Deck 16 - Network Security Concepts

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/102

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:52 PM on 9/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

103 Terms

1
New cards
What are the three components of the CIA Triad?
Confidentiality, Integrity, and Availability
2
New cards
Confidentiality (security)
Ensuring sensitive information is accessed only by authorized individuals and kept away from those not authorized to possess it
3
New cards
Integrity (security)
Assuring the accuracy, reliability, and trustworthiness of data and systems; checks if data or systems have been altered
4
New cards
Availability (security)
Ensuring that data, systems, and resources are accessible to authorized users when needed
5
New cards
Name two mechanisms used to protect confidentiality
Access controls (passwords, biometrics) and encryption
6
New cards
Name two mechanisms used to protect integrity
Checksums/cryptographic hash functions and digital signatures
7
New cards
Name three mechanisms used to ensure availability
Redundancy, fault tolerance, and backup systems (plus disaster recovery plans)
8
New cards
What attack is a major threat to availability?
Distributed Denial of Service (DDoS)
9
New cards
Risk (formula)
Risk = Threat x Vulnerability
10
New cards
Risk (definition)
The probability of a threat exploiting a vulnerability
11
New cards
Asset (security)
Anything within an environment that should be protected
12
New cards
Asset valuation
A dollar value assigned to an asset based on actual cost and nonmonetary expenses
13
New cards
Threat
Any potential occurrence that may harm an asset
14
New cards
Threat agent / threat actor
People, programs, or systems that use threats to cause harm
15
New cards
Threat event
An occurrence that leads to the exploitation of vulnerabilities
16
New cards
Threat vector (attack vector)
The path or means by which an attacker can gain access to a target in order to cause harm
17
New cards
Vulnerability
The weakness in an asset, or the absence/weakness of a safeguard or countermeasure, that could be exploited
18
New cards
Exposure (security)
Actual or anticipated damage from a threat
19
New cards
Safeguard
Anything that removes or reduces a vulnerability, thereby reducing risk
20
New cards
Attack (security)
The threat exploiting the vulnerability
21
New cards
Breach
The occurrence of a security mechanism being bypassed or thwarted by a threat agent
22
New cards
AAA stands for
Authentication, Authorization, and Accounting
23
New cards
Authentication
The process of verifying the identity of a user, device, or other entity; a prerequisite to granting access to resources
24
New cards
Authorization
Determines what an authenticated user is permitted to do by matching user/system credentials against an access control list
25
New cards
Accounting (AAA)
Also called auditing; ensured by keeping a track record (logging) and monitoring of user actions
26
New cards
"Something you know" (authentication factor)
Knowledge-based authentication such as a password, PIN, or answers to secret questions
27
New cards
"Something you have" (authentication factor)
Possession-based authentication such as a security token, smart card, or mobile phone (OTP/push notification)
28
New cards
"Something you are" (authentication factor)
Biometric authentication such as fingerprints, facial recognition, iris scans, or voice patterns
29
New cards
"Somewhere you are" (authentication factor)
Location-based authentication determined through IP address, GPS, or geolocation methods
30
New cards
"Something you do" (authentication factor)
Behavioral biometrics, such as keystroke dynamics or mouse-use patterns, used to authenticate a user
31
New cards
Multifactor Authentication (MFA)
A security process requiring more than one independent category (factor) of credentials to verify a user's identity
32
New cards
Why is "something you know" the weakest authentication factor?
It is commonly used but vulnerable to theft, guessing, or brute-force attacks
33
New cards
How can systems (not people) be authenticated?
Using certificates and cryptographic keys, IP allow lists, or MAC address filtering
34
New cards
What does authorization determine?
What an authenticated user is allowed to do, by establishing their rights and privileges
35
New cards
Access Control List (ACL)
A list of permissions attached to a resource, used to enforce access control
36
New cards

MAC

Mandatory Access Control: An access control model where access rights are regulated by a central authority based on levels of security clearance; common in government/military systems; users cannot change permissions

37
New cards
Discretionary Access Control (DAC)
An access control model where the resource owner decides access levels; the most flexible model, but risks users granting excessive access
38
New cards
Role-Based Access Control (RBAC)
Assigns permissions based on a user's role within an organization; common in corporate environments to streamline access management
39
New cards
Rule-Based Access Control
Access decisions are based on a set of rules defined by the system administrator, e.g. firewall rules based on source/destination IP
40
New cards

