Security+ Acronyms

0.0(0)
Studied by 6 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/175

flashcard set

Earn XP

Description and Tags

Security+ Acronyms w/ Definitions

Last updated 12:57 PM on 2/17/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

176 Terms

1
New cards

Authentication, Authorization, Accounting (AAA)

A security framework that controls access to computer resources and tracks user activity.

2
New cards

Access Control List (ACL)

A list of permissions that controls who can access a system resource and what operations they can perform.

3
New cards

Advanced Encryption Standard (AES)

A cryptographic algorithm that encrypts and decrypts data using a symmetric block cipher.

4
New cards

Authentication Header (AH)

A security protocol in IPSec that ensures the integrity of packet headers and data, provides user authentication and offers optional replay protection and access protection.

5
New cards

Automated Indicator Sharing (AIS)

A service provided by the Cybersecurity and Infrastructure Security Agency (CISA) to enable real-time exchange of cyber threat indicators and defensive measures.

6
New cards

Annualized Loss Expectancy (ALE)

A metric used in risk management to estimate the expected monetary loss an organization could face from a specific risk over one year.

7
New cards

Access Point (AP)

A device that connects wireless client devices in an infrastructure to each other and provides access to a distribution system.

8
New cards

Application Programming Interface (API)

A software intermediary that allows two applications to communicate with each other.

9
New cards

Advanced Persistent Threat (APT)

A cyber attack where a hacker gains unauthorized access to a network and remains undetected, typically to steal sensitive data.

10
New cards

Annualized Rate of Occurrence (ARO)

The estimated probability of a specific event happening within a given year.

11
New cards

Address Resolution Protocol (ARP)

A protocol that maps IP addresses to MAC addresses.

12
New cards

ARP Poisoning

An attack that exploits the IP address to MAC resolution to steal, modify, or redirect frames within a local area network.

13
New cards

Adversarial Tactics, Techniques, & Common Knowledge (ATT&CK)

A framework documenting how cyber attackers behave in security incidents to improve detection and response strategies.

14
New cards

Acceptable Use Policy (AUP)

A set of rules governing how a network, website, or service can be used.

15
New cards

Bourne Again Shell (BASH)

A shell program and command language commonly used as the default login shell for multiple Linux distributions.

16
New cards

Business Continuity Plan (BCP)

A strategy for maintaining service delivery and recovering during disruptions.

17
New cards

Business Impact Analysis (BIA)

A process predicting the consequences of a business disruption and the resources needed to recover.

18
New cards

Basic Input/Output System (BIOS)

Firmware pre-installed on a computer's motherboard initiating the computer system.

19
New cards

Bridge Protocol Data Unit (BPDU)

A network packet carrying information between switches to prevent loops and optimize performance.

20
New cards

Certificate Authority (CA)

A trusted third-party issuing digital certificates to verify identities.

21
New cards

Cloud Access Security Broker (CASB)

A software used to ensure data protection and regulatory compliance for cloud services.

22
New cards

Counter Mode/CBC-MAC Protocol (CCMP)

A security protocol that uses the Advanced Encryption Standard (AES) algorithm to encrypt data and provide data integrity and confidentiality. Part of the 802.11i standard for wireless local area networks (WLANs) and was introduced in the Wi-Fi Protected Access 2 (WPA2) wireless security standard.

23
New cards

Confidentiality, Integrity, Availability (CIA)

A model for information security representing three key principles.

24
New cards

Continuity of Operation Planning (COOP)

A process ensuring organizations can perform essential functions during emergencies.

25
New cards

Certificate Revocation List (CRL)

A list of revoked digital certificates not to be trusted.

26
New cards

Cloud Service Provider (CSP)

A company offering cloud-based services like storage and applications.

27
New cards

Certificate Signing Request (CSR)

A message sent by an applicant to a CA to apply for a digital identity certificate.

28
New cards

Cross-Site Request Forgery (CSRF or XSRF)

Exploits applications that use cookies to authenticate users, track sessions, or perform an unwanted action on a user's behalf

29
New cards

Channel Service Unit (CSU)

A hardware device that connects a local area network (LAN) to a wide area network (WAN). It acts as a bridge between the network router and the service provider's equipment.

