Security + Definitions

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/64

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:23 AM on 10/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

65 Terms

1
New cards

Dictionary attack

tries a list of common words/passwords against an account.

2
New cards

Credential stuffing

uses stolen username/password combinations from another breach.

3
New cards

Brute force

systematically tries many possible combinations.

4
New cards

Password spraying

tries one common password against many accounts

5
New cards

Tokenization

replaces sensitive data with a token

6
New cards

Encryption

scrambles data using a key; can be decrypted

7
New cards

Hashing

one-way transformation; commonly used to verify integrity/store passwords

8
New cards

Certificate Authority (CA)

issues and manages digital certificates.

9
New cards

Obfuscation

makes code or information difficult to understand while preserving its functionality (Something easy to understand โ†’ to something hard)

10
New cards

Honeynet

collection of interconnected honeypots designed to simulate a larger network.

11
New cards

Configuration baseline

an approved standard configuration that you can compare systems against.

12
New cards

Seperation of duties

split critical responsibilities between people

13
New cards

Least privilege

give someone only the access they need to perform their job.

14
New cards

Pharming

redirects users to a fraudulent website, often without them realizing they're being redirected.

15
New cards

Tailgating

physically follows someone into a restricted area

16
New cards

Shoulder Surfer

watches someone enter information

17
New cards

DNS Sinkhole

redirects requests for a malicious or nonexistent domain/IP to a controlled destination.

18
New cards

Collision resistance

prevents finding two inputs with the same hash

19
New cards

CA

issues/signs certificates

20
New cards

RA

verifies identity and handles registration before certificates are issued

21
New cards

shares secret key without transmitting that secret key directly across the network.

Diffie-Hellman62

22
New cards

Change management

includes approval, documentation, testing, maintenance windows, and rollback plans.

23
New cards

Authentication Logs

record login attempts and authentication failures

24
New cards

Secure Boot

ensures that only cryptographically signed and trusted software components are loaded during the system startup process, preventing malware from loading before the operating system

25
New cards

Active OS Fingerprinting

sending carefully structured, non-standard network packets to a target system and analyzing the specific response characteristics

26
New cards

Netflow

collects metadata about traffic (source, destination, ports, etc.) rather than full packet payloads

27
New cards

Privacy by design

requires that privacy considerations be integrated into system design and development from the beginning, rather than being added as an afterthought.

28
New cards

Incident Response

A set of procedures that an investigator follows when examining a computer security incident

29
New cards

Secert Sharing

splits a secret into multiple parts, where a minimum number of parts (threshold) are required to reconstruct the original secret.

30
New cards

Black Box

testing a system without any prior knowledge of its internal structure, simulating an external attacker's perspective.

31
New cards

Spyware

secretly monitor and record user activities, including keystrokes, browsing habits, and personal information, often for malicious purposes.

32
New cards

Input Validation Vulnerability

when web applications don't properly validate, filter, or sanitize user input, leading to various attacks like XSS, SQL injection, and command injection.

33
New cards

Pass-the-ticket

reuses stolen Kerberos ticket-granting tickets (TGTs) or service tickets to impersonate users without needing credentials, allowing lateral movement in Active Directory environments.

34
New cards

Layer 7

Application Layer

35
New cards

Layer 6

Presentation Layer

36
New cards

Layer 5

Session Layer

37
New cards

Layer 4

Transport Layer

38
New cards

Layer 3

Network Layer

39
New cards

Layer 2

Data Link Layer

40
New cards

Layer 1

Physical Layer

41
New cards

Statefull Firewall

tracks the ongoing state/context of active network connections (like a TCP handshake), allowing it to intelligently permit return traffic that's part of an already-established, legitimate session without needing an explicit rule for every response packet

42
New cards

IPsec

a suite of protocols used to create secure, encrypted VPN tunnels at the network layer

43
New cards

SD-WAN

intelligently manages and routes traffic across multiple types of connections between branch offices and central/cloud resources, optimizing performance and reliability compared to relying on a single traditional fixed circuit type

44
New cards

VLAN hopping

an attacker exploits switch configuration weaknesses to send traffic that jumps from one VLAN to another, bypassing the logical segmentation VLANs are meant to enforce

45
New cards

S/MIME

(Secure/Multipurpose Internet Mail Extensions) provides encryption and digital signing for email messages, using certificates to verify sender identity and protect message content from being read by unauthorized parties in transit

46
New cards

Data Sovereignty

legal requirements or organizational policy dictating that certain data must be stored and processed within a specific country's borders, often due to regulations governing where citizen or organizational data may legally reside

47
New cards

Round-robin algorithm

distributes incoming requests sequentially and evenly across all available servers in rotation, regardless of each server's current load, which is simple to implement but doesn't account for differences in server capacity or current workload.

48
New cards

Availabilty Zone

physically distinct, isolated location within a cloud region, each with its own independent power, cooling, and networking, allowing a cloud architecture to remain resilient even if an entire data center within that zone experiences an outage.

49
New cards

ARP Poisioning

when an attacker sends falsified ARP messages on a local network, associating their own MAC address with the IP address of a legitimate device ( causing traffic intended for that device to be redirected through the attacker's machine instead

50
New cards

Air-Gapped Network

physically isolated from all other networks, including the internet, with no network-based connection whatsoever

51
New cards

Out of band Management

provides a separate, dedicated communication path for administering network devices, allowing administrators to reach and manage a device even if the primary production network is down or compromised.

52
New cards

Containerization

packages an application along with its dependencies into a lightweight, portable unit that shares the host operating system's kernel, making containers much more resource-efficient and faster to start than traditional virtual machines

53
New cards

Dicrionary Attack

tries a large list of likely passwords (common words, phrases, previously breached passwords) against a single account, testing many passwords per account

54
New cards

Identity Federation

Using a centralized Identity Provider (IdP) with federated tokens (such as SAML, OAuth, or OIDC tokens) allows multiple independent applications to authenticate users through a single, centralized identity management source without needing separate user databases for each app.

55
New cards

Insecure Direct Object Reference (IDOR)

when an application provides direct access to objects (like files, documents, or database records) based on user-supplied inputโ€”such as a sequential numeric identifier in the URLโ€”without performing adequate authorization checks to verify whether the user actually owns or is permitted to access that specific object.

56
New cards

Risk Avoidance

involves eliminating the risk entirely by discontinuing the activity or process introducing the threat.

57
New cards

Risk Acceptance

involves acknowledging the vulnerability or risk, evaluating that the cost or effort of remediation outweighs the potential impact, and choosing to take no proactive technical measures to change it.

58
New cards

Risk mitigation

involves implementing controls or safeguards to reduce the likelihood or impact of the risk.

59
New cards

Risk Transfer

involves shifting the impact of the risk to a third party, such as purchasing insurance or outsourcing.

60
New cards

Risk Calculation

Risk = (Probalility X Impact)

61
New cards

Psychology Acceptance

Ensures that security controls are transparent to users

62
New cards

Crediential Scan

logs in with an account that has read access, letting the scanner inspect installed patches, local configuration, and registry or file settings that can't be seen from the network

63
New cards

Non intrusive scan

identifies vulnerabilities by observing and probing gently without attempting to exploit or disrupt the target, which makes it the safer choice for fragile systems like industrial controllers

64
New cards

Exposure Factor

is the percentage of an asset's value expected to be lost if a particular threat is realized, and it is used in risk calculations alongside asset value.

65
New cards

Passive reconnaissance

gathers information without directly interacting with the target