1/77
Practice flashcards covering security domains, attack types, technical controls, and operational metrics based on Professor Messer's practice exams.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Operational Controls
Security controls often implemented by people instead of systems, such as security guards and awareness programs.
Managerial Controls
Administrative controls associated with security design and implementation, such as policies and procedures.
Physical Controls
Controls used to limit physical access, such as badge readers, fences, and guard shacks.
Technical Controls
Controls implemented using systems, including operating system controls, firewalls, and automated processes.
Vishing
Social engineering over the telephone, or voice phishing, used to obtain personal information such as bank account numbers or dates of birth.
SQL Injection
An attack type involving commands sent directly to a database using a vulnerable web application.
On-path Attacks
Attacks where an attacker sits invisibly between two devices to gather information or modify data streams in real-time.
DDoS (Distributed Denial of Service)
A service outage caused by multiple third-parties working together to overwhelm a server.
Keylogger
Malware installed to capture all information typed into a keyboard, including login credentials.
SPF (Sender Policy Framework)
A list of all authorized mail servers for a specific domain.
DMARC (Domain-based Message Authentication Reporting and Conformance)
A protocol that specifies the disposition of spam emails, such as whether they are accepted, sent to junk, or rejected.
DKIM (Domain Keys Identified Mail)
A method to validate digitally signed messages from a specific email server.
MTBF (Mean Time Between Failures)
A prediction of how often a repairable system or hardware is expected to fail between repairs.
RTO (Recovery Time Objectives)
A timeframe defined to restore a particular service level following an outage.
MTTR (Mean Time to Repair / Mean Time to Restore)
The amount of time it takes to repair a component or restore a system.
RPO (Recovery Point Objective)
The minimum data or operational state required to categorize a system as recovered.
MOA (Memorandum of Agreement)
A formal document where both sides agree to a broad set of goals and objectives associated with a partnership.
SOW (Statement of Work)
A detailed list of tasks or items to be completed as part of overall project deliverables.
Integrity
The trustworthiness of data, often verified via digital signatures to confirm data has not been changed.
Race Condition
An issue occurring when two processes happen at similar times, often with unexpected results.
Deterrent Control
A security control that discourages an action but does not directly stop an attack, such as a login banner.
Access Control Vestibule
A room designed to restrict the flow of individuals through an area, commonly used to evaluate credentials in high-security zones.
Record-level Encryption
An encryption strategy used in databases to encrypt specific columns while storing other details as plaintext.
Journaling
A method to minimize database corruption by writing data to a temporary journal before committing it to a database.
MDM (Mobile Device Manager)
A centralized management system used for establishing security policies, traceability, and data segmentation for mobile devices.
False Negative
A result from a vulnerability scan or test that fails to detect an issue when one actually exists.
802.1X
A standard for port-based network access control that uses a centralized authentication server for user credentials.
Posture Assessment
An evaluation of a system's configuration during login to ensure all security controls are up to date.
Smishing
A social engineering attack conducted via SMS or text messages.
DNS Poisoning
An attack that modifies a DNS server to redirect client computers to an unauthorized IP address.
Zero Trust
A security model where nothing is inherently trusted and every request must be validated at a policy enforcement point.
Tokenization
The process of replacing sensitive data, such as credit card numbers, with a non-sensitive functional placeholder.
HSM (Hardware Security Module)
A high-end cryptographic hardware appliance designed to securely store and protect private keys and certificates.
TPM (Trusted Platform Module)
A hardware chip on a computer motherboard used for cryptographic functions and protecting against brute-force attacks.
Rootkit
Malware designed to modify core system files and remain invisibly hidden on an infected system.
Steganography
The process of hiding data by embedding it within a different media type, such as an image file.
Air Gap
A physical separation and segmentation strategy that ensures no possible communication path exists between two networks.
WAF (Web Application Firewall)
A specialized appliance designed to protect web-based applications from SQL injections and unexpected input.
Jump Server
A highly secured device used to provide administrative access to internal routers, switches, and firewalls on a remote network.
SD-WAN (Software Defined Wide Area Network)
An extension of WAN functionality that allows corporate locations to efficiently access cloud-based services.
OSINT (Open Source Intelligence)
Information gathered from publicly available sources such as social media, corporate websites, and online forums.
BYOD (Bring your own Device)
model where the employee owns the mobile device but can also use the same device for work.
