Module 5 Flash Cards

5.0(7)
studied byStudied by 50 people
5.0(7)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/174

flashcard set

Earn XP

Description and Tags

Flash cards for module 5 cyber systems

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

175 Terms

1
New cards

Confidentiality

Protect info from unauthorized access, whether intentional or accidental.

2
New cards

Integrity

Ensure that info is authentic and unedited, and the source is genuine.

3
New cards

Availability

Ensure the info is accessible by authorized users.

4
New cards

Intentional Actors

Attackers who want to access information. A person, group, or entity (state actor)

5
New cards

Unintentional Actors

Bugs in the OS and software or mistakes made by administrators.

6
New cards

Local Threat

A disgruntled or untrained employee

7
New cards

Remote Threat

A hacker from across the globe (State actors, hacking groups)

8
New cards

Risk assessment

Determine applicable threats both local and remote, effectiveness of current security controls, and security posture.

9
New cards

Steps to build a secure server

Plan the installation of the OS —> Install, configure, and secure the OS. Install, configure and secure server software. Ensure content is properly secured, employ appropriate network protection mechanisms. Finally Employ secure administration and maintenance processes.

10
New cards

Simplicity

Security mechanisms should be as simple as possible with complexity at the root of many issues.

11
New cards

Fail-Safe

The system should fail in a secure manner

12
New cards

Backups

Critical data should be maintained in the event of catastrophic system failure.

13
New cards

Separation of Privilege

Functions, to the degree possible, should use ___________ and provide as much granularity as possible.

14
New cards

Least Privilege

This principle dictates that each task, process, or user is granted the minimum rights required to perform its job.

15
New cards

User Education

This can be provided through training and education, ______ should understand the necessity of security.

16
New cards

Defense-in-Depth

A single security mechanism is generally insufficient, mechanisms need to be layered to prevent compromise.

17
New cards

Work Factor

Understand what it takes to break the system or network’s security features.

18
New cards

Maintain logs

Records should be maintained so that if a compromise does occur, evidence of the attack is available to the organization.

19
New cards

Application security

The process of developing, testing, and adding security features within applications to prevent security vulnerabilities against threats such as unauthorized access and modification.

20
New cards

Authentication

Ensure that a user is who they say they are.

21
New cards

Authorization

The system can validate that a user has permission to access the application by comparing the user’s identity with a list of authorized users.

22
New cards

Accounting

Logging can help identify who got access to the data and how.

23
New cards

Encryption

Other security measures can protect sensitive data from being seen or even used by a cybercriminal.

24
New cards

Application security controls

Techniques to enhance the security of an application at the coding level, making it less vulnerable to threats.

25
New cards

Static testing

Analyzes code at fixed points during its development.

26
New cards

Dynamic testing

Analyzes running code while simulating outside, or “black box” attacks

27
New cards

Interactive testing

Combines elements of both static and dynamic testing

28
New cards

Mobile testing

Designed specifically for the mobile environments and can examine how an attacker can leverage the mobile OS and the aps running on the in its entirety.

29
New cards

Security Training for Developers

It is critical that developers receive proper security training. tailored to the specific needs of their role.

30
New cards

Adopt a DevSecOps approach

The shift-left approach, aims to detect security holes from day one in order to prevent security issues to begin with and to resolve them as quickly as possible if they do indeed arise.

31
New cards

Automate

Virtually impossible to mitigate the endless number of vulnerabilities that exist using a manual approach, this is critical in order to allow teams to focus on more challenging undertakings.

32
New cards

Update and Patch Regularly

Installing software updates and patches is one of the most effective ways to keep your software secure.

33
New cards

Encrypt your data

Encryption of both data at rest and in transit is key, using an SSL/TLS with a current certificate.

34
New cards

Use Pen-testing

This type of ethical hacker attempts to break into the application in order to detect vulnerabilities and find potential attack vectors with the aim of protecting the system from a real attack.

35
New cards

“Session”

Refers to a connection for ongoing data exchange between two parties (client and server).

36
New cards

Session management funcitons

Establishing and keeping alive the communications links for the duration of the session, keeping the communication secure, synchronizing the dialogue between the two nodes, determining whether communications have been stopped and figuring out whether to restart the transmission or terminate the communication.

37
New cards

Session ID

A unique identifier assigned for tracking a customer accessing an organization’s website.

38
New cards

Session Hijacking

If a hacker obtains a customer’s session ID info, the attacker is able to manipulate the active sessions.

39
New cards

OWASP (Open Web Application Security)

considers the improper implementation of authorization/authentication as the second biggest risk to application security.

40
New cards

Authentication tokens

These are frequently sent over the network and are vulnerable to man in the middle, XSS, XSRF, Brute Force, and social engineering.

41
New cards

Man in the Middle Attacks (MITM)

Someone intercepting data being sent between two parties.

