All the Domains

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/558

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:12 PM on 10/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

559 Terms

1
New cards

Control Category - Technical

Security controls implemented using automated systems, software, or hardware mechanisms (e.g., operating system controls, firewalls, anti-virus).

2
New cards

Control Category - Managerial

Administrative security controls focused on the design, strategic management, and implementation of security (e.g., security policies, standard operating procedures).

3
New cards

Control Category - Operational

Security controls executed and maintained by people rather than automated systems (e.g., security guards, awareness training programs).

4
New cards

Control Category - Physical

Controls that physically limit real-world access to facilities, buildings, and tangible assets (e.g., fences, locks, badge readers, guard shacks).

5
New cards

Control Type - Preventive

Controls that actively block, restrict, or stop unauthorized access or security events before they can occur (e.g., firewall rules, door locks).

6
New cards

Control Type - Deterrent

Controls that discourage or psychologically dissuade an attacker from attempting an intrusion without directly blocking access (e.g., splash screens, warning signs, front desks).

7
New cards

Control Type - Detective

Controls designed to identify, record, and log security events or intrusion attempts as they occur or after the fact (e.g., reviewing system logs, motion detectors).

8
New cards

Control Type - Corrective

Controls applied after an event is detected to mitigate impact, reverse damage, and restore systems to operational status (e.g., restoring backups, fire extinguishers).

9
New cards

Control Type - Compensating

Alternative controls used when primary safeguards are unavailable or insufficient to minimize weakness exploitation (e.g., separation of duties, temporary firewall blocks, backup generators).

10
New cards

Control Type - Directive

Administrative safeguards that guide, direct, or instruct subjects toward security compliance (e.g., compliance procedures, training, "Authorized Personnel Only" signs).

11
New cards

CIA Triad - Confidentiality

Preventing the unauthorized disclosure of information through controls like encryption, access permissions, and multi-factor authentication.

12
New cards

CIA Triad - Integrity

Ensuring data is stored and transferred without undetected modification using mechanisms like hashing, digital signatures, and certificates.

13
New cards

CIA Triad - Availability

Ensuring systems and networks remain operational and accessible to authorized users via redundancy, fault tolerance, and patching.

14
New cards

Non-Repudiation

A cryptographic guarantee that a person cannot deny the authenticity or origin of a signed message or transaction.

15
New cards

AAA Framework - Identification

The initial claim of an identity made by an entity, typically established using a username.

16
New cards

AAA Framework - Authentication

The process of proving a claimed identity using credentials such as passwords, tokens, or biometrics.

17
New cards

AAA Framework - Authorization

Determining and granting specific rights and resource access based on a proven identity.

18
New cards

AAA Framework - Accounting

Tracking and recording resource utilization, including logon times, transferred data volume, and logoff events.

19
New cards

Authenticating Systems

Authenticating unattended machines or network devices using digitally signed certificates issued by a trusted Certificate Authority (CA).

20
New cards

Authorization Models

Adding an abstraction layer (such as roles or attributes) between users and resources to streamline administration and scale access control.

21
New cards

Gap Analysis

An extensive comparison evaluating an organization's current security posture against a defined baseline standard or framework (e.g., NIST, ISO).

22
New cards

Zero Trust Architecture

A holistic security strategy where no user, device, or process is implicitly trusted, requiring continuous verification for every connection.

23
New cards

Zero Trust - Control Plane

The functional plane that defines policies, evaluates security rules, and governs the operational decisions of the data plane.

24
New cards

Control Plane - Adaptive Identity

Evaluating contextual risk indicators (e.g., geographic location, connection method, IP address) to dynamically adjust authentication strength.

25
New cards

Control Plane - Threat Scope Reduction

Minimizing the total number of potential entry and exploitation points across the enterprise environment.

26
New cards

Control Plane - Policy-Driven Access Control

Combining contextual identity attributes with a strict, predefined set of rules to determine resource access.

27
New cards

Control Plane - Policy Engine (PE)

The core component of the Policy Decision Point that evaluates access requests against security policies to grant, deny, or revoke access.

28
New cards

Control Plane - Policy Administrator (PA)

The control component that communicates with the Policy Enforcement Point to issue or revoke credentials and session access tokens.

29
New cards

Zero Trust - Data Plane

The operational plane that processes, encrypts, forwards, and handles the actual network frames, packets, and resource traffic.

30
New cards

Data Plane - Implicit Trust Zones

Network segments or zones where traffic is traditionally allowed without granular per-request verification, which Zero Trust seeks to eliminate.

31
New cards

Data Plane - Subject / System

The user, application, or non-human automated system requesting entry to access an enterprise resource.

32
New cards

Data Plane - Policy Enforcement Point (PEP)

The inline gatekeeper component that allows, monitors, and terminates network connections based on commands from the Policy Administrator.

33
New cards

Physical Security - Bollards / Barricades

Physical barriers used to channel pedestrian traffic safely and block vehicle ramming attempts.

