Cisco CCNP Security Core (SCOR) 350-701 flashcards
162 free flashcards. Tap a card to flip it.
SSL Decryption Placement
Flip cardStrategic placement of SSL decryption capabilities within the network to enable deep inspection of encrypted traffic for security threats or policy enforcement while minimizing performance impact on critical infrastructure.
- Decryption is resource-intensive and requires dedicated hardware/software.
- Best placed on specialized content security gateways (e.g., web proxy, NGFW with advanced capabilities).
- Typically occurs after basic firewalling but before deep content inspection.
Memory trick: Dedicated Gateway Deciphers, Deeply Inspects, Delivers Security.
Security Policies
Flip cardFormal, documented statements that define the rules, requirements, and responsibilities for protecting an organization's information assets.
- Provide a framework for security controls.
- Driven by legal, regulatory, and business requirements.
- Communicated to all relevant personnel.
Memory trick: Policies are the rules written down, to keep the company's data sound.
Private Cloud
Flip cardA cloud computing environment dedicated exclusively to a single organization, providing maximum control and isolation.
- Exclusive use by one organization.
- High control over infrastructure and data.
- Can be on-premises or hosted by a third party.
Memory trick: Think of cloud models as types of housing: Public is an apartment, Private is a custom home.
Asset Management (Security)
Flip cardThe systematic process of identifying, tracking, categorizing, and maintaining all organizational assets, including hardware, software, and data, to ensure their security.
- Crucial for vulnerability management and incident response.
- Includes maintaining inventory, configurations, and patch levels.
- Helps understand the scope and impact of security incidents.
Memory trick: Managing assets is like knowing your tools, keeping them sharp and following the rules.
Cloud Hardware Security Module (HSM)
Flip cardA dedicated, cloud-based hardware appliance that generates, stores, and protects cryptographic keys within a tamper-resistant environment.
- Offers the highest level of key security (e.g., FIPS 140-2 Level 3).
- Provides exclusive control over encryption keys for the customer.
- Suitable for stringent regulatory compliance and sensitive data.
Memory trick: HSM is like having your own bank vault for keys, under your lock and key alone.
Security Orchestration, Automation, and Response (SOAR)
Flip cardA category of security software that enables organizations to collect security alerts, standardize incident response, and automate various security tasks and workflows.
- Integrates disparate security tools.
- Automates repetitive tasks, reducing manual effort.
- Orchestrates complex incident response playbooks.
Memory trick: SOAR makes cloud security fly on autopilot, responding to threats fast.
EDR for APT Detection & Forensics
Flip cardEndpoint Detection and Response (EDR) is an endpoint security solution that continuously monitors endpoints to detect advanced persistent threats (APTs) and stealthy attacks, providing deep forensic visibility and enabling rapid incident response.
- Detects threats beyond signature-based AV.
- Provides deep endpoint visibility and forensic data.
- Enables rapid containment and response to advanced attacks.
Memory trick: To catch hidden threats, you need an endpoint detective with a microscope, not just a guard at the gate.
Legal & Regulatory Compliance
Flip cardThe process of ensuring that an organization adheres to all relevant laws, regulations, and industry standards pertaining to information security and data privacy.
- Non-compliance can lead to significant fines, legal penalties, and reputational damage.
- Requires continuous monitoring and adaptation to evolving legal landscapes.
- Examples include GDPR, CCPA, HIPAA, PCI DSS.
Memory trick: Governance ensures policies, risks, and compliance are all in check.
Data Locality and Sovereignty
Flip cardPrinciples that dictate where data must be stored (locality) and which legal jurisdiction's laws apply to that data (sovereignty), often driven by regulatory requirements.
- Ensures compliance with data residency laws.
- Impacts cloud region selection and data architecture.
- Crucial for global businesses handling sensitive data.
Memory trick: Cloud data must follow its country's rules and stay in its place.
AWS S3 Bucket Policy
Flip cardA resource-based access policy that specifies who can access items in an S3 bucket and what actions they can perform.
- JSON-based policy attached directly to an S3 bucket.
- Can grant or deny permissions to AWS accounts, IAM users, roles, or services.
- Evaluated with IAM user policies to determine final permissions.