42
New cards

XSS (Cross-Site Scripting)

An attacker can maliciously inject JavaScript into an application running on the victim’s browser. Prevented easily by using input validation as well as secure cookies

43
New cards

XSRF (Cross-Site Request Forgery)

Allows an attacker to piggyback on an existing active session. The goal is to submit a fake request and get you to click on it. Prevention typically requires the use of an anti-______ token.

44
New cards

Brute Force Attack

Incessantly guessing auth tokens until one of the attempts proves successful.

45
New cards

Physical Access

An attacker with _______ to a victim’s device can steal auth tokens in multiple ways

46
New cards

Secure Socket Layers (SSL)

Provided a secure encryption communication method for TCP connections, especially HTTP. Replaced by TLS.

47
New cards

Transport Layer Security (TLS)

A widely adopted security protocol designed to facilitate privacy and data security for communications over the Internet. Encrypts the communication between web applications and servers, etc…

48
New cards

Components of TLS

Encryption, Authentication, and Integrity

49
New cards

TLS certificate

Contains important information about who owns the domain, along with the server’s public key, both of which are important for validating the server’s identity.

50
New cards

TLS handshake

Specify which version of TLS, decide on which cipher suites to use, authenticate the identify of the server using the server’s TLS certificate, and generate session keys for encrypting messages between them after the handshake is complete.

51
New cards

Cipher suite

A set of algorithms that specifies details such as which shared encryption keys, or session keys, will be used for that particular session.

52
New cards

System Boundary

The point where data transfers from the intranet to the internet and vice versa.

53
New cards

Fuzzing

A type of application security testing where developers test the results of unexpected values or inputs to discover which ones cause the application to act in an unexpected way that might open a security hole.

54
New cards

Boundary Protection

The monitoring and control of communications at the external boundary of an information system to prevent and detect malicious and other unauthorized communication. Through gateways, routers, firewalls, guards, and encrypted tunnels.

55
New cards

Control objectives

Statements of the desired result or purpose to be achieved by implementing said control

56
New cards

Demilitarized zone (DMZ)

A physical or logical subnet that separates an internal network from the internet.

57
New cards

Boundary Interaction Best Practices

Scan for unauthorized connections, deny comms with malicious IPs, no unauth ports, configure monitor systems to record packets, use IDS sensors, use Network based intrusion prevention, use NetFlow collection, use application layer filtering proxy servers, decrypt network traffic at Proxy, require all remote logins to use multi-factor auth, and manage all devices remotely logging into internal networks.

58
New cards

Firewalls

A software or hardware-based network security system controlling incoming and outgoing network traffic.

59
New cards

Packet Filtering

A technique used to control network access by monitoring outgoing and incoming packets and either allowing or blocking them. Accomplished by implementing Access Control Lists

60
New cards

Proxy

A network device or software acting on behalf of clients to retrieve requested content from the internet.

61
New cards

Web Proxy

A proxy dedicated solely to web traffic.

62
New cards

Network Address Translation (NAT)

An internet standard that enables a local area network to use one set of IP address for internal traffic and a second set for external traffic.

63
New cards

Intrusion Detection System (IDS)

A system that scans, audits, and monitors the security infrastructure for signs of attacks in progress. It is passive but can still identify malicious activity and provide evidence to inform us of an attack.

64
New cards

IDS functions

Recognition of patterns associated with known attacks, Statistical analysis of abnormal traffic patterns, assessment and integrity check of defined files, monitoring and analysis of user and system activity, network traffic analysis, and even log analysis.

65
New cards

IDS sensors

Installed on a dedicated device or on the devices already installed on a network. Can analyze every packet traversing the network. Tie into a centralized command console that monitors them and generates alerts.

66
New cards

Air Force Enterprise Configuration Management Office (AFECMO)

Creates pre-configured operating system images that are compliant with all applicable TCNOs and STIGs. perform SDC/SSC testing and risk analysis on TCNOs/IAVMs published to the AFCYBER Readiness Center Site.

67
New cards

690 Network Support Squadron (NSS)/AMAC

Will direct NOSs, base NCCs/CFPs, and PMOs through the Acknowledgement Compliance Tool (ACT) to implement Normal vulnerability remediation actions. Authorize NOS personnel to test software and OS updates as well as the associated Remedy CRQ ticket for the TCNO with relevant changes and confirm with software dashboard. Normal = 11 days

68
New cards

Network Operations Squadron (NOS)/Cyberspace Operations Squadron (COS)/Vulnerability Remediation Operator (VRO)

Execute vulnerability remediation to reduce AFIN risk through the implementation of approved countermeasures.

69
New cards

NOS, COS, and VRO countermeasures

Configuration changes to systems, installation of patches, removal of non-approved software, searching for malicious files, upgrades of applications, reinstallation of OSs, and correction of system configs against stigs.

70
New cards

NOS

Responsible for patching vulnerabilities on servers, network infrastructure, boundary devices, and all other IP capable asses within their respective AOR utilizing both enterprise automated tools and manual processes.

