Cisco Certified Support Technician (CCST) Cybersecurity flashcards
150 free flashcards. Tap a card to flip it.
Vulnerability Prioritization
Flip cardThe process of ranking vulnerabilities based on their risk to an organization, considering factors like severity, exploitability, and business impact to allocate remediation resources effectively.
- Focuses on risk: impact x likelihood.
- Guides resource allocation.
- Often involves CVSS scores, threat intelligence, and asset criticality.
Memory trick: Risk Ranks Repairs Right Away.
CVSS Environmental Score
Flip cardA component of the Common Vulnerability Scoring System (CVSS) that measures the impact of a vulnerability based on the specific operational environment and implemented security controls.
- Adjusts the base score for an organization's unique context.
- Considers factors like compensatory controls, asset criticality, and security requirements.
- Provides a more accurate reflection of actual risk than the base score alone.
Memory trick: Base is General, Environment is Real.
Temporary Mitigation
Flip cardA temporary measure taken to reduce the immediate risk of an identified vulnerability while a permanent solution is being developed or implemented.
- Provides immediate protection.
- Not a permanent fix.
- Often involves configuration changes or security device rules.
Memory trick: When a vulnerability hits hard, shield it fast, buy time for the permanent fix, and keep business moving.
Security Policy
Flip cardA high-level statement issued by management that outlines the organization's security goals and rules.
- Mandatory and foundational.
- Defines 'what' and 'why' of security.
- Supported by standards, baselines, and procedures.
Memory trick: Policies are the law, Standards are the rules, Procedures are the steps.
Preventive Control
Flip cardA preventive control is a security measure designed to deter or stop unauthorized actions or events from occurring.
- Acts proactively to reduce the likelihood of an attack or incident.
- Examples include firewalls, access controls, encryption, and security awareness training.
- Aims to block threats before they can impact systems or data.
Memory trick: PDRC: Prevent, Detect, Recover, Correct.
Black-Box Penetration Testing
Flip cardBlack-box penetration testing is a type of security assessment where the tester has no prior knowledge of the target system's internal structure, source code, or infrastructure.
- Simulates an external attacker.
- Focuses on publicly exposed interfaces and common attack vectors.
- Requires more time for reconnaissance and discovery.
Memory trick: BOXES: Black (unknown), Gray (some), White (all).
Vulnerability Prioritization Failure
Flip cardOccurs when the assigned severity or priority of a vulnerability does not accurately reflect its true risk to the organization, leading to delayed or inadequate remediation and potential exploitation.
- Can result from underestimating exploitability or impact.
- Often leads to critical vulnerabilities being addressed too late.
- Requires a holistic view of the vulnerability, asset, and threat landscape.
Memory trick: Identify, Assess, Remediate, Monitor: The continuous cycle of security.
Next-Generation Firewall (NGFW)
Flip cardAn NGFW is a deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and intelligence from outside the firewall.
- Combines traditional firewall features with advanced capabilities.
- Performs deep packet inspection at the application layer (Layer 7).
- Integrates intrusion prevention (IPS) and advanced threat intelligence.
Memory trick: NGFW: The 'Smart Wall' that sees inside apps.
Rootkit Eradication
Flip cardThe challenging process of completely removing deeply embedded and persistent malware (rootkits) from a compromised system.
- Rootkits hide their presence and often survive reboots.
- Traditional AV/AM tools may not detect or remove them fully.
- Full system re-imaging is often the most reliable eradication method.
Memory trick: When the pest is too deep, you must rebuild the whole house.
Honeypot
Flip cardA security mechanism, typically a computer system or network segment, that is intentionally left vulnerable to attract and trap attackers to study their methods.
- Acts as a decoy for attackers.
- Gathers threat intelligence on TTPs.
- Does not protect production systems directly, but provides insights.
- Can be low-interaction or high-interaction.
Memory trick: Honeypot: A sweet trap for bad guys to learn their moves.
IPsec (Internet Protocol Security)
Flip cardA suite of protocols that provides security services (authentication, integrity, confidentiality) at the IP layer of the network.
- Operates at OSI Layer 3 (Network Layer).
- Provides both encryption and authentication.
- Commonly used for VPNs and securing internal network communications.
- Consists of Authentication Header (AH) and Encapsulating Security Payload (ESP).
Memory trick: IPsec: Securing the 'road' (IP) itself, not just the 'cargo' (applications).
MACsec (802.1AE)
Flip cardIEEE 802.1AE (MACsec) is a standard for providing connectionless data confidentiality and integrity for media access independent protocols.
