COMPTIA Network Security+

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/61

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:39 PM on 7/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

62 Terms

1
New cards

Keylogger attack/ Spyware attack

Records what you type

Steals information

Hides itself from the operating system while maintaining privileged access

2
New cards

Rootkit attack

Hides malware and gives deep control of a system

Stays hidden and maintains access

Persistent access

Administrator/root privileges

3
New cards

Public Key

Encrypts data or verify digital signatures

4
New cards

Private Key

Decrypts data and creates digital signatures

5
New cards

Data Custodian

Stores, backs up, and protects the data according to the owner’s policies

6
New cards

Data User

Accesses and uses the data appropriately

7
New cards

Data Owner

Classifies data and decides who can access it

8
New cards

What is an injection attack?

An attack where an attacker inserts malicious commands or data into an application to make it perform unintended actions

9
New cards

SQL Injection

An attack where malicious SQL commands are inserted into an application to access or manipulate a database.

10
New cards

Command Injection

An attack where an attacker injects operating system commands into an application

11
New cards

What is the best defense against injection attacks?

Input validation and parameterized queries/ prepared statements

12
New cards

Trojan

Malware disguised as legitimate software that tricks users into installing it

13
New cards

Worm

Malware that can copy itself and spread automatically across networks without needing a user to install it

14
New cards

Virus

Attaches itself to an executable file and spreads when users run the file

15
New cards

Incident response steps

PICERL

Preparation

Identification

Containment

Eradication

Recovery

Lessons Learned

16
New cards

Drive-by download

Malware installs when visiting a compromised website

17
New cards

Hashing

One way, irreversible technique for securing data

18
New cards

CVSS

Provides a standardized system for rating vulnerabilities

19
New cards

CVE

A database for storing known vunerabilities

20
New cards

Package Monitoring

Helps identify and address vulnerabilities in software packages

21
New cards

Operational Security

Risk management process that encourages managers to view information protection from an adversary’s perspective

22
New cards

Playbook

Detailed, step-by-step procedures for handling specific incidents like phishing attacks

23
New cards

SNMP

Simple Network Management Protocol

Manages and monitors network devices

Does not monitor communications among software applications

24
New cards

SPF

Sender Policy Framework

Allows someone to specify which servers are allowed to send emails on behalf of the company’s domain

25
New cards

DMARC

Domain-based Message Authentication, Reporting and Conformance

Builds upon DKIM & SPF, it doesn’t use cryptographic signatures

26
New cards

DKIM

Domain Keys Identified Mail

Allows senders to associate a domain name with an email, proving its authenticity using a cryptographic signature

27
New cards

SE Linux

Supports access control policies, ensuring processes only have the permissions they require and no more

28
New cards

Enumeration

Systematically counting or listing assets, ensuring they are all accounted for and no unauthorized assets are present

29
New cards

Attestation

Process where data owners periodically review, validate and confirm the access right of all users

30
New cards

Federation

Making it so employees don’t need multiple passwords for multiple apps

31
New cards

Secure Enclave

Storage system embedded in devices to save symmetric and asymmetric keys

32
New cards

Incremental Backups

Only the changes since the last backup,

less resources

33
New cards

Differential Backups

All changes since the last full backup

34
New cards

Corrective Controls

Brings a system or environment back to its desired state post-incident

They don’t act to guide consistent actions

35
New cards

RoT

Root of Trust

A source that can always be trusted within a cryptographic system

*This does not describe the internet protocol used for obtaining the revocation status of a digital certficate

36
New cards

CRL

Cert Revocation List

List of certificates that have been revoked by a certificate authority before their scheduled expiration date

37
New cards

CA

Certificate Authority

Trusted entities that issue and manage security credentials and public keys for message encryption

38
New cards

80-HTTP

Web traffic

39
New cards

443-HTTPS

Secure Web Traffic

40
New cards

Policy engine

Makes access control decisions based on pre-defined policies and contextual info about subject/system

41
New cards

SIEM Tool

Collects logs from multiple devices and correlates them to detect security threats

42
New cards

OCSP

Online certificate Status Protocol

An internet protocol used for obtaining the revocation status of a digital certificate

43
New cards

Directive controls

Guides actions and ensure consistent behavior or actions within an organization

44
New cards

Firewall

A technical security control that monitors and controls incoming and outgoing network traffic based on predetermined security rules

45
New cards

Encryption

A technical security control that involves encoding data to prevent unauthorized access

46
New cards

Vulnerability management

A managerial security control that involves identifying, assessing, and remediating vulnerabilities in systems and networks

47
New cards

53-DNS

Network services

Name resolution

48
New cards

389-DHCP

Network Services

auto IP assignment

49
New cards

389-LDAP

Network Services

Directory services

50
New cards

22-SSH

Remote access port

Secure remote login

51
New cards

23-Telnet

Remote access port

Insecure remote login

52
New cards

3389-RDP

Remote access port

Remote desktop

53
New cards

20/21-FTP

File transfer port

54
New cards

445-SMB

File transfer port

Windows file sharing

55
New cards

25-SMTP

Email port

Sending email

56
New cards

110-POP3

Email port

Download email

57
New cards

143-IMAP

Email port

Sync email

58
New cards

Policy Admin

Defines and manages the access control policy used by the policy engine

59
New cards

Wildcard certificate

Can be used to secure multiple domains under a single main domain

60
New cards

Third Party Certificate

A ticket that is signed and verified by an external CA

61
New cards

PCI-DSS

Payment Card Industry Data Security Standard

Specifically addresses the protection of cardholder data

62
New cards