Cisco Certified Support Technician (CCST) Cybersecurity flashcards
150 free flashcards. Tap a card to flip it.
Due Diligence
Flip cardThe process of conducting a thorough investigation and review of a potential business partner, system, or process to identify and assess associated risks before making a decision or entering into an agreement.
- Proactive risk assessment.
- Involves thorough investigation.
- Crucial for third-party relationships.
Memory trick: Vendors require Vigilant Due Diligence to Avoid Risk.
Risk Transfer (Outsourcing)
Flip cardA risk response strategy where the responsibility for certain risks, and often the associated assets or operations, is shifted to a third-party entity through contractual agreements.
- Common in cloud computing and managed services.
- Does not eliminate the company's overall risk, as ultimate accountability remains.
- Requires careful vendor selection and contract negotiation.
Memory trick: Move it, Share it, Give it away: The transfer ways.
Risk Reduction
Flip cardA risk response strategy that involves implementing controls or countermeasures to decrease the likelihood of a risk event occurring, or to lessen its impact if it does occur.
- Most common risk response strategy.
- Includes technical, administrative, and physical controls.
- Aims to lower the overall risk level to an acceptable threshold.
Memory trick: Reduce, Isolate, Control: The three ways to lessen risk.
Forced Risk Acceptance
Flip cardA situation where an organization is compelled to accept certain risks due to external factors, resource limitations, or the impracticality of implementing further mitigation or avoidance strategies, even if those risks exceed their ideal risk appetite.
- Acceptance due to unavoidable constraints.
- No practical alternative solutions.
- Often involves legacy systems or high costs.
Memory trick: Acceptance is a choice, but sometimes it's forced.
Risk Matrix
Flip cardA qualitative risk assessment tool that plots risks based on their likelihood (probability) and impact (consequence) to determine their overall severity or priority. It typically uses color-coded cells.
- Visualizes likelihood vs. impact.
- Categorizes risk severity.
- Aids in risk prioritization.
Memory trick: Matrices Register Tolerance for Appetite.
Inherent Risk
Flip cardThe level of risk before any risk mitigation controls or countermeasures have been applied. It is the raw risk an organization faces.
- Calculated based on raw likelihood and impact.
- Serves as a baseline for risk assessment.
- Often contrasted with residual risk.
Memory trick: Inherent risk is the raw, untamed danger.
Risk Acceptance
Flip cardA risk management strategy where an organization acknowledges a risk and decides to take no action to reduce or eliminate it, often due to cost-benefit analysis or business necessity.
- No new controls are implemented.
- Decision is often made after a cost-benefit analysis.
- Can be passive (unaware) or active (informed choice).
Memory trick: Accepting risk is like shrugging off a minor threat.
Risk Identification
Flip cardThe process of discovering, recognizing, and describing risks that could affect an organization's assets.
- First step in risk management.
- Involves identifying threats, vulnerabilities, and assets.
- Can be qualitative or quantitative.
Memory trick: Identify, Analyze, Respond, Monitor: The four pillars of risk control.
Risk Avoidance
Flip cardA risk management strategy that involves eliminating the risk by deciding not to engage in the activity or process that carries the risk. It is often used for high-impact, high-likelihood risks.
- Eliminates the risk entirely.
- Achieved by not performing the risky activity.
- Often results in lost opportunities.
Memory trick: AART: Avoid, Accept, Reduce, Transfer.
Qualitative Risk Rating
Flip cardA method of assessing risk by assigning descriptive values (e.g., Low, Medium, High) to the likelihood and impact of a risk, often using a matrix.
- Uses descriptive categories instead of numeric values.
- Subjective but useful for initial prioritization.
- Often represented in a grid or matrix.
Memory trick: Qualitative matrix: Like a weather forecast, not exact numbers.
Residual Risk
Flip cardThe risk that remains after all risk mitigation efforts have been implemented. It is the leftover risk an organization faces after controls are in place.
- It's the risk remaining after controls.
- It cannot be entirely eliminated.
- Must be monitored and managed.
Memory trick: Remember 'RIM' for Risk: Inherent, Mitigated, Residual.
Compliance Risk
Flip cardThe risk of legal or regulatory sanctions, material financial loss, or loss of reputation an organization may suffer as a result of its failure to comply with laws, regulations, rules, or standards of best practice.
- Arises from failure to adhere to internal policies or external mandates.
- Can lead to fines, legal action, and reputational damage.
- Requires continuous monitoring and updates to policies.
Memory trick: Operations, Strategy, Compliance, Reputation: O.S.C.R. the business risks.
Secure Configuration Baseline
Flip cardA standardized set of security configurations and settings applied to systems and devices to reduce vulnerabilities and establish a secure starting point.
- Involves disabling unnecessary services and features.
- Applies security patches and updates.
- Reduces the attack surface of systems.
Memory trick: A secure baseline is like a strong foundation for your house.
Centralized Endpoint Management
Flip cardThe practice of managing and securing all endpoints within an organization from a single, central platform, ensuring consistent policy application and visibility.
- Ensures uniform security posture across all devices.
- Facilitates remote patching and configuration.
- Crucial for mobile and off-site devices.
Memory trick: Good practices keep endpoints safe and sound, even on the go.
Full Disk Encryption (FDE)
Flip cardA security method that encrypts all data on a hard drive, including the operating system, making the data unreadable without the correct decryption key or password.
- Protects data at rest.
- Essential for laptops and mobile devices.
- Prevents unauthorized access if device is lost or stolen.
Memory trick: Encryption locks your data in a digital safe.
Heuristic/Behavioral Analysis
Flip cardAn endpoint security technique that detects malware by analyzing its behavior and characteristics (e.g., system calls, API usage, file changes) rather than relying on predefined signatures. It is effective against zero-day and polymorphic threats.
