Cisco Certified Support Technician (CCST) Cybersecurity flashcards
150 free flashcards. Tap a card to flip it.
Defense in Depth
Flip cardA cybersecurity strategy that employs multiple layers of security controls to protect information and systems. The idea is that if one layer of defense is breached, another layer will be in place to prevent or detect further unauthorized access.
- Based on military strategy of layered fortifications.
- Combines administrative, technical, and physical controls.
- Aims to slow down attackers and provide multiple detection points.
Memory trick: Defense in Depth is like an onion: many layers protect the core.
CVSS Exploit Code Maturity (E)
Flip cardThe CVSS Exploit Code Maturity (E) temporal metric measures the current state of exploit techniques or code availability for a vulnerability.
- Rated as Not Defined, Unproven, Proof-of-Concept, Functional, or High.
- Unproven means no exploit code is available or it's theoretical.
- Functional means reliable exploit code is available, but may require some customization.
- High means automated, easy-to-use exploit code is widely available.
Memory trick: Temporal is REM: Remediation, Exploit, Report.
CVSS Confidentiality Impact
Flip cardThe CVSS Confidentiality Impact metric measures the impact on the confidentiality of the information managed by the vulnerable system if the vulnerability is exploited.
- Rated as None, Low, or High.
- High means there is a total loss of confidentiality, resulting in all resources within the impacted scope being divulged.
- Low means there is some loss of confidentiality, but information disclosure is limited.
Memory trick: CIA Triad helps remember CVSS impacts.
Dynamic Application Security Testing (DAST)
Flip cardA black-box testing methodology that analyzes a running application from the outside to identify vulnerabilities by simulating attacks and observing application behavior.
- Detects runtime vulnerabilities (e.g., authentication, session management, misconfigurations).
- Does not require access to source code.
- Identifies issues that only appear during execution.
Memory trick: Dynamic runs to find runtime flaws.
Static Application Security Testing (SAST)
Flip cardA 'white-box' testing method that analyzes application source code, bytecode, or binary code for security vulnerabilities without executing the program.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities in source code.
- Helps reduce remediation costs significantly.
Memory trick: Static Code, Early Fix.
Credentialed Scan
Flip cardA vulnerability scan performed with valid authentication credentials to the target system, allowing for deeper inspection of internal configurations and patch levels.
- Provides a more accurate and comprehensive vulnerability assessment.
- Detects missing patches, misconfigurations, and software vulnerabilities.
- Requires legitimate user accounts on target systems.
Memory trick: Credentials open more doors for deeper scans.
Incident Response
Flip cardThe organized approach an organization takes to address and manage the aftermath of a security breach or cyberattack. The goal is to handle the situation in a way that limits damage and reduces recovery time and costs.
- Follows a structured lifecycle (e.g., NIST SP 800-61).
- Involves preparation, detection & analysis, containment, eradication & recovery, post-incident activity.
- Requires clear roles, communication, and documentation.
Memory trick: Security program needs: policies to guide, assessments to know risks, response for when things go wrong.
Non-repudiation
Flip cardThe assurance that someone cannot deny something. In cybersecurity, it ensures that the sender cannot deny having sent a message, and the recipient cannot deny having received it.
- Often implemented using digital signatures.
- Provides proof of origin and integrity.
- Crucial for legal and contractual agreements.
Memory trick: Security: Can I Trust All Actions?
Botnet
Flip cardA network of compromised computers (bots) controlled by a threat actor (bot-herder) via a command-and-control (C2) server.
- Used for coordinated attacks (DoS, spam, data theft).
- Infected machines 'phone home' to C2 servers.
- Users are often unaware their machine is part of a botnet.
Memory trick: Malware types: Virus spreads, Worm replicates, Ransomware locks, Spyware watches, Botnet obeys.
Confidentiality
Flip cardThe security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.
- Prevents unauthorized disclosure.
