Security+

0.0(0)
Studied by 6 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/165

flashcard set

Earn XP

Description and Tags

Security+ Terms

Last updated 9:06 PM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

166 Terms

1
New cards

AAA

Security framework used to control access to computer resources, enforce policies, and audit usage within a network.

2
New cards

AUP

Defines how users are allowed to use organizational technology.

3
New cards

BIA

Determines the impact of a disruption on the business.

4
New cards

CCMP

WPA2 security protocol that uses AES to protect Wi-Fi traffic.

5
New cards

DHE

Key exchange using temporary keys, providing forward secrecy.

6
New cards

DES

Older symmetric encryption algorithm that is now insecure.

7
New cards

ECC

Asymmetric cryptography what provides strong security with smaller keys and smaller IoT devices.

8
New cards

ECDHE

ECC-based key exchange using temporary keys for forward secrecy.

9
New cards

EFS

Windows feature that provides file-level encryption.

10
New cards

ESP

IPsec component providing confidentiality, integrity, and authentication.

11
New cards

FDE

Encrypts an entire storage drive.

12
New cards

FTPS

FTP secured using SSL/TLS.

13
New cards

GPG

Open-source implementation of OpenPGP for encryption and digital signatures.

14
New cards

HSM

Dedicated hardware for securely storing and managing cryptographic keys.

15
New cards

IKE

Sets up IPsec connections and establishes cryptographic keys.

16
New cards

IPsec

Suite of protocols that secures IP network traffic. Provides: Encryption, Authentication, and Integrity.

17
New cards

IRP

Plan for responding to and recovering from security incidents.

18
New cards

KEK

Cryptographic key used to protect other cryptographic keys.

19
New cards

MIME

Allows email to contain attachments and different types of content.

20
New cards

MD5

Older hashing algorithm that is considered insecure.

21
New cards

PGP

Encryption and digital-signature system for emails and files.

22
New cards

PFS

Protects past sessions if a long-term key is later compromised.

23
New cards

PKI

Framework for managing public keys, private keys, and digital certificates.

24
New cards

PSK

Shared secret/password used for authentication.

25
New cards

RADIUS

AAA protocol commonly used for network access authentication.

26
New cards

RSA

Asymmetric cryptosystem used for encryption and digital signatures.

27
New cards

S/MIME

Adds encryption and digital signatures to email.

28
New cards

SED

Storage drive that automatically encrypts data using built-in hardware.

29
New cards

SHA-1

Older hashing algorithm that is considered insecure.

30
New cards

SFTP

Secure file transfer protocol that uses SSH.

31
New cards

SRTP

Secures real-time audio and video communications.

32
New cards

SSL

Older security protocol replaced by TLS.

33
New cards

TACACS+

AAA protocol commonly used for network device administration.

34
New cards

TKIP

Wi-Fi security protocol designed to improve WEP.

35
New cards

TLS

Modern protocol for securing network communications.

36
New cards

TPM

Hardware security chip that securely stores keys and helps verify device integrity.

37
New cards

WEP

Older, insecure Wi-Fi security protocol.

38
New cards

WPA2

Wi-Fi security standard commonly using CCMP/AES.

39
New cards

Preventive Security Control

Stops or prevents a security incident from occurring.

40
New cards

Deterrent Security Control

Discourages attackers from attempting an attack.

41
New cards

Detective Security Control

Identifies or discovers security incidents.

42
New cards

Corrective Security Control

Fixes or restores systems after an incident.

43
New cards

Compensating Security Control

Alternative control used when the primary control isn't feasible.

44
New cards

Directive Security Control

Tells users or employees what they should or shouldn't do.

45
New cards

PE

Makes the access decision based on security policies and available information.

46
New cards

PA

Carries out the Policy Engine's decision and communicates it to the PEP.

47
New cards

PEP

Enforces the access decision by allowing or denying access.

48
New cards

PDP

General term for the component that makes access-control decisions.

49
New cards

Control Plane

Makes decisions and manages/defines security policies.

50
New cards

Data Plane

Enforces policies and handles the actual network/data traffic.

51
New cards

Honeypot

Fake system designed to attract and detect attackers.

52
New cards

Honeynet

Network of honeypots designed to attract and monitor attackers.

