1/50
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Metric that provide early warnings of increasing risk exposures, enabling organization’s leadership to manage these risks proactively
Key Risk Indicators
Risk Threshold
Defined level of risk an organization is willing to accept
Risk Metrics
Quantitative measures of risk
Risk Parameters
Specific variables used within risk assessment processes
Time-of-check (TOC)
Vulnerability that occurs when an attacker exploits the time gap between the verification of data and its use, potentially leading to unauthorized or malicious activities
Memory Leaks
When a program doesn’t release memory that it no longer needs, leading to potential system slowdowns or crashes
Race Conditions
The unexpected order and timing of events in software execution
Resource Exhuastion
The overuse of system resources, be it CPU time, memory, or others, which can lead to denial of service
Key Exchange
A process in which two communicating parties establish a shared secret key, typically used for symmetric encryption.
Asymmetric Encryption
Uses different keys for encryption and decryption
Symmetric Encryption
Uses the same key for both encryption and decryption
Hashing
Converting input data into a fixed-length string of bytes
Resilience
The ability of the system to quickly recover from failures and maintain operational performance, crucial for ensuring availability during adverse conditions
Availability
Guaranteeing a system will continue to operate so that the system can be used regardless of conditions
Scalability
The system can expand when more resources are needed without creating lags or problems for users
Ease of Deployment
New instances and the entire cloud environment can be easily created
SD-WAN
Provides centralized network management, flexible routing, and traffic management capabilities
TLS
Operates at the application layer and is primarily used for securing application-level communication
SASE
Cloud-based solution that integrates network security and WAN capabilities
AH
Protocol component of IPSec which offers packet integrity
ECC
Asymmetric, type of trapdoor function that is efficient with shorter key lengths
Diffie-Hellman
Algorithm for secure key exchange
DSA
Algorithm used for digital signatures
RSA
Asymmetric, requires longer key lengths
Inline
Device that is designed to interact with network traffic actively and can take actions such as accepting, rejecting, or modifying packets
SASE
Form of cloud architecture that combines a number of services as a single service
Fail-close
What happens when a network encounters errors and exceptions
Remote Access
Allows users to connect to a network or device from a distant location
802.1X
Standard developed by the IEEE to govern port-based network access
Fail-open
When errors occur or exceptions are encountered, the system continues allowing access rather than denying access
IDS
Monitors network traffic for malicious activities
Fail-close
When errors occur or exceptions are encountered, the system denies further access
Inadequate buffer overflow protections
Which security concerns might arise with the use of RTOS?
Public key
When sending an encrypted message, a client would use which of the following to ensure only the destination company can decrypt and read the message?
Private key
When receiving an encrypted message from a client, the holding company would use which of the following to decrypt the message?
Key escrow
The secure storage of cryptographic keys, ensuring they can be accessed under specific conditions
Wildcard Certficate
Secures multiple subdomains under a main domain but doesn’t directly involve message encryption or decryption
Buffer Overflow
A type of memory corruption that occurs when a program writes more data than the allocated buffer, the area of memory set aside to temporarily hold user input, can hold
Buffer Underflow
A type of memory corruption that occurs when a program reads more data than the allocated buffer can provide, causing it to read from invalid memory locations
Memory Fragmentation
A type of memory issue that occurs when a program allocates and frees memory in an irregular or inefficient manner, causing the available memory to be divided into small and non-contiguous blocks
Memory Leak
A type of memory issue that occurs when a program fails to release or free the memory that it has allocated, causing it to consume more and more memory over time.
End-of-life vulnerability
Can allow a hardware attack that involves exploiting vulnerabilities in devices that are no longer supported or updated by the manufacturer
Legacy vulnerability
May allow an attack that involves exploiting vulnerabilities in devices that are outdated or obsolete
Hardware tampering
A hardware attack that involves physically altering or damaging hardware devices to compromise their functionality
Hardware cloning
A hardware attack that involves creating unauthorized copies of hardware devices to counterfeit their functionality
WPA2-PSK
Leverages a passphrase to create a kye, called the PMK, to encrypt communication
Dragonfly handshake with a MAC address hash
Feature of the WPA3’s SAE method
Password Authenticated Key Exchange (PAKE)
A method associated with WPA3’s SAE protocol to share keys
Trapdoor function
What best describes RSA’s underlying mathematical property used for public key cryptography?
Ensuring the vendor’s practices align with the organization’s requirements
Which of the following is an example of due diligence?
Environmental variables refer to the unique characteristics of an organization's infrastructure that can affect vulnerability assessments and risk analysis
Environment Variables