- Achieved through encryption, access controls, and authentication.
- Part of the CIA triad.
Memory trick: Confidentiality guards secrets, Integrity keeps truth, Availability ensures presence.
Distributed Denial of Service (DDoS)
Flip cardA cyberattack where multiple compromised computer systems (a botnet) are used to flood a target system with traffic, rendering it unavailable to legitimate users.
- Uses multiple sources to launch the attack.
- Aims to exhaust resources (bandwidth, CPU, memory).
- Makes services unavailable (denial of service).
Memory trick: DDoS: A crowd of attackers shutting down a single door.
Vulnerability Scan Scheduling
Flip cardVulnerability scan scheduling involves planning when to conduct scans to maximize their effectiveness in identifying vulnerabilities while minimizing impact on business operations.
- Often performed during off-peak hours or dedicated maintenance windows.
- Considerations include system criticality, network bandwidth, and potential for disruption.
- Regularity is key for continuous monitoring, but timing is crucial for operational continuity.
Memory trick: Scan Smart: Time, Scope, Impact, Credentials.
Vulnerability Management Policy
Flip cardA formal document outlining an organization's approach to identifying, assessing, prioritizing, and remediating security vulnerabilities.
- Provides a framework for consistent vulnerability handling.
- Includes roles, responsibilities, and procedures.
- Essential for a mature cybersecurity posture.
Memory trick: Policy's foundation is built on who does what, then how, and finally with what tools.
Uncredentialed Scan Limitations
Flip cardDrawbacks of performing a vulnerability scan without providing authentication credentials to the target system.
- Limited to network-level services and open ports.
- Cannot inspect internal configurations, patch levels, or file permissions.
- May miss many internal vulnerabilities, leading to an incomplete risk picture.
Memory trick: No keys, no entry, only what's visible from outside.
Availability
Flip cardThe security principle that ensures authorized users have timely and uninterrupted access to information and resources when needed.
- Ensures uptime and access.
- Achieved through redundancy, backups, disaster recovery, and fault tolerance.
- Part of the CIA triad.
Memory trick: Availability means 'always on' for everyone authorized.
Centralized Patch Management
Flip cardA system or process that automates the identification, testing, approval, and deployment of software updates and security patches across an organization's entire IT infrastructure.
- Ensures consistent and timely application of patches.
- Reduces manual effort and human error.
- Improves overall security posture by closing known vulnerability gaps.
Memory trick: Centralize for control, Automate for speed, Test for safety.
Vulnerability Prioritization Factors
Flip cardKey elements considered when ranking vulnerabilities to determine which should be addressed first based on risk.
- Exploitability: How easily can the vulnerability be exploited?
- Impact: What is the potential damage if exploited?
- Asset Criticality: How important is the affected system to the business?
- Remediation Availability: Is a patch or workaround readily available?
Memory trick: Impact, Exploit, Asset, Patch: Prioritize with these four.
Vulnerability Scan Frequency
Flip cardThe rate at which vulnerability scans are performed on systems or networks.
- Higher frequency reduces time-to-detection for new vulnerabilities.
- Balances security needs with resource consumption.
- Should be tailored to asset criticality and change rate.
Memory trick: Scan often, find fast, stay secure.
Mitigation for Unpatchable Vulnerabilities
Flip cardStrategies employed to reduce the risk of vulnerabilities for which no direct software patch or fix is available, often involving compensating controls or changes in environment.
- Essential for unsupported or end-of-life software.
- Focuses on reducing exploitability or impact.
- Examples include network segmentation, access control, or IPS rules.
Memory trick: No patch? Build a fence, not just a note saying 'beware'.
Confidentiality (CIA Triad)
Flip cardThe principle that sensitive information is protected from unauthorized access or disclosure. It ensures that data is only accessible to those who are authorized to view it.
- Achieved through encryption, access controls, and proper data handling.
- Prevents data breaches and unauthorized sharing.