Memory trick: For S3, policies are the gatekeepers, IAM defines who's who.
Policy Decision Point (PDP)
Flip cardA component in a Network Access Control (NAC) system responsible for evaluating security policies and making access decisions for connecting endpoints.
- Evaluates endpoint attributes against defined policies.
- Determines the appropriate level of network access.
- Communicates decisions to the Policy Enforcement Point (PEP).
Memory trick: Supplicants supplicate, Authenticator authenticates, PDP decides, PEP enforces.
802.1X Multi-domain Authentication (MDA)
Flip cardAn 802.1X feature that enables independent authentication for different types of devices (e.g., voice and data) connected to the same switch port, preventing unauthorized devices from leveraging an already authenticated device's access.
- Separates voice and data authentication.
- Enhances security for IP phone deployments.
- Prevents piggybacking attacks.
Memory trick: Don't just authenticate the phone, authenticate everything behind it!
Modern Endpoint Security
Flip cardNext-generation endpoint protection that goes beyond traditional antivirus to include advanced threat detection, response, and forensic capabilities.
- Protects against fileless malware, ransomware, and zero-day threats.
- Provides deep visibility into endpoint behavior and activities.
- Enables rapid investigation and remediation of incidents.
Memory trick: For modern threats, you need an 'EDR detective' on every endpoint.
Dual-Mode Wireless Access (EAP-TLS & Captive Portal)
Flip cardA wireless network design that uses different authentication methods for different user groups (e.g., EAP-TLS for corporate devices requiring strong certificate-based security, and a Captive Portal for guests needing simple web-based access with segmentation).
- Accommodates diverse security needs.
- Provides strong corporate device authentication.
- Offers easy and isolated guest access.
Memory trick: Corporate gets a key, guests fill out a form, both stay in their own rooms.
Confidentiality
Flip cardThe security principle that ensures sensitive information is protected from unauthorized access, disclosure, or theft.
- Prevents unauthorized viewing or access to data.
- Often achieved through encryption, access controls, and proper data handling.
- A cornerstone of the CIA triad.
Memory trick: Confidentiality means keeping secrets secret, like a locked diary.
Defense in Depth for Vulnerable Endpoints
Flip cardEmploying multiple layers of security controls to protect endpoints, especially when direct patching or upgrades are not immediately feasible.
- Assumes that no single security measure is foolproof.
- Emphasizes compensating controls when primary defenses are weak.
- Network segmentation is a critical compensating control for unpatchable systems.
Memory trick: If you can't fix the server's 'shield', then put a 'wall' around it.
Cloud Native Application Protection Platform (CNAPP)
Flip cardA unified security platform that provides a broad set of security capabilities for cloud-native applications across the entire lifecycle, from development to runtime.
- Integrates multiple security functions (CSPM, CIEM, CWPP, container security).
- Covers development (shift-left), build, deploy, and runtime phases.
- Essential for securing containerized and serverless environments.
Memory trick: For cloud-native apps, CNAPP is the all-in-one protector.
Integrity
Flip cardThe principle that data and systems are accurate, complete, and have not been modified by unauthorized entities or in an unauthorized manner.
- Protects against unauthorized alteration or destruction.
- Often maintained through hashing, digital signatures, and access controls.
- Crucial for trustworthy data and system operations.
Memory trick: CIA: 'C' for 'Cover' the secrets, 'I' for 'Intact' data, 'A' for 'Always' there.
Multi-region Active-Active Database with Synchronous Replication
Flip cardA database deployment strategy where multiple active instances of a database are deployed across different cloud regions, and all writes are synchronously replicated to ensure strong consistency across all instances.
- Provides highest levels of availability and disaster recovery.
- Ensures strong data consistency across all regions.
- Writes are committed to all active regions before acknowledgment, incurring higher latency.
Memory trick: Synchronous Active-Active: Everyone's on the same page, all the time, everywhere.
SAML (Security Assertion Markup Language)
Flip cardAn XML-based standard for exchanging authentication and authorization data between security domains.
- Enables Single Sign-On (SSO) for web applications.
- Used for federated identity management.
- Involves an Identity Provider (IdP) and a Service Provider (SP).
