1/75
Built from CompTIA's official CS0-004 V4 exam objectives (v2.0)
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Logging concept: ingestion
Collecting logs from sources into a central platform such as a SIEM
Why does time synchronization (NTP) matter for logging?
Event timestamps must line up across systems so you can build an accurate timeline and correlate events
Log integrity and security
Protecting logs from tampering (hashing, write-once storage, restricted access) so they stay trustworthy as evidence
Log retention
How long logs are kept, set by policy and regulation (e.g., PCI DSS) and storage cost
System hardening
Reducing attack surface: remove unneeded services/software, apply patches, enforce secure configuration baselines
Zero Trust Network Architecture (ZTNA) core idea
Never trust, always verify: authenticate and authorize every request regardless of network location, with least privilege
SASE (Secure Access Service Edge)
Cloud-delivered combination of network (SD-WAN) and security services (SWG, CASB, ZTNA, firewall) at the edge
Hybrid cloud
A mix of on-premises infrastructure and public/private cloud services working together
Cloud native
Applications built to run in the cloud using services like containers, microservices, and managed APIs
Virtualization vs. containerization
VMs virtualize hardware and run a full guest OS each; containers share the host OS kernel and are lighter weight
Why are APIs a security concern?
They expose application functions and data; weak authentication, excessive data exposure, and missing rate limits are common issues
PAM (Privileged Access Management)
Controls, vaults, and monitors accounts with elevated rights (admin/root), often with just-in-time access and session recording
Secrets management
Securely storing and rotating credentials, API keys, and certificates in a vault instead of hard-coding them
SSO (Single Sign-On)
One authentication grants access to multiple applications
MFA (Multifactor Authentication)
Requires two or more factor types: something you know, have, or are
OT / ICS / SCADA
Operational technology: systems that control physical processes. ICS = industrial control systems; SCADA = supervisory control and data acquisition
Why are OT/ICS networks hard to patch?
They are availability-critical, often legacy, and downtime can affect physical safety, so they are usually segmented and monitored instead
MDM (Mobile Device Management)
Enforces policy on mobile devices: enrollment, encryption, app control, remote wipe
Network-related indicator: rogue device
An unauthorized device on the network, e.g., unknown MAC/IP, rogue access point
Network-related indicator: enumeration
Scanning or probing to list hosts, ports, services, or accounts (a reconnaissance sign)
Network indicator: traffic on unexpected ports
Services or outbound connections on unusual ports can indicate C2, tunneling, or an unauthorized service
Host-related indicators of compromise
Resource spikes (CPU/disk/network), unauthorized software, suspicious/rogue processes, file system changes, data exfiltration
LOLBins
Living Off the Land Binaries: legitimate built-in tools (powershell.exe, certutil, mshta, rundll32) abused by attackers to avoid detection
Application-related indicators
Service disruption and anomalous activity such as unexpected errors, new accounts, or unusual requests
Cloud-related indicators
Anomalous activity and resource compromise, e.g., unexpected instances (cryptomining), odd API calls, new access keys
Typosquatting
Registering a lookalike domain with a common misspelling to trick users
URL shorteners as an indicator
They hide the real destination, so they are commonly used in phishing links
Impossible travel
Logins from locations too far apart for the time elapsed, suggesting account compromise
Identity-based indicators
IAM account compromise, unauthorized access, impossible travel
BEC (Business Email Compromise)
Fraud via impersonating or compromising a business email account to trick staff into payments or data disclosure
CyberChef
Browser tool for decoding, parsing, and transforming data (Base64, hex, XOR, etc.) - the "Swiss Army knife" for analysts
Wireshark vs. tcpdump
Wireshark: GUI packet analyzer. tcpdump: command-line packet capture
Snort and Suricata
Open-source network IDS/IPS engines that match traffic against rules
Zeek
