Cisco CCNP Security Core (SCOR) 350-701 flashcards
162 free flashcards. Tap a card to flip it.
IoT Device Network Access
Flip cardSecurely onboarding and segmenting IoT devices with limited capabilities, often requiring non-802.1X authentication methods combined with device profiling.
- IoT devices may lack complex authentication protocol support.
- MAC Authentication Bypass (MAB) is a common method.
- Device profiling is crucial for identifying and segmenting IoT based on type/function.
Memory trick: For 'dumb' IoT, check their 'address' and 'who' they are.
Threat Intelligence
Flip cardEvidence-based knowledge, including context, mechanisms, indicators, implications, and actionable advice about an existing or emerging menace or hazard to assets.
- Provides context for security events and helps predict future attacks.
- Can be strategic, operational, or tactical.
- Used to enhance detection, prevention, and response capabilities.
Memory trick: Intelligence helps SOCs respond to threats proactively.
Cisco Firepower Management Center (FMC)
Flip cardThe centralized management console for Cisco Firepower Threat Defense (FTD) and Firepower Next-Generation IPS (NGIPS) devices, providing unified policy, visibility, and automation.
- Manages multiple FTD/NGIPS devices.
- Centralized policy deployment and updates.
- Unified event logging and reporting.
Memory trick: FMC is the central brain for all Firepower muscle.
Key Management Service (KMS)
Flip cardA cloud service that helps you create and control the encryption keys used to encrypt your data.
- Centralizes key generation, storage, and access control.
- Integrates with other cloud services for data encryption.
- Often supports FIPS 140-2 validated hardware for key protection.
Memory trick: KMS: Keys Masterfully Secured for your data.
Security Best Practices
Flip cardRecommended methods, procedures, or techniques that are generally accepted as the most effective ways to achieve a security objective, often based on industry standards or expert consensus.
- Examples include 'least privilege', 'defense in depth', 'zero trust', 'shift-left'.
- Help organizations build robust security programs and reduce risk.
- Are continuously evolving with new threats and technologies.
Memory trick: Best practices make security better, stronger, faster.
Web Application Firewall (WAF)
Flip cardA security solution that protects web applications from common web-based attacks by filtering and monitoring HTTP traffic between the application and the internet.
- Operates at the application layer (Layer 7).
- Protects against OWASP Top 10 vulnerabilities (e.g., SQLi, XSS).
- Can be deployed as a cloud service, appliance, or software.
Memory trick: A WAF is like a bouncer for your website, checking everyone at the door for bad intentions.
Risk Management
Flip cardThe systematic process of identifying, assessing, and treating risks to an organization's assets, ensuring that security controls are proportionate to the level of risk.
- Involves risk identification, analysis, evaluation, and treatment.
- Aims to reduce risks to an acceptable level.
- Often uses vulnerability assessments and threat modeling.
Memory trick: Risk Management is 'RISK'ing 'MANAGE'ment 'ACTIONS'.
802.1X Port Control Modes
Flip cardSettings on a switch port that determine how 802.1X authentication is handled.
- Auto: Requires successful authentication for network access.
- Force Authorized: Bypasses authentication, always grants access.
- Force Unauthorized: Blocks all network access, regardless of authentication.
Memory trick: Auto is 'Ask', Force Authorized is 'Always Yes', Force Unauthorized is 'Always No'.
Traffic Mirroring (Cloud)
Flip cardA cloud networking feature that copies network traffic from a source (e.g., VM network interface) to a destination (e.g., another VM, network interface, or network load balancer) for monitoring and analysis.
- Enables passive monitoring of network traffic.
- Essential for IDS/IPS, network forensics, and performance monitoring.
- Similar to traditional network 'port mirroring' or 'SPAN'.
Memory trick: Traffic Mirroring is like having a security camera for your network packets.
Cloud-Native Secure Web Gateway (SWG)
Flip cardA security service delivered from the cloud that protects users from web-based threats and enforces internet use policies, regardless of location.
- Provides consistent web security for all users.
- Leverages cloud scalability and global presence.
- Often integrates with other SASE components.