- A fundamental pillar of information security.
Memory trick: CIA: Confidentiality is keeping secrets, Integrity is keeping truth, Availability is keeping access.
Security Awareness Program
Flip cardA structured initiative designed to educate employees about cybersecurity threats, best practices, and their role in protecting organizational assets.
- Reduces human error as a security vulnerability.
- Should be continuous, relevant, and engaging.
- Covers topics like phishing, password hygiene, data handling.
Memory trick: Awareness: Know your people, teach them well, keep it fresh, measure success.
Access Control
Flip cardA security technique that regulates who or what can view or use resources in a computing environment. It enforces policies that determine authorized access.
- Involves authentication (who you are) and authorization (what you can do).
- Can be physical (doors) or logical (passwords, firewalls).
- Often implemented through Access Control Lists (ACLs) or Role-Based Access Control (RBAC).
Memory trick: Access Control is like a bouncer checking your ID and permissions.
CVSS Confidentiality Impact (C)
Flip cardA CVSS Base Metric that measures the impact on the confidentiality of the information managed by the affected component. It assesses the degree to which information is disclosed to unauthorized individuals.
- Rated as None, Low, or High.
- High impact means total loss of confidentiality.
- Crucial for data breaches and unauthorized access vulnerabilities.
Memory trick: C.I.A. (Confidentiality, Integrity, Availability) are the impact stars.
Uncredentialed Scan
Flip cardA vulnerability scan performed without providing any authentication credentials to the target system, simulating an unauthenticated attacker.
- Identifies externally exploitable vulnerabilities.
- Mimics an attacker with no prior access.
- Less thorough than a credentialed scan for internal flaws.
Memory trick: Credentials: Yes or No.
Phishing
Flip cardA type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information, such as usernames, passwords, and credit card details, often by disguising themselves as a trustworthy entity in electronic communication.
- Often uses email, text messages (smishing), or phone calls (vishing).
- Relies on deception and urgency to manipulate victims.
- Aims to steal credentials, financial information, or install malware.
Memory trick: Social engineering: Phishing is bait, pretexting is a story, tailgating is following.
Brute-force Attack
Flip cardA brute-force attack is a trial-and-error method used to obtain information such as user passwords or personal identification numbers (PINs). It involves exhaustively trying every possible combination until the correct one is found.
- Attempts all possible combinations.
- Can be time-consuming but effective.
- Often targets weak passwords or login mechanisms.
Memory trick: Brute-force is like trying every key on a keychain until one fits.
Authentication
Flip cardThe process of verifying the identity of a user, process, or device before granting access to a system or resource.
- Proves 'who you are'.
- Often relies on something you know, have, or are.
- Precedes authorization.
Memory trick: AAA: Authenticate first, Authorize next, then Audit.
Compensating Controls
Flip cardSecurity controls implemented to provide an alternative or temporary measure of protection when a primary control is not feasible or effective.
- Reduces risk when direct remediation is not possible.
- Often temporary until a permanent fix is available.
- Examples: WAF rules, IPS signatures, network segmentation.
Memory trick: Zero-Day, Mitigate Today.
Software Composition Analysis (SCA)
Flip cardAn automated process that identifies open-source and third-party components within an application and scans them for known security vulnerabilities and licensing issues.
- Crucial for applications using many external libraries.
- Helps manage supply chain risks.
- Often integrated into CI/CD pipelines.
Memory trick: SAST is code, DAST is live, SCA is ingredients, Manual is human eyes.
Continuous Vulnerability Scanning
Flip cardContinuous vulnerability scanning is an ongoing, automated process of identifying security weaknesses and misconfigurations across an organization's IT infrastructure and applications.
- Provides real-time or near real-time visibility into the security posture.
- Helps detect new vulnerabilities as they emerge or as the environment changes.
- Often integrates with patch management and security information and event management (SIEM) systems.
Memory trick: SCAN constantly to CATCH risks.
