1/323
source: https://www.secuspark.com/glossary/security-plus-acronyms / https://partners.comptia.org/docs/default-source/resources/comptia-security-sy0-701-exam-objectives-(5-0)
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
AAA
authentication, authorization, accounting | security framework that controls access to computer resources, enforces policies, and audits usage
ACL
access control list | a set of rules that filters network traffic or defines permissions for accessing resources
AES
advanced encryption standard | symmetric block cipher - the current standard for encrypting data at rest & in transit
AES-256
advanced encryption standard 256-bit | symmetric block cipher - 256-bit keys
AH
authentication header | IPSec protocol providing data integrity and origin authentication
AI
artificial intelligence | technology that allows computers/machines to simulate human learning
AIS
automated indicator sharing | CISA service that allows real-time exchange of cyber-threat indicators between organizations
ALE
annualized loss expectancy | expected monetary loss from a risk per year (SLE x ARO)
AP
access point | a network device that connects wireless devices and a wired network
API
application programming interface | set of protocols and tools enabling software applications to communicate with each other
APT
advanced persistent threat | a complex, long-term cyberattack where an attacker gains and maintains unauthorized access
ARO
annualized rate of occurrence | the estimated frequency of a threat happening within a single year
ARP
address resolution protocol | layer 2 protocol that links an IP address to a MAC address on a local network segment
ASLR
address space layout randomization | OS security technique that randomizes memory addresses used by processes to prevent buffer overflow exploits
ATT&CK
adversarial tactics, techniques, and common knowledge | MITRE framework cataloging known adversary behaviors/tactics used in cyber attacks
AUP
acceptable use policy | organizational policy defining permitted and prohibited uses of technology and data
AV
antivirus | software designed to detect, prevent, and remove malware from computer systems
BASH
bourne again shell | a command-line interpreter and scripting language used mainly in Unix-based OS
BCP
business continuity planning | the process of creating plans to ensure critical business functions continue working during and after a disaster
BGP
border gateway protocol | the routing protocol that makes the internet work by exchanging routing information between autonomous systems on the internet
BIA
business impact analysis | a process for determining and evaluating the potential effects of an interruption to critical business operations
BIOS
basic input/output system | a type of firmware installed on the computer’s motherboard and checks/coordinates the hardware before the OS starts
BPA
business partners agreement | a legal document defining terms, responsibilities, and expectations between business partners
BPDU
bridge protocol data unit | a data message exchanged between network switches to map the network layout and prevent loops
BYOD
bring your own device | a policy that allows employees to use personal devices to access organizational resources/data
CA
certificate authority | a trusted entity that issues, manages, and revokes digital certs within a PKI hierarchy
CAPTCHA
completely automated public turing test to tell computers and humans apart | challenge-response test used to determine whether a user is human, preventing automated bot abuse
CAR
corrective action report | a formal document organizations use to address and rectify issues/errors/deficiencies identified in processes, operations, systems
CASB
cloud access security broker | a software/hardware tool that stands between enterprise users and cloud service providers to monitor traffic and enforcec corporate security policies
CBC
cipher block chaining | a block cipher where each block of plaintext is XORed (exclusive OR) with the previous ciphertext block before encryption
CCMP
computer mode / CBC-MAC protocol | AES-based encryption protocol used in WPA2 to provide confidentiality, integrity, and authentication for wireless frames
CCTV
closed-circuit television | a video surveillance system used to monitor, record, and protect physical facilities, assets, and people
CERT
computer emergency response team | a team of security professionals handling cyber incidents and coordinating response efforts
CFB
cipher feedback | a mode of operation that converts a block cipher into a self-synchronizing stream cipher
CHAP
challenge handshake authentication protocol | an authentication protocol using a three-way handshake with a shared secret - periodically re-verifies identity
CIA
confidentiality, integrity, availability | foundational information security model used to guide an organization’s security procedures and policies
CIO
chief information officer | a high-level executive responsible for an organization’s overall internall IT equipment, infrastructure, and technology operations
CIRT
computer incident response team | organizational team responsible for detecting, analyzing, and responding to security incidents
CMS
content management system | software platform for creating and managing digital content
COOP
continuity of operation planning | management policy & procedures used to guide a business response to a major loss and disruptions
COPE
corporate owned, personally enabled | mobile device deployment model where the organization owns the device but allows limited personal use
CP
contingency planning | a coordinated strategy involving plans, procedures, and other technical measures that allow the recovery of information systems, operations, etc. after an interruption
CRC
cyclical redundancy check | a checksum algorithm used to detect accidental changes in data, ensuring data integrity
CRL
certificate revocation list | a published list of serial numbers for certificates that a CA has revoked before their actual expiration date
CSO
chief security officer | a senior-level executive responsible for overseeing an organization’s security program- including the management of physical security and information/cybersecurity
CSP
cloud service provider | an organization that offers cloud computing services - like SaaS, PaaS, SaaS, etc
CSR
certificate signing request | an encoded message sent to a CA containing the public key & identity information to request a digital certificate
CSRF/XSRF
cross-site request forgery | web attack that forces an authenticated user to submit unintended requests to a trusted application
CSU
channel service unit | a hardware device used to connect a digital telecommunication line to a router or other data terminal equipment
CTM
counter mode | a mode of operation that turns a block cipher into a stream-like encryption method
CTO
chief technology officer | a senior executive overseeing an organization’s technology strategy and development