34
New cards

Physical Security - Access Control Vestibule

A multi-door physical security portal where opening one door enforces the locking of the other to prevent unauthorized piggybacking.

35
New cards

Physical Security - Fencing

A physical boundary perimeter (transparent or opaque) often topped with razor wire to deter and prevent climbing.

36
New cards

Physical Security - Video Surveillance (CCTV)

Networked cameras providing real-time property monitoring, motion recognition alerts, and recorded evidence.

37
New cards

Physical Security - Guards and Access Badges

Security personnel stationed at reception areas to verify employee access badges and enforce two-person integrity.

38
New cards

Physical Security - Lighting

Positioned lighting fixtures designed to eliminate shadows, enhance camera and facial recognition, and discourage intruders.

39
New cards

Physical Sensors - Infrared

Sensors detecting thermal infrared radiation in daylight or complete darkness, commonly utilized in motion detectors.

40
New cards

Physical Sensors - Pressure

Sensors configured to identify changes in applied physical force on floors, mats, or window panes.

41
New cards

Physical Sensors - Microwave

Active sensors transmitting microwave pulses across broad areas to detect perimeter movement.

42
New cards

Physical Sensors - Ultrasonic

Sensors emitting high-frequency sound waves that analyze reflected sound waves to track room motion and proximity.

43
New cards

Deception Technology - Honeypots & Honeynets

Honeypots are decoy virtual systems built to lure and study attackers; honeynets are interconnected networks of multiple honeypots.

44
New cards

Deception Technology - Honeyfiles & Honeytokens

Honeyfiles are lure files (e.g., passwords.txt) alerting on access; honeytokens are fake API keys or email addresses used to trace stolen data.

45
New cards

Change Management - Approval Process

A formal process for managing change that includes request forms, scope definition, scheduling, impact and risk analysis, Change Control Board approval, and end-user acceptance.

46
New cards

Change Management - Ownership

The individual or entity who requests and manages the change process to ensure procedures are properly followed without necessarily performing the technical work.

47
New cards

Change Management - Stakeholders

Individuals or departments across the organization who are impacted by a system change and require input or visibility into the process.

48
New cards

Change Management - Impact Analysis

Evaluating the risk value (high, medium, low) of a proposed change, potential cascading system failures, and the operational risk of not making the change.

49
New cards

Change Management - Test Results

Validating software upgrades or patches in an isolated sandbox testing environment prior to production deployment to confirm stability and verify backout plans.

50
New cards

Change Management - Backout Plan

A documented, pre-tested procedure and reliable backup set used to revert systems to their original operational state if a change fails.

51
New cards

Change Management - Maintenance Window

A scheduled timeframe (typically overnights or non-peak production hours) designated for executing changes to minimize operational disruption.

52
New cards

Change Management - Standard Operating Procedure (SOP)

Well-documented, formal procedures hosted on an organization's intranet that establish the living baseline for executing enterprise changes.

53
New cards

Technical Implications - Allow List / Deny List

Security controls restricting application execution, where allow lists block everything unless explicitly approved and deny lists block known malicious software.

54
New cards

Technical Implications - Restricted Activities

Strictly defined boundaries of an approved change order ensuring technicians do not execute modifications outside the authorized scope without further review.

55
New cards

Technical Implications - Downtime

Planned periods of service unavailability scheduled during maintenance windows, often minimized via automation and secondary failover systems.

56
New cards

Technical Implications - Service Restart

Stopping and restarting a background daemon or operating system service to apply new configuration settings without a full system reboot.

57
New cards

Technical Implications - Application Restart

Completely closing and re-launching an application instance to enforce software modifications and load new settings.

58
New cards

Technical Implications - Legacy Applications

Older, mission-critical software that is no longer supported by the original developer, requiring custom internal documentation, quirks management, and operational workarounds.

59
New cards

Technical Implications - Dependencies

Interconnected technical relationships where one component or service requires another specific library, service, or firmware version to function before updates can occur.

60
New cards

Documentation - Updating Diagrams

Modifying network and system topology diagrams following a change to maintain accurate physical and logical address and connectivity maps.

61
New cards

Documentation - Updating Policies and Procedures

Revising internal standard operating procedures and security baselines to reflect newly added infrastructure and altered system workflows.

62
New cards

Version Control

Tracking configuration and file modifications over time (e.g., router configs, OS patches, registry files) to facilitate auditability and rapid rollbacks.

63
New cards

Public Key Infrastructure (PKI)

The comprehensive framework of policies, procedures, hardware, software, and people used to create, distribute, manage, store, and revoke digital certificates.

64
New cards

PKI - Public Key

An asymmetric cryptographic key that is freely distributed to anyone, used to encrypt data or verify a digital signature.

65
New cards

PKI - Private Key

The confidential, mathematically paired asymmetric key kept strictly secret by the owner, used to decrypt data or generate digital signatures.

66
New cards

PKI - Key Escrow

An arrangement where cryptographic decryption keys are held and secured by an authorized third party for recovery or legal access.