Compensating Control
Flip cardA security control implemented to satisfy the requirements of a security measure that cannot be met due to technical or business constraints, providing an alternative means to reduce risk.
- Used when primary controls are not feasible.
- Provides an equivalent level of protection.
- Must be carefully chosen to match the risk it mitigates.
Memory trick: When the main door is broken, use a strong alternative window.
Data Classification
Flip cardThe process of organizing data into categories based on its sensitivity, value, and regulatory requirements, to ensure appropriate security controls are applied.
- Establishes levels like Public, Internal, Confidential, Restricted.
- Guides the implementation of access controls, encryption, and retention policies.
- Crucial for compliance with data protection regulations.
Memory trick: Security Program: Policy, Risk, Incident, Awareness, Data, Access
Risk Mitigation
Flip cardThe process of implementing controls or measures to reduce the likelihood or impact of a risk event, rather than eliminating the risk entirely.
- Aims to reduce, not eliminate, risk.
- Involves implementing security controls or compensating measures.
- Often used when risk avoidance or transfer is not feasible.
Memory trick: Avoid, Mitigate, Transfer, Accept.
Application Vulnerabilities
Flip cardWeaknesses or flaws within software applications that can be exploited by attackers to gain unauthorized access, cause denial of service, or compromise data.
- Can exist in code, design, or configuration.
- Often identified through code review, penetration testing, and vulnerability scanning.
- Examples include SQL injection, XSS, broken authentication.
Memory trick: Threats: Apps, Humans, Networks, Physical
Command Injection
Flip cardA type of web vulnerability that allows an attacker to execute arbitrary operating system commands on the host server through a vulnerable application input.
- Occurs when an application passes unsanitized user input to a system shell.
- Can lead to full system compromise.
- Mitigated by input validation and using safer APIs.
Memory trick: XSS scripts, SQL queries, Command runs, Auth breaks.
Data Encryption
Flip cardData encryption is the process of converting information into a code to prevent unauthorized access. It scrambles data into an unreadable format, making it secure during storage (at rest) and transmission (in transit).
- Protects confidentiality.
- Requires a key for decryption.
- Applied to data at rest or in transit.
Memory trick: Encryption is like putting your secret diary in a locked box, even if someone finds the box, they can't read it.
CVSS Remediation Level
Flip cardA CVSS Temporal Metric that measures the availability of a fix for a vulnerability. It influences the overall risk score by indicating how likely it is that an organization can mitigate the vulnerability.
- Part of CVSS Temporal Metrics.
- Reflects the maturity and availability of a fix or workaround.
- Can significantly lower the overall environmental score if a fix is readily available.
Memory trick: Environmental scores adapt the base, with Temporal and Environmental metrics making it truly local.
Centralized Vulnerability Management
Flip cardAn approach using a single platform to manage vulnerability identification, assessment, and remediation across an entire organization's diverse IT assets.
- Provides continuous visibility and consistent policies.
- Essential for large, distributed environments.
- Automates scanning, reporting, and tracking.
Memory trick: Central Scan, Always On.
Principle of Least Privilege
Flip cardA security concept that dictates that a user, program, or process should be given only the minimum necessary rights, privileges, or permissions to perform its job or function, and no more. This limits the potential damage from a compromise.
- Reduces the attack surface and potential impact of a breach.
- Applies to users, applications, and services.
- Often implemented through Role-Based Access Control (RBAC).
Memory trick: Access control: Least Privilege means only what you need, Separation of Duties means no one person does it all.
Cross-Site Scripting (XSS)
Flip cardA type of security vulnerability typically found in web applications. XSS enables attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to bypass access controls, impersonate users, or steal session cookies.
- Involves injecting malicious JavaScript or HTML.
- Executes in the victim's browser, not the server.
- Often results from improper input validation/sanitization.
Memory trick: Web attacks: SQL is database, XSS is browser, DDoS is traffic.