Network security monitor that turns traffic into rich logs (conn, dns, http, etc.) rather than only signature alerts
SIEM
Aggregates and correlates logs from many sources for alerting, search, and investigation
OTX, MISP, OpenCTI
Threat intelligence platforms. OTX = Open Threat Exchange; MISP = Malware Information Sharing Platform; OpenCTI = Open Cyber Threat Intelligence
EDR vs. XDR
EDR monitors and responds on endpoints. XDR extends detection/response across endpoint, network, email, and cloud
WHOIS
Lookup of domain registration data (registrar, dates, contacts)
AbuseIPDB
Community database for checking an IP address's abuse reputation
GeoIP
Maps an IP address to an approximate geographic location
strings (file analysis)
Extracts printable text from a binary; may reveal URLs, commands, or file names
VirusTotal
Service that scans files, hashes, URLs, or IPs against many AV engines and reputation sources
YARA
Rule-based tool for identifying and classifying malware by patterns in files or memory
Joe Sandbox and Cuckoo Sandbox
Sandboxes that run suspicious files in an isolated environment to observe behavior
MXToolbox
Email/DNS analysis: check MX, SPF, DKIM, DMARC records and blacklists
UEBA
User and entity behavior analytics: baselines normal behavior and flags anomalies. OpenUBA is an open-source example
Common structured data formats in security tools
JSON, XML, YAML, and EVTX (Windows event log format)
EVTX
Windows Event Log file format
Scripting languages to be able to read on the exam
Python, PowerShell, and shell scripts
Pattern recognition tools
Regular expressions and interpreting suspicious commands (e.g., encoded PowerShell, certutil downloads)
APT (Advanced Persistent Threat)
Well-resourced, usually state-linked actor that maintains long-term stealthy access to a target
Insider threat
Risk from someone with legitimate access (malicious or negligent) misusing it
MITRE ATT&CK
Knowledge base of adversary tactics, techniques, and procedures (TTPs) used to map and hunt behavior
Pyramid of Pain
Ranks IoCs by how painful they are for an attacker to change: hashes (trivial) up to TTPs (tough)
Pyramid of Pain order, easiest to hardest for attacker to change
Hash values, IP addresses, domain names, network/host artifacts, tools, TTPs
Heat map (threat intel)
Visual of which ATT&CK techniques or areas are most observed or most covered by detections
Attribution
Identifying who is behind an attack; often low confidence and not required to respond
Confidence level factors for intel
Timeliness, relevance, accuracy
OSINT vs. closed-source intelligence
OSINT = publicly available. Closed-source = restricted/paid/proprietary sources. Intel sharing = trusted exchange like ISACs
Atomic vs. behavioral IoC
Atomic: single data point (IP, hash, domain). Behavioral: pattern of actions (e.g., Office spawning PowerShell)
IoC lifecycle steps
Collection, analysis, application/usage
STRIDE
Threat model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege
Cyber deception
Honeypots, honeytokens, and decoys that lure and detect attackers
Playbook vs. runbook
Playbook: response process for a scenario type. Runbook: step-by-step operational procedure for a task, often automatable
SOAR
Security Orchestration, Automation, and Response: automates repetitive tasks and workflows across tools
IaC (Infrastructure as Code)
Defining infrastructure in version-controlled code for repeatable, auditable deployments
Data enrichment
Adding context (reputation, geolocation, asset owner) to alerts to speed triage
Rule/alert tuning
Adjusting detection rules to reduce false positives while keeping true detections
API vs. webhook vs. plug-in
API: request/response interface. Webhook: sends an event to a URL when something happens. Plug-in: add-on extending a tool
AI risk: hallucination
The model produces confident but false output; verify before acting
AI risk: model poisoning
Corrupting training data or the model to alter its behavior
AI risk: malicious prompts
Prompt injection or crafted inputs that manipulate the model's output or actions
AI risk: data exposure
Sensitive data entered into AI tools may be leaked or retained
AI governance
Legal/regulatory compliance and AI usage policies
AI use cases in security operations
Comparing artifacts, analyzing logs, document creation, incident investigation, event correlation, automation and orchestration