Sec+ practice test stuff

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/86

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:59 PM on 6/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

87 Terms

1
New cards

compensating control

Alternative security measure deployed when a primary safeguard is impractical or cannot be implemented

2
New cards

OSINT (open-source intelligence)

Data gathered from publicly available feeds mass media and internet records for investigative purposes

3
New cards

Wireless deauthentication

Spoofed management frames sent to sever the link between a client station and an access point forcing a reconnect

4
New cards

wireless disassociation

A formal protocol notification that gracefully terminates an active wireless session before a device roams

5
New cards

DNS poisoning

Exploiting vulnerabilities in name resolution servers to inject forged records and redirect traffic to malicious servers

6
New cards

RBAC (Role based Access control)

Authorization framework where system permissions are tied directly to specific job functions and organizational positions

7
New cards

SDN(Software-defined networking)

Architecture that decouples the network routing logic from the underlying physical hardware forwarding assets

8
New cards

Shadow IT

Hardware software or cloud services deployed within an organization without the explicit approval or knowledge of the department

9
New cards

Nation state

Highly sophisticated and well-funded cyber actors operating under the direction of a sovereign government for espionage

10
New cards

Hacktivist

Individuals or groups executing disruptive digital campaigns to promote a specific political agenda or social cause

11
New cards

Organized crime

Structured syndicates executing sophisticated digital operations primarily driven by financial theft and monetary extortion

12
New cards

Self-assessment

An internal evaluation conducted by an organization to measure its own security posture against specific frameworks

13
New cards

Regulatory compliance

Adherence to external laws governmental mandates and industry-specific legal requirements regarding data handling

14
New cards

Vendor monitoring

Continuous oversight and risk evaluation of third-party service providers to ensure security standards are maintained

15
New cards

Attestation

A formal declaration or technical proof verifying that a specific system state or configuration meets strict requirements

16
New cards

OCSP stapling

A mechanism where a web server queries certificate validity on behalf of the client to speed up connection validation

17
New cards

CSR generation

Creating a formal request containing a public key to be submitted to an authority for digital signing

18
New cards

Wildcard

A public key certificate that uses an asterisk to secure a base domain along with all its immediate subdomains

19
New cards

TLS handshake

The initial negotiation phase where cryptographic protocols keys and cipher suites are established between client and server

20
New cards

Resource consumption

The exhaustion of computational assets like memory CPU or storage often caused by poorly optimized code or denial attacks

21
New cards

RAID (Redundant Array of Independent Disks)

Storage technology that combines multiple physical drives into a single logical unit for fault tolerance

22
New cards

Due diligence

The investigative research and vetting an organization performs before entering into a business contract or partnership

23
New cards

Right-to-audit

A contractual clause permitting an organization to inspect the security controls and operational records of a third party

24
New cards

Chain of custody

Chronological documentation showing the continuous seizure control transfer and analysis of digital evidence

25
New cards

Legal hold

An internal directive ordering the preservation of all relevant data and documents for potential or active litigation

26
New cards

E-discovery

The process of identifying locating and securing electronic records to be used as evidence in a legal proceeding

27
New cards

HIPS (Host-based IPS)

An endpoint security application that actively monitors local system behavior to block malicious activities

28
New cards

UTM logs

Unified threat management logs - Consolidated security records aggregating events from firewalls web filters and intrusion detection systems

29
New cards

MFA(Multi-Factor Authentication )

Identity verification process requiring at least two distinct categories of credentials before granting access

30
New cards

ACL(Access Control List )

A sequential registry of rules determining which users or network packets are permitted or denied entry

31
New cards

physical control

Measures to protect assets using physical barriers like locks fencing and guards

32
New cards

operational control

Security measures implemented by people such as training and incident response plans

33
New cards

managerial control

Administrative policies and guidelines directing an organization's overall security stance

34
New cards

DKIM

Cryptographic authentication method that verifies emails were sent by the actual domain owner

35
New cards

SPF

Email authentication protocol listing authorized IP addresses allowed to send mail for a domain

36
New cards

DMARC

Policy framework using SPF and DKIM to determine email authenticity and handle failures

37
New cards

NDA

Legal contract binding parties to keep confidential information secret

38
New cards

MOU

Formal agreement between parties outlining a shared intent and mutual goals without legal bonding

39
New cards

MOA

Document describing specific cooperative activities and financial commitments between parties

40
New cards

MSA

Master contract governing future transactions and defining overall terms of a business relationship