Memory trick: Cloud-SWG: Global Security, Unified Policies, Real-time Intelligence.
Cisco Secure Endpoint Console
Flip cardThe centralized web-based management interface for Cisco Secure Endpoint, providing comprehensive visibility, control, and access to all endpoint security features, detection engines, response actions, and forensic tools.
- Centralized management for all endpoints.
- Access to all detection and response features.
- Used for policy configuration, incident investigation, and remediation.
Memory trick: The Endpoint Console is the 'Cockpit' for flying your Secure Endpoint fleet.
EDR for Zero Trust
Flip cardEndpoint Detection and Response (EDR) is a key technology in Zero Trust architectures, providing continuous, real-time monitoring of endpoint activities to assess security posture and detect threats, enabling 'never trust, always verify' for device access.
- Continuous endpoint monitoring.
- Real-time threat detection and response.
- Enables dynamic access decisions in Zero Trust.
Memory trick: For Zero Trust, constantly check the endpoint's pulse, not just its ID card.
Least Privilege
Flip cardA security principle where every user, process, and program is granted only the minimum permissions necessary to perform its function.
- Reduces the attack surface.
- Limits the 'blast radius' of a security breach.
- Fundamental for zero-trust architectures.
Memory trick: Cloud Security: Protect Data, Isolate Threats, Respond Fast, Trust No One.
Remote Access VPN (SSL/TLS)
Flip cardA technology that allows individual remote users to securely connect to a private network over a public network (like the internet) using an encrypted tunnel, often leveraging SSL/TLS protocols.
- Provides secure remote connectivity.
- Often integrates with endpoint posture assessment.
- Commonly implemented with clients like Cisco Secure Client (AnyConnect).
Memory trick: Remote workers need a secure tunnel and a check-up before entering the network.
Cloud Direct Connect / ExpressRoute / Interconnect
Flip cardDedicated, private network connections that establish a direct link between an on-premises data center and a cloud provider's network, bypassing the public internet.
- Provides increased bandwidth and more consistent network experience.
- Offers enhanced security by bypassing the public internet.
- Typically used for hybrid cloud architectures and large data transfers.
Memory trick: Direct Connect is like building your own private highway to the cloud.
Shift Left Security
Flip cardThe practice of integrating security testing and practices earlier in the software development lifecycle (SDLC) to identify and remediate vulnerabilities sooner.
- Reduces cost and effort of fixing vulnerabilities.
- Involves security testing in design, code, and build phases.
- Common in DevOps and CI/CD pipelines.
Memory trick: Shift Left: Security checks move to the start of the pipeline.
Distributed Content Security Architecture (SASE)
Flip cardAn architectural approach that integrates network and security services into a single, cloud-native platform, providing consistent content security, centralized management, and shared threat intelligence for distributed enterprises and cloud environments.
- Combines WAN capabilities (SD-WAN) with network security services (FWaaS, SWG, CASB, ZTNA).
- Delivers security as a service from the cloud edge.
- Ensures consistent policy enforcement regardless of user location or device.
Memory trick: Cloud-Native Security: Consistent, Centralized, Connected.
SASE (Secure Access Service Edge)
Flip cardA cloud-native architectural model that converges networking (SD-WAN) and security (FWaaS, SWG, CASB, ZTNA) into a single, global, cloud-delivered service to secure distributed workforces and cloud-first enterprises.
- Delivers security services from the cloud edge, close to the user.
- Ensures consistent security policies for all users, on any device, anywhere.
- Reduces complexity, improves performance, and enhances agility for remote work.
Memory trick: SASE Secures All, Seamlessly Everywhere.
SSL/TLS Inspection
Flip cardThe process of decrypting SSL/TLS encrypted traffic to inspect its contents for security threats, then re-encrypting it before forwarding.
- Enables deep packet inspection of encrypted data.
- Requires a trusted certificate authority.
- Can be resource-intensive.
Memory trick: Deciphering the secret message requires a trusted intermediary.
Email Sandboxing
Flip cardA technique used by email security gateways to execute suspicious email attachments in a virtual, isolated environment to observe their behavior for malicious activity.