Memory trick: SAML: Seamless Access for Many Logins.
WSA-ISE Integration
Flip cardIntegrating Cisco Secure Web Appliance (WSA) with Cisco Identity Services Engine (ISE) to leverage centralized identity management for applying granular, user- and group-based web access and content filtering policies.
- ISE provides user and group context to WSA.
- Enables dynamic policies that follow users across devices and locations.
- Enhances visibility and control over web usage based on identity.
Memory trick: ISE Identifies Users, WSA Wiseley Steers Access.
802.1X Port Configuration
Flip cardCommands required on a Cisco Catalyst switch interface to enable and configure IEEE 802.1X port-based authentication.
- Requires AAA configuration for authentication methods.
- Uses `authentication port-control auto` or `dot1x port-control auto` for enablement.
- Switch acts as the Authenticator PAE (Port Access Entity).
Memory trick: To make the port 'smart', enable control, set PAE, and point to AAA.
Cisco FTD Custom Application ID
Flip cardThe ability within Cisco Firepower Threat Defense (FTD) to define unique signatures for proprietary or unrecognized applications, enabling granular control.
- Uses the Application Detector in FMC.
- Identifies applications independent of port.
- Crucial for controlling internal or niche applications.
Memory trick: Detect and define your own unique apps.
Active-Active Multi-Cloud
Flip cardAn architectural pattern where an application runs simultaneously across two or more distinct cloud providers, with traffic distributed between them, enabling high availability, disaster recovery, and resilience.
- Workloads are active in multiple cloud environments concurrently.
- Provides immediate failover capabilities between providers.
- Requires consistent security policies and configurations across all active clouds.
Memory trick: Active-Active: Multiple clouds, all running, ready to switch instantly.
Zero Trust for Legacy ICS
Flip cardApplying Zero Trust principles, particularly micro-segmentation, is critical for securing vulnerable legacy Industrial Control System (ICS) endpoints by strictly limiting communication and preventing lateral movement, as these systems cannot typically run modern agents or be patched.
- Essential for unpatchable, vulnerable systems.
- Prevents lateral movement.
- Requires strict network segmentation and policy enforcement.
Memory trick: Don't trust any connection to the old factory machines; build tiny, locked rooms for each.
AMP for Firepower Exclusions
Flip cardA configuration within Cisco Firepower's Advanced Malware Protection (AMP) that allows administrators to specify trusted files (by hash) or sources (by domain/IP) to bypass malware analysis, preventing legitimate content from being incorrectly blocked.
- Used to whitelist known good files or sources.
- Prevents false positives from strict malware detection.
- Can be based on file hash, file type, application, or network zone.
Memory trick: AMP Exclusion: Allowing Approved Artifacts, Avoiding Accidental Blocks.
Security Frameworks
Flip cardA structured set of guidelines, best practices, and standards that organizations can use to manage and improve their cybersecurity risk posture and establish a comprehensive security program.
- Provide a common language and systematic approach to security.
- Examples include NIST Cybersecurity Framework, ISO 27001, CIS Controls.
- Help organizations comply with regulations and achieve security objectives.
Memory trick: Frameworks build the foundation for a strong security house.
Zero Trust Principle: Continuous Verification
Flip cardThe zero-trust principle that requires continuous monitoring and re-evaluation of user and device trustworthiness throughout the duration of a session, rather than granting static access.
- Trust is never implicit; it is always earned and continuously validated.
- Contextual factors (location, device posture, behavior) are continually assessed.
- Access can be revoked or adjusted dynamically if conditions change.
Memory trick: Never trust, always verify, and verify continuously.
WSA Web Caching
Flip cardA feature of the Cisco Secure Web Appliance (WSA) that stores copies of frequently accessed web content locally to reduce latency and bandwidth consumption.
- Improves user experience by speeding up web access.
- Reduces internet bandwidth usage.
- Can be configured with various caching policies.
Memory trick: Cache the web, speed up the net.
Virtual Network Firewall (VNF)
Flip cardA software-based firewall deployed within a cloud environment that provides advanced network security features, including deep packet inspection, stateful inspection, and intrusion prevention for virtual networks.
- Offers capabilities similar to physical next-generation firewalls (NGFWs).