30
New cards

Common Vulnerability Enumeration (CVE)

A list of publicly known vulnerabilities with unique identifiers.

31
New cards

Common Vulnerability Scoring System (CVSS)

A system assigning numerical scores to CVEs to indicate severity.

32
New cards

Discretionary Access Control (DAC)

A model where the owner controls who can access resources.

33
New cards

Distributed Denial of Service (DDoS)

A cyberattack that overwhelms a target with traffic from multiple sources.

34
New cards

Digital Encryption Standard (DES)

An outdated symmetric key method of data encryption using a 56-bit key.

35
New cards

Dynamic Host Configuration Protocol (DHCP)

A protocol that assigns IP addresses and configuration parameters to devices on a network.

36
New cards

Diffie Hellman Ephemeral (DHE)

A method of securely generating a symmetric key over a public channel.

37
New cards

DomainKeys Identified Mail (DKIM)

Email authentication method verifying sender and integrity using a key pair.

38
New cards

Dynamic Link Library (DLL)

A file containing reusable code and data for multiple programs.

39
New cards

Domain Message Authentication Reporting and Conformance (DMARC)

An email authentication protocol for verifying the legitimacy of email senders.

40
New cards

Domain Name System (DNS)

A system translating domain names into IP addresses.

41
New cards

Denial of Service (DoS)

An attack making a network resource unavailable by overwhelming it with requests.

42
New cards

Data Privacy Officer (DPO)

A professional responsible for compliant and ethical handling of personal data.

43
New cards

Disaster Recovery Plan (DRP)

A document outlining how an organization responds to disasters to maintain operations.

44
New cards

Extensible Authentication Protocol (EAP)

A protocol framework supporting various authentication methods.

45
New cards

Elliptic Curve Cryptography (ECC)

A public-key technique using elliptic curves for generating key pairs.

46
New cards

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE)

A key agreement protocol establishing a shared secret over an insecure channel.

47
New cards

Endpoint Detection and Response (EDR)

Technology monitoring and responding to threats on endpoints.

48
New cards

Encrypted File System (EFS)

Encryption control technique allowing users to control who can read files.

49
New cards

Encapsulated Security Payload (ESP)

An encryption protocol that protects data in transit between computers by encrypting and authenticating data packets.

50
New cards

Full Disk Encryption (FDE)

The process of encrypting all the data on the hard drive used to boot a computer, including the computer's OS, and permitting access to the data only after successful authentication to the encrypted product

51
New cards

File Integrity Management (FIM)

Process verifying the authenticity of files to detect tampering.

52
New cards

False Rejection Rate (FRR)

A metric used to measure how often a biometric system incorrectly denies access to an authorized user.

53
New cards

File Transfer Protocol (FTP)

A standard protocol allowing file transfers between computers.

54
New cards

FTPS

Secure version of File Transfer Protocol.

55
New cards

General Data Protection Regulation (GDPR)

EU law regulating the collection and processing of personal data.

56
New cards

Group Policy Object (GPO)

Settings defining system appearance and behavior for a group of users.

57
New cards

High Availability (HA)

A system characteristic ensuring a high level of operational performance.

58
New cards

Host-based Intrusion Detection System (HIDS)

System monitoring and analyzing internal computing systems and network packets.

59
New cards

Host-based Intrusion Prevention System (HIPS)

Uses behavioral analysis and network filtering to monitor a computer's files, registry keys, and running processes. It can detect suspicious activity by comparing current activity to a baseline of normal activity.

60
New cards

Hardware Security Module (HSM)

Tamper-resistant devices managing cryptographic keys and processes.

61
New cards

Hyper-text Markup Language (HTML)

Foundation of web applications, often exploited for XSS or SQLi attacks.

62
New cards

Infrastructure as a Service (IaaS)

A cloud computing model that provides on-demand access to computing resources such as servers, storage, networking, and virtualization.

63
New cards

Infrastructure as Code (IaC)

Method managing infrastructure through code instead of manual processes.

64
New cards

Identity and Access Management (IAM)

Ensures appropriate access to tools based on job roles.