- Detects zero-day and advanced malware.
- Prevents malware from reaching end-user systems.
- Part of Advanced Malware Protection (AMP).
Memory trick: Sandbox isolates the unknown, reputation flags the bad.
URL Filtering
Flip cardA content security feature that categorizes websites and enforces access policies based on these categories to control user access to web content.
- Blocks or allows access to websites based on categories (e.g., gambling, social media).
- Can generate alerts or log events for policy violations.
- Often integrated into firewalls or dedicated web security gateways.
Memory trick: URL's Categorical Gatekeeper Guards Web Access.
Virtual Private Network (VPN)
Flip cardA technology that creates a secure, encrypted connection over a less secure network, such as the internet.
- Establishes a private network over a public network.
- Encrypts data transmitted between endpoints.
- Used for remote access and site-to-site connectivity.
Memory trick: Cloud connections need a secure tunnel to keep secrets safe.
Network Access Control (NAC)
Flip cardA security solution that restricts network access to endpoints that do not comply with predefined security policies.
- Authenticates users and devices.
- Assesses device security posture (e.g., antivirus, patches).
- Enforces granular access policies based on compliance.
Memory trick: NAC is the bouncer checking IDs and dress code at the network club.
ESA Sender Groups & Mail Flow Policies
Flip cardCisco Secure Email Gateway (ESA) uses Sender Groups within Mail Flow Policies to apply differentiated handling to emails based on the sending source, enabling exceptions for trusted senders.
- Groups senders (e.g., trusted partners, spammers).
- Mail Flow Policies apply rules to specific sender groups.
- Allows bypassing or modifying security checks for trusted sources.
Memory trick: Sender Groups are VIP lanes in the email traffic.
Zero Trust Principle: Verify Explicitly
Flip cardA core Zero Trust principle stating that all access requests, regardless of origin, must be explicitly authenticated and authorized based on all available data points (identity, device, context) and continuously re-evaluated.
- No implicit trust granted based on network location.
- Requires strong authentication and authorization for every access.
- Access is continuously monitored and re-verified.
Memory trick: Zero Trust: 'Never Trust, Always Verify' – it's like a strict bouncer at every door.
SOAR (Security Orchestration, Automation, and Response)
Flip cardA platform that helps automate and orchestrate security operations tasks, incident response, and threat management.
- Automates repetitive security tasks.
- Orchestrates workflows across multiple security tools.
- Facilitates faster incident response.
Memory trick: SOAR: Soaring above incidents with Automated Responses.
Continuous Improvement
Flip cardAn ongoing effort to enhance products, services, or processes through iterative evaluation and refinement.
- Involves regular review and adaptation.
- Aims to increase effectiveness and efficiency.
- Often uses feedback loops and pilot programs.
Memory trick: Best practices are 'BEST' because they 'Bring' 'Effective' 'Security' 'Techniques'.
Cisco Secure Endpoint Engines: Threat Grid
Flip cardThe Threat Grid Malware Analysis Engine in Cisco Secure Endpoint provides dynamic, cloud-based sandbox analysis of suspicious files to uncover malicious behavior and identify advanced, evasive threats.
- Performs dynamic behavioral analysis.
- Uses a cloud sandbox environment.
- Detects evasive and zero-day malware.
Memory trick: Secure Endpoint is a 'Swiss Army Knife' of engines, each with a sharp purpose.
Security Monitoring & Analysis
Flip cardThe continuous process of collecting, reviewing, and analyzing security-related data from various sources to detect and respond to threats.
- Often relies on SIEM systems.
- Utilizes logs, alerts, and threat intelligence.
- Aims for early detection of security incidents.
Memory trick: Ops are the 'DO'ers, 'OPERATING' the security 'CONTROLS'.
Data Loss Prevention (DLP)
Flip cardA set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
- Identifies sensitive data based on patterns, keywords, or fingerprints.
- Monitors data in motion, at rest, and in use.
- Prevents unauthorized data exfiltration.
Memory trick: Don't Let Private data Out!
