Exam Domain
A major section of the exam covering related topics.
Getting Started with CCST Cybersecurity
Free knowledge base
Everything from the course in one searchable place: 293 entries. Use it to review before a practice test or look up a word you forgot.
293 results
A major section of the exam covering related topics.
Getting Started with CCST Cybersecurity
The percentage of exam questions allocated to a specific domain.
Getting Started with CCST Cybersecurity
The global testing provider for Cisco certification exams.
Getting Started with CCST Cybersecurity
A question with one correct answer from several options.
Getting Started with CCST Cybersecurity
A question requiring selection of all correct answers.
Getting Started with CCST Cybersecurity
Document detailing exam performance by domain.
Getting Started with CCST Cybersecurity
Cisco's detailed list of content covered on an exam.
Getting Started with CCST Cybersecurity
To remember the exam structure, think 'D-W-F-R': Domains, Weightings, Format, Resources. It's like building a house: first the plan (Domains), then prioritizing materials (Weightings), setting up the build (Format), and using the right tools (Resources).
Getting Started with CCST Cybersecurity
The CCST Cybersecurity exam typically has 40-50 questions and a duration of 50 minutes. Remember these numbers precisely.
Getting Started with CCST Cybersecurity
Ignoring domain weightings and studying all topics equally.
Getting Started with CCST Cybersecurity
Not checking the official Cisco website for the most current exam topics.
Getting Started with CCST Cybersecurity
Underestimating the importance of time management during the exam.
Getting Started with CCST Cybersecurity
Official validation of skills and knowledge.
Getting Started with CCST Cybersecurity
Beginning stage of a career or certification path.
Getting Started with CCST Cybersecurity
Foundational, broad IT skills certification.
Getting Started with CCST Cybersecurity
Specialized, advanced skills in a domain.
Getting Started with CCST Cybersecurity
Highest level, demonstrating deep expertise.
Getting Started with CCST Cybersecurity
Cisco Certified Support Technician.
Getting Started with CCST Cybersecurity
Cisco Certified Network Associate.
Getting Started with CCST Cybersecurity
To remember the Cisco certification levels, think 'E.A.P.E.A.': Entry, Associate, Professional, Expert, Architect. Like you're 'Eating Apples, Peaches, Every Afternoon'!
Getting Started with CCST Cybersecurity
The CCST Cybersecurity is an entry-level certification. It is NOT a prerequisite for the CCNA, but it provides a strong foundation. Remember the hierarchy: Entry > Associate > Professional > Expert > Architect.
Getting Started with CCST Cybersecurity
Confusing CCST with CCNA: CCST is entry-level and more focused on support/foundational concepts, while CCNA is associate-level and covers broader networking.
Getting Started with CCST Cybersecurity
Believing CCST is a prerequisite for all other Cisco certs: It's a great starting point, but not strictly required for all higher-level certifications.
Getting Started with CCST Cybersecurity
Underestimating the value of entry-level certifications: They provide crucial foundational knowledge and open doors to initial job roles.
Getting Started with CCST Cybersecurity
Preventing unauthorized disclosure of information.
Foundational Security Principles
Maintaining accuracy, completeness, and consistency of data.
Foundational Security Principles
Ensuring authorized users can access information when needed.
Foundational Security Principles
Foundational model for information security: Confidentiality, Integrity, Availability.
Foundational Security Principles
Ensuring a party cannot deny having performed an action.
Foundational Security Principles
Safeguards to avoid, detect, counteract, or minimize risks.
Foundational Security Principles
Transforming data to prevent unauthorized access.
Foundational Security Principles
Transforming data into fixed-size string for integrity checks.
Foundational Security Principles
CIA: 'C' for 'Confidential' (secrets), 'I' for 'Intact' (unchanged), 'A' for 'Accessible' (always there).
Foundational Security Principles
The exam frequently tests your understanding of the CIA Triad. Be ready to identify which principle is violated or upheld by specific security measures or attack types. For example, a DDoS attack directly impacts Availability.
Foundational Security Principles
Confusing integrity with confidentiality; integrity is about data accuracy, confidentiality is about secrecy.
Foundational Security Principles
Underestimating the importance of availability; downtime can be as damaging as a data breach.
Foundational Security Principles
Forgetting about non-repudiation as a critical security concept, especially in transaction-heavy environments.
Foundational Security Principles
Malicious software designed to harm or exploit computer systems.
Foundational Security Principles
Fraudulent communication to trick individuals into revealing info.
