1/127
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the three Security Principles?
Confidentiality, Integrity, and Availability.
Confidentiality
The security principle that ensures information is only disclosed or made available to authorized users.
Integrity
The security principle that ensures information is only modified in an authorized manner.
Availability
The security principle that ensures information is accessible by authorized users whenever required.
Vulnerability
A weakness or flaw in a system's design, implementation, operation, or management.
Threat
Any event that can negatively impact a system through unauthorized access, destruction, disclosure or modification of data, or denial of service. In order for a threat to get through, a vulnerability must be exploited.
Threat Actor
A person or group who exploits a vulnerability.
Data Breach
The exposure of data to an unauthorized user.
Data Loss
The loss of access to data.
Data Exfiltration
The unauthorized transfer of data.
Script Kiddie
An unskilled individual who uses malicious scripts developed by security hackers to exploit vulnerabilities.
State Actor
A person or group who is acting on behalf of a government.
Hacktivist
An activist who uses computer-based techniques to promote the activist's agenda. They often operate as part of a larger group or collective.
Cyber Syndicate
A criminal syndicate which uses the Internet to engage in criminal conduct, like fraud, extortion, ransom, and identity theft.
Competitor
A rival organization whose activities have the potential to reduce another organization's share of the market, usually by performing espionage, harming reputation, or deny customer access.
Threat Vector
A path or means by which an attack is realized.
What are examples of Threat Vectors?
Direct Access, Wireless, Vulnerable Software, Unsupported Systems and Applications, Messaging, Image, Supply Chain, Social Media, Removable Media, and the Cloud.
Attack Surface
The sum of the points on a system's boundary where a threat actor can attempt to enter, cause an effect on, or extract data from. It consists of the system's vulnerabilities.
What are examples of Attack Surface?
Unencrypted wireless data, lack of user training, open ports, default passwords, and unpatched operating systems.
Automated Indicator Sharing (AIS)
A capability that enables the real-time exchange of threat intelligence.
Structured Threat Information Expression (STIX)
A standardized markup languages for expressing threat intelligence.
Trusted Automated Exchange of Intelligence Information (TAXII)
An application protocol for sharing threat intelligence.
Threat Intelligence Source
Public or private information resource on security threats, attacks, and attackers.
Open-Source Intelligence
Intelligence data derived from publicly available information on an individual or organization.
Predictive Analysis
Using gathered intelligence from threat intelligence sources to determine the likelihood of future security events.
Vulnerability Database
A database for storing, maintaining, and disseminating information, via feeds, about security vulnerabilities in a system or software.
Social Engineering
The manipulation of people into revealing information or performing actions that may compromise a system's security.
Influence Principle
A concept that takes advantage of human nature to manipulate a target.
What are examples of Influence Principles?
Authority, Familiarity, Intimidation, Trust, Consensus, Scarcity, and Urgency.
Watering Hole Attack
An attack method that infects web sites that a group is likely to trust and visit.
Typosquatting
A form of cybersquatting that relies on mistakes, such as typographical errors, made by Internet users when inputting information into a Web browser.
Pharming
A phishing attack that automatically redirects the user to a fake site using altered DNS entries.
Phishing
A social-based attack in which the attacker "fishes" for confidential info by sending a fraudulent message to a target. Vishing is via phone, and Smishing is over text.
Spear Phishing
A phishing attack that targets only specific users.
Whaling
A phishing attack that targets only wealthy individuals.
Malware
Malicious software developed to compromise the confidentiality, integrity, or availability of data.
What are the classifications of Malware?
Spread, Block, Spy, Mislead, and Hide.
Virus
A type of malware that spreads; it self-replicates and moves throughout a system, taking up resources and attempting to find data.
Fileless Virus
a virus that exists in memory only, making the virus impossible to detect by scanning for infected files.
Worm
A destructive computer program that bores its way through a computer's files or through a computer's network.
Bot
A device infected with malware than enables an attacker to remotely control (some) functions of a device.
Cryptomalware
Malware to remain in place for as long as possible, quietly mining cryptocurrency in the background.
Ransomware
Software that encrypts programs and data until a ransom is paid to remove it.
Spyware
A type of malware that locates and saves data from users without them knowing about it.
Bloatware
A program that uses an excessive amount of disk space, consumes resources, and may include spyware.
Keylogger
A type of malware that records keystrokes to gain personal information like credit card numbers or passwords.
Trojan
A type of malware disguised as legitimate software, such as a game or application, that steals information or causes unwanted damage.
Remote Access Trojan (RAT)
A Trojan that also gives the threat agent unauthorized remote access to the victim's computer by using specially configured communication protocols.
Potentially Unwanted Program (PUP)
A PUP is a software inadvertently installed that contains adware, installs toolbars, or has other objectives. Does not necessarily cause damage.
Backdoor
A type of malware that enables unauthenticated access to a device, allowing an attacker to bypass regular authentication procedures.
Logic Bomb
A type of malware that activates an attack when specific conditions are met.
Rootkit
A type of malware that provides administrative, or root access to a computing device without permission or detection.
Security Control
A mechanism used to protect the confidentiality, integrity, and availability of an organization's systems and data.
Technical Control
A control that is performed by the system.
Managerial Control
A control that addresses risk management and governance through established procedures.
Operational Control
A control that is performed by employees.