RADIUS for Dynamic Policy
Flip cardRemote Authentication Dial-In User Service (RADIUS) is a client/server protocol that enables network devices to communicate with a centralized AAA server for authentication and to receive dynamic authorization attributes (like VLANs or ACLs) for policy enforcement.
- Centralizes AAA services.
- Enables dynamic policy assignment.
- Widely used in 802.1X and VPN deployments.
Memory trick: The network device asks RADIUS for the rules, and RADIUS sends them back to enforce.
Shared Responsibility Model (PaaS)
Flip cardIn Platform as a Service (PaaS), the cloud provider manages the underlying infrastructure and platform, while the customer is responsible for their application and data.
- Provider handles OS, runtime, middleware, virtualization, physical infrastructure.
- Customer handles application code, application configuration, data, identity/access management.
- Different from IaaS (more customer responsibility) and SaaS (more provider responsibility).
Memory trick: PaaS: Provider handles the platform, you handle your app's code and secrets.
High Availability (HA)
Flip cardA system's ability to remain operational for an extended period, minimizing downtime through redundant components and failover mechanisms, directly supporting the Availability principle.
- Achieved through redundancy, clustering, load balancing, and disaster recovery.
- Crucial for mission-critical systems and services.
- Measured by uptime percentages (e.g., 'five nines' = 99.999% uptime).
Memory trick: Uptime, always on, always ready: that's Availability's core.
Flexible Wireless Access
Flip cardThe ability of a wireless network to support diverse authentication and authorization methods for different user groups (e.g., corporate, guest) from a single infrastructure.
- Often achieved using 802.1X with a central RADIUS server.
- Allows for dynamic VLAN assignment based on user/device identity.
- Supports methods like EAP-TLS, PEAP, and Web Authentication.
Memory trick: To serve all, the Wi-Fi 'gatekeeper' needs a flexible ID system.
FMC Identity Policy
Flip cardA Firepower Management Center (FMC) policy that integrates with external identity sources (e.g., Active Directory) to enable identity-based access control and content security.
- Maps users/groups to security policies.
- Enables granular, user-aware firewall rules.
- Requires integration with an identity source (e.g., AD, LDAP).
Memory trick: Identity Policy: Your digital ID card for network access.
Availability
Flip cardThe security principle that ensures authorized users can reliably access information and systems when needed, without undue delay or disruption.
- Crucial for business continuity and operational effectiveness.
- Protected through redundant systems, disaster recovery, and fault tolerance.
- Threatened by DoS attacks, hardware failures, and power outages.
Memory trick: CIA: Confidentiality, Integrity, Availability – keeping secrets, keeping true, keeping ready.
Endpoint Detection and Response (EDR)
Flip cardA cybersecurity solution that continuously monitors and collects endpoint data, providing real-time visibility, threat detection, and response capabilities.
- Offers deep visibility into endpoint activities.
- Facilitates threat hunting and forensic investigations.
- Goes beyond traditional antivirus by focusing on post-compromise detection and response.
Memory trick: When the antivirus fails, EDR is the 'detective' for your endpoint.
Cisco TrustSec Micro-segmentation
Flip cardA security architecture that uses Security Group Tags (SGTs) to classify network traffic based on user or device identity, enabling granular, identity-based policy enforcement (SGACLs) for micro-segmentation.
- Reduces attack surface by limiting lateral movement.
- Policies are identity-based, not IP-based.
- Simplifies network segmentation management.
Memory trick: For critical data, tag and segment every server based on its role, not just its location.
Security Metrics
Flip cardQuantifiable measurements used to assess the effectiveness, efficiency, and impact of an organization's information security program and controls.
- Help track progress, identify trends, and justify security investments.
- Should be relevant, measurable, actionable, and timely.
- Examples include patching compliance rate, number of incidents, time to detect/respond.
Memory trick: Metrics make security progress visible and actionable.
Enterprise DLP
Flip cardA comprehensive data loss prevention solution that protects sensitive information across network, endpoint, and cloud environments.
- Covers data in motion, at rest, and in use.
- Enforces policies across multiple channels (email, web, USB).
