1/47
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Digital Identity
A unique representation of a subject engaged in an online transaction
Digital User Athentication
The process of verifying the identity of a user attempting to access a digital system
Basic Identification Requirement
A system must identify users, processes acting on their behalf, and devices
Basic Authentication Requirement
A system must verify the identities of users, processes, and devices before granting access
Privileged Account
An account with elevated permissions to perform sensitive or administrative operations
Something the Individual Knows
Authentication based on secret knowledge, such as a password or PIN
Something the Individual Possesses
Authentication based on possession of an object, such as a smart card or security token
Something the Individual Is (static biometrics)
Authentication based on physical characteristics, such as fingerprints or facial features
Something the Individual Does (dynamic biometrics)
Authentication based on behavioral characteristics, such as typing patterns or voice characteristics
Password-Based Authentication
A method of verifying identity using a user identifier and a secret password
User Identifier (User ID)
A value used to identify the account requesting access
Password
A secret sequence of characters used as evidence of identity
Offline Dictionary Attack
An attacker steals passwords hashes and attempts to discover passwords by testing common guesses offline
Specific Account Attack
An attack directed at guessing the password of one particular user account
Popular Password Attack
An attack that tries commonly used passwords against multiple accounts
Workstation Hijacking
Using an unattended computer that is already logged in to gain unauthorized access
Password Guessing
Attempting to discover a password by testing likely possibilities
Automatic Workstation Logout
A defense that ends or locks an unattended session after a period of inactivity
Password Hashing
Applying a cryptographic hash function to a password so the system stores a hash instead of the original password
Salt
A random value combined with a password before hashing
Purpose of Salting
Prevents identical passwords from producing identical stored hashes and makes precomputed password attacks more difficult
Password Verification with Hashing
The system hashes the entered password with the stored salt and compares the result to the stored hash
Dictionary Attack
Attempts to discover passwords by testing lists of common words, names, known passwords, and variations
Password Variation Attack
Tests modified passwords using capitalization, reversed words, symbols, or character substitutions
Rainbow Table
A precomputed lookup structure used to speed up recovery of passwords from hashes
Weak Password
A short, common, predictable, or easily guessed password
Password Cracking
The process of discovering passwords through guessing, hash comparisons, or other attacks
User Education
Teaching users to create stronger passwords and avoid predictable password choices
Reactive Password Checking
Testing existing passwords for weaknesses and requiring users to replace those found to be insecure
Proactive Password Checking
Checking proposed passwords before accepting them to prevent weak password selection
Password Rule Enforcement
Requiring passwords to satisfy specified length, complexity, or other security conditions
Multifactor Authentication (MFA)
Authentication requiring two or more distinct types of evidence to verify identity
Two-Factor Authentication (2FA)
A form of MFA requiring two different authentication factors
Purpose of MFA
Strengthens security by making a single compromised authentication factor insufficient for access
Token-Based Authentication
Authentication using an object possessed by the user as evidence of identity
Authentication Token
A physical or digital object used to prove possession during authentication
Contact Card
A card that communicates with a reader through exposed electrical contacts
Contactless Card
A card that communicates wirelessly using an embedded antenna
Magnetic Stripe Card
A card that stores a limited amount of fixed information on a magnetic strip
Memory Card
A card that stores information but has limited or no independent processing capability
Smart Card
An authentication token containing electronic circuitry capable of storing and, in some cases, processing information
Smart Card Physical Characteristics
The physical form of the authentication device, such as a card or other portable token
Smart Card Electronic Interface
The method by which a smart card communicates with a reader, typically contact or contactless
Smart Card Authentication Protocol
The procedure used by a smart token and authentication system to verify identity
Smart Token
A token with electronic functionality used to support authentication
One-Time Password (OTP)
A password or code intended for a single authentication event or limited time period
Authenticator App
A mobile application that generates authentication codes
SMS Authentication
Authentication that sends a verification code to a user’s phone by text message