Professor Messer SY0-701 All Acronyms

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/184

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:07 AM on 6/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

185 Terms

1
New cards

802.1X

IEEE 802.1X

Port-based Network Access Control (NAC). You don't get access to the network until you authenticate. Centralized authentication (802.1X).

2
New cards

AAA

Authentication, Authorization, Accounting

Identification (who you claim to be), authentication (prove it), authorization (what access), accounting (resources used).

3
New cards

ABAC

Attribute-Based Access Control

Users can have complex relationships to applications and data. Access may be based on many different criteria. A "next generation" authorization model.

4
New cards

ACL

Access Control List

Allow or disallow traffic. Groupings of categories: source IP, destination IP, port number, time of day, application, etc.

5
New cards

AD

Active Directory

A database of everything on the network. Computers, user accounts, file shares, printers, groups, and more. Primarily Windows-based.

6
New cards

AES

Advanced Encryption Standard

Encryption algorithm. Used in GCMP for data confidentiality. Performs AES encryption in hardware.

7
New cards

AIC

Availability, Integrity, Confidentiality

Alternate ordering of the CIA Triad.

8
New cards

ALE

Annualized Loss Expectancy

ARO x SLE.

9
New cards

API

Application Programming Interface

The "glue" for the microservices. Work together to act as the application. EDR is API driven. Integrations and APIs. Interact with third-party devices and services.

10
New cards

APT

Advanced Persistent Threat

Nation states. Constant attacks, massive resources. Commonly an APT.

11
New cards

ARO

Annualized Rate of Occurrence

How likely is it that a hurricane will hit? In Montana? In Florida?

12
New cards

ARP

Address Resolution Protocol

ARP poisoning. On-path attack on the local IP subnet. ARP has no security.

13
New cards

AUP

Acceptable Use Policy

What is acceptable use of company assets? Detailed documentation. May be documented in the Rules of Behavior. May be part of the employee handbook or a separate AUP.

14
New cards

AV

Asset Value

The value of the asset to the organization.

15
New cards

BFF

Basic Fuzzing Framework

CERT BFF.

16
New cards

BPA

Business Partners Agreement

Going into business together. Owner stake. Financial contract.

17
New cards

BYOD

Bring Your Own Device

Employee owns the device. Need to meet the company's requirements. You can't trust everyone's computer.

18
New cards

C2C

Cloud to Cloud

Always have backups. Cloud to Cloud (C2C).

19
New cards

CA

Certificate Authority

An organization has a trusted CA. Most organizations maintain their own CAs.

20
New cards

CCO

Central Compliance Officer

Large organizations have a CCO.

21
New cards

CERT

Computer Emergency Response Team

Carnegie Mellon CERT. CERT Basic Fuzzing Framework (BFF).

22
New cards

CIA

Confidentiality, Integrity, Availability

The fundamentals of security. Sometimes referenced as the AIC Triad.

23
New cards

CIS

Center for Internet Security

Popular benchmarks. https://www.cisecurity.org/cis-benchmarks/

24
New cards

COOP

Continuity of Operations Planning

Not everything goes according to plan. Disasters can cause a disruption to the norm.

25
New cards

COPE

Corporate Owned, Personally Enabled

Company buys the device. Used as both a corporate device and a personal device.

26
New cards

CRL

Certificate Revocation List

Maintained by the Certificate Authority (CA). Can contain many revocations in a large file.

27
New cards

CSR

Certificate Signing Request

Create a key pair, then send the public key to the CA to be signed.

28
New cards

CSRF

Cross-Site Request Forgery

One-click attack, session riding. Takes advantage of the trust that a web application has for the user.

29
New cards

CSS

Cascading Style Sheets

XSS was originally called cross-site because CSS was something else entirely.

30
New cards

CSV

Comma-Separated Values

Hybrid data format. CSV, XML, JSON, etc.

31
New cards

CTA

Cyber Threat Alliance

Members upload specifically formatted threat intelligence. CTA scores each submission.

32
New cards

CVE

Common Vulnerabilities and Exposures

The vulnerabilities can be cross-referenced online. https://cve.mitre.org/cve/

33
New cards

CVSS

Common Vulnerability Scoring System

Quantitative scoring of a vulnerability — 0 to 10. 63% of code in production are unpatched. Vulnerabilities rated high or critical (CVSS >= 7.0).

34
New cards

CYOD

Choose Your Own Device

Similar to COPE, but with the user's choice of device.