- Can inspect traffic at layer 7 (application layer).
- Crucial for securing East-West traffic within a cloud VPC.
Memory trick: For deep cloud traffic inspection, you need a smart firewall, not just a gate.
Zero Trust Tenets
Flip cardCore principles guiding the implementation of a zero-trust security model, emphasizing 'never trust, always verify'.
- Verify explicitly: Authenticate and authorize every access request.
- Use least privilege access: Grant only necessary permissions.
- Assume breach: Design with the expectation that systems will be compromised.
Memory trick: Zero Trust: No one's trusted, everyone's checked, expect the worst.
Cisco TrustSec Security Group Tag (SGT)
Flip cardA logical label assigned to network traffic that identifies the security group of the source user or device, enabling identity-based segmentation and policy enforcement.
- Represents a logical security group.
- Carried in network frames/packets (e.g., SGT in SGT-Encapsulated IP header).
- Used by network devices to enforce policies.
Memory trick: TrustSec uses 'Tags' (SGTs) like VIP badges to define who can go where.
Cloud Access Security Broker (CASB)
Flip cardA security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed.
- Provides visibility into cloud application usage.
- Enforces data security policies (DLP, encryption).
- Detects threats and anomalous behavior in cloud services.
Memory trick: CASB is the 'C'loud 'A'ccess 'S'ecurity 'B'ouncer, watching all your SaaS apps.
AMP for Endpoints (Cisco Secure Endpoint)
Flip cardAn endpoint security solution that provides comprehensive protection against advanced malware, including detection, prevention, and response capabilities, using continuous monitoring and behavioral analysis.
- Protects against file-based malware, ransomware, and zero-day threats.
- Uses a combination of signatures, behavioral analysis, and cloud intelligence.
- Provides visibility into file trajectory and retrospective security.
Memory trick: AMP on Endpoints: Attacks Measured, Protected Precisely.
WSA Application Control
Flip cardCisco Secure Web Appliance's Application Visibility and Control (AVC) feature enables granular control over specific functions within web applications, beyond just allowing or blocking the entire application.
- Controls specific actions (e.g., file upload, chat) within web apps.
- Requires HTTPS inspection for encrypted traffic.
- Integrated into Access Policies on WSA.
Memory trick: WSA's AVC gives you a magnifying glass for app actions.
MAB with Profiling for IoT
Flip cardA secure network access method for resource-constrained IoT devices where devices are authenticated based on their MAC address (MAB), and then network profiling identifies the device type to apply specific, restrictive access policies.
- Suitable for devices without 802.1X support.
- Leverages device profiling for identification.
- Enables granular policy enforcement for IoT.
Memory trick: For 'dumb' IoT, let their MAC be their ID, and then profile them harshly.
Cisco ISE for VPN Access
Flip cardCisco Identity Services Engine (ISE) integrates with VPN solutions (like Cisco Secure Firewall VPN) to provide centralized authentication, authorization, and posture assessment for remote access.
- Acts as the RADIUS server for VPN authentication.
- Performs posture assessment on VPN clients (e.g., via Cisco Secure Client).
- Enforces granular access based on user identity and device compliance.
Memory trick: For VPN, ISE decides 'who's in' and 'is their device clean'.
Role-Based Access Control (RBAC)
Flip cardAn access control model where permissions are associated with specific roles, and users are assigned to roles, thereby inheriting the permissions of those roles.
- Simplifies access management by grouping permissions into roles.
- Users gain permissions by being assigned to roles.
- Widely used in cloud environments for managing access to resources.
Memory trick: RBAC: If you have the 'R'ole, you get the 'B'enefits of 'AC'cess.
Cisco Identity Services Engine (ISE)
Flip cardA comprehensive, centralized policy management platform that enables secure access for wired, wireless, and VPN connections, providing identity-based authentication, authorization, and accounting (AAA) services.
- Centralizes AAA services.
- Enables granular, identity-based access control.
- Integrates with various identity stores and network devices.
Memory trick: ISE is the brain for all network access decisions, everywhere.
Principle of Least Privilege
Flip cardA security principle requiring that a user, program, or process be granted only the minimum access rights necessary to perform its task.