67
New cards

Encryption Level - Full-Disk

Encrypting an entire physical storage drive (e.g., BitLocker, FileVault) to protect all system files and data at rest.

68
New cards

Encryption Level - Partition / Volume

Encrypting a specific dedicated logical drive sector, volume, or partition rather than the entire physical disk.

69
New cards

Encryption Level - File

Encrypting individual files on a filesystem (such as Windows Encrypting File System - EFS) to restrict access per user.

70
New cards

Encryption Level - Database (Transparent)

Encrypting all tables and database information on disk using a centralized symmetric key.

71
New cards

Encryption Level - Database (Record-Level)

Encrypting specific individual columns or fields within a database using distinct symmetric keys to isolate sensitive records.

72
New cards

Encryption - Transport / Communication

Protecting data actively moving across a network using encrypted channels such as HTTPS, SSL/TLS, and IPsec VPN tunnels.

73
New cards

Encryption - Asymmetric Cryptography

A cryptographic model utilizing mathematically related public and private key pairs for encryption and digital signatures.

74
New cards

Encryption - Symmetric Cryptography

A fast cryptographic scheme that uses a single, shared secret key to both encrypt and decrypt data.

75
New cards

Key Exchange

The process of sharing an encryption key across an insecure medium, either out-of-band (telephone, courier) or in-band using asymmetric encryption.

76
New cards

Cryptographic Algorithms

The mathematical formulas and ciphers agreed upon by communicating endpoints to perform encryption and decryption operations.

77
New cards

Cryptographic Key Length

The size of a cryptographic key measured in bits, where larger keys exponentially increase mathematical resistance against brute-force attacks.

78
New cards

Key Stretching

Strengthening a weak key or password by repeatedly hashing the hash through thousands of iterations to slow down brute-force attacks.

79
New cards

Cryptographic Tools - TPM

Trusted Platform Module; a dedicated cryptographic hardware processor on a device motherboard that provides burned-in keys and secures BitLocker.

80
New cards

Cryptographic Tools - HSM

Hardware Security Module; a high-end, clustered hardware appliance designed to securely store and accelerate thousands of enterprise keys.

81
New cards

Cryptographic Tools - Key Management System

A centralized software console used to generate, store, rotate, map, and log encryption keys separately from the protected data.

82
New cards

Cryptographic Tools - Secure Enclave

An isolated hardware coprocessor running its own boot ROM, memory encryption, and true random number generation to protect device secrets.

83
New cards

Obfuscation

The process of making data, code, or payment details confusing and difficult to understand while leaving it technically readable and functional.

84
New cards

Obfuscation - Steganography

The technique of concealing a secret message or payload inside another non-suspicious carrier container (e.g., within image, audio, or video files).

85
New cards

Obfuscation - Tokenization

Replacing sensitive data (e.g., credit card numbers) with a non-sensitive placeholder token that maps back to raw values via a secure token server.

86
New cards

Obfuscation - Data Masking

Hiding portions of sensitive data or PII from view on display interfaces while leaving the raw data intact in storage.

87
New cards

Hashing

A one-way mathematical function that converts arbitrary data into a fixed-length string or fingerprint to verify data integrity.

88
New cards

Hash Collision

A cryptographic anomaly where two completely different plaintext inputs generate the exact same hash digest.

89
New cards

Salting

Adding random data to a password before hashing to ensure identical passwords generate unique hashes and defeat rainbow tables.

90
New cards

Digital Signatures

A cryptographic scheme where a sender hashes plaintext and encrypts the hash with their private key to provide authenticity, integrity, and non-repudiation.

91
New cards

Blockchain

A decentralized, distributed digital ledger that records, verifies, and cryptographically chains transaction blocks across peer nodes.

92
New cards

Blockchain - Open Public Ledger

A transparent, distributed ledger maintained across all network computers where transactions are replicated and visible to everyone.

93
New cards

Digital Certificates

An X.509 formatted credential that cryptographically binds an applicant's public key with a digital signature from a Certificate Authority.

94
New cards

Root of Trust

An inherently trusted foundational component (such as an HSM, Secure Enclave, or root CA) upon which subsequent system trust is established.

95
New cards

Certificate Authority (CA)

A trusted third party or internal server responsible for vetting applicants, issuing certificates, and digitally signing them with its private key.

96
New cards

Third-Party Certificate Authority

A commercial CA whose root certificates are pre-installed and inherently trusted across standard web browsers.

97
New cards

Self-Signed Certificates

Certificates generated and signed internally by an organization's private CA without paying for a commercial third-party signature.

98
New cards

Certificate Signing Request (CSR)

A formal request containing an applicant's public key and identity data submitted to a CA to obtain a digitally signed certificate.

99
New cards

Wildcard Certificates

A certificate that uses a wildcard notation (e.g., *.domain.com) to provide SSL/TLS protection for all first-level subdomains under a domain.

100
New cards

Certificate Revocation - CRL vs. OCSP

A Certificate Revocation List (CRL) is a downloaded file of revoked certs; OCSP queries an online responder via HTTP for real-time status.