1/61
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Keylogger attack/ Spyware attack
Records what you type
Steals information
Hides itself from the operating system while maintaining privileged access
Rootkit attack
Hides malware and gives deep control of a system
Stays hidden and maintains access
Persistent access
Administrator/root privileges
Public Key
Encrypts data or verify digital signatures
Private Key
Decrypts data and creates digital signatures
Data Custodian
Stores, backs up, and protects the data according to the owner’s policies
Data User
Accesses and uses the data appropriately
Data Owner
Classifies data and decides who can access it
What is an injection attack?
An attack where an attacker inserts malicious commands or data into an application to make it perform unintended actions
SQL Injection
An attack where malicious SQL commands are inserted into an application to access or manipulate a database.
Command Injection
An attack where an attacker injects operating system commands into an application
What is the best defense against injection attacks?
Input validation and parameterized queries/ prepared statements
Trojan
Malware disguised as legitimate software that tricks users into installing it
Worm
Malware that can copy itself and spread automatically across networks without needing a user to install it
Virus
Attaches itself to an executable file and spreads when users run the file
Incident response steps
PICERL
Preparation
Identification
Containment
Eradication
Recovery
Lessons Learned
Drive-by download
Malware installs when visiting a compromised website
Hashing
One way, irreversible technique for securing data
CVSS
Provides a standardized system for rating vulnerabilities
CVE
A database for storing known vunerabilities
Package Monitoring
Helps identify and address vulnerabilities in software packages
Operational Security
Risk management process that encourages managers to view information protection from an adversary’s perspective
Playbook
Detailed, step-by-step procedures for handling specific incidents like phishing attacks
SNMP
Simple Network Management Protocol
Manages and monitors network devices
Does not monitor communications among software applications
SPF
Sender Policy Framework
Allows someone to specify which servers are allowed to send emails on behalf of the company’s domain
DMARC
Domain-based Message Authentication, Reporting and Conformance
Builds upon DKIM & SPF, it doesn’t use cryptographic signatures
DKIM
Domain Keys Identified Mail
Allows senders to associate a domain name with an email, proving its authenticity using a cryptographic signature
SE Linux
Supports access control policies, ensuring processes only have the permissions they require and no more
Enumeration
Systematically counting or listing assets, ensuring they are all accounted for and no unauthorized assets are present
Attestation
Process where data owners periodically review, validate and confirm the access right of all users
Federation
Making it so employees don’t need multiple passwords for multiple apps
Secure Enclave
Storage system embedded in devices to save symmetric and asymmetric keys
Incremental Backups
Only the changes since the last backup,
less resources
Differential Backups
All changes since the last full backup
Corrective Controls
Brings a system or environment back to its desired state post-incident
They don’t act to guide consistent actions
RoT
Root of Trust
A source that can always be trusted within a cryptographic system
*This does not describe the internet protocol used for obtaining the revocation status of a digital certficate
CRL
Cert Revocation List
List of certificates that have been revoked by a certificate authority before their scheduled expiration date
CA
Certificate Authority
Trusted entities that issue and manage security credentials and public keys for message encryption
80-HTTP
Web traffic
443-HTTPS
Secure Web Traffic
Policy engine
Makes access control decisions based on pre-defined policies and contextual info about subject/system
SIEM Tool
Collects logs from multiple devices and correlates them to detect security threats
OCSP
Online certificate Status Protocol
An internet protocol used for obtaining the revocation status of a digital certificate
Directive controls
Guides actions and ensure consistent behavior or actions within an organization
Firewall
A technical security control that monitors and controls incoming and outgoing network traffic based on predetermined security rules
Encryption
A technical security control that involves encoding data to prevent unauthorized access
Vulnerability management
A managerial security control that involves identifying, assessing, and remediating vulnerabilities in systems and networks
53-DNS
Network services
Name resolution
389-DHCP
Network Services
auto IP assignment
389-LDAP
Network Services
Directory services
22-SSH
Remote access port
Secure remote login
23-Telnet
Remote access port
Insecure remote login
3389-RDP
Remote access port
Remote desktop
20/21-FTP
File transfer port
445-SMB
File transfer port
Windows file sharing
25-SMTP
Email port
Sending email
110-POP3
Email port
Download email
143-IMAP
Email port
Sync email
Policy Admin
Defines and manages the access control policy used by the policy engine
Wildcard certificate
Can be used to secure multiple domains under a single main domain
Third Party Certificate
A ticket that is signed and verified by an external CA
PCI-DSS
Payment Card Industry Data Security Standard
Specifically addresses the protection of cardholder data