- Reduces the attack surface.
- Limits the damage from successful attacks.
- Applies to user permissions, network access, and application roles.
Memory trick: Least Privilege: Only the keys you need, nothing more.
Security Audit
Flip cardA systematic, independent examination of an organization's security posture to determine the extent to which security controls are adequate and effective.
- Often conducted by external parties.
- Verifies compliance with policies, regulations, and standards.
- Identifies control weaknesses and areas for improvement.
Memory trick: Assessments 'ASSESS' what's 'SECURE' or 'NOT' in the 'SYSTEM'.
Security Group (Cloud)
Flip cardA virtual firewall that controls inbound and outbound traffic for one or more network interfaces or instances in a cloud environment.
- Stateful packet filtering.
- Operates at the instance/ENI level.
- Allows granular control over ports and protocols.
- Acts as a micro-segmentation tool within a VPC.
Memory trick: Security Groups: Guarding instances, port by port.
Security Laws & Regulations
Flip cardMandatory legal requirements established by governmental bodies or industry associations that dictate how organizations must protect data and systems.
- Non-compliance can lead to severe penalties.
- Often dictate data privacy, breach notification, and security controls.
- Vary significantly by geography and industry.
Memory trick: Laws and Regulations are the rules from above, binding our security with governmental love.
WSA URL Filtering & AVC
Flip cardCisco WSA's URL Filtering blocks web categories, and its Application Visibility and Control (AVC) identifies and manages specific applications, including those used for policy evasion.
- URL Filtering uses reputation and categorization databases.
- AVC identifies applications independent of port.
- Together, they enforce web policies and prevent bypasses.
Memory trick: Filter the URLs, Control the Apps to prevent ghosts.
Cisco Secure Endpoint Features
Flip cardCisco Secure Endpoint (formerly AMP for Endpoints) is an EDR solution offering advanced threat protection for endpoints, including behavioral analysis, machine learning, exploit prevention, and ransomware rollback capabilities.
- Detects fileless malware and ransomware.
- Uses behavioral analysis and machine learning.
- Provides ransomware rollback and forensic tools.
Memory trick: To fight new threats, the endpoint needs a smart guard who can undo mistakes.
Security Operations Lifecycle - Detect
Flip cardThe phase in security operations focused on identifying security incidents, anomalies, and potential threats through continuous monitoring, logging, and analysis.
- Involves tools like IDS/IPS, SIEM, and endpoint detection.
- Aims to identify malicious activity as early as possible.
- Requires baseline understanding of normal network behavior.
Memory trick: Prevent, Detect, Respond, Recover; a cycle for security to discover.
Security Governance
Flip cardThe framework of responsibilities and practices exercised by the board and executive management with the goal of providing strategic direction for security activities.
- Establishes roles, responsibilities, and accountability.
- Ensures security aligns with business objectives.
- Includes policies, standards, and oversight.
Memory trick: Governance is the 'GO' for 'Organizational' security 'VE'hicle's 'RN'ules and 'ANCE'stry.
Secure Access Service Edge (SASE)
Flip cardSASE is a cloud-native architecture that converges network security functions (like SWG, CASB, FWaaS, ZTNA) with WAN capabilities into a single, global, cloud-delivered service model.
- Delivers security and networking as a service from the cloud edge.
- Designed for distributed workforces and cloud application access.
- Provides consistent policy enforcement regardless of user location.
Memory trick: SASE is like a 'Security Assistant' that helps remote users 'Securely Access Services Everywhere' in the cloud.
L2TP/IPsec VPN
Flip cardA VPN protocol combining Layer 2 Tunneling Protocol (L2TP) for tunneling and IPsec for encryption, authentication, and integrity, commonly used for secure remote access.
- Provides strong confidentiality (encryption).
- Ensures data integrity (hashing).
- Suitable for remote access scenarios.
Memory trick: To keep data secret and untouched, use IPsec's strong shield with a tunnel.
ESA Content Filters
Flip cardCisco Secure Email Gateway (ESA) policies that inspect email content (subject, body, attachments) for specific keywords, patterns, or data types to enforce security or compliance rules.
- Used for data loss prevention (DLP) and compliance.
