Security+ Fundamental Security Concepts

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/62

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:44 PM on 8/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

63 Terms

1
New cards

What is a gap analysis?

A comparison between the current security state and the desired security state to identify missing controls and improvements.

2
New cards

Why is a security gap analysis performed?

To identify cybersecurity risks, vulnerabilities, and areas where security controls need improvement.

3
New cards

What four categories of controls can a gap analysis identify?

Technical, Physical, Managerial, and Operational controls.

4
New cards

What are residual risks?

Risks that remain after security controls have been implemented.

5
New cards

What are common security gaps?

Weak/shared passwords, poor patch management, excessive privileges, missing acceptable use policies, weak physical security, poor auditing, and configuration errors.

6
New cards

What is Zero Trust (ZT)?

A security model that assumes no user or device is trusted by default, regardless of network location.

7
New cards

What does Zero Trust replace?

The traditional "Trust but Verify" security model.

8
New cards

What is the core principle of Zero Trust?

Never trust, always verify.

9
New cards

What does ZTNA stand for?

Zero Trust Network Access.

10
New cards

What security principle is heavily enforced in Zero Trust?

Least Privilege.

11
New cards

What is adaptive authentication?

Authentication that changes based on the user's level of risk.

12
New cards

What is another name for adaptive authentication?

Risk-based authentication.

13
New cards

What are the goals of Zero Trust?

Reduce attack surface, reduce threat scope, improve visibility, and minimize risk.

14
New cards

What is the Policy Decision Point (PDP)?

The Zero Trust component that makes access decisions.

15
New cards

What does the Policy Engine (PE) do?

Determines whether access should be granted, denied, or revoked.

16
New cards

What does the Policy Administrator (PA) do?

Creates or shuts down communication paths after the Policy Engine makes a decision.

17
New cards

What is a Policy Enforcement Point (PEP)?

A device or application that enforces access decisions.

18
New cards

Give examples of Network Policy Enforcement Points (PEPs).

Firewalls, routers, switches, and authentication proxies.

19
New cards

Give examples of Application Policy Enforcement Points (PEPs).

API gateways, VLANs, resource groups, and trusted cloud services.

20
New cards

What is the Zero Trust Control Plane?

The portion of Zero Trust responsible for making policy decisions.

21
New cards

What is the Zero Trust Data Plane?

The portion that carries user traffic after authorization.

22
New cards

What is a honeypot?

A decoy system designed to attract attackers.

23
New cards

What is the primary purpose of a honeypot?

To detect, observe, and slow attackers.

24
New cards

What is a honeynet?

A network made up of multiple honeypots.

25
New cards

What is a honeytoken?

A fake file or credential used to detect attackers or malicious insiders.

26
New cards

What do deception technologies help security teams analyze?

Attacker behavior, attack techniques, and kill chain activities.

27
New cards

What is the purpose of security fences?

To deter and prevent unauthorized physical access.

28
New cards

What are bollards?

Physical barriers that prevent vehicles from entering restricted areas.

29
New cards

What is a mantrap?

A secured entry area with two interlocking doors allowing only one person through at a time.

30
New cards

What attacks do mantraps help prevent?

Tailgating and piggybacking.

31
New cards

What authentication factor is an access badge?

Something you have.

32
New cards

Why are visitor logs maintained?

To record and track guests entering a facility.

33
New cards

What security functions do guards perform?

Preventive, detective, and deterrent controls.

34
New cards

What type of control is CCTV?

A detective physical security control.

35
New cards

Besides detecting incidents, how can cameras improve security?

They also deter attackers.

36
New cards

Why should cameras be combined with lighting?

To improve visibility and reduce blind spots.

37
New cards

What are the four major types of security lighting?

Continuous, standby, movable, and emergency lighting.

38
New cards

What does a photoelectric sensor detect?

A break in a light beam.

39
New cards

What does a passive infrared (PIR) sensor detect?

Infrared energy (body heat).

40
New cards

What does a vibration sensor detect?

Movement or vibration.

41
New cards

What does an acoustic sensor detect?

Changes in sound.

42
New cards

What does a microwave sensor detect?

Movement using high-frequency radio waves.

43
New cards

What does an electro-mechanical sensor detect?

A broken electrical circuit, such as when a door or window opens.

44
New cards

What environmental conditions do sensors commonly monitor?

Temperature and moisture.

45
New cards

What is change management?

A structured process for implementing changes while minimizing risk.

46
New cards

What usually comes before change management?

Configuration management.

47
New cards

What are the phases of the change management lifecycle?

Submit, Approve, Document, Test, Implement, and Review (After-Action Report).

48
New cards

What is a Change Impact Analysis?

An analysis that determines how a proposed change affects systems, users, and processes.

49
New cards

What is another name for Change Impact Analysis?

Gap Analysis.

50
New cards

What is a rollback (backout) plan?

A recovery plan used if a change fails.

51
New cards

What is a maintenance window?

A scheduled period during which changes are made.

52
New cards

What is an SOP?

Standard Operating Procedure.

53
New cards

What does RACI stand for?

Responsible, Accountable, Consulted, Informed.

54
New cards

How many Accountable people should there be in a RACI model?

Exactly one.

55
New cards

What is an allow list?

A list that explicitly permits approved actions or access.

56
New cards

What is a deny list?

A list that explicitly blocks prohibited actions or access.

57
New cards

Why is downtime important in change management?

Changes can affect system availability.

58
New cards

What technical considerations are important during change management?

Service restarts, legacy systems, dependencies, and secure state transitions.

59
New cards

What is a CMDB?

Configuration Management Database.

60
New cards

What is a CMS?

Configuration Management System.

61
New cards

Why is a CMDB important?

It supports asset management, change management, patch management, and incident management.

62
New cards

What does version control track?

Operating systems, applications, firmware, drivers, code, containers, patches, TPMs, and updates.

63
New cards