Computer Security Exam 1 - TXST Randall Klepteko

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/49

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:51 AM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

50 Terms

1
New cards

Access Control (AC)

Rules that govern what Identities can access which resources.

2
New cards

Access Control List (ACL)

Defines rights for each resource, from the perspective of the resource.

3
New cards

Capability List (CL)

Defines rights for each subject, from the perspective of the subject.

4
New cards

Discretionary Access Control (DAC)

Access is defined by the owner of the file.

5
New cards

Role-Based Access Control (RBAC)

Access is defined by a person's job or title.

6
New cards

Attribute Based Access Control (ABAC)

Access is defined by various parameters like work shift, location, or department(attributes), offering more flexibility then roles.

7
New cards

Mandatory Access Control (MAC)

Access Clarification that discriminates security policies into different types usually based on department or data sensitivity. (Bell LaPadula/Biba)

8
New cards

Bell LaPadula

Restricts confidentiality, allowing information flow from lower to higher security levels

NO READ UP

NO WRITE DOWN

<p>Restricts confidentiality, allowing information flow from lower to higher security levels</p><p>NO READ UP</p><p>NO WRITE DOWN</p>
9
New cards

Biba Model

Supports integrity limiting information flow from higher to lower levels.

NO READ DOWN

NO WRITE UP

<p>Supports integrity limiting information flow from higher to lower levels.</p><p>NO READ DOWN</p><p>NO WRITE UP</p>
10
New cards

Access Control Matrix

Extensively defines access rules in detail by individual rights for all subjects and objects.

11
New cards

Clark Wilson Model

A policy model that enforces integrity through certification and auditing.

12
New cards

Availability

Security principle that resources are accessible.

13
New cards

Confidentiality

Security principle that information should only be shared with appropriate parties.

14
New cards

Integrity

Security principle that communication should not be modified between parties.

15
New cards

Protocol

Defines what actions are to be taken to implement security goals.

16
New cards

Practice

Implements the actions in attaining security

17
New cards

Polymorphic Virus

Changes its code without changing its algorithm to evade static detection.

18
New cards

Logic Bomb

A Program that resides in the background until a specific sets of facts occurs

19
New cards

Autorun Virus

A virus that runs as soon as a disk or (USB) is started. "Boot sector viruses and rootkits are related but aren't on exam."

20
New cards

Trojan Horse

A malicious program that looks and acts like a benign program.

21
New cards

Worm

A malicious program that replicates and propagates on its own.

22
New cards

Stealth Virus

Catches kernel traces and calls to remove any revealing details.

23
New cards

Update Trojan

A malicious program disguised as a software update, leveraging normal maintenance procedures.

24
New cards

Distributed Denial of Service

An attack that uses multiple agents against a single victim to deny availability

25
New cards

Social Engineering

Using society's norms and expectations as a method to generate a desired response.

26
New cards

Side-Channel Attack

An attack that uses signals recovered during an indirect method of reception

27
New cards

Man-In-The-Middle

An attack conducted by an individual watching packets in the communication handshake process

28
New cards

Brute Force

An attack where all possible combinations (passwords) are attempted.

29
New cards

Phising

An email designed and sent to an unsuspecting victim to solicit into taking various actions( African Prince, single email)

30
New cards

Catfishing

A formal social engineering technique where a series of texts, or emails are used to gain the confidence of a potential victim (Multiple Interactions)

31
New cards

Spear Phising

A phishing attempt directed at a specific individual or company, tailored to their intrests.

32
New cards

Spoofing

Creating a fake object (like a login page, Randall did to his teacher) designed to open an attack surface against someone who uses it.

33
New cards

Buffer Overflow

Pushing an input value past the edge of memory allocated

34
New cards

Dumpster Diving

The act of targeting the recycle bin for secrets

35
New cards

Zero-Day

An attack or vulnerability seen in the public for the first time

36
New cards

Penetration Tester

An outside party hired to validate a company's security

37
New cards

Shoulder Surfing

Watching while someone types a password

38
New cards

Reverse Engineering

To break apart an application to figure out how it works by generating source code from the applications code and examining it,

39
New cards

Fratenize

Building an individual relationship for either benign or malfeasant purposes.

40
New cards

Port Probing

A research methodology that scans remote targets for potential attack openings.

41
New cards

Cascading

A method for defining rule priority by only following the first rule activated

42
New cards

Steganography

The act of hiding data within plain sight in another medium

43
New cards

SSH (secure shell)

An application layer protocol that ensures secrecy regardless of the underling network security. It was developed to provide secure remote access over unencrypted protocols like Telnet.

44
New cards

CVE( Common Vulnerbailites and Exposures)

A real time online public library with descriptions of known attack vectors and mitigating methods of all systems worldwide.

45
New cards

File System Structure of Linux

Linux uses a hierarchal file system starting with the root directory /(root)

Key directories include:

/bin (essential user command binaries)

/usr/bin (most user commands)

/lib,/lib32, lib64 Contain shared libraries for binaries.

46
New cards

Permissions

Linux permissions are represented in three groups (owner, group, others) and three types (read, write, execute)

D: Denotes a directory

R: Read Permission

W: Write Permission

X: Execute Permission

47
New cards

Redirection Links

Used to Point other directories or files, optimizing the file system structure.

48
New cards

Virus

attach itself to other code to propagate.

49
New cards

Firewall

Used to limit communication between internet networks

50
New cards

Script Virus

A virus composed of a sequence of instructions that are interpreted rather then executed directly (visual basic)