65
New cards

Internet Key Exchange (IKE)

A secure key management protocol that is used to set up a secure, authenticated communications channel between two devices.

66
New cards

Internet Message Access Protocol (IMAP)

Protocol allowing email clients to retrieve messages from a mail server.

67
New cards

Internet Protocol Security (IPsec)

Protocols encrypting and authenticating IP packets for secure communication.

68
New cards

Incident Response Plan (IRP)

Procedures for detecting and recovering from cybersecurity incidents.

69
New cards

Initialization Vector (IV)

An arbitrary number used with a secret key for secure encryption.

70
New cards

Layer 2 Tunneling Protocol (L2TP)

Protocol creating secure tunnels for data transmission.

71
New cards

Local Area Network (LAN)

Network interconnecting computers within a single physical location.

72
New cards

Lightweight Directory Access Protocol (LDAP)

Standard protocol for accessing distributed directory services.

73
New cards

Mandatory Access Control (MAC)

Security model limiting resource access based on predefined rules.

74
New cards

Media Access Control (MAC)

The layer that controls the hardware responsible for interaction with the wired (electrical or optical) or wireless transmission medium.

75
New cards

Master Boot Record (MBR)

A crucial component of a computer's storage device that contains information about the hard disk partitions and the operating system (OS)

76
New cards

Message Digest 5 (MD5)

Hash function generating a 128-bit value, insecure for cryptographic applications.

77
New cards

Mobile Device Management (MDM)

Software managing, monitoring, and securing mobile devices.

78
New cards

Multi-protocol Label Switching (MPLS)

Technology directing data packets based on labels.

79
New cards

Managed Security Service Provider (MSSP)

Third-party offering outsourced security services.

80
New cards

Mean Time Between Failures (MTBF)

Predicted elapsed time between failures of a system.

81
New cards

Mean Time to Failure (MTTF)

Average time a product functions before its first failure.

82
New cards

Mean Time to Repair (MTTR)

Average time taken for a system to recover from a failure.

83
New cards

Network Access Control (NAC)

System controlling devices accessing a network based on security compliance.

84
New cards

Network Address Translation (NAT)

Mapping multiple private addresses to a public IP address.

85
New cards

Near Field Communication (NFC)

Short-range technology enabling data exchange between devices nearby.

86
New cards

Next-generation Firewall (NGFW)

Advanced firewall processing and blocking dangerous network traffic.

87
New cards

Network-based Intrusion Detection System (NIDS)

Monitors network traffic at strategic points for malicious activity.

88
New cards

Network-based Intrusion Prevention System (NIPS)

Active system analyzing network packets to block threats.

89
New cards

Network Time Protocol (NTP)

Protocol synchronizing computer clocks across a network.

90
New cards

Open Authorization (OAuth)

An open standard protocol that allows third-party applications to access a user's protected resources without requiring the user to share their login credentials.

91
New cards

Online Certificate Status Protocol (OCSP)

Protocol checking if a digital certificate is valid or revoked.

92
New cards

Open-source Intelligence (OSINT)

Insight gained from publicly available data sources.

93
New cards

Open Vulnerability Assessment Language (OVAL)

Standard promoting open security content and information exchange.

94
New cards

PKCS #12 (P12)

File format for storing cryptographic objects in a single file.

95
New cards

Platform as a Service (PaaS)

A cloud computing model where a third-party provider delivers a complete development environment, including servers, operating systems, storage, and development tools, allowing users to build, test, and deploy applications without managing the underlying infrastructure.

96
New cards

Privileged Access Management (PAM)

Focuses on control, monitoring, and protection of privileged accounts.

97
New cards

Password-based Key Derivation Function 2 (PBKDF2)

A widely used cryptographic algorithm designed to securely derive a cryptographic key from a user's password

98
New cards

Private Branch Exchange (PBX)

Phone system managing internal and external calls of a company.

99
New cards

Packet Capture (PCAP)

Technique intercepting data packets over a network.

100
New cards

Payment Card Industry Data Security Standard (PCI DSS)

Guidelines ensuring secure processing, storage, or transmission of credit card information.