35
New cards

DAC

Discretionary Access Control

Used in most operating systems. You create a spreadsheet. As the owner, you control who has access. Linux traditionally uses DAC.

36
New cards

DAP

Directory Access Protocol

DAP ran on the OSI protocol stack. LDAP is lightweight.

37
New cards

DDoS

Distributed Denial of Service

Launch an army of computers to bring down a service. Use all the bandwidth or resources. Asymmetric threat. Botnet attack.

38
New cards

DKIM

Domain Keys Identified Mail

A mail server digitally signs all outgoing mail. The public key is in the DKIM TXT record.

39
New cards

DLL

Dynamic Link Library

A Windows library containing code and data. Many applications can use this library. Attackers inject a path to a malicious DLL.

40
New cards

DLP

Data Loss Prevention

Where's your data? Stop the data before the attacker gets it. Data "leakage."

41
New cards

DMARC

Domain-based Message Authentication, Reporting, and Conformance

An extension of SPF and DKIM. The domain owner decides what receiving email servers should do with emails not validating using SPF and DKIM.

42
New cards

DNS

Domain Name System

DNS poisoning. Modify the DNS server. DNS query: udp/53. DNS filtering. Perform a DNS lookup. SPF, DKIM, and DMARC all use DNS TXT records.

43
New cards

DoS

Denial of Service

Force a service to fail. Overload the service. Cause a system to be unavailable.

44
New cards

EAP

Extensible Authentication Protocol

An authentication framework. Many different ways to authenticate based on RFC standards. EAP integrates with 802.1X.

45
New cards

EDR

Endpoint Detection and Response

A different method of threat protection. Detect a threat, investigate the threat, respond to the threat. Posture assessment checks EDR version.

46
New cards

EF

Exposure Factor

The percentage of the value lost due to an incident.

47
New cards

EFS

Encrypting File System

Windows file level encryption.

48
New cards

EOL

End of Life

Manufacturer stops selling a product. May continue supporting the product. Important for security patches and updates.

49
New cards

EOSL

End of Service Life

Manufacturer stops selling a product. Support is no longer available. No ongoing security patches or updates.

50
New cards

ESI

Electronically Stored Information

Separate repository for ESI. Many different data sources and types.

51
New cards

FaaS

Function as a Service

Apps are separated into individual, autonomous functions. Also called serverless architecture.

52
New cards

FDE

Full Disk Encryption

Encrypt everything on the drive. BitLocker, FileVault, etc.

53
New cards

FIM

File Integrity Monitoring

Some files change all the time. Some files should NEVER change. Monitor important operating system and application files.

54
New cards

FTP

File Transfer Protocol

Insecure protocol. All traffic sent in the clear. Many proxies are multipurpose proxies — HTTP, HTTPS, FTP, etc.

55
New cards

GCMP

Galois/Counter Mode Protocol

A stronger encryption than WPA2. Data confidentiality with AES. Message Integrity Check with GMAC.

56
New cards

GDPR

General Data Protection Regulation

European Union regulation. Data protection and privacy for individuals in the EU. Data collected on EU citizens must be stored in the EU.

57
New cards

GLBA

Gramm-Leach-Bliley Act

Disclosure of privacy information from financial institutions.

58
New cards

GMAC

Galois Message Authentication Code

Message Integrity Check (MIC) with GMAC.

59
New cards

GPS

Global Positioning System

Geolocation. Mobile devices, very accurate. Somewhere you are. Geolocation to a very specific area.

60
New cards

HA

High Availability

Always on, always available. May include many different components working together.

61
New cards

HIPAA

Health Insurance Portability and Accountability Act

Extensive healthcare standards for storage, use, and transmission of health care information. Privacy laws for everyone in a country.

62
New cards

HIPS

Host-based Intrusion Prevention System

Recognize and block known attacks. Secure OS and application configs, validate incoming service requests.

63
New cards

HSM

Hardware Security Module

Used in large environments. Clusters, redundant power. Securely store thousands of cryptographic keys.

64
New cards

HTTP

Hypertext Transfer Protocol

A proxy may only know one application — HTTP. In-the-clear web browsing. Port 80.

65
New cards

HTTPS

Hypertext Transfer Protocol Secure

Some sites are now HTTPS-only. Encrypted web browsing. Port 443.

66
New cards

HVAC

Heating, Ventilation, and Air Conditioning

Target Corp. breach. Heating and AC firm in Pennsylvania was infected. VPN credentials for HVAC techs was stolen.

