TestOut Security Pro Vocab

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/61

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:11 AM on 6/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

62 Terms

1
New cards

SOC

Security operations center

Where security pros monitor and protect info assets

2
New cards

CIRT, CSIRT, CERT

Computer incident/security incident/emergency response team

Team responsible for incident response, with expertise across all domains

3
New cards

Managerial controls

Provides oversight of information system

4
New cards

Operational controls

Implemented by people in day-to-day routines

5
New cards

Technical controls

In the system

6
New cards

Physical

Hardware to deter/detect

7
New cards

Preventative

Acts before an incident to reduce attack likelyhood

8
New cards

ACLs

Access control lists

Collections of access control entries (ACEs) that determine which subjects are allowed privileges

9
New cards

Detective

Acts during an incident to record it

10
New cards

Corrective

Acts after incident to minimize impact

11
New cards

Directive control

Enforcing a rule through a policy

12
New cards

Deterrent control

Discourages intrusion attempts

13
New cards

Compensating

Takes on risk mitigation when a primary control fails

14
New cards

CIO

Chief information officer

Manages tech assets and procedures

15
New cards

CTO

Chief technology officer

Using new technology and innovations

16
New cards

CSO

Chief security officer

Responsible for system security

17
New cards

ISSO

Information systems security officer

Implementing of security policies, frameworks, controls

18
New cards

Characteristics of threat actors

Internal / external

Level of sophistication / capability

Resources / funding

19
New cards

Types of hackers

Unskilled attacker / script kiddie

Hacktivist

Nation-state

Organized

Internal

20
New cards

APT

Advanced persistent threat

Attacker maintaining access to a network

21
New cards

Shadow IT

Unintentional insider threat

Opening attack vectors, (ie. installing software) without authorization

22
New cards

Lure

Attack enticing a victim into using/opening a USB, document, image, program, etc

23
New cards

Pretexting

Using lies or half-truths to get someone to believe a falsehood

24
New cards

Pharming

Redirecting from a legit website to a fraudulent one

25
New cards

Watering hole attack

Targeting specific websites that a group or organization uses frequently

26
New cards

Worm

Malware that replicates between processes in the system memory and can spread over networks

27
New cards

Shellcode

Lightweight blocks of malicious code that exploits vulnerabilities to gain access to systems

28
New cards

RAT

Remote access Trojan

Creates a backdoor remote administration channel to allow a threat actor to access the host

29
New cards

C&C

Command and control

Infrastructure that attackers use to control malware over botnets

30
New cards

Covert channel

Subverts network security systems and policies to transfer data

31
New cards

IRC

Internet relay chat

Protocol allowing users to chat, send messages

32
New cards

Rootkit

Modifies system files at the kernel level to conceal its presence

33
New cards

Asymmetric encryption examples

RSA, ECC algorithms

34
New cards

Blockchain

List of transaction records stored in an open public ledger

35
New cards

Data masking

Obfuscating with generic info that maintains the structure/format of the original data

36
New cards

Tokenization

Obfuscating with tokens substituted for real data

37
New cards

TPM

Chip for crypto purposes

38
New cards

Secure enclave

Protected area in system memory

39
New cards

Cryptographic primitive

Single hash function, symmetric cipher, or asymmetric cipher

40
New cards

Digitial signature

Message encrypted with the sender’s public key that is appended to a message to prove integrity

41
New cards

Key stretching

Strengthens weak input by salting and hashing a key

42
New cards

HMAC

Hash-based message authentication code

Used to verify integrity and authenticity by combining a hash of the message with a secret key

43
New cards

KEK

Key encryption key

Private key used to encrypt the symmetric bulk media encryption key

44
New cards

Opal storage specification

Standards for implementing device encryption on storage devices

45
New cards

SAN

Subject alternative name

Field in a digital cert allowing a host to use multiple subdomains

46
New cards

Wildcard

PKI - digital cert that will match numerous subdomains

47
New cards

CRL

Certificate revocation list

48
New cards

OSCP

Online certificate status protocol

49
New cards

Root certificate

CA that issues certificates to intermediate CAs

50
New cards

Self-signed cert

Digital cert signed by the entity that issued it and not the CA

51
New cards

Escrow

Storage of a backup key with a third party

52
New cards

Symmetric encryption examples

CES, RC, blowfish, IDEA, twofish, CAST, DES, AES

53
New cards

Asymmetric encryption examples

Diffie-Hellman, RSA, DSA, ECC

54
New cards

Ephemeral keys

New key for each transmission (perfect forward secrecy)

55
New cards

Stream cipher

Symmetric, encrypts one bit at a time, one time pad, uses XOR

56
New cards

Block cipher

Symmetric, encrypts one block at a time, pads last block

57
New cards

ECB

Electronic Codebook

Simplest, just encrypts each block simultaneously

58
New cards

CBC

Cipher Block Chaining

Random IV, then ciphertext of previous block for subsequent IVs

59
New cards

OFB

Output Feedback Mode

Repeatedly encrypts an IV and XORs its output with the plaintext to make ciphertext (stream cipher-esque)

60
New cards

CTR

Counter mode

Uses a nonce and encrypted counter instead of IV

61
New cards

GCM

Galois/Counter Mode

Like CTR, but combines ciphertext with a hash, authenticated

62
New cards

Homomorphic encryption

Allows computations before decryption