- Provides Layer 2 encryption and authentication.
- Protects against eavesdropping and tampering on local networks.
- Ensures data integrity and confidentiality for Ethernet frames.
Memory trick: MACsec Makes All Communication Secure.
Lessons Learned
Flip cardA critical component of the post-incident phase where an organization reviews the incident response process to identify strengths, weaknesses, and areas for improvement.
- Involves analyzing the incident timeline and response actions.
- Aims to improve incident response plans, tools, and training.
- Contributes to organizational security maturity.
Memory trick: After the Fire, Learn and Improve.
Port Security
Flip cardPort Security is a Cisco switch feature that restricts input to a switch port by limiting and identifying MAC addresses of stations allowed to access the port.
- Restricts MAC addresses on a port
- Can be configured to shut down or restrict traffic
- Prevents unauthorized device connections
Memory trick: Lock down the port like a bouncer at a club.
Preparation Phase
Flip cardThe initial phase of incident response focused on establishing policies, training personnel, and procuring tools to effectively handle future security incidents.
- Involves creating incident response policies and procedures.
- Includes training staff on their roles and responsibilities.
- Ensures necessary security tools and resources are available.
Memory trick: Prepare with Policies, People, and Tools.
Dynamic ARP Inspection (DAI)
Flip cardA Layer 2 security feature that helps prevent ARP spoofing and ARP poisoning attacks by validating ARP packets in an Ethernet network.
- Validates IP-to-MAC address bindings in ARP packets.
- Requires a trusted DHCP snooping database for dynamic bindings.
- Can be configured to drop or log invalid ARP packets.
- Protects against man-in-the-middle attacks at Layer 2.
Memory trick: DAI: The network's ID checker for ARP requests, ensuring no fake IDs (IP-MAC pairs).
Advanced Persistent Threat (APT)
Flip cardA prolonged and targeted cyberattack where an intruder gains access to a network and stays there undetected for a significant period of time.
- Characterized by stealth, sophistication, and persistence.
- Often involves nation-states or state-sponsored groups.
- Primary goals are data exfiltration, espionage, or sabotage.
Memory trick: APTs Aim for Persistent Pillage.
Initial Containment
Flip cardThe immediate actions taken to limit the scope and impact of an incident, often involving isolation or blocking measures.
- Focuses on stopping the immediate threat.
- May involve disabling accounts, blocking IPs, or isolating systems.
- Precedes detailed analysis or full eradication.
Memory trick: Don't Panic, Plan, Contain, Eradicate, Recover, Learn.
Firewall
Flip cardA network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
- Acts as a barrier between trusted and untrusted networks.
- Filters traffic based on IP addresses, ports, and protocols.
- Can be hardware, software, or cloud-based.
Memory trick: Firewalls Fend off Foreigners Fast.
Physical Security
Flip cardPhysical security refers to the protection of physical assets, including network infrastructure, from unauthorized access, damage, or theft.
- Crucial for data center and wiring closet protection
- Involves locks, surveillance, access controls
- Prevents direct tampering with hardware
Memory trick: Physical protection starts with the physical space.
Transport Layer Security (TLS)
Flip cardA cryptographic protocol designed to provide communications security over a computer network, widely used for securing web traffic (HTTPS).
- Successor to SSL (Secure Sockets Layer).
- Provides encryption, authentication, and data integrity.
- Uses digital certificates for server identity verification.
Memory trick: TLS Takes care of Traffic's Tunnels.
Incident Prioritization
Flip cardThe process of ranking security incidents based on their potential impact, urgency, and severity to determine the order of response.
- Considers factors like data sensitivity, system criticality, and attack severity.
- Helps allocate limited incident response resources efficiently.
- Often uses a scoring system or predefined criteria.
Memory trick: Prioritize alerts like traffic lights: Red for urgent, Yellow for caution, Green for go later.
Chain of Custody
Flip cardThe chronological documentation or paper trail showing the seizure, custody, control, transfer, analysis, and disposition of physical or electronic evidence.
- Ensures evidence integrity and authenticity.
- Required for evidence to be admissible in legal proceedings.
- Documents every handler and action performed on the evidence.
Memory trick: Chain of Custody is like a meticulous diary for every piece of evidence.
Eradication Phase
Flip cardThe incident response phase where the root cause of the incident (e.g., malware, exploited vulnerability) is removed from the affected systems and environment.
- Follows containment and precedes recovery.
- Involves cleaning compromised systems, removing malware, and closing backdoors.
- Ensures the threat is completely eliminated.
Memory trick: Contain, Eradicate, Recover: The Cleanup Crew.