41
New cards

SOW

Detailed document specifying work requirements deliverables and timelines for a project

42
New cards

SLA

Agreement defining expected service levels performance metrics and penalties for non-compliance

43
New cards

BPA

Legal agreement between business partners detailing responsibilities profit sharing and operations

44
New cards

continuous integration

Development practice of frequently merging code changes into a central repository

45
New cards

escalation

Process of routing a security incident to higher authorities or specialists

46
New cards

WPA 3

Latest Wi-Fi security standard featuring improved encryption and protection against brute-force attacks

47
New cards

802.1X

Network authentication standard that restricts unauthorized devices from connecting to a LAN

48
New cards

configuration enforcement

Process of ensuring systems maintain adherence to defined secure baselines

49
New cards

enumeration

Attacker technique used to gather detailed network information like usernames and open shares

50
New cards

security awareness campaign

Program designed to educate employees about cyber threats and safe computing habits

51
New cards

replay attack

Cyberattack where valid data transmission is maliciously repeated or delayed

52
New cards

compliance vaulting

Secure archiving of data to meet regulatory retention and legal requirements

53
New cards

SCAP

Suite of specifications for standardizing flaws and configuration security management

54
New cards

RTOS

Operating system designed to process data and events in real-time with precise timing

55
New cards

CRL

List of digital certificates that have been revoked by the issuing authority before expiration

56
New cards

SASE

Architecture combining network security functions with WAN capabilities delivered as a cloud service

57
New cards

CYOD

Policy allowing employees to choose an approved device from a company-provided list

58
New cards

COPE

Corporate policy where the company owns the device but allows employees personal use

59
New cards

SCADA

Industrial control system architecture used to monitor and operate high-level processes

60
New cards

HTTP: TCP/80

Unencrypted web traffic protocol operating over TCP port 80

61
New cards

HTTPS: TCP/443

Encrypted web traffic protocol using SSL/TLS operating over TCP port 443

62
New cards

Secure Terminal: TCP/22

Secure Shell protocol for encrypted remote access operating over TCP port 22

63
New cards

application layer/management

Network segment handling software interaction and system administration

64
New cards

FIM (File Integrity)

Detects unauthorized file changes in critical system or application files

65
New cards

Endpoint DLP

Prevents data loss from user devices by monitoring data in use in RAM USB or clipboard

66
New cards

Network DLP

Blocks sensitive data traversing the network by inspecting data in motion

67
New cards

Server DLP

Protects stored sensitive data on servers by scanning data at rest

68
New cards

Cloud DLP

Protects data in cloud apps by monitoring cloud application traffic

69
New cards

Email DLP

Blocks sensitive data in inbound or outbound email at the gateway or cloud level

70
New cards

USB Blocking

Endpoint agent feature preventing data exfiltration or malware via USB storage

71
New cards

Data Plane (Forwarding Plane)

Network device component responsible for forwarding packets based on rules

72
New cards

Control Plane

Network device component making routing decisions and populating the Data Plane

73
New cards

Management Plane

Network device interface used for system configuration monitoring and administration

74
New cards

PEP (Policy Enforcement Point)

Security component inspecting every packet entering or leaving a zone like a bouncer

75
New cards

PDP (Policy Decision Point)

The brain making access decisions based on user role device type and factors

76
New cards

PA (Policy Administrator)

Component that issues time-limited access tokens for user access

77
New cards

Mandatory Access Control (MAC)

OS-enforced access restriction based on security labels like Secret or Top Secret

78
New cards

Discretionary Access Control (DAC)

Access model where the data owner decides who gets access permissions

79
New cards

Role-Based Access Control (RBAC)

Access permissions granted based on job functions like Manager or Team Lead

80
New cards

Rule-Based Access Control

System-enforced access model based on specific pre-defined rules

81
New cards

Attribute-Based Access Control (ABAC)

Dynamic access control evaluating multiple user resource and environmental attributes

82
New cards

SIEM

Centralized platform for log aggregation correlation and security data analysis via Syslog or API

83
New cards

Anti-Virus/Malware

Software detecting malicious programs using signature and behavioral detection

84
New cards

DLP

Prevents data exfiltration using content inspection techniques like regex and fingerprinting

85
New cards

SNMP

Device monitoring protocol utilizing polling and traps over UDP ports 161 and 162

86
New cards

NetFlow

Traffic flow analysis tool providing flow-based network statistics over UDP

87
New cards

Vulnerability Scanner

Tool identifying security weaknesses via port scanning and vulnerability signatures