CVE
common vulnerabilities and exposures | a catalog of publicly known cybersecurity vulnerabilities, each assigned a unique identifier
CVSS
common vulnerability scoring system | an open framework for rating the severity of security vulnerabilities on a 0-10 scale
CYOD
choose your own device | mobile deployment model where employees can select from a list of approved corporate devices
DAC
discretionary access control | an access control model where the data owner determines who can access the resource
DBA
database administrator | role responsibility for managing, securing, and maintaining database systems
DDoS
distributed denial of service | a cyber attack where multiple systems are flooded with an overwhelming amount of traffic in an attempt to crash a service, website, application, etc
DEP
data execution prevention | hardware/OS security feature preventing code execution from memory regions marked as non-executable
DES
data encryption standard | a legacy symmetric cipher using a 56-bit key - replaced by AES
DHCP
dynamic host configuration protocol | a protocol that automatically assigns IP addresses and network configuration to devices on a network
DHE
diffie-hellman ephemeral | a secure key exchange method that generates a unique, temporary session key for every connection, providing perfect forward secrecy
DKIM
domain keys identified mail | an email authentication method using digital signatures to verify the sender domain and message integrity
DLL
dynamic link library | a shared library file in Windows containing code and data that can be loaded by mulitple programs simultaneously
DLP
data loss prevention | technology and policies that detect and prevent unauthorized exfiltration of sensitive data
DMARC
domain message authentication reporting and conformance | an email authentication policy that builds on SPF (sender policy framework) and DKIM to prevent domain spoofing/phishing
DNAT
destination network address translation | a networking technique that changes the destination IP address inside the header of an incoming data packet
DNS
domain name system | hierarchical naming system that translates human-readable domain names to IP addresses
DoS
denial of service | a cyberattack that disrupts a service by overwhelming it with traffic or exploiting a vulnerability to make it unavailable and inaccessible
DPO
data protection officer | a role required by GDPR to oversee data protection strategy, compliance, and data subject requests
DRP
disaster recovery plan | a documented process for restoring IT infrastructure/operations after a catastrophic event
DSA
digital signature algorithm | a federal standard for digital signatures providing authentication and non-repudiation
DSL
digital subscriber line | a high-speed internet technology that enables the transmission of digital signals over standard telephone lines
EAP
extensible authentication protocol | a framework for providing multiple authentication methods for wireless and point-to-point connections
ECB
electronic code book | the simplest and weakest form of block cipher encryption where each block of plaintext is encrypted individually
ECC
elliptic curve cryptography | public-key cryptography based on elliptic curve mathematics- provides stronger security with smaller key sizes
ECDHE
elliptic curve diffie-hellman ephemeral | a secure key exchange algorithm that enables two parties to establish a shared secret over an insecure network without having to transmit the secret
ECDSA
elliptic curve digital signature algorithm | a public-key cryptographic method used to create & verify digital signatures
EDR
endpoint detection and response | a security solution that continuously monitors endpoints (devices/APs connected to a network) for suspicious activity and enables quick investigation and response
EFS
encrypting file system | a Windows feature that provides file-level encryption on NTFS volumes using certificate-based keys
ERP
enterprise resource planning | an integrated software system managing main business processes like finance, HR, and supply chain
ESN
electronic serial number | a unique 32-bit identifier embedded onto a microchip inside a wireless phone
ESP
encapsulated security payload | an IPSec protocol providing confidentiality, data integrity, and authentication for IP packets
FACL
file system access control list | an OS-level list specifying permissions granted to users/groups for file system objects
FDE
full disk encryption | the encryption of an entire storage device so all data is protected at rest- including the OS and temp files
FIM
file integrity monitoring | a security control that detects unauthorized chnges to critical system files/configurations
FPGA
field programmable gate array | an integrated circuit configured by the customer after manufacturing- used in specialized hardware applications
FRR
false rejection rate | a metric in cybersecurity & biometric authentication that measures the probability that a system will incorrectly deny access to a legitimate, authorized user
FTP
file transfer protocol | a protocol for transferring files over TCP using port 21 for control and port 20 for data, transmitting in cleartext
FTPS
secured file transfer protocol | FTP with added TLS/SSL encryption
GCM
galois counter mode | an authenticated encryption mode providing confidentiality and data integrity at high speed - uses an initialization vector in its processing
GDPR
general data protection regulation | an EU regulation governing the collection, processing, and protection of personal data for residents
GPG
gnu privacy guard | open-source implementation of the OpenPGP standard for encrypting and signing data and communications
GPO
group policy object | an Active Directory mechanism for centrally managing/configuring settings for users and computers in a domain
GPS
global positioning system | provides users with positioning, navigation, and timing services (PNT) - it’s a satellite-based navigation system that tells you your exact location/time anywhere on Earth
GPU
graphics processing unit | a computer chip designed to rapidly perform advanced mathematical calculations for rendering images, video, and 3D animations
GRE
generic routing encapsulation | a tunneling protocol that encapsulates various network layer protocols inside point-to-point connections
HA
high availability | a system design approach ensuring service remains operational with minimal downtime- often using redundancy and failover
HDD
hard disk drive | a data storage device that uses mechanical spinning platters to store and retreive digital information
HIDS
host-based intrusion detection system | a security agent monitoring a single host for any suspicious activity, file changes, and policy violations
HIPS
host-based intrusion prevention system | a security agent that monitors and can block malicious activity on a host in real time