- Provides granular reporting and incident response capabilities.
Memory trick: DLP guards all data exits.
DevSecOps
Flip cardAn approach that integrates security into every phase of the software development lifecycle (SDLC), from design and development to operations, emphasizing automation and collaboration.
- Shifts security 'left' (earlier in SDLC).
- Automates security testing within CI/CD pipelines.
- Fosters collaboration between development, security, and operations teams.
Memory trick: DevSecOps is like a seatbelt for your code, put it on at the start of the journey.
Security Assessment
Flip cardThe process of evaluating the security posture of an information system, application, or network to identify vulnerabilities, risks, and control deficiencies.
- Can include vulnerability scans, penetration tests, code reviews, and architecture reviews.
- Aims to provide a comprehensive understanding of security weaknesses.
- Often conducted by independent third parties.
Memory trick: Assessments 'ASSESS' what's 'SECURE' or 'NOT' in the 'SYSTEM'.
Security Group Tagging (SGT)
Flip cardA technology used in Cisco TrustSec to classify network traffic based on the identity of the user or device, rather than IP address, allowing for dynamic, identity-based access control policies.
- Enables micro-segmentation.
- Simplifies policy management.
- Part of Cisco TrustSec architecture.
Memory trick: Tag your users, not just their IPs, for dynamic access.
Multi-Cloud Strategy
Flip cardThe practice of using multiple cloud computing services from different providers within a single architecture.
- Enhances resilience and avoids vendor lock-in.
- Distributes workloads to mitigate single-provider outages.
- Can increase management complexity.
Memory trick: Multi-Cloud means multiple providers, multiple options, multiple protections.
Serverless Security Best Practices
Flip cardSecurity considerations and techniques specifically applied to serverless architectures to mitigate unique risks.
- Focus on IAM roles and Least Privilege.
- Validate and sanitize all input.
- Secure API Gateway endpoints.
- Monitor function execution and logs.
Memory trick: Serverless: Less servers, more focus on identity and input.
ICS Content Security Strategy
Flip cardContent security for Industrial Control Systems (ICS) prioritizes operational integrity and low latency, often relying on non-intrusive methods like DNS-layer security with strict whitelisting for external communications.
- ICS networks require high availability and deterministic operations.
- Deep packet inspection or endpoint agents can disrupt ICS systems.
- DNS-layer security offers low-latency, non-intrusive protection.
- Strict whitelisting is common for external access in ICS.
Memory trick: Industrial Control Systems: Low Latency, DNS Layer, Whitelist Wins.
Cisco Secure Endpoint Engines
Flip cardCisco Secure Endpoint (formerly AMP for Endpoints) utilizes multiple detection engines to provide comprehensive protection against various types of threats.
- Combines signature, behavioral, and cloud-based analysis.
- Protects against known and unknown (zero-day) threats.
- Engines work in concert for multi-layered protection.
Memory trick: Each engine has a 'specialty' for fighting malware.
OAuth 2.0 Implicit Grant
Flip cardAn OAuth 2.0 authorization flow where the access token is issued directly to the client (typically a browser-based application) by the authorization server, often via a URL fragment, without an intervening authorization code exchange.
- Deprecated due to security vulnerabilities (e.g., token leakage).
- Access token is exposed in the browser's URL.
- Replaced by Authorization Code Flow with PKCE for public clients.
Memory trick: OAuth grants: codes are safe, direct tokens are risky.
Identity-Based Access Control
Flip cardA security mechanism that grants or denies access to resources based on the authenticated identity of the user or service, rather than just network attributes.
- Essential for 'least privilege' implementation.
- Often implemented using IAM roles, policies, and attributes.
- Provides granular control over data and application resources.
Memory trick: Data access needs identity, not just network gates.
Cisco TrustSec
Flip cardA security framework that uses identity and context to classify network traffic into Security Group Tags (SGTs) and enforce policy based on these tags.
- Decouples security policy from network topology.
- Uses Security Group Tags (SGTs) for group-based access control.
- Cisco ISE is the central policy and SGT assignment engine.
