CompTIA CySA+

0.0(0)
Studied by 1 person
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/61

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:16 PM on 6/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

62 Terms

1
New cards

Security Control

Mitigates vulnerabilities and risk to ensure the CIA, non-repudiation, and authentication of data

2
New cards

NIST SP 800-53

Security and Privacy Controls for Information Systems and Organizations

3
New cards

Techinal (Logical) Controls

A category of security control that is implemented as a system (hardware, software, or firmware)

4
New cards

Operational Controls

A category of security control that is implemented primarily by people rather than systems

5
New cards

Managerial Controls

A category of security control that provides oversight of the information system

6
New cards

Preventative Control

A control that acts to eliminate or reduce the likelihood that an attack can succeed

7
New cards

Detective Control

A control that identifies and records any attempted or successful intrusion

8
New cards

Corrective Control

A control that acts to eliminate or reduce the impact of an instrusion event

9
New cards

Physical Control

A control that acts against in-person intrusion attempts

10
New cards

Deterrent Control

A control that discourages intrusion attempts

11
New cards

Compensating Control

A control that acts as a substitute for a principal control

12
New cards

Responsive Control

System that actively monitors for potential vulnerabilities or attacks, and then takes action to mitigate them before they can cause damage

13
New cards

Security Intelligence

Process where data is generated and is then collected, processed, analyzed, and disseminated to provide insights into the security status

14
New cards

Cyber Threat Intelligence

Investigation, collection, analysis, and dissemination of info about emerging threats and threat sources to provide data about the external threat landscape

15
New cards

Information Sharing and Analysis Center (ISAC)

A non-profit group set up to share sector-specific threat intelligence and security best practices amongst its members

16
New cards

Critical Infrastructure

Any physical or virtual infrastructure considered so vital to the US that its destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination of these

17
New cards

Diamond Model of Intrusion Analysis

A framework for analyzing cybersecurity incidents and intrusions by exploring the relationships between four core features, adversary, capability, infrastructure, and victim

18
New cards

MRTG

Used for graphing traffic trends on network links, useful for spotting unusual traffic patterns

19
New cards

DGA

Used by malware to obfuscate their C2 servers’ IP addresses

20
New cards

OSSIM

Open-source SIEM developed by AlienVault

21
New cards

Syslog

Centralized log management solution

22
New cards

Carving

Extracting data from an image when that data has no associated file system metadata

23
New cards

Rogue Devices - Mitigation

Use digital certs on endpoints and servers to authenticate and encrypt traffic using IPSec or HTTPS

24
New cards

Network Tap

Physical device attached to cabling to record packets passing over that network segment

25
New cards

Network Mapping and Host Discovery

Enumeration scanners can identify hosts via banner grabbing or fingerprinting of devices across the network

26
New cards

Wireless Monitoring

Wireless sniffing can be used to find unknown or unidentifiable SSIDs showing up within range of the office

27
New cards

Packet Sniffing and Traffic Flow

Used to identify the use of unauthorized protocols on the netowrk and unusual peer-to-peer communication flows

28
New cards

NAC and Intrusion Detection

Automated scanning with defense and remediation suites can try to prevent rogue devices from accessing the network

29
New cards

FTP

Port 21

30
New cards

SMTP

Port 25

31
New cards

POP3

110

32
New cards

RPCBIND

Port 111

33
New cards

MSRPC

Port 135

34
New cards

NETBIOS-SSN (Windows file sharing with pre-Windows 2000)

Poer 139

35
New cards

IMAP

Port 143

36
New cards

IMAPS

Port 993

37
New cards

POP3S

Port 995

38
New cards

PPTP

Port 1723

39
New cards

MySQL

Port 3306

40
New cards

VNC (Like RDP but open-source)

Port 5900

41
New cards

Code of Conduct

Defined set of rules, ethics, and expectations for employees in a particular job role

42
New cards

Privileged User Agreement (PUA)

Contract with terms stating a code of conduct for employees is assigned based on their higher level permissions on the network

43
New cards

Acceptable Use Policy

Policy that governs employees’ use of company equipment and Internet services

44
New cards

Function as a Service (FAAS)

A cloud service model that supports serverless software architecture by provisioning runtime containers in which code is executed in a particular programming language

45
New cards

Security Orchestration, Automation, and Response (SOAR)

Class of security tools that facilitates incident response, threat hunting, and security configuration by orchestrating automated run-books and delivering data enrichment

46
New cards

Next-Gen SIEM

A SIEM with an integrated SOAR

47
New cards

Six Sigma

An iterative process that involves key steps including define, measure, analyze, improve, and control

48
New cards

Lean/Lean Methodology

Focuses on minimizing waste and maximizing value in all of your processes

49
New cards

Continual Service Improvement Model (CSI)

A process that helps organizations identify and implement changes to improve their services

50
New cards

Dual Control Execution

2 individuals verifying or authorizing and transaction

51
New cards

Nmap: -sn

Host discovery

52
New cards

Nmap: List Scan (-sL)

Lists IPs from supplied target range(s) and performs a reverse DNS query to discover any host names associated with this IPs

53
New cards

Nmap: Sparse Scanning (—scan-delay <Time>)

Issues probes with delays to become stealthier to avoid IDS or IPS detection

54
New cards

Nmap: Scan Timing (-Tn)

Issues probes with a timing [pattern with n being the pattern to utilize (0 is slowest and 5 is fastest)

55
New cards

Nmap: TCP Idle Scan (-sl)

Makes scan appear that another machine (a zombie) started the scan

56
New cards

Nmap: Fragmentation(-f or —mtu)

Splits TCP header of each probe between multiple IP datagrams to make it hard for an IDS or IPS to detect

57
New cards

Reaver

A command-line tool used to perform brute force attacks against WPS-enabled access points

58
New cards

SDLC - Waterfall

Phases of the SDLC cascade so that each phase starts only when all tasks in previous phase are complete

59
New cards

SDLC - Agile

Focuses on iterative and incremental development to account for evolving requirements and expectations

60
New cards

Security Development Life Cycle (SDL)

Microsoft’s security framework for app development that supports dynamic development processes

61
New cards

OWASP Software Security Assurance Process

OWASP’s security framework for secure app developement

62
New cards

SysAdmin, Network, and Security (SANS) Institute

Company specializing in cyber security and secure web app development training and sponsors the Global Information Assurance Certification (GIAC)