Behavioral Analytics
Flip cardBehavioral analytics in cybersecurity involves monitoring and analyzing user and system activity to detect anomalies that may indicate a threat, including unknown (zero-day) exploits.
- Detects deviations from baseline behavior
- Effective against zero-day threats
- Uses machine learning and AI for pattern recognition
Memory trick: Behavioral analytics spots the 'ghost' of an unknown attack.
Web Proxy Server
Flip cardA server that acts as an intermediary for requests from clients seeking resources from other servers. It can filter content, cache data, and provide anonymity.
- Can block access to malicious websites.
- Filters web content based on policies.
- Enhances security and can improve performance.
Memory trick: Web Proxy: Your internet bouncer, keeping the bad stuff out.
HTTPS (Hypertext Transfer Protocol Secure)
Flip cardHTTPS is the secure version of HTTP, using SSL/TLS to encrypt communication, authenticate the server, and ensure data integrity between a web browser and a website.
- Uses TLS for encryption
- Authenticates the web server to the client
- Protects against eavesdropping and tampering
Memory trick: HTTPS is HTTP with a secure 'S' for TLS.
Microsegmentation
Flip cardMicrosegmentation is a security technique that creates isolated network segments for individual workloads or applications, allowing for fine-grained security policies.
- Enhances East-West traffic control
- Limits lateral movement of attackers
- Applies granular security policies
Memory trick: Segment the network like tiny, secure rooms.
Security Information and Event Management (SIEM)
Flip cardA security solution that helps organizations detect, analyze, and respond to security threats by collecting and correlating security event data from across their IT environment.
- Aggregates logs from multiple sources.
- Uses correlation rules to identify potential incidents.
- Provides real-time monitoring and alerting.
Memory trick: SIEM Sees Everything Important.
DHCP Snooping
Flip cardDHCP Snooping is a switch security feature that acts as a firewall between untrusted hosts and trusted DHCP servers, preventing rogue DHCP servers and enforcing DHCP lease integrity.
- Filters DHCP messages based on trusted/untrusted ports
- Prevents rogue DHCP servers
- Builds and maintains a DHCP binding table
Memory trick: Snooping 'snoops' on DHCP to keep it honest.
VLANs and Client Isolation
Flip cardVLANs (Virtual Local Area Networks) logically segment a network, while Client Isolation (or AP Isolation) prevents devices within the same broadcast domain (e.g., on a guest Wi-Fi) from communicating directly with each other.
- VLANs provide network segmentation for different user groups.
- Client Isolation prevents inter-client communication on the same Wi-Fi.
- Ideal for secure guest networks.
- Enhances security by limiting lateral movement and snooping.
Memory trick: Guest Wi-Fi: VLANs for the 'hotel floor', Client Isolation for 'private rooms'.
Air Gap
Flip cardA security measure that involves physically isolating a secure network or computer from unsecured networks, such as the public internet.
- Provides ultimate isolation for critical systems.
- Prevents direct electronic communication.
- Often used in industrial control systems and highly sensitive environments.
Memory trick: Air Gap: The ultimate 'no entry' sign for network traffic.
Endpoint Detection and Response (EDR)
Flip cardA cybersecurity solution that continuously monitors and records endpoint activity, providing visibility into threats and enabling rapid detection and response.
- Collects detailed endpoint telemetry (process, file, network activity).
- Helps detect sophisticated attacks that bypass traditional defenses.
- Facilitates forensic investigation and threat hunting on endpoints.
Memory trick: EDR is like a CCTV camera for your computer, recording everything.
SQL Injection
Flip cardA web security vulnerability that allows attackers to interfere with the queries an application makes to its database, often by inserting malicious SQL code into input fields.
- Occurs due to improper input validation.
- Can lead to unauthorized data access, modification, or deletion.
- Mitigated by prepared statements and input sanitization.
Memory trick: SQL Injections Steal Secret Queries.
Network Isolation (Quarantine VLAN)
Flip cardNetwork isolation, often achieved by moving a compromised device to a quarantine VLAN, is the practice of separating a device from the rest of the network to prevent further spread of malware or unauthorized access. It's crucial for incident response.
- Prevents lateral movement of threats.
- Allows for forensic analysis in a controlled environment.
- Maintains system operational state for investigation.
Memory trick: When a device is 'sick', put it in a 'quarantine room' to stop the spread.
Isolation Containment
Flip cardA containment strategy that involves completely disconnecting a compromised or suspicious system, user, or segment from the network to prevent further damage or spread.
- Often a rapid, aggressive containment method.
