Gap Analysis , Zero Trust , Physical Security , Deception and Disruption

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/8

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:58 PM on 8/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

9 Terms

1
New cards

What is a Gap Analysis?

An evaluation that compares an organization's current security posture against a desired standard, framework, or regulatory baseline to identify missing controls (the "gaps") and build a remediation roadmap.

2
New cards

What is the core philosophy of Zero Trust?

"Never trust, always verify." Implicit trust based on network location (e.g., being inside the corporate office or on the VPN) is completely eliminated; every access request must be authenticated, authorized, and validated dynamically.

3
New cards

What are key implementation components of a Zero Trust architecture?

  • Micro-segmentation (breaking the network into tiny zones)

  • Continuous device health and behavior monitoring

  • Least-privilege access enforced per application, not per network session


4
New cards

What is a Mantrap (Airlock)?

A physical security control consisting of two interlocking doors with a small space between them. The first door must close and verify identity (often via biometrics) before the second door can open, specifically designed to prevent tailgating/piggybacking.

5
New cards

Physical controls for asset protection (Rack-level)

Rack-level locks, locked server cabinet doors, and physical port blockers to prevent hardware theft and unauthorized physical plug-ins (like rogue USB rubber duckies).

6
New cards

Environmental controls in physical security

HVAC systems with strict temperature and humidity monitoring, plus fire suppression systems (like pre-action or clean-agent systems), designed to protect server hardware and media vaults.

7
New cards

What is a Honeypot?

A decoy system, server, or application deployed on a network that contains simulated vulnerabilities and attractive fake data to lure, distract, and study attackers without risking real assets.

8
New cards

What are Honeyfiles (Canary Tokens)?

Decoy files (e.g., passwords.txt) placed in sensitive locations. Because legitimate users have no reason to touch them, any attempt to access or read a honeyfile instantly triggers an alert in the SOC.

9
New cards

What is a Honeynet?

An entire network of multiple decoy systems designed to lure attackers, allowing security teams to safely observe, log, and gather threat intelligence on active attacker TTPs (Tactics, Techniques, and Procedures).