Vulnerability Prioritization Failure
Flip cardOccurs when the assigned severity or priority of a vulnerability does not accurately reflect its true risk to the organization, leading to delayed or inadequate remediation and potential exploitation.
- Can result from underestimating exploitability or impact.
- Often leads to critical vulnerabilities being addressed too late.
- Requires a holistic view of the vulnerability, asset, and threat landscape.
Memory trick: Identify, Assess, Remediate, Monitor: The continuous cycle of security.
Security Policy
Flip cardA high-level statement issued by management that outlines the organization's security goals and rules.
- Mandatory and foundational.
- Defines 'what' and 'why' of security.
- Supported by standards, baselines, and procedures.
Memory trick: Policies are the law, Standards are the rules, Procedures are the steps.
Preventive Control
Flip cardA preventive control is a security measure designed to deter or stop unauthorized actions or events from occurring.
- Acts proactively to reduce the likelihood of an attack or incident.
- Examples include firewalls, access controls, encryption, and security awareness training.
- Aims to block threats before they can impact systems or data.
Memory trick: PDRC: Prevent, Detect, Recover, Correct.
CVSS Environmental Score
Flip cardThe Environmental Score in CVSS measures the severity of a vulnerability based on the specific security posture and importance of the affected system within an organization's own environment.
- Customizes vulnerability severity for specific organizational contexts.
- Considers compensating controls and asset importance.
- Adjusts the Base Score to reflect real-world risk.
Memory trick: Base Time Environment, Impact's the Key.
Temporary Mitigation
Flip cardActions taken to reduce the immediate risk of a vulnerability when full remediation is not immediately possible. These measures are often less comprehensive but provide interim protection.
- Used when patching or full remediation is delayed.
- Aims to reduce exploitability or impact.
- Examples include network segmentation, access restrictions, or disabling services.
Memory trick: Mitigation builds a temporary wall when the main gate is broken.
White-box Assessment
Flip cardA type of security assessment where the assessor has complete knowledge of the target system's internal structure, design, and often credentials.
- Provides maximum visibility into system internals.
- Allows for thorough analysis of code, configurations, and architecture.
- Often used for comprehensive vulnerability assessments and source code reviews.
Memory trick: Black knows nothing, Gray knows some, White knows all.
Integrity (CIA Triad)
Flip cardThe assurance that information is accurate, consistent, and trustworthy throughout its entire lifecycle and has not been altered or destroyed in an unauthorized manner.
- Protects against unauthorized modification or deletion.
- Ensures data is reliable and uncorrupted.
- Maintained through access controls, hashing, and backups.
Memory trick: CIA: Confidentiality, Integrity, Availability are the foundational pillars.
Integrity
Flip cardThe security principle that ensures information is accurate, complete, and has not been subject to unauthorized modification or destruction.
- Part of the CIA Triad.
- Often implemented using hashing, digital signatures, and access controls.
- Protects against data tampering and corruption.
Memory trick: CIA: C for 'Can't see it', I for 'Intact', A for 'Always there'
Workaround (Vulnerability Management)
Flip cardA temporary solution or alternative method implemented to reduce the risk of a vulnerability being exploited until a permanent fix (e.g., a patch) can be deployed.
- Provides immediate, short-term protection.
- Does not fully resolve the underlying vulnerability.
- Often involves configuration changes, disabling features, or implementing compensating controls.
Memory trick: Patch fixes, Workaround stalls, Mitigation reduces, Remediation is all.
Vulnerability Remediation Failure
Flip cardVulnerability remediation failure occurs when identified security weaknesses are not addressed or fixed effectively within established timeframes, leading to continued exposure to risk.
- Can result from inadequate patching, misprioritization, or lack of resources.
- Often a critical breakdown in the vulnerability management lifecycle.
- Directly increases the likelihood of successful exploitation.
