Mitigation Techniques - CompTIA Security+ SY0-701 - 2.5

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/5

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:17 PM on 3/29/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

6 Terms

1
New cards

Mitigation techniques

- Patching

• Monthly updates -Incremental (and important)

• Third-party updates -Application developers, device drivers

• Auto-update -Not always the best option

• Emergency out-of-band updates -Zero-day and important security discoveries

- Encryption

- Monitoring

- Least privilege

- Configuration enforcement

- Decommissioning

2
New cards

Encryption

Prevent access to application data files

- File system encryption

File level encryption

- Windows EFS

Full disk ecryption (FDE)

- Encrypt everything on the drive

- Bitlocker, FileVault, Etc.

Application data encryption

- Managed by the app

- Stored data is protected

3
New cards

Monitoring

Aggregate information from devices

- Built-in sensors, separate devices

- Integrated into servers, switches, routers, firewalls, etc

Sensors

- Intrusion prevention systems, firewall logs, authentication logs, web server access logs, data base transaction logs, email logs

Collectors

- Proprietary consoles (IPS, firewall), SIEM consoles, syslog servers

- Many SIEMs include a correlation engine to compare diverse sensor data

4
New cards

Least Privilege

Rights and permissions should be set to the bare minimum

- You only get exactly what's needed to complete your objective

All user accounts must be limited

- Applications should run with minimal priveleges

Don't allow users to run with admin privileges

5
New cards

Configuration enforcement

• Perform a posture assessment

- Each time a device connects

• Extensive check

- OS patch version

- EDR (Endpoint Detection and Response) version

- Status of firewall and EDR

- Certificate status

• Systems out of compliance are quarantined

- Private VLAN with limited access

- Recheck after making corrections

6
New cards

Decommissioning

Should b

Explore top notes

note
Chapter 31
Updated 377d ago
0.0(0)
note
Chapter 29.1
Updated 1403d ago
0.0(0)
note
Redox chemistry
Updated 769d ago
0.0(0)
note
Escape and Avoidance Learning
Updated 1289d ago
0.0(0)
note
6 IGOs
Updated 1167d ago
0.0(0)
note
Civil Rights Movement
Updated 321d ago
0.0(0)
note
Chapter 31
Updated 377d ago
0.0(0)
note
Chapter 29.1
Updated 1403d ago
0.0(0)
note
Redox chemistry
Updated 769d ago
0.0(0)
note
Escape and Avoidance Learning
Updated 1289d ago
0.0(0)
note
6 IGOs
Updated 1167d ago
0.0(0)
note
Civil Rights Movement
Updated 321d ago
0.0(0)

Explore top flashcards

flashcards
The Rise & Spread of Islam
35
Updated 1138d ago
0.0(0)
flashcards
Phrasal verb C1C2
100
Updated 564d ago
0.0(0)
flashcards
FOOD TECH FOOD QUALITY
64
Updated 589d ago
0.0(0)
flashcards
Gran Hotel 8-11
37
Updated 1125d ago
0.0(0)
flashcards
spanish imperfect verbs
75
Updated 851d ago
0.0(0)
flashcards
Mythology Vocabulary 2
25
Updated 1146d ago
0.0(0)
flashcards
The Rise & Spread of Islam
35
Updated 1138d ago
0.0(0)
flashcards
Phrasal verb C1C2
100
Updated 564d ago
0.0(0)
flashcards
FOOD TECH FOOD QUALITY
64
Updated 589d ago
0.0(0)
flashcards
Gran Hotel 8-11
37
Updated 1125d ago
0.0(0)
flashcards
spanish imperfect verbs
75
Updated 851d ago
0.0(0)
flashcards
Mythology Vocabulary 2
25
Updated 1146d ago
0.0(0)