encrypts an entire drive/partition, including OS data.

84
New cards

What is BitLocker’s physical theft protection?

Data remains encrypted even if the physical drive is removed from the computer.

85
New cards

BitLocker To Go

BitLocker encryption for removable drives such as USB flash drives.

86
New cards

EFS (Encrypting File System)

Encrypts individual files/folders at the file-system level rather than an entire disk.

87
New cards

BitLocker vs. EFS

BitLocker encrypts an entire drive/partition; EFS encrypts individual files/folders.

88
New cards

Active Directory Domain Services (AD DS)

Microsoft's directory service for centrally organizing, authenticating, and managing domain objects.

89
New cards

What are managed objects in the Active Directory?

Users, computers, groups, and other organizational/network resources.

90
New cards

Domain (Active Directory)

A logical grouping of users, computers, and resources managed together.

91
New cards

Domain Controller

A server that hosts and maintains a copy of the Active Directory database.

92
New cards

What occurs when you add a Computer to a Domain?

It automatically adds the computer to the centrally managed domain environment.

93
New cards

OU (Organizational Unit)

A logical container used to hold users accounts, computers, and other OUs.

The OU is the group to which a group policy will be applied.

94
New cards

Active Directory Users and Computers (ADUC).

Tne tool to Manage AD Users, Computers, and Groups

95
New cards

Group Policy

Centralized management of Windows user and computer configurations.

96
New cards

Examples of things a Group Policy can enable/disable?

Items such as application settings, login scripts, network configurations, and security parameters.

97
New cards

GPO (Group Policy Object)

A collection of settings applied to users/computers through Group Policy.

98
New cards

Command to Force Group Policy Update

gpupdate /force

99
New cards

Login Script

A script/program/command configured to run automatically when a user logs in.

100
New cards

Folder Redirection

Redirecting Windows folders such as Desktop/Documents to a central network location while appearing normal to the user.