ABAC

Attribute-Based Access Control: Uses policies that evaluate attributes (characteristics) of users, the environment, and resources; provides fine-grained access control based on multiple factors

41
New cards
Principle of Least Privilege
Limiting the access rights of users, accounts, and processes to only the resources absolutely required to perform their functions or tasks
42
New cards
Single Sign-On (SSO)
A feature where users log in once and gain access to multiple systems without needing to re-authenticate
43
New cards
Two benefits of SSO
Reduces password fatigue (fewer passwords to manage) and centralizes authentication control for easier security policy enforcement
44
New cards

IAM

Identity and Access Management: A security framework that ensures the right individuals and systems get safe access to the correct technology resources.

45
New cards
LDAP
Lightweight Directory Access Protocol; a protocol for accessing and maintaining distributed directory information (users, groups) over an IP network; foundation of Microsoft Active Directory
46
New cards
Federation (identity)
The process of linking and managing the same identity or set of credentials across different systems and organizational boundaries to enable SSO
47
New cards
SAML
Security Assertion Markup Language; an open XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider
48
New cards

SAML: Identity Provider (IdP)

Security Assertion Markup Language: The service that authenticates users and provides identity information to service providers (e.g., Okta, Azure AD, Google Identity)

49
New cards
SAML: Service Provider (SP)
The application or service that relies on information from the IdP to provide access to the user
50
New cards
OAuth
An open standard for access delegation; grants applications limited access to a user's data on another website without exposing the user's password (authorization, not authentication)
51
New cards
OpenID Connect
An identity layer built on top of OAuth 2.0 that allows clients to verify the identity of the end-user based on authentication performed by an authorization server
52
New cards
RADIUS
Remote Authentication Dial-In User Service; a networking protocol providing centralized AAA management for users who connect to and use a network service
53
New cards
TACACS+
Terminal Access Controller Access-Control System Plus; a Cisco protocol providing centralized AAA services, similar to RADIUS
54
New cards

TOTP

Time-Based One-Time Password: Uses a time-limited code or token generated by an app/device that expires after a short duration, reducing the window for unauthorized access

55
New cards
Geofencing
A location-based service that uses GPS, RFID, Wi-Fi, or cellular data to trigger a pre-programmed action when a device enters or exits a virtual geographic boundary
56
New cards
Physical security
Measures that protect assets, personnel, and data from physical actions and events that could cause serious loss or damage
57
New cards
Purpose of security cameras
Act as a deterrent to unauthorized actions and provide crucial evidence in the event of a security breach or incident
58
New cards
Modern electronic locks
Integrate locks with access control systems, allowing sophisticated management of entry permissions and tracking of access history
59
New cards
Deception and disruption technology
Cybersecurity strategies and tools designed to mislead, confuse, or disrupt malicious actors by creating traps or illusions to divert attackers away from real assets
60
New cards
Honeypot
A decoy security mechanism that imitates a real computer, network, or information system to detect, deflect, or study hacking attempts; it is isolated and monitored
61
New cards
Honeynet
A network of honeypots that simulates a full network environment to attract attackers and provide deeper insight into their tactics and lateral movement
62
New cards
Honeyfile
A decoy file placed within a network's file system, designed to appear legitimate and attractive; unauthorized access alerts security personnel
63
New cards
Honeytoken
A broader term for any decoy data or token (fake account, database record, etc.) inserted into a system, where interaction indicates a compromise or unauthorized access
64
New cards
Data locality
Refers to the geographical location where data is stored, processed, and managed, ensuring compliance with regional legal requirements
65
New cards
PCI DSS
Payment Card Industry Data Security Standard; a set of security standards ensuring companies that accept, process, store, or transmit credit card information maintain a secure environment
66
New cards
GDPR
General Data Protection Regulation; a comprehensive EU data protection regulation governing the processing and movement of personal data, giving individuals rights such as access, correction, and deletion
67
New cards
Network segmentation enforcement
Dividing a network into smaller segments or subnets to improve security and performance, limiting access to sensitive data and containing potential breaches
68
New cards
Guest network
Provides internet access to visitors without exposing the main network and its sensitive resources
69
New cards
BYOD segmentation
Placing Bring Your Own Device (personal) devices on a separate network segment to limit their access to sensitive data/systems while still allowing productivity
70
New cards