CYOD (Choose Your Own Device)
A policy that allows employees to choose from a selection of devices to use for work purposes, typically provided or approved by the employer.
MDM (Mobile Device Manager)
A type of software used to manage, secure, and monitor mobile devices in an organizational environment, ensuring compliance with security policies.
COPE (Corporately Owned, Personally Enabled)
A model where the employer provides mobile devices to employees, allowing them some personal use while maintaining control over the device's security and management.
SDN (Software Defined Networking)
A network architecture approach that allows centralized control over the network by separating the control plane from the data plane, enabling more flexible and efficient management of network resources.
Domain Hijacking
A malicious attack where an unauthorized user takes control of a registered domain name, often leading to phishing or fraud.
DDoS
is an attack that overwhelms a target's resources, making it unavailable to users by flooding it with traffic from multiple compromised sources.
Disassociation attack
A type of attack that disrupts the connection between a client and a Wi-Fi network by sending disassociation frames, causing the client to lose its connection and potentially reconnect to a malicious access point.
Buffer overflow
A vulnerability that occurs when a program writes more data to a buffer than it can hold, potentially allowing attackers to execute arbitrary code or crash the system.
Ledger
A digital or physical record used to track and store financial transactions, ensuring accurate accounting and auditing practices.
HSM (Hardware Security Module)
provides secure key storage and cryptographic functions for servers and applications.
On-path attack
An on-path attack is often used to capture, monitor, or inject information into an existing data flow.
SSO (Single Sign On)
accepts valid authentication requests and allows users to access multiple resources without requiring additional user authentications.
OSINT (Open Source Intelligence)
is information gathered from publicly available sources such as social media sites, online forums, and other data sources.
MFA (Multi-Factor Authentication)
is used to provide additional proof of a user's identity during the authentication process.
SCAP (Security Content Automation Protocol)
is a standard method used by security tools to identify and act on the same criteria.
XSS (Cross-site Scripting)
is an exploit which uses the trust in a browser to gain access to a web site. An XSS attachment describes a malicious script included in an email or similar delivery mechanism.
Federation
links a user's digital identity and access rights across separate organizations or trust domains
UTM (Unified Threat Management)
system is a legacy all-in-one security device which combines a firewall, anti-virus, content filtering, and other security features into a single system.
PKI (Public Key Infrastructure)
is a method of describing the public-key encryption technologies and its supporting policies and procedures.
Non-repudiation
Non-repudiation is used to verify the source of data or a message. Digital signatures are commonly used
Key escrow
describes a third-party responsible for holding or managing keys or certificates. does not provide verification of a data source.
Asymmetric encryption
describes data encryption using one key and the decryption of this data with a different key
Steganography
describes hiding one type of data within another media type. For example, hiding encrypted data within an image is a form of ___________
SD-WAN (Software Defined Networking in a Wide Area Network)
network allows users to efficiently communicate directly to cloud-based applications.
SOW (Statement of Work)
is a detailed list of tasks, items, or processes to be completed by a third-party. The ___ lists the job scope, location, deliverables, and any other specifics associated with the agreement. The ___ is also used as a checklist to verify the job was completed properly by the service provider.
SLA (Service Level Agreement)
sets the minimum terms of service between a customer and a service provider. This agreement often contains terms for expected uptime, response time requirements, and other minimum service levels required by the customer
NDA (Non-Disclosure Agreement)
is a confidentiality agreement between parties. The agreement is designed to protect information such as trade secrets, business activities, or anything else included
BPA (Business Partners Agreement)
is used between entities going into business together.
LDAP (Lightweight Directory Access Protocol)
is a common standard for authentication. ____ is an open standard and is available across many different operating systems and devices.
CA (Certificate Authority)
is a trusted service for certificate creation and management.
SIEM (Security and Information Management)
A ____ service consolidates log files from diverse systems and can create reports based on the correlation of this data.
WAF (Web Application Firewall)
is used to protect a web-based application from exploits and other attacks.
Hashing
is a one-way cryptographic function which takes an input, such as a password, and creates a fixed size string of random information.
Data masking
hides data from human eyes. For example, instead of showing a credit card number, the ___ ___ will show asterisks in all but the last four digits.
Asymmetric encryption
is an encryption method which uses one key for encryption and a different key for decryption.