71
New cards

VROs

Create patch packages for all vulnerabilities impacting the preponderance of the AFIN to be deployed using enterprise remediation capabilities.

72
New cards

Mandatory Deployments

Target all machines that require an update, are not a part of an exemption, and are not designated a PMO/Medical. A deadline of one day.

73
New cards

Available Deployments

Target all systems, unless stated otherwise by the tasking authority.

74
New cards

Cookies

Used to store details about the session. Which may present a security risk.

75
New cards

Program Management Office (PMO)

Responsible for remediating assets that are supported by a weapons system. Coordinate vulnerability remediation on servers, within their respective AORs with NOSs, until acceptable compliance levels are achieved.

76
New cards

Command Cyber Readiness Inspection (CCRI)

DISA-led formal inspection designed to increase accountability and the security posture of DoD Information Networks according to DoD standards.

77
New cards

CCRI process

Typically every 3 years. The inspection culminates in a week-long visit by a visit by a DISA inspection team, who perform a deep dive into the installation’s cybersecurity posture.

78
New cards

CCRI Graded Areas: Contributing Factors

Contributing Factors: Culture, Capability, and Conduct

79
New cards

CCRI Culture

Command leadership engagement in cybersecurity program, awareness and implementation of STIG reqs, authority to operate, plan of action & milstones, and Program managed system baselines.

80
New cards

CCRI Capability

Computer cyber security server provider (CCSP) alignment, external NIDS-CCSP monitoring, internal NIDS-CCSP monitoring, local incident handling, and continuity of operations plan (COOP).

81
New cards

CCRI Conduct

IA workforce-DoD 8570 Training, configuration management processes, and comprehensive vulnerability management program.

82
New cards

CCRI graded areas: endpoint security

ESS is a suite of centrally managed DCO tools that provide a means for the denial of adversary actions.

83
New cards

CCRI graded areas: site vulnerability scan

DISA calculates the score, or vulnerability index (VI) based on the total number of systems, the number of vulnerabilities on each system, and the level of severity of those vulnerabilities. No concern → Minor concern → Minimal concern → Moderate concern → Critical concern.

84
New cards

CCRI graded areas: STIGS

DISA checks to see whether or not the base is aware of and implementing STIG requirements. Also evaluates how well STIGs are implemented.

85
New cards

Assessment & Authorizations (A&A) requirements

Utilizes the Risk Management Framework (RMF) process to submit a complete and accurate security plan.

86
New cards

Risk Management Framework (RMF)

Prepare, Categorize, Assess, Authorize, and Monitor are parts of what?

87
New cards

Vulnerability Assessment Tools (VATS)

Software packages used on information systems or networks to scan looking for weaknesses like open port exploitations, weak passwords, and security configuration errors leading to potential misuse and abuse.

88
New cards

Vulnerability Management System (VMS)

A DoD information system used to record, track, and disseminate critical vulnerability information throughout the DoD Enterprise network.

89
New cards

Assured Compliance Assessment Solution (ACAS)

Automatically identifies configuration vulnerabilities threatening the security of the DoD’s computer systems. Enhances the availability and security of the DoD Information Network (DoDIN) by ensuring adherence to Information Assurance (IA) and Network Operations (NetOps) policies.

90
New cards

Security Center

Single console access used by ACAS managing Nessus scans at the enterprise network level. real-time detection of network anomalies and is scalable.

91
New cards

Nessus

A comprehensive vulnerability scanner. It performs configuration scans of servers, network devices and databases to test for specific policy settings and can check internal security policy compliance.

92
New cards

Passive Vulnerability Scanner (PVS)

Monitors the network in real-time, continuously looking for new hosts, applications and new vulnerabilities without requiring the need for active scanning.

93
New cards

Microsoft Enterprise Configuration Manager (MECM)

Designed to support a faster pace of system updating and patch management for our network connected Windows devices.

94
New cards

Host assessment

The assessment of critical servers, which may be vulnerable to attacks if not adequately tested or not generated from a tested machine image.

95
New cards

Network and wireless assessment

The assessment of policies and practices to prevent unauthorized access to private or public networks and network-accessible resources.

96
New cards

Database assessment

The assessment of databases or big data systems for vulnerabilities and misconfigurations, identifying rogue databases or insecure dev/test environments, and classifying sensitive data across an organization’s infrastructure.

97
New cards

Applications scans

The identifying of security vulnerabilities in web applications and their source code by automated scans on the front-end or stat/dynamic analysis of source code.

98
New cards

Vulnerability assessment scanning process

four steps: vulnerability identification, analysis, assessment and remediation.

99
New cards

DISA Security Technical Implementations Guides (STIGS)

The configuration standards for DOD IA and IA enabled devices/systems. Describes how to minimize network-based attacks and prevent system access when the attacker is interfacing with the system, either physically at the machine or over a network.

100
New cards

SRG-STIG Library Compliation

Compilations of STIGs and SRGs

Explore top flashcards