53
New cards

Honeyfile

Fake/decoy file designed to detect unauthorized access.

54
New cards

Honeytoken

Fake piece of data or credential designed to detect/alert unauthorized use.

55
New cards

Technical Security Control Category

Uses technology to protect systems and data.

56
New cards

Managerial Security Control Category

Management decisions, policies, and oversight that manage security risks.

57
New cards

Operational Security Control Category

Security processes and procedures carried out by people.

58
New cards

Physical Security Control Category

Protects physical facilities, equipment, and people.

59
New cards

CIA

Three fundamental goals of information security.

60
New cards

Confidentiality

Ensures information is accessible only to authorized users.

61
New cards

Integrity

Ensures information remains accurate and is not improperly modified.

62
New cards

Availability

Ensures systems and data are accessible when needed.

63
New cards

Non-repudiation

Verifies who a user or device is.

64
New cards

Authentication

Verifies who a user or device is.

65
New cards

Authorization

Determines what an authenticated user or device is allowed to access or do.

66
New cards

Accounting

Records and tracks what a user or device does.

67
New cards

IDEA

Older symmetric block cipher, largely replaced by AES.

68
New cards

Block Cipher

Encrypts data in fixed-size blocks/chunks.

69
New cards

CBC

Chains ciphertext blocks together so each block depends on the previous block.

70
New cards

CFB

Uses a block cipher like a stream cipher, allowing encryption of smaller amounts of data.

71
New cards

CTM

Uses a unique counter and encryption key to generate pseudorandom data for encryption.

72
New cards

ECB

Older, simple block cipher mode where blocks are encrypted independently, which can reveal patterns

73
New cards

GCM

Provides both encryption/confidentiality and authentication/integrity

74
New cards

Resource Reuse

When physical resources are reused between VMs, potentially allowing data from one VM to be exposed to another

75
New cards

VM

A virtualized computer that runs on physical hardware

76
New cards

Hypervisor

Software that manages VMs and allocates physical resources such as CPU, memory, and storage

77
New cards

VM Escape

An attack where an attacker breaks out of a VM and gains access to the host or potentially other VMs

78
New cards

KDC

Centralized server that distributes cryptographic keys and authenticates users/services

79
New cards

TGT

A Kerberos ticket that lets a user access multiple network services without re-entering their credentials.

80
New cards

RC4

A deprecated stream cipher used in some legacy applications

81
New cards

SHA-3

Modern cryptographic hash function used to ensure data integrity.

82
New cards

HMAC

Combines a hash function with a secret key to verify a message’s integrity and authenticity.

83
New cards

CRC

Non-cryptographic hash used for error checking, not security.

84
New cards

Digital Signature

Cryptographic technique that uses the sender’s private key to verify a message’s authenticity and integrity.

85
New cards

DSA

Public-key algorithm used to create and verify digital signatures for authenticity and integrity.

86
New cards

ECDSA

Public-key algorithm that uses elliptic curves to create and verify digital signatures for authenticity and integrity. More computationally efficient algorithm.

87
New cards

PBKDF2

A key stretching algorithm.

88
New cards

PKCS

A set of standards defining formats and methods for public keys, private keys, digital signatures, and certificates.

89
New cards

P12

A file format for securely storing and exchanging private keys and digital certificates.

90
New cards

Digital Certificate

An electronic document that binds an identity to a public key, proving the key belongs to the proper sender.

91
New cards

RA

Verifies the identity of users requesting certificates and approves or rejects certificate requests before the CA issues the certificate.

92
New cards

OCSP

An Internet protocol used to check the revocation status of a digital certificate in real time.

93
New cards

Wildcard Certificate

A certificate that secures multiple subdomains of the same domain using a (*).

94
New cards

CSR

A request sent to a CA to obtain a digital certificate, containing the requester’s identity information and public key.

95
New cards

X.509

Standard format for digital certificates.

96
New cards

SAN

Extension in an X.509 that lets you specify additional names.

97
New cards

OID

Identifier used for PKI objects

98
New cards

Nation-State

Threat actor: Governments

99
New cards

Unskilled

Threat Actor: Script Kiddie

100
New cards

Hacktivist

Threat Actor: Activism