Physical Control
A control that secures the physical environment.
Preventive Control
A control that prevents a security issue.
Deterrent Control
A control that deters an individual from violating security policies.
Directive Control
A control that gives direction.
Detective Control
A control that detects a security issue.
Corrective Control
A control that restores normal operations after a security issue occurs.
Identity and Access Management (IAM)
A framework of technologies and policies for managing user identities in a system and controlling user access to the system's resource.
Identity Proofing
The process of verifying a user's identity during account creation.
Attribute
A specific characteristic of an identity.
Authentication
The act of verifying or proving a user's claim to an identity.
Authentication Factors
The different types of evidence a user can provide to prove the user's claim to an identity.
Access Control Model
A set of technology-independent rules for controlling access to an object by a subject.
What are examples of Authentication Factors?
Knowledge Factor: Something you know.
Possession Factor: Something you have.
Inherence Factor: Something you are.
Location Factor: Somewhere you are.
Behavior Factor: Something you can do.
Two-Factor Authentication
An authentication method requiring two different authentication factors.
Knowledge-Based Authentication
An authentication method requiring knowledge of a user's personal information.
Time-Based One-Time Password
A one-time password that changes periodically, using an increment of time called a timestep.
HMAC-Based One-Time Password (HOTP)
A one-time password that changes when a specific event occurs.
Software Token
An application that generates an OTP.
Security Token
A physical device that an authorized computer services user is given to ease authentication.
Trusted Platform Module (TPM)
A secure processor that performs cryptographic operations.
Full Disk Encryption
System that encrypts all data saved to a hard disk automatically and transparently.
Password Authentication Protocol (PAP)
An authentication protocol used for authenticating a client to a server over a point-to-point connection. It is down only once per session at the time of the initial connection establishment.
Challenge Handshake Authentication Protocol (CHAP)
An authentication protocol that uses a shared secret to authenticate a client to a server, periodically re-authenticating the client with challenges.
Kerberos
An authentication protocol that uses a ticket-based mechanism to authenticate a user and enable a user to access a network service. It uses port 88 by default.
What are the components of a Kerberos setup?
Key Distribution Center: A trusted third party that authenticates a user and enables a user to access a service hosted on a server.
Authentication Server: Authenticates a user.
Ticket-Granting Server: Issues a ticket to a user that enables a user to access a service.
Extensible Authentication Protocol (EAP)
An authentication framework for transporting different types of authentication protocols. Messages include:
EAP Request
EAP Response
EAP Success
EAP Failure
EAP-TLS
A form of EAP that uses transport-layer security and certificates for mutual authentication.
EAP-FAST
A form of EAP that uses a protected access credential to establish a transport-layer tunnel between a server and client.
PEAP
A form of EAP that encapsulates EAO messages within an encrypted and authenticated transport-layer tunnel. Does not require a client certificate.
IEEE 802.1X
A standard used for port-based access control that is used for passing EAP messages over a wired network.
What the the components of an IEEE 802.1X setup?
Supplicant: A user or device that wants to authenticate to a network.
Authentication Server: A server that authenticates a supplicant and makes an access control decision.
Authenticator: A device that acts as a proxy for a supplicant and controls a supplicant's communication with an authentication server.
Remote Authentication Dial-In User Service (RADIUS)
A protocol where a RADIUS server provides authentication and authorization services and a RADIUS client is a Network Access Server that acts as an intermediary for a connection request from a user to the RADIUS server.
Terminal Access Controller Access-Control System Plus (TACACS+)
A TACACS+ client is a Network Access Server. A TACACS+ server holds authentication information about users, and the NAS forwards information from the user to be checked against the server.
Security Assertions Markup Language (SAML)
An XML-based data format used to exchange authentication information between a client and a service. There are three roles defined in SAML.
What are the three roles in SAML?
Principal: A human user.
Identity Provider: An entity that creates, manages, and maintains identity information for a principal.
Service Provider: An entity that provides a service to a principal.
SAML Assertion Statements
Authentication Statement: Asserts a principal authenticated at a specific time using a specific authentication method.
Attribute Statement: Asserts that a principal is associated with a specific attribute.
Authorization Statement: Asserts that a principal is permitted to perform a specific action on a specific resource.
Account Types
User Account: Assigned to an individual that wants to access a computer resource.
Privileged Account: Assigned to a system administrator with full authorization and control.
Shared Account: An account accessed by more than one user.
Guest Account: Assigned to a temporary user.
Service Account: Assigned to an application or service.
Discretionary Access Control (DAC)
An access control model in which access to an object is at the discretion of the object's owner.
Mandatory Access Control (MAC)
An access control model in which access to an object is mandated by a set of rules and classification labels.
Role-Based Access Control (RBAC)
An access control model in which a subject's access rights to an object are based on the subject's role within a system.
Attribute-Based Access Control (ABAC)
An access control model in which access to an object is based on attributes and access control policies that define the allowable operations for a given attribute combination.
Rule-Based Access Control
An access control model that based on a list of predefined rules that determine what accesses should be granted.
Encryption
Encryption uses an algorithm and a key to hide the meaning of a message. Asymmetric encryption involves two different keys for encryption and decryption. Symmetric encryption uses the same key, and can be either done with a stream or block cipher.
Cryptographic Hash Function
Outputs a fixed-length string for a variable-length input string.