Foundational Security Principles
Malware that encrypts data and demands payment for decryption.
Foundational Security Principles
Attack to make a service unavailable by overwhelming it.
Foundational Security Principles
Manipulating people to gain access or information.
Foundational Security Principles
Exploiting web app vulnerabilities to manipulate database queries.
Foundational Security Principles
Attacker intercepts and relays communication between two parties.
Foundational Security Principles
Remember 'V.W.T.R.S.A.R.' for common malware: Viruses, Worms, Trojans, Ransomware, Spyware, Adware, Rootkits. It's like a secret agent's code!
Foundational Security Principles
The exam expects you to differentiate between various malware types (virus, worm, Trojan, ransomware, spyware, adware, rootkit) and social engineering techniques (phishing, spear phishing, pretexting, baiting, tailgating). Know the primary goal of each attack.
Foundational Security Principles
Confusing the specific characteristics of different malware types (e.g., a virus needs a host program, a worm is self-replicating).
Foundational Security Principles
Underestimating the effectiveness of social engineering; it preys on human trust, not just technical flaws.
Foundational Security Principles
Failing to distinguish between DoS (single source) and DDoS (multiple sources) attacks.
Foundational Security Principles
A structured approach to manage an organization's information security risks.
Foundational Security Principles
High-level statements guiding security decisions and organizational behavior.
Foundational Security Principles
A structured set of guidelines and best practices for managing cybersecurity risk.
Foundational Security Principles
A widely adopted framework for managing and reducing cybersecurity risks.
Foundational Security Principles
An international standard for information security management systems (ISMS).
Foundational Security Principles
A documented plan for how an organization will react to security breaches.
Foundational Security Principles
The ongoing process of enhancing a security program to adapt to new threats.
Foundational Security Principles
To remember the key components, think 'P.R.I.S.T.I.N.E.': Policies, Risk management, Incident response, Standards, Training, Infrastructure, Network security, Evaluation.
Foundational Security Principles
The exam often tests your understanding of *why* security programs are necessary and the *components* that make them effective. Look for keywords like 'structured approach,' 'risk management,' 'policies,' and 'incident response' when identifying correct answers.
Foundational Security Principles
Confusing a security program with just security software; it's much broader.
Foundational Security Principles
Believing a security program is a one-time setup rather than an ongoing process.
Foundational Security Principles
Underestimating the importance of human elements like training and awareness.
Foundational Security Principles
EU law on data protection and privacy.
Foundational Security Principles
US law protecting patient health information.
Foundational Security Principles
California law granting consumer data rights.
Foundational Security Principles
Adhering to laws, regulations, and standards.
Foundational Security Principles
Moral principles guiding professional conduct.
Foundational Security Principles
High-level statement of organizational intent.
Foundational Security Principles
Detailed, step-by-step instructions for tasks.
Foundational Security Principles
Think 'LEG' for Legal, Ethical, Governance. Like a strong leg supporting a table, these three pillars support a secure organization.
Foundational Security Principles
Memorize the acronyms and their associated regions/industries: GDPR (EU, data privacy), HIPAA (US, healthcare), CCPA (California, consumer data). The exam often tests your ability to match the regulation to its primary focus.
Foundational Security Principles
Confusing a policy (what to do) with a procedure (how to do it).
Foundational Security Principles
Assuming compliance with one regulation means compliance with all others.
Foundational Security Principles
Believing that ethical behavior is only necessary when legal obligations exist.
Foundational Security Principles
A weakness in a system that can be exploited by an attacker.
Network Security Fundamentals
Code or technique used to take advantage of a vulnerability.
Network Security Fundamentals
CIA: 'C' for 'Confidential' secrets, 'I' for 'Intact' data, 'A' for 'Always' accessible.
Network Security Fundamentals
The exam frequently tests your understanding of the CIA triad. Be ready to identify which principle is violated in a given scenario. Keywords like 'unauthorized access' point to confidentiality, 'data alteration' to integrity, and 'system downtime' to availability.
Network Security Fundamentals
Confusing integrity with confidentiality; they are distinct concepts.
Network Security Fundamentals
Underestimating the importance of availability; a system that's always down is useless.
Network Security Fundamentals
Believing that security is a one-time setup rather than an ongoing process.
Network Security Fundamentals
Network security system that controls traffic based on rules.
Network Security Fundamentals
Intrusion Detection System; monitors for suspicious activity and alerts.
