Professor Messer's CompTIA SY0-701 Security+ Practice Exams Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/77

flashcard set

Earn XP

Description and Tags

Practice flashcards covering security domains, attack types, technical controls, and operational metrics based on Professor Messer's practice exams.

Last updated 5:50 PM on 8/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

78 Terms

1
New cards

Operational Controls

Security controls often implemented by people instead of systems, such as security guards and awareness programs.

2
New cards

Managerial Controls

Administrative controls associated with security design and implementation, such as policies and procedures.

3
New cards

Physical Controls

Controls used to limit physical access, such as badge readers, fences, and guard shacks.

4
New cards

Technical Controls

Controls implemented using systems, including operating system controls, firewalls, and automated processes.

5
New cards

Vishing

Social engineering over the telephone, or voice phishing, used to obtain personal information such as bank account numbers or dates of birth.

6
New cards

SQL Injection

An attack type involving commands sent directly to a database using a vulnerable web application.

7
New cards

On-path Attacks

Attacks where an attacker sits invisibly between two devices to gather information or modify data streams in real-time.

8
New cards

DDoS (Distributed Denial of Service)

A service outage caused by multiple third-parties working together to overwhelm a server.

9
New cards

Keylogger

Malware installed to capture all information typed into a keyboard, including login credentials.

10
New cards

SPF (Sender Policy Framework)

A list of all authorized mail servers for a specific domain.

11
New cards

DMARC (Domain-based Message Authentication Reporting and Conformance)

A protocol that specifies the disposition of spam emails, such as whether they are accepted, sent to junk, or rejected.

12
New cards

DKIM (Domain Keys Identified Mail)

A method to validate digitally signed messages from a specific email server.

13
New cards

MTBF (Mean Time Between Failures)

A prediction of how often a repairable system or hardware is expected to fail between repairs.

14
New cards

RTO (Recovery Time Objectives)

A timeframe defined to restore a particular service level following an outage.

15
New cards

MTTR (Mean Time to Repair / Mean Time to Restore)

The amount of time it takes to repair a component or restore a system.

16
New cards

RPO (Recovery Point Objective)

The minimum data or operational state required to categorize a system as recovered.

17
New cards

MOA (Memorandum of Agreement)

A formal document where both sides agree to a broad set of goals and objectives associated with a partnership.

18
New cards

SOW (Statement of Work)

A detailed list of tasks or items to be completed as part of overall project deliverables.

19
New cards

Integrity

The trustworthiness of data, often verified via digital signatures to confirm data has not been changed.

20
New cards

Race Condition

An issue occurring when two processes happen at similar times, often with unexpected results.

21
New cards

Deterrent Control

A security control that discourages an action but does not directly stop an attack, such as a login banner.

22
New cards

Access Control Vestibule

A room designed to restrict the flow of individuals through an area, commonly used to evaluate credentials in high-security zones.

23
New cards

Record-level Encryption

An encryption strategy used in databases to encrypt specific columns while storing other details as plaintext.

24
New cards

Journaling

A method to minimize database corruption by writing data to a temporary journal before committing it to a database.

25
New cards

MDM (Mobile Device Manager)

A centralized management system used for establishing security policies, traceability, and data segmentation for mobile devices.

26
New cards

False Negative

A result from a vulnerability scan or test that fails to detect an issue when one actually exists.

27
New cards

802.1X

A standard for port-based network access control that uses a centralized authentication server for user credentials.

28
New cards

Posture Assessment

An evaluation of a system's configuration during login to ensure all security controls are up to date.

29
New cards

Smishing

A social engineering attack conducted via SMS or text messages.

30
New cards

DNS Poisoning

An attack that modifies a DNS server to redirect client computers to an unauthorized IP address.

31
New cards

Zero Trust

A security model where nothing is inherently trusted and every request must be validated at a policy enforcement point.

32
New cards

Tokenization

The process of replacing sensitive data, such as credit card numbers, with a non-sensitive functional placeholder.

33
New cards

HSM (Hardware Security Module)

A high-end cryptographic hardware appliance designed to securely store and protect private keys and certificates.

34
New cards

TPM (Trusted Platform Module)

A hardware chip on a computer motherboard used for cryptographic functions and protecting against brute-force attacks.

35
New cards

Rootkit

Malware designed to modify core system files and remain invisibly hidden on an infected system.

36
New cards

Steganography

The process of hiding data by embedding it within a different media type, such as an image file.

37
New cards

Air Gap

A physical separation and segmentation strategy that ensures no possible communication path exists between two networks.

38
New cards

WAF (Web Application Firewall)

A specialized appliance designed to protect web-based applications from SQL injections and unexpected input.

39
New cards

Jump Server

A highly secured device used to provide administrative access to internal routers, switches, and firewalls on a remote network.

40
New cards

SD-WAN (Software Defined Wide Area Network)

An extension of WAN functionality that allows corporate locations to efficiently access cloud-based services.