ICS

Industrial Control System: A general term encompassing several types of control systems (SCADA, DCS, PLCs) used in industrial production

71
New cards
SCADA
Supervisory Control and Data Acquisition; systems used to monitor and control industrial processes across distributed sites
72
New cards
Internet of Things (IoT)
The network of physical objects (embedded with electronics, software, sensors) that traditionally do not require internet access but connect to collect and exchange data
73
New cards
Encryption
The process of converting readable (plaintext) data into a secure, unreadable format (ciphertext) that can only be read or processed after it is decrypted
74
New cards
Encryption of data in transit
Encrypting data that is being transferred over a network to keep it secure and private while moving between endpoints; common protocols: HTTPS, SSL/TLS, VPN
75
New cards
Encryption of data at rest
Encrypting data stored on physical media (e.g., hard drives, USB drives) to prevent unauthorized access; techniques include full disk encryption (FDE) and encrypted file systems
76
New cards
Four goals of cryptography
Confidentiality, Integrity, Authentication, and Non-repudiation
77
New cards
Cryptography goal: Confidentiality
Ensuring information is accessible only to those authorized to have access, via encryption
78
New cards
Cryptography goal: Integrity
Guaranteeing that information is protected from unauthorized or accidental changes, verified using cryptographic hash functions
79
New cards
Cryptography goal: Authentication
Verifying the identity of a user, device, or entity in a communication process, e.g., via digital certificates
80
New cards
Cryptography goal: Non-repudiation
Preventing an entity from denying their involvement in a transaction or activity; digital signatures ensure a signer cannot later deny having signed
81
New cards
Symmetric encryption
A type of cryptographic algorithm that uses the same shared key for both encryption and decryption
82
New cards
Symmetric encryption: key sharing
The same key used for encrypting and decrypting data must be securely shared and kept secret between communicating parties
83
New cards
Symmetric encryption: speed
Symmetric algorithms are generally faster and more efficient than asymmetric algorithms, making them suitable for encrypting large amounts of data
84
New cards
Symmetric encryption: key management challenge
Securely distributing and managing the shared key is the biggest challenge; if a key is intercepted or leaked, the security of all data encrypted with it is compromised
85
New cards
Symmetric encryption: scalability formula
For N users to communicate securely with each other, N(N-1)/2 unique key pairs are needed, making key management impractical in large networks
86
New cards
Symmetric encryption: non-repudiation weakness
Symmetric key cryptography does not provide non-repudiation, since the same key is used by all parties and it cannot be determined who performed the encryption/decryption
87
New cards
Asymmetric encryption
Also known as public-key cryptography; a cryptographic system that uses a pair of keys, a public key and a private key, to encrypt and decrypt data
88
New cards
Asymmetric encryption: public key
Can be used to encrypt data and decrypt it; is shared with anyone
89
New cards
Asymmetric encryption: private key
Can be used to encrypt and decrypt data; is kept secret with the owner only
90
New cards
Asymmetric encryption process
A sender encrypts data using the recipient's public key; only the recipient's corresponding private key can decrypt it
91
New cards
Asymmetric encryption: advantages
Solves the key distribution problem of symmetric encryption (public keys can be shared openly) and provides a method for digital signatures, supporting authentication and non-repudiation
92
New cards
Asymmetric encryption: disadvantages
More computationally intensive/slower than symmetric encryption for large amounts of data, and requires careful management of the private key
93
New cards
Public Key Infrastructure (PKI)
A framework used to create, manage, distribute, use, store, and revoke digital certificates and manage public-key encryption
94
New cards
PKI functions
Encryption/decryption of data, creation and verification of digital signatures, and certificate management (issuance and revocation by the CA)
95
New cards
X.509 digital certificate
A standard format for digital certificates containing attributes such as version number, subject name, issuer name, validity period, public key, and serial number
96
New cards
Certificate Authority (CA)
A trusted entity that issues, verifies, and revokes digital certificates
97
New cards

CA certificate

Certificate Authority: A digital document issued by a trusted organization that verifies identities and binds them to cryptographic keys to secure online communications.

98
New cards
End entity certificate

A digital document issued to a specific user, device, or server that authenticates identity and enables secure communication.

99
New cards
Domain Validation (DV) certificate
A certificate that verifies domain control only, offering a basic level of assurance
100
New cards
Extended Validation (EV) certificate
A certificate offering a higher level of assurance, verifying that the applicant is a legitimate business