Network Security Fundamentals
Intrusion Prevention System; detects and actively blocks malicious traffic.
Network Security Fundamentals
Virtual Private Network; creates a secure, encrypted connection over public networks.
Network Security Fundamentals
Firewall technique inspecting individual packets by header info.
Network Security Fundamentals
Firewall technique that tracks the state of active network connections.
Network Security Fundamentals
IDS/IPS method matching known attack patterns.
Network Security Fundamentals
IDS/IPS method identifying deviations from normal network behavior.
Network Security Fundamentals
F-I-V: Firewalls are the Front door, IDS/IPS are the Investigators, and VPNs are the Veiled passages.
Network Security Fundamentals
The CCST Cybersecurity exam expects you to differentiate clearly between the passive role of an IDS (detect and alert) and the active role of an IPS (detect and prevent). Also, know the core benefits of VPNs: confidentiality, integrity, and authentication.
Network Security Fundamentals
Confusing IDS (detection only) with IPS (detection and prevention). Remember, 'P' for Prevention means it actively stops threats.
Network Security Fundamentals
Assuming a firewall alone is sufficient for all network security. Firewalls are crucial, but IDS/IPS and VPNs provide additional layers of defense.
Network Security Fundamentals
Not understanding the difference between IPsec VPNs (often for site-to-site or full tunnel remote access) and SSL/TLS VPNs (often for clientless or application-specific remote access).
Network Security Fundamentals
Dividing a network into smaller, isolated subnetworks to limit threat spread.
Network Security Fundamentals
A buffer network for public-facing servers, protecting the internal LAN.
Network Security Fundamentals
Security model: 'never trust, always verify' every access request.
Network Security Fundamentals
Granular network segmentation, isolating individual workloads or applications.
Network Security Fundamentals
Employing multiple layers of security controls to protect assets.
Network Security Fundamentals
The technique attackers use to move through a network after initial access.
Network Security Fundamentals
Logical grouping of network devices, independent of physical location.
Network Security Fundamentals
Think 'SEGMENTATION = STOP EVIL GOING EVERYWHERE, MAKING EVERY NETWORK TIGHT AND ORDERLY NOW!'
Network Security Fundamentals
The exam often tests your understanding of the *purpose* of segmentation. Focus on 'limiting lateral movement,' 'reducing attack surface,' and 'isolating critical assets.' Also, know that a DMZ is for *public-facing* servers.
Network Security Fundamentals
Thinking segmentation only applies to physical separation; logical segmentation (VLANs) is equally important.
Network Security Fundamentals
Failing to review and update segmentation policies, leading to outdated or ineffective controls.
Network Security Fundamentals
Over-segmenting without proper planning, which can complicate network management and troubleshooting.
Network Security Fundamentals
Wired Equivalent Privacy, an obsolete and insecure wireless security protocol.
Network Security Fundamentals
Wi-Fi Protected Access 2, current standard for robust wireless network security.
Network Security Fundamentals
Wi-Fi Protected Access 3, the latest and most secure wireless security standard.
Network Security Fundamentals
A rogue access point mimicking a legitimate one to intercept traffic.
Network Security Fundamentals
Network Access Control, restricts network access based on security policies.
Network Security Fundamentals
An IEEE standard for port-based network access control.
Network Security Fundamentals
Service Set Identifier, the name of a wireless network.
Network Security Fundamentals
NAC process of checking device health and compliance.
Network Security Fundamentals
WPA3 is the WINNER for Wireless Protection! (WEP is a WEAK loser)
Network Security Fundamentals
The exam will test your knowledge of wireless security protocols, specifically their strengths and weaknesses. Memorize that WEP is bad, WPA2 is good, and WPA3 is best. Understand that NAC is about policy enforcement for device access.
Network Security Fundamentals
Using WEP or WPA (original) for wireless security, which are easily cracked.
Network Security Fundamentals
Not segmenting guest wireless networks from internal corporate networks.
Network Security Fundamentals
Relying solely on MAC address filtering for wireless security, as MAC addresses can be spoofed.
Network Security Fundamentals
Any device connected to a network, target for attacks.
Endpoint Protection and Management
Method or path used by attackers to gain access.
Endpoint Protection and Management
Self-replicating malware that attaches to programs.
Endpoint Protection and Management
Self-replicating malware that spreads across networks.
Endpoint Protection and Management
Malware disguised as legitimate software.
Endpoint Protection and Management
To remember the