- Identifies suspicious actions that indicate malicious intent.
- Can detect previously unknown (zero-day) malware.
- Often used in conjunction with signature-based detection for comprehensive protection.
Memory trick: Instead of a mugshot, behavioral analysis watches what the malware 'does' to catch it.
Host-based Firewall Rules
Flip cardRules configured on an individual computer (host) to control inbound and outbound network traffic, enhancing endpoint security.
- Operates at the endpoint level.
- Can be configured to allow or deny traffic based on ports, protocols, and IP addresses.
- Incorrect configuration can create vulnerabilities.
Memory trick: Every open door is an opportunity for friends or foes.
Memory Forensics and Analysis
Flip cardThe process of collecting and analyzing data from the volatile memory (RAM) of a computer system to detect signs of malicious activity, such as rootkits, process injection, and other in-memory attacks that do not leave traces on persistent storage.
- Crucial for detecting fileless malware and advanced persistent threats (APTs).
- Identifies malicious code or data operating directly within RAM.
- Requires specialized tools to capture and analyze memory dumps.
Memory trick: To catch the ghost in the machine, you need to look inside its 'thoughts' (memory).
Mobile Device Management (MDM)
Flip cardA security solution used to manage, monitor, and secure mobile devices (smartphones, tablets, laptops) across an organization. It enforces policies, manages applications, and can remotely control or wipe devices, especially useful in BYOD scenarios.
- Enforces security policies (e.g., passcodes, encryption) on mobile devices.
- Manages application deployment and updates.
- Allows for remote wipe, including selective wipe for corporate data on personal devices.
Memory trick: MDM is like having a remote control for the work part of an employee's personal phone.
Network Access Control (NAC)
Flip cardA security solution that restricts network access to devices that do not meet specified security policies. It authenticates users and devices, assesses their security posture, and enforces access control.
- Prevents unauthorized devices from connecting to the network.
- Can perform health checks on devices (e.g., AV status, patch levels).
- Often integrates with identity management systems and can quarantine non-compliant devices.
Memory trick: NAC is the bouncer at the network's club, checking everyone's ID and dress code.
Data Loss Prevention (DLP)
Flip cardA set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users, preventing its unauthorized transmission outside the organization.
- Identifies and classifies sensitive data.
- Monitors data in use, in motion, and at rest.
- Enforces policies to prevent data exfiltration.
Memory trick: DLP is the guard dog for your data, keeping it from running away.
Incident Response: Eradication
Flip cardThe phase of incident response focused on removing the cause of the incident and eliminating threat actors' access to systems and data.
- Involves cleaning compromised systems.
- Often includes patching vulnerabilities.
- Aims to prevent re-occurrence.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-Incident.
Least Functionality
Flip cardA security principle requiring that systems, applications, and services be configured to provide only the minimum necessary functions to perform their intended purpose.
- Reduces the attack surface.
- Minimizes potential vulnerabilities.
- Involves disabling unnecessary services and closing unused ports.
Memory trick: Least Functionality: 'Less is more' for security.
Host-based Firewall
Flip cardA software application that runs on a single host (e.g., a workstation or server) and monitors and controls incoming and outgoing network traffic based on predefined security rules.
- Protects individual endpoints from network threats.
- Can filter traffic based on IP addresses, ports, protocols, and applications.
- Essential for enforcing network security policies at the endpoint level.
Memory trick: The endpoint firewall is like a digital bouncer, checking IDs for all network traffic.
Mobile Application Management (MAM)
Flip cardSoftware that enables organizations to manage and secure corporate applications and data on mobile devices, often used in BYOD scenarios to separate business and personal content.
- Manages applications and data, not the entire device.
- Allows for selective wiping of corporate data.
- Enforces policies on specific corporate apps.
Memory trick: MDM controls the phone, MAM controls the apps.
Vulnerability Management
Flip cardThe cyclical practice of identifying, classifying, prioritizing, remediating, and mitigating vulnerabilities in systems and applications.
- Proactive approach to security.
- Includes scanning, assessment, and remediation.
- Addresses misconfigurations and missing patches.
Memory trick: Vulnerability Management: Find and fix the security holes before attackers do.
Antivirus/Anti-malware
Flip cardSoftware designed to detect, prevent, and remove malicious software, including viruses, worms, Trojans, and ransomware, from computer systems.
- Uses signature-based and heuristic-based detection.
- Protects against various forms of malware.
- Essential for endpoint security.
Memory trick: Each tool has a specific job to guard the endpoint.
Application Sandbox
Flip cardA security mechanism that isolates a running program in a restricted environment, preventing it from interacting with other parts of the system or network outside of its defined boundaries.
- Contains potential exploits and malware.
- Limits damage to the sandboxed environment.
- Commonly used for web browsers, email clients, and document viewers.
Memory trick: Sandbox: A 'playpen' for risky apps, keeping messes contained.
Application Whitelisting
Flip cardA security strategy that allows only explicitly approved applications to execute on a system, blocking all others by default.
- Enhances security by preventing unauthorized software.
- Can reduce attack surface and malware infections.
- Requires careful management of the approved application list.
Memory trick: Whitelist says, 'Only you can play here!'
EDR Telemetry and Forensics
Flip cardThe capability of Endpoint Detection and Response (EDR) systems to continuously collect detailed endpoint activity data (telemetry) and provide tools for forensic analysis to reconstruct security incidents.
- Records process activity, file changes, network connections.
- Enables deep dive into incident timelines.
- Crucial for understanding attack vectors and scope.
Memory trick: EDR's logs are the 'CCTV footage' of your endpoint's activities.