Memory trick: Breach from VULNERABILITY: Unpatched, Unknown, Misconfigured, Exploited.
Gray-Box Penetration Testing
Flip cardA penetration testing method where the tester has some limited knowledge of the target system's internal structure, architecture, or credentials, often simulating an insider threat or an external attacker who has gained initial access.
- Combines elements of black-box and white-box testing.
- More efficient than black-box for specific scenarios.
- Provides a realistic view from a potentially compromised user's perspective.
Memory trick: Black is blind, White is all, Gray is a peek inside.
Remediation Planning
Flip cardThe phase in vulnerability management where actions are designed and prepared to address identified vulnerabilities, including scheduling, backups, and rollback strategies.
- Occurs after assessment and prioritization.
- Involves detailed steps for applying fixes.
- Includes contingency plans like backups and rollbacks.
Memory trick: Plan, Fix, Test, Repeat.
Encryption in Transit
Flip cardThe process of encrypting data as it is transmitted over a network, ensuring that if intercepted, it remains unreadable and unintelligible to unauthorized parties.
- Commonly implemented using TLS (Transport Layer Security) or SSL (Secure Sockets Layer).
- Protects data from eavesdropping and man-in-the-middle attacks.
- Essential for sensitive data communication over public networks like the internet.
Memory trick: Data is safe: At Rest, In Transit, In Use.
Vulnerability Workflow Management
Flip cardThe process and tools used to track and manage vulnerabilities from discovery through remediation, verification, and closure.
- Ensures accountability for vulnerability resolution.
- Provides visibility into the status of all identified vulnerabilities.
- Often integrates with IT service management (ITSM) systems.
Memory trick: Scan Assets, Report Findings, Manage Workflow for Remediation.
DDoS Attack
Flip cardA Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple sources.
- Uses multiple compromised devices (botnet) to launch the attack.
- Aims to exhaust target resources like bandwidth, CPU, or memory.
- Results in legitimate users being unable to access services.
Memory trick: Many attacks, but DDoS is like a traffic jam caused by too many cars.
Social Engineering
Flip cardThe psychological manipulation of people into performing actions or divulging confidential information.
- Exploits human trust, curiosity, or fear.
- Common forms include phishing, pretexting, baiting, quid pro quo.
- Often a precursor to other attacks like malware delivery.
Memory trick: Social Engineering: The art of tricking people, not computers.
False Positive (Vulnerability Assessment)
Flip cardA false positive in vulnerability assessment is an erroneous report by a security tool, indicating the presence of a vulnerability that, upon further investigation, is determined not to exist.
- Can lead to wasted effort in remediation.
- Often requires manual verification to differentiate from true positives.
- Common in automated scanning due to heuristic analysis or outdated signatures.
Memory trick: SCAN RESULTS: True/False, Positive/Negative.
Black-Box Penetration Testing
Flip cardBlack-box penetration testing is a type of security assessment where the tester has no prior knowledge of the target system's internal structure, source code, or infrastructure.
- Simulates an external attacker.
- Focuses on publicly exposed interfaces and common attack vectors.
- Requires more time for reconnaissance and discovery.
Memory trick: BOXES: Black (unknown), Gray (some), White (all).
Rootkit
Flip cardA type of malicious software designed to hide its presence and activity on a computer system while providing privileged, persistent access to an attacker.
- Operates at a low level (kernel or user mode).
- Can modify operating system files or kernel modules.
- Difficult to detect and remove with standard tools.
Memory trick: Malware: Viruses, Worms, Trojans, Ransom, Rootkits, Spyware, Adware
Asset Inventory Management (Vulnerability Management)
Flip cardThe process of identifying, cataloging, and maintaining an accurate and up-to-date list of all hardware, software, and data assets within an organization's scope.
- Foundation of any security program.
- Crucial for knowing what needs protection and assessment.
- Prevents 'shadow IT' and overlooked systems.
Memory trick: Know Your Assets, Then Protect.