1/64
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Dictionary attack
tries a list of common words/passwords against an account.
Credential stuffing
uses stolen username/password combinations from another breach.
Brute force
systematically tries many possible combinations.
Password spraying
tries one common password against many accounts
Tokenization
replaces sensitive data with a token
Encryption
scrambles data using a key; can be decrypted
Hashing
one-way transformation; commonly used to verify integrity/store passwords
Certificate Authority (CA)
issues and manages digital certificates.
Obfuscation
makes code or information difficult to understand while preserving its functionality (Something easy to understand โ to something hard)
Honeynet
collection of interconnected honeypots designed to simulate a larger network.
Configuration baseline
an approved standard configuration that you can compare systems against.
Seperation of duties
split critical responsibilities between people
Least privilege
give someone only the access they need to perform their job.
Pharming
redirects users to a fraudulent website, often without them realizing they're being redirected.
Tailgating
physically follows someone into a restricted area
Shoulder Surfer
watches someone enter information
DNS Sinkhole
redirects requests for a malicious or nonexistent domain/IP to a controlled destination.
Collision resistance
prevents finding two inputs with the same hash
CA
issues/signs certificates
RA
verifies identity and handles registration before certificates are issued
shares secret key without transmitting that secret key directly across the network.
Diffie-Hellman62
Change management
includes approval, documentation, testing, maintenance windows, and rollback plans.
Authentication Logs
record login attempts and authentication failures
Secure Boot
ensures that only cryptographically signed and trusted software components are loaded during the system startup process, preventing malware from loading before the operating system
Active OS Fingerprinting
sending carefully structured, non-standard network packets to a target system and analyzing the specific response characteristics
Netflow
collects metadata about traffic (source, destination, ports, etc.) rather than full packet payloads
Privacy by design
requires that privacy considerations be integrated into system design and development from the beginning, rather than being added as an afterthought.
Incident Response
A set of procedures that an investigator follows when examining a computer security incident
Secert Sharing
splits a secret into multiple parts, where a minimum number of parts (threshold) are required to reconstruct the original secret.
Black Box
testing a system without any prior knowledge of its internal structure, simulating an external attacker's perspective.
Spyware
secretly monitor and record user activities, including keystrokes, browsing habits, and personal information, often for malicious purposes.
Input Validation Vulnerability
when web applications don't properly validate, filter, or sanitize user input, leading to various attacks like XSS, SQL injection, and command injection.
Pass-the-ticket
reuses stolen Kerberos ticket-granting tickets (TGTs) or service tickets to impersonate users without needing credentials, allowing lateral movement in Active Directory environments.
Layer 7
Application Layer
Layer 6
Presentation Layer
Layer 5
Session Layer
Layer 4
Transport Layer
Layer 3
Network Layer
Layer 2
Data Link Layer
Layer 1
Physical Layer
Statefull Firewall
tracks the ongoing state/context of active network connections (like a TCP handshake), allowing it to intelligently permit return traffic that's part of an already-established, legitimate session without needing an explicit rule for every response packet
IPsec
a suite of protocols used to create secure, encrypted VPN tunnels at the network layer
SD-WAN
intelligently manages and routes traffic across multiple types of connections between branch offices and central/cloud resources, optimizing performance and reliability compared to relying on a single traditional fixed circuit type
VLAN hopping
an attacker exploits switch configuration weaknesses to send traffic that jumps from one VLAN to another, bypassing the logical segmentation VLANs are meant to enforce
S/MIME
(Secure/Multipurpose Internet Mail Extensions) provides encryption and digital signing for email messages, using certificates to verify sender identity and protect message content from being read by unauthorized parties in transit
Data Sovereignty
legal requirements or organizational policy dictating that certain data must be stored and processed within a specific country's borders, often due to regulations governing where citizen or organizational data may legally reside
Round-robin algorithm
distributes incoming requests sequentially and evenly across all available servers in rotation, regardless of each server's current load, which is simple to implement but doesn't account for differences in server capacity or current workload.
Availabilty Zone
physically distinct, isolated location within a cloud region, each with its own independent power, cooling, and networking, allowing a cloud architecture to remain resilient even if an entire data center within that zone experiences an outage.
ARP Poisioning
when an attacker sends falsified ARP messages on a local network, associating their own MAC address with the IP address of a legitimate device ( causing traffic intended for that device to be redirected through the attacker's machine instead
Air-Gapped Network
physically isolated from all other networks, including the internet, with no network-based connection whatsoever
Out of band Management
provides a separate, dedicated communication path for administering network devices, allowing administrators to reach and manage a device even if the primary production network is down or compromised.
Containerization
packages an application along with its dependencies into a lightweight, portable unit that shares the host operating system's kernel, making containers much more resource-efficient and faster to start than traditional virtual machines
Dicrionary Attack
tries a large list of likely passwords (common words, phrases, previously breached passwords) against a single account, testing many passwords per account
Identity Federation
Using a centralized Identity Provider (IdP) with federated tokens (such as SAML, OAuth, or OIDC tokens) allows multiple independent applications to authenticate users through a single, centralized identity management source without needing separate user databases for each app.
Insecure Direct Object Reference (IDOR)
when an application provides direct access to objects (like files, documents, or database records) based on user-supplied inputโsuch as a sequential numeric identifier in the URLโwithout performing adequate authorization checks to verify whether the user actually owns or is permitted to access that specific object.
Risk Avoidance
involves eliminating the risk entirely by discontinuing the activity or process introducing the threat.
Risk Acceptance
involves acknowledging the vulnerability or risk, evaluating that the cost or effort of remediation outweighs the potential impact, and choosing to take no proactive technical measures to change it.
Risk mitigation
involves implementing controls or safeguards to reduce the likelihood or impact of the risk.
Risk Transfer
involves shifting the impact of the risk to a third party, such as purchasing insurance or outsourcing.
Risk Calculation
Risk = (Probalility X Impact)
Psychology Acceptance
Ensures that security controls are transparent to users
Crediential Scan
logs in with an account that has read access, letting the scanner inspect installed patches, local configuration, and registry or file settings that can't be seen from the network
Non intrusive scan
identifies vulnerabilities by observing and probing gently without attempting to exploit or disrupt the target, which makes it the safer choice for fragile systems like industrial controllers
Exposure Factor
is the percentage of an asset's value expected to be lost if a particular threat is realized, and it is used in risk calculations alongside asset value.
Passive reconnaissance
gathers information without directly interacting with the target