1/165
Security+ Terms
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
AAA
Security framework used to control access to computer resources, enforce policies, and audit usage within a network.
AUP
Defines how users are allowed to use organizational technology.
BIA
Determines the impact of a disruption on the business.
CCMP
WPA2 security protocol that uses AES to protect Wi-Fi traffic.
DHE
Key exchange using temporary keys, providing forward secrecy.
DES
Older symmetric encryption algorithm that is now insecure.
ECC
Asymmetric cryptography what provides strong security with smaller keys and smaller IoT devices.
ECDHE
ECC-based key exchange using temporary keys for forward secrecy.
EFS
Windows feature that provides file-level encryption.
ESP
IPsec component providing confidentiality, integrity, and authentication.
FDE
Encrypts an entire storage drive.
FTPS
FTP secured using SSL/TLS.
GPG
Open-source implementation of OpenPGP for encryption and digital signatures.
HSM
Dedicated hardware for securely storing and managing cryptographic keys.
IKE
Sets up IPsec connections and establishes cryptographic keys.
IPsec
Suite of protocols that secures IP network traffic. Provides: Encryption, Authentication, and Integrity.
IRP
Plan for responding to and recovering from security incidents.
KEK
Cryptographic key used to protect other cryptographic keys.
MIME
Allows email to contain attachments and different types of content.
MD5
Older hashing algorithm that is considered insecure.
PGP
Encryption and digital-signature system for emails and files.
PFS
Protects past sessions if a long-term key is later compromised.
PKI
Framework for managing public keys, private keys, and digital certificates.
PSK
Shared secret/password used for authentication.
RADIUS
AAA protocol commonly used for network access authentication.
RSA
Asymmetric cryptosystem used for encryption and digital signatures.
S/MIME
Adds encryption and digital signatures to email.
SED
Storage drive that automatically encrypts data using built-in hardware.
SHA-1
Older hashing algorithm that is considered insecure.
SFTP
Secure file transfer protocol that uses SSH.
SRTP
Secures real-time audio and video communications.
SSL
Older security protocol replaced by TLS.
TACACS+
AAA protocol commonly used for network device administration.
TKIP
Wi-Fi security protocol designed to improve WEP.
TLS
Modern protocol for securing network communications.
TPM
Hardware security chip that securely stores keys and helps verify device integrity.
WEP
Older, insecure Wi-Fi security protocol.
WPA2
Wi-Fi security standard commonly using CCMP/AES.
Preventive Security Control
Stops or prevents a security incident from occurring.
Deterrent Security Control
Discourages attackers from attempting an attack.
Detective Security Control
Identifies or discovers security incidents.
Corrective Security Control
Fixes or restores systems after an incident.
Compensating Security Control
Alternative control used when the primary control isn't feasible.
Directive Security Control
Tells users or employees what they should or shouldn't do.
PE
Makes the access decision based on security policies and available information.
PA
Carries out the Policy Engine's decision and communicates it to the PEP.
PEP
Enforces the access decision by allowing or denying access.
PDP
General term for the component that makes access-control decisions.
Control Plane
Makes decisions and manages/defines security policies.
Data Plane
Enforces policies and handles the actual network/data traffic.
Honeypot
Fake system designed to attract and detect attackers.
Honeynet
Network of honeypots designed to attract and monitor attackers.
Honeyfile
Fake/decoy file designed to detect unauthorized access.
Honeytoken
Fake piece of data or credential designed to detect/alert unauthorized use.
Technical Security Control Category
Uses technology to protect systems and data.
Managerial Security Control Category
Management decisions, policies, and oversight that manage security risks.
Operational Security Control Category
Security processes and procedures carried out by people.
Physical Security Control Category
Protects physical facilities, equipment, and people.
CIA
Three fundamental goals of information security.
Confidentiality
Ensures information is accessible only to authorized users.
Integrity
Ensures information remains accurate and is not improperly modified.
Availability
Ensures systems and data are accessible when needed.
Non-repudiation
Verifies who a user or device is.
Authentication
Verifies who a user or device is.
Authorization
Determines what an authenticated user or device is allowed to access or do.
Accounting
Records and tracks what a user or device does.
IDEA
Older symmetric block cipher, largely replaced by AES.
Block Cipher
Encrypts data in fixed-size blocks/chunks.
CBC
Chains ciphertext blocks together so each block depends on the previous block.
CFB
Uses a block cipher like a stream cipher, allowing encryption of smaller amounts of data.
CTM
Uses a unique counter and encryption key to generate pseudorandom data for encryption.
ECB
Older, simple block cipher mode where blocks are encrypted independently, which can reveal patterns
GCM
Provides both encryption/confidentiality and authentication/integrity
Resource Reuse
When physical resources are reused between VMs, potentially allowing data from one VM to be exposed to another
VM
A virtualized computer that runs on physical hardware
Hypervisor
Software that manages VMs and allocates physical resources such as CPU, memory, and storage
VM Escape
An attack where an attacker breaks out of a VM and gains access to the host or potentially other VMs
KDC
Centralized server that distributes cryptographic keys and authenticates users/services
TGT
A Kerberos ticket that lets a user access multiple network services without re-entering their credentials.
RC4
A deprecated stream cipher used in some legacy applications
SHA-3
Modern cryptographic hash function used to ensure data integrity.
HMAC
Combines a hash function with a secret key to verify a message’s integrity and authenticity.
CRC
Non-cryptographic hash used for error checking, not security.
Digital Signature
Cryptographic technique that uses the sender’s private key to verify a message’s authenticity and integrity.
DSA
Public-key algorithm used to create and verify digital signatures for authenticity and integrity.
ECDSA
Public-key algorithm that uses elliptic curves to create and verify digital signatures for authenticity and integrity. More computationally efficient algorithm.
PBKDF2
A key stretching algorithm.
PKCS
A set of standards defining formats and methods for public keys, private keys, digital signatures, and certificates.
P12
A file format for securely storing and exchanging private keys and digital certificates.
Digital Certificate
An electronic document that binds an identity to a public key, proving the key belongs to the proper sender.
RA
Verifies the identity of users requesting certificates and approves or rejects certificate requests before the CA issues the certificate.
OCSP
An Internet protocol used to check the revocation status of a digital certificate in real time.
Wildcard Certificate
A certificate that secures multiple subdomains of the same domain using a (*).
CSR
A request sent to a CA to obtain a digital certificate, containing the requester’s identity information and public key.
X.509
Standard format for digital certificates.
SAN
Extension in an X.509 that lets you specify additional names.
OID
Identifier used for PKI objects
Nation-State
Threat actor: Governments
Unskilled
Threat Actor: Script Kiddie
Hacktivist
Threat Actor: Activism