- Can be applied to inbound and outbound mail.
- Supports regular expressions and dictionaries.
Memory trick: Content filters read the email's heart.
Security Awareness Training
Flip cardA program designed to educate employees about cybersecurity risks, organizational policies, and best practices to reduce human-related security incidents.
- Focuses on common threats like phishing and social engineering.
- Aims to foster a security-conscious culture.
- Often mandatory and conducted regularly.
Memory trick: Best practices are 'BEST' because they 'Bring' 'Effective' 'Security' 'Techniques'.
Security Framework
Flip cardA structured set of guidelines, best practices, and processes designed to help organizations manage and improve their overall cybersecurity posture.
- Provides a common language and systematic approach to security.
- Examples include NIST Cybersecurity Framework, ISO 27001.
- Helps establish, implement, maintain, and continually improve information security.
Memory trick: Frameworks provide the 'FRAME' for 'WORK'ing on security.
FTD DLP Policies
Flip cardCisco Firepower Threat Defense (FTD) Data Loss Prevention (DLP) policies are used to inspect network traffic for sensitive data and prevent its unauthorized exfiltration, often leveraging custom classifiers.
- Inspects data payload for sensitive information.
- Uses predefined or custom classifiers (e.g., regex, file properties).
- Can block, log, or alert on sensitive data exfiltration.
Memory trick: DLP is the watchful librarian for your digital secrets.
Serverless Supply Chain Security
Flip cardSecurity practices focused on protecting serverless applications from vulnerabilities introduced through third-party libraries, open-source components, and the development pipeline.
- Includes dependency scanning for known vulnerabilities (SCA).
- Emphasizes code signing and integrity verification.
- Integrates security checks throughout the CI/CD pipeline for functions.
Memory trick: For serverless, 'Code Signing' is like putting a tamper-proof seal on your function.
Incident Response
Flip cardThe organized approach to addressing and managing the aftermath of a security breach or cyber attack, aiming to contain, eradicate, and recover from the incident.
- Follows a structured process (e.g., NIST SP 800-61).
- Crucial for minimizing damage and recovery time.
- Involves detection, analysis, containment, eradication, recovery, and post-incident activities.
Memory trick: When an alarm blares, Incident Response prepares!
DNS-Layer Security (Cisco Umbrella)
Flip cardA security service that provides protection against malicious domains by intercepting and resolving DNS requests, blocking access to known bad destinations before a connection is established.
- Operates at the DNS layer, providing protection regardless of port or protocol.
- Blocks access to malware, phishing, and C2 servers.
- Can be deployed quickly and provides protection on and off-network.
Memory trick: DNS Request Denied, Danger Dissolved, Defenses Deployed.
Cloud Security Posture Management (CSPM)
Flip cardA category of cloud security tools that continuously monitor and improve the security posture of cloud infrastructure.
- Identifies misconfigurations, compliance violations, and risks.
- Provides visibility and actionable remediation steps.
- Applies to IaaS and PaaS components.
Memory trick: CSPM: Constantly Scans for Posture Misconfigurations.
Third-Party Risk Management (TPRM)
Flip cardThe process of identifying, assessing, and mitigating risks associated with outsourcing business functions or using services provided by external vendors, suppliers, or partners.
- Crucial for maintaining supply chain security and regulatory compliance.
- Involves due diligence, contract review, ongoing monitoring, and termination planning.
- Risks include data breaches, service disruptions, and compliance failures.
Memory trick: When you outsource, you outsource the work, not the risk.
CloudTrail (AWS)
Flip cardAn AWS service that records API calls made within an AWS account, providing an audit trail of actions.
- Logs all API calls for auditing and compliance.
- Tracks actions by users, roles, and services.
- Helps with security analysis and troubleshooting.
Memory trick: CloudTrail: Tracks every Trail of activity.
Cisco FTD Application Identification
Flip cardCisco Firepower Threat Defense uses deep packet inspection and an Application Detector to identify applications, independent of port or protocol, for granular access control.
- Identifies applications regardless of port.
- Uses signatures, heuristics, and behavioral analysis.
- Enables granular Access Control Policy enforcement.
Memory trick: Access Control permits, Application Detector identifies.