Memory trick: ISE is the 'bouncer' that hands out the 'VIP tags' (SGTs).
SNMPv2c Vulnerabilities
Flip cardSNMPv2c uses plain-text community strings for authentication and lacks encryption, making it vulnerable to eavesdropping and data manipulation.
- Community strings sent in plain text
- No encryption for messages
- Vulnerable to sniffing and data tampering
- SNMPv3 addresses these issues with authentication and encryption
Memory trick: SNMPv2c: Open book, no lock.
Threat Emulation (Sandboxing)
Flip cardThreat emulation, often implemented via sandboxing, involves executing suspicious files or URLs in a virtual, isolated environment to observe and analyze their behavior for malicious activity without risking the production network.
- Detects zero-day exploits and APTs.
- Analyzes unknown files and URLs.
- Operates in a safe, isolated environment.
Memory trick: To catch new monsters, you need a safe cage.
Stateful Inspection Firewall
Flip cardA stateful inspection firewall monitors the state of active connections, making decisions based on the connection's context and allowing return traffic for legitimate outbound sessions.
- Tracks connection state (e.g., SYN, SYN-ACK, ACK).
- Allows return traffic for outbound connections automatically.
- Blocks unsolicited inbound connections.
- Operates at the network and transport layers.
Memory trick: Stateful remembers the conversation, like a good bouncer.
Stateful Firewall Failover
Flip cardA high availability feature where redundant firewalls synchronize their connection state tables, allowing active sessions to persist during a failover event.
- Ensures continuous application connectivity
- Prevents session drops during device failure
- Requires synchronization of state information (e.g., NAT, VPN tunnels)
Memory trick: Stateful: Keep the conversation going.
HTTPS Port
Flip cardHTTPS (Hypertext Transfer Protocol Secure) is a secure version of HTTP that uses SSL/TLS encryption, typically operating on TCP port 443.
- Encrypts communication between a web browser and server.
- Protects data integrity and confidentiality.
- Uses TCP port 443 by default.
Memory trick: Secure web is always on 443, like a safe house.
Software-Defined Networking (SDN) for Security
Flip cardSDN applies to security by providing a centralized, programmable control plane that enables dynamic, granular, and consistent security policy enforcement across diverse network environments, including hybrid clouds.
- Decouples control plane from data plane.
- Enables automation and orchestration of security policies.
- Facilitates micro-segmentation and dynamic threat response.
- Offers consistent policy across hybrid and multi-cloud.
Memory trick: SDN: software 'DEFINES' security in the cloud.
Port Address Translation (PAT)
Flip cardA form of Network Address Translation (NAT) that maps multiple private IP addresses to a single public IP address by using distinct port numbers for each translation.
- Also known as NAT Overload
- Conserves public IP addresses
- Commonly used for home and small office internet access
Memory trick: PAT shares the public door with many keys.
Dedicated DDoS Mitigation
Flip cardDedicated DDoS mitigation services or appliances provide comprehensive protection against Distributed Denial of Service attacks by detecting, analyzing, and filtering malicious traffic to ensure the availability of legitimate services.
- Protects against volumetric, protocol, and application-layer attacks.
- Uses advanced techniques like scrubbing and behavioral analysis.
- Operates at scale, often upstream from the protected network.
Memory trick: When the flood comes, you need a strong dam and a smart filter.
Unicast Reverse Path Forwarding (uRPF)
Flip cardA security feature that prevents IP spoofing by checking if the source IP address of an incoming packet has a valid reverse path in the routing table.
- Mitigates IP spoofing attacks
- Verifies source IP against routing table
- Drops packets with invalid reverse paths
- Can operate in strict or loose mode
Memory trick: uRPF: Check the return address.
Micro-segmentation
Flip cardMicro-segmentation is a security technique that divides a data center or cloud network into highly granular, isolated segments down to the individual workload level, allowing for precise security policy enforcement.
- Enhances East-West traffic security.
- Reduces the attack surface and lateral movement.
- Often implemented using software-defined networking (SDN) or hypervisor-level controls.
Memory trick: Micro-segmentation: tiny fences for every cloud VM.