Advanced Security+ Prep

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/50

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:45 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

51 Terms

1
New cards

Metric that provide early warnings of increasing risk exposures, enabling organization’s leadership to manage these risks proactively

Key Risk Indicators

2
New cards

Risk Threshold

Defined level of risk an organization is willing to accept

3
New cards

Risk Metrics

Quantitative measures of risk

4
New cards

Risk Parameters

Specific variables used within risk assessment processes

5
New cards

Time-of-check (TOC)

Vulnerability that occurs when an attacker exploits the time gap between the verification of data and its use, potentially leading to unauthorized or malicious activities

6
New cards

Memory Leaks

When a program doesn’t release memory that it no longer needs, leading to potential system slowdowns or crashes

7
New cards

Race Conditions

The unexpected order and timing of events in software execution

8
New cards

Resource Exhuastion

The overuse of system resources, be it CPU time, memory, or others, which can lead to denial of service

9
New cards

Key Exchange

A process in which two communicating parties establish a shared secret key, typically used for symmetric encryption.

10
New cards

Asymmetric Encryption

Uses different keys for encryption and decryption

11
New cards

Symmetric Encryption

Uses the same key for both encryption and decryption

12
New cards

Hashing

Converting input data into a fixed-length string of bytes

13
New cards

Resilience

The ability of the system to quickly recover from failures and maintain operational performance, crucial for ensuring availability during adverse conditions

14
New cards

Availability

Guaranteeing a system will continue to operate so that the system can be used regardless of conditions

15
New cards

Scalability

The system can expand when more resources are needed without creating lags or problems for users

16
New cards

Ease of Deployment

New instances and the entire cloud environment can be easily created

17
New cards

SD-WAN

Provides centralized network management, flexible routing, and traffic management capabilities

18
New cards

TLS

Operates at the application layer and is primarily used for securing application-level communication

19
New cards

SASE

Cloud-based solution that integrates network security and WAN capabilities

20
New cards

AH

Protocol component of IPSec which offers packet integrity

21
New cards

ECC

Asymmetric, type of trapdoor function that is efficient with shorter key lengths

22
New cards

Diffie-Hellman

Algorithm for secure key exchange

23
New cards

DSA

Algorithm used for digital signatures

24
New cards

RSA

Asymmetric, requires longer key lengths

25
New cards

Inline

Device that is designed to interact with network traffic actively and can take actions such as accepting, rejecting, or modifying packets

26
New cards

SASE

Form of cloud architecture that combines a number of services as a single service

27
New cards

Fail-close

What happens when a network encounters errors and exceptions

28
New cards

Remote Access

Allows users to connect to a network or device from a distant location

29
New cards

802.1X

Standard developed by the IEEE to govern port-based network access

30
New cards

Fail-open

When errors occur or exceptions are encountered, the system continues allowing access rather than denying access

31
New cards

IDS

Monitors network traffic for malicious activities

32
New cards

Fail-close

When errors occur or exceptions are encountered, the system denies further access

33
New cards

Inadequate buffer overflow protections

Which security concerns might arise with the use of RTOS?

34
New cards

Public key

When sending an encrypted message, a client would use which of the following to ensure only the destination company can decrypt and read the message?

35
New cards

Private key

When receiving an encrypted message from a client, the holding company would use which of the following to decrypt the message?

36
New cards

Key escrow

The secure storage of cryptographic keys, ensuring they can be accessed under specific conditions

37
New cards

Wildcard Certficate

Secures multiple subdomains under a main domain but doesn’t directly involve message encryption or decryption

38
New cards

Buffer Overflow

A type of memory corruption that occurs when a program writes more data than the allocated buffer, the area of memory set aside to temporarily hold user input, can hold

39
New cards

Buffer Underflow

A type of memory corruption that occurs when a program reads more data than the allocated buffer can provide, causing it to read from invalid memory locations

40
New cards

Memory Fragmentation

A type of memory issue that occurs when a program allocates and frees memory in an irregular or inefficient manner, causing the available memory to be divided into small and non-contiguous blocks

41
New cards

Memory Leak

A type of memory issue that occurs when a program fails to release or free the memory that it has allocated, causing it to consume more and more memory over time.

42
New cards

End-of-life vulnerability

Can allow a hardware attack that involves exploiting vulnerabilities in devices that are no longer supported or updated by the manufacturer

43
New cards

Legacy vulnerability

May allow an attack that involves exploiting vulnerabilities in devices that are outdated or obsolete

44
New cards

Hardware tampering

A hardware attack that involves physically altering or damaging hardware devices to compromise their functionality

45
New cards

Hardware cloning

A hardware attack that involves creating unauthorized copies of hardware devices to counterfeit their functionality

46
New cards

WPA2-PSK

Leverages a passphrase to create a kye, called the PMK, to encrypt communication

47
New cards

Dragonfly handshake with a MAC address hash

Feature of the WPA3’s SAE method

48
New cards

Password Authenticated Key Exchange (PAKE)

A method associated with WPA3’s SAE protocol to share keys

49
New cards

Trapdoor function

What best describes RSA’s underlying mathematical property used for public key cryptography?

50
New cards

Ensuring the vendor’s practices align with the organization’s requirements

Which of the following is an example of due diligence?

51
New cards

Environmental variables refer to the unique characteristics of an organization's infrastructure that can affect vulnerability assessments and risk analysis

Environment Variables