67
New cards

IAM

Identity and Access Management

Give the right permissions to the right people at the right time. Prevent unauthorized access.

68
New cards

IaaS

Infrastructure as a Service

Cloud service model. Responsibility matrix.

69
New cards

ICMP

Internet Control Message Protocol

Used in DDoS reflection and amplification. An example of protocol abuse.

70
New cards

ICS

Industrial Control Systems

Large-scale, multi-site. PC manages equipment.

71
New cards

IDS

Intrusion Detection System

Alarm or alert. Does not prevent.

72
New cards

IMAP

Internet Message Access Protocol

Insecure protocol. All traffic sent in the clear.

73
New cards

IMAPS

IMAP Secure

Encrypted version of IMAP. Use the encrypted versions.

74
New cards

IoT

Internet of Things

Sensors, smart devices, wearable technology, facility automation. Weak defaults.

75
New cards

IPS

Intrusion Prevention System

Watch network traffic. Stop it before it gets into the network. Usually integrated into an NGFW. Different ways to find malicious traffic.

76
New cards

IPsec

Internet Protocol Security

Network-level encryption. IPsec tunnels, VPN connections. Site-to-site IPsec VPN. Always-on. Firewalls often act as VPN concentrators.

77
New cards

ISO

International Organization for Standardization

Many standards are already available. ISO, NIST.

78
New cards

ITU

International Telecommunications Union

Wrote the X.500 specification.

79
New cards

JSON

JavaScript Object Notation

Hybrid data format. CSV, XML, JSON, etc.

80
New cards

Kerberos

Kerberos

Used in conjunction with an authentication database. RADIUS, LDAP, TACACS+, Kerberos, etc.

81
New cards

LDAP

Lightweight Directory Access Protocol

Protocol for reading and writing directories over an IP network. An organized set of records, like a phone directory. Used in conjunction with an authentication database.

82
New cards

MAC

Mandatory Access Control

The operating system limits the operation on an object. Based on security clearance levels. Every object gets a label. SELinux adds MAC to Linux.

83
New cards

MD5

Message Digest 5

First published in April 1992. Collisions identified in 1996.

84
New cards

MDM

Mobile Device Manager or Mobile Device Management

Often need additional security policies and systems. An MDM becomes relatively useless after jailbreaking. Manage company-owned and user-owned mobile devices.

85
New cards

MFA

Multi-Factor Authentication

76% of organizations aren't using MFA for management console users. This is why we have MFA. Use another factor with the card.

86
New cards

MIB

Management Information Base

A database of data for SNMP.

87
New cards

MIC

Message Integrity Check

GCMP security services include MIC with GMAC.

88
New cards

MOA

Memorandum of Agreement

The next step above a MOU. Both sides conditionally agree to the objectives.

89
New cards

MOU

Memorandum of Understanding

Both sides agree in general to the contents. Usually states common goals.

90
New cards

MSA

Master Service Agreement

Legal contract and agreement of terms. A broad framework to cover later transactions.

91
New cards

MSP

Managed Service Provider

Supply chain vector. Access many different customer networks from one location.

92
New cards

MTBF

Mean Time Between Failures

The time between outages. Total uptime / number of breakdowns.

93
New cards

MTTR

Mean Time to Repair

Commonly referenced as resilience. How quickly can you recover? Average time required to fix an issue. Includes time spent diagnosing the problem.

94
New cards

NAC

Network Access Control

Port-based NAC. 802.1X prevents access to the network until the authentication succeeds. Agentless NAC. Integrated with Active Directory.

95
New cards

NAT

Network Address Translation

One of the simplest "proxies" is NAT. A network-level proxy. Most firewalls can be layer 3 devices (routers). NAT functionality.

96
New cards

NDA

Non-Disclosure Agreement

Confidentiality agreement between parties. Information in the agreement should not be disclosed. Private/classified/restricted data may require an NDA.

97
New cards

NetFlow

NetFlow

Gather traffic statistics from all traffic flows. Shared communication between devices.

98
New cards

NGFW

Next-Generation Firewall

The OSI Application Layer firewall. Can be called application layer gateway, stateful multilayer inspection, or deep packet inspection.

99
New cards

NIST

National Institute of Standards and Technology

Publishes SP800-61 Computer Security Incident Handling Guide. Technical Guide to Information Security Testing and Assessment. Managed by NIST. Many standards are already available from ISO and NIST.

100
New cards

NTP

Network Time Protocol

Used in DDoS reflection and amplification. An example of protocol abuse. NTP: udp/123.