41
New cards

OSINT (Open Source Intelligence)

Information gathered from publicly available sources such as social media, corporate websites, and online forums.

42
New cards

BYOD (Bring your own Device)

model where the employee owns the mobile device but can also use the same device for work.

43
New cards

CYOD (Choose Your Own Device)

A policy that allows employees to choose from a selection of devices to use for work purposes, typically provided or approved by the employer.

44
New cards

MDM (Mobile Device Manager)

A type of software used to manage, secure, and monitor mobile devices in an organizational environment, ensuring compliance with security policies.

45
New cards

COPE (Corporately Owned, Personally Enabled)

A model where the employer provides mobile devices to employees, allowing them some personal use while maintaining control over the device's security and management.

46
New cards

SDN (Software Defined Networking)

A network architecture approach that allows centralized control over the network by separating the control plane from the data plane, enabling more flexible and efficient management of network resources.

47
New cards

Domain Hijacking

A malicious attack where an unauthorized user takes control of a registered domain name, often leading to phishing or fraud.

48
New cards

DDoS

is an attack that overwhelms a target's resources, making it unavailable to users by flooding it with traffic from multiple compromised sources.

49
New cards

Disassociation attack

A type of attack that disrupts the connection between a client and a Wi-Fi network by sending disassociation frames, causing the client to lose its connection and potentially reconnect to a malicious access point.

50
New cards

Buffer overflow

A vulnerability that occurs when a program writes more data to a buffer than it can hold, potentially allowing attackers to execute arbitrary code or crash the system.

51
New cards

Ledger

A digital or physical record used to track and store financial transactions, ensuring accurate accounting and auditing practices.

52
New cards

HSM (Hardware Security Module)

provides secure key storage and cryptographic functions for servers and applications.

53
New cards

On-path attack

An on-path attack is often used to capture, monitor, or inject information into an existing data flow.

54
New cards

SSO (Single Sign On)

accepts valid authentication requests and allows users to access multiple resources without requiring additional user authentications.

55
New cards

OSINT (Open Source Intelligence)

is information gathered from publicly available sources such as social media sites, online forums, and other data sources.

56
New cards

MFA (Multi-Factor Authentication)

is used to provide additional proof of a user's identity during the authentication process.

57
New cards

SCAP (Security Content Automation Protocol)

is a standard method used by security tools to identify and act on the same criteria.

58
New cards

XSS (Cross-site Scripting)

is an exploit which uses the trust in a browser to gain access to a web site. An XSS attachment describes a malicious script included in an email or similar delivery mechanism.

59
New cards

Federation

links a user's digital identity and access rights across separate organizations or trust domains

60
New cards

UTM (Unified Threat Management)

system is a legacy all-in-one security device which combines a firewall, anti-virus, content filtering, and other security features into a single system.

61
New cards

PKI (Public Key Infrastructure)

is a method of describing the public-key encryption technologies and its supporting policies and procedures.

62
New cards

Non-repudiation

Non-repudiation is used to verify the source of data or a message. Digital signatures are commonly used

63
New cards

Key escrow

describes a third-party responsible for holding or managing keys or certificates. does not provide verification of a data source.

64
New cards

Asymmetric encryption

describes data encryption using one key and the decryption of this data with a different key

65
New cards

Steganography

describes hiding one type of data within another media type. For example, hiding encrypted data within an image is a form of ___________

66
New cards

SD-WAN (Software Defined Networking in a Wide Area Network)

network allows users to efficiently communicate directly to cloud-based applications.

67
New cards

SOW (Statement of Work)

is a detailed list of tasks, items, or processes to be completed by a third-party. The ___ lists the job scope, location, deliverables, and any other specifics associated with the agreement. The ___ is also used as a checklist to verify the job was completed properly by the service provider.

68
New cards

SLA (Service Level Agreement)

sets the minimum terms of service between a customer and a service provider. This agreement often contains terms for expected uptime, response time requirements, and other minimum service levels required by the customer

69
New cards

NDA (Non-Disclosure Agreement)

is a confidentiality agreement between parties. The agreement is designed to protect information such as trade secrets, business activities, or anything else included

70
New cards

BPA (Business Partners Agreement)

is used between entities going into business together.

71
New cards

LDAP (Lightweight Directory Access Protocol)

is a common standard for authentication. ____ is an open standard and is available across many different operating systems and devices.

72
New cards

CA (Certificate Authority)

is a trusted service for certificate creation and management.

73
New cards

SIEM (Security and Information Management)

A ____ service consolidates log files from diverse systems and can create reports based on the correlation of this data.

74
New cards

WAF (Web Application Firewall)

is used to protect a web-based application from exploits and other attacks.

75
New cards

Hashing

is a one-way cryptographic function which takes an input, such as a password, and creates a fixed size string of random information.

76
New cards

Data masking

hides data from human eyes. For example, instead of showing a credit card number, the ___ ___ will show asterisks in all but the last four digits.

77
New cards

Asymmetric encryption

is an encryption method which uses one key for encryption and a different key for decryption.

78
New cards