- Can disrupt legitimate business operations temporarily.
- Used when the immediate threat outweighs the impact of disconnection.
Memory trick: Containment is like putting a physical barrier around the problem.
Network Packet Analyzer
Flip cardA tool used to capture and inspect individual data packets traveling over a computer network, allowing for detailed analysis of network communication.
- Provides granular visibility into network traffic.
- Used for troubleshooting, security analysis, and protocol development.
- Can reveal malicious payloads, C2 communications, and data exfiltration.
Memory trick: Packet Analyzer: Peeking at Network's Invisible Conversations.
Vulnerability Scanner
Flip cardA vulnerability scanner is a software tool used to identify security weaknesses in systems, networks, and applications by testing against known vulnerabilities.
- Automates vulnerability detection
- Identifies misconfigurations and missing patches
- Provides reports on security posture
Memory trick: A scanner 'scans' for security holes.
Accountability (Security Principle)
Flip cardThe ability to trace all actions on a system to a specific individual or process, ensuring responsibility for those actions.
- Relies heavily on logging and auditing mechanisms.
- Essential for incident response and forensics.
- Supports non-repudiation of actions.
Memory trick: CIA Triad and A for Accountability.
Containment
Flip cardThe incident response phase focused on limiting the scope and impact of an incident, preventing further damage or spread of the attack.
- Involves isolating compromised systems.
- May include blocking malicious traffic or accounts.
- Aims to stop the immediate threat from expanding.
Memory trick: Containment is like putting a STOP sign on the incident's spread.
Forensic Toolkit (FTK)
Flip cardA software suite used for digital forensics, providing tools to acquire, process, and analyze digital evidence while maintaining its integrity.
- Ensures evidence integrity through hashing and write-blocking.
- Used for data recovery, password cracking, and email analysis.
- Critical for legal and investigative purposes.
Memory trick: Tools for Incidents: Detect, Analyze, Preserve.
Network Intrusion Prevention System (NIPS)
Flip cardA security tool that monitors network traffic for malicious activity and actively blocks or prevents detected threats in real-time.
- Operates in-line with network traffic.
- Can block malicious packets or connections.
- Effective against various attacks, including DoS and exploits.
Memory trick: NIPS: Network's In-line Protector, Stopping Bad Stuff.
Common Network Ports
Flip cardStandardized communication endpoints used by network protocols for specific services.
- Ports 0-1023 are 'well-known ports' assigned to common services.
- Blocking unnecessary ports reduces the attack surface.
- HTTP uses 80, HTTPS uses 443.
Memory trick: Web traffic is Hella Hot on 80 and 443.
Workaround Containment
Flip cardA containment strategy that involves implementing temporary fixes, configuration changes, or patches to stop the immediate threat or prevent further exploitation, allowing operations to continue with reduced risk.
- Focuses on immediate, temporary mitigation.
- Does not fully eradicate or recover the system.
- Buys time for a permanent solution or full eradication.
Memory trick: Containment: Isolate, Segment, Workaround, Restore.
Intrusion Prevention System (IPS)
Flip cardAn IPS is a network security device that monitors network and/or system activities for malicious policy violations and can automatically take actions to prevent detected threats.
- Actively blocks malicious traffic
- Uses signatures and behavioral analysis
- Can perform SSL/TLS inspection
Memory trick: IPS actively prevents trouble, unlike an IDS that just watches.
Detection & Analysis
Flip cardThe phase of incident response where security events are identified, evaluated, and confirmed as security incidents, determining their nature and scope.
- Involves monitoring systems for anomalies.
- Includes initial triage and investigation.
- Aims to understand the incident's impact and characteristics.
Memory trick: Prepare to Detect, Contain, Eradicate, Recover, and Post-Analyze.
Data Diode
Flip cardA data diode is a hardware device that enforces one-way data flow, ensuring that data can only travel in a single direction across a network boundary.
- Physically enforces unidirectional data flow
- Used in critical infrastructure (ICS/SCADA)
- Prevents data leakage and reverse control signals
Memory trick: A data diode is a one-way street for data.
Recovery Phase
Flip cardThe incident response phase where systems and services are restored to normal operation, often involving data restoration, system hardening, and continuous monitoring.
- Begins after eradication of the threat.
- Includes verifying system integrity and functionality.
- Aims to return the organization to business as usual.
Memory trick: Recovery is like hitting the 'reset' button after the storm.
Network Segmentation
Flip cardThe practice of dividing a computer network into smaller, isolated segments or subnets to improve security, performance, and manageability.
- Isolates critical assets from less trusted segments.
- Limits the lateral movement of attackers.
- Implemented using VLANs, firewalls, and routing.
Memory trick: Segmentation Separates Sensitive Systems.
Digital Signature
Flip cardA mathematical scheme for demonstrating the authenticity of digital messages or documents. A valid digital signature gives a recipient reason to believe that the message was created by a known sender (authenticity) and that it was not altered in transit (integrity).
- Provides authenticity and integrity.
- Uses asymmetric cryptography (public/private key pairs).
- Ensures non-repudiation (sender cannot deny sending).
- Commonly used for software updates, email, and document signing.
Memory trick: Digital Signature: Your 'signed and sealed' proof for digital data.
Virtual Private Network (VPN)
Flip cardA network technology that creates a secure, encrypted connection over a public network, allowing users to send and receive data as if their computing devices were directly connected to the private network.
- Provides secure remote access to internal networks.
- Encrypts data transmitted over the public internet.
- Creates a 'tunnel' for private communication.
Memory trick: VPN Provides Private Paths.
Post-Incident Activity
Flip cardThe final phase of incident response, focusing on learning from the incident, documenting findings, improving processes, and updating policies to prevent recurrence.
- Includes creating incident reports and conducting 'lessons learned' meetings (hot washes).
- Aims for continuous improvement of the incident response plan.
- Ensures vulnerabilities exploited are addressed and policies are updated.
Memory trick: After the incident, review, learn, and grow.
Attribute-Based Access Control (ABAC)
Flip cardAn authorization model that grants or denies access to resources based on a set of attributes associated with the user, resource, and environmental conditions.
- Highly granular and flexible access control.
- Uses attributes for user, resource, and environment.
- Evaluates policies dynamically at the time of access.
- Goes beyond roles to provide more context-aware access.
Memory trick: ABAC: Access is based on 'A'll the 'B'its 'A'bout 'C'ontext.
Risk Impact
Flip cardThe magnitude of harm or negative consequences that could result from the occurrence of a risk event. It quantifies the severity.
- Can be financial, operational, reputational, legal, or safety-related.
- Often assessed qualitatively (e.g., Low, Medium, High) or quantitatively (monetary value).
- A key component in calculating overall risk level.
Memory trick: Impact: Like a meteor hitting, what's the damage?
Compliance Risk
Flip cardThe potential for legal sanctions, financial losses, or damage to reputation resulting from an organization's failure to adhere to laws, regulations, standards, and internal policies.
- Driven by regulatory requirements (e.g., HIPAA, GDPR).
- Can result in fines, legal action, and loss of license.
- Requires continuous monitoring and adaptation to new laws.
Memory trick: Compliance risk is like a watchful legal eagle.
Residual Risk
Flip cardThe risk that remains after all risk mitigation efforts have been implemented. It is the leftover risk an organization faces after controls are in place.
- It's the risk remaining after controls.
- It cannot be entirely eliminated.
- Must be monitored and managed.
Memory trick: Remember 'RIM' for Risk: Inherent, Mitigated, Residual.
Qualitative Risk Rating
Flip cardA method of assessing risk by assigning descriptive values (e.g., Low, Medium, High) to the likelihood and impact of a risk, often using a matrix.
- Uses descriptive categories instead of numeric values.
- Subjective but useful for initial prioritization.
- Often represented in a grid or matrix.
Memory trick: Qualitative matrix: Like a weather forecast, not exact numbers.
Risk Transfer (Outsourcing)
Flip cardA risk management strategy where the financial or operational responsibility for a risk is shifted to a third party, often through insurance, contracts, or outsourcing services.
- Does not eliminate the risk, only reassigns responsibility.
- Common in cloud computing, insurance, and managed security services.
- Requires careful contract review to ensure adequate coverage.
Memory trick: Transferring risk is like handing off a hot potato.
Risk Avoidance
Flip cardA risk management strategy that involves eliminating the risk by deciding not to engage in the activity or process that carries the risk. It is often used for high-impact, high-likelihood risks.
- Eliminates the risk entirely.
- Achieved by not performing the risky activity.
- Often results in lost opportunities.
Memory trick: AART: Avoid, Accept, Reduce, Transfer.
Risk Acceptance
Flip cardA risk response strategy where an organization consciously decides to take no action to reduce or eliminate a specific risk, often because the cost of mitigation outweighs the potential impact, or the risk is deemed low.
- Can be passive (unaware) or active (conscious decision).
- Often used for low-impact or low-likelihood risks.
- Requires documentation of the decision and rationale.
Memory trick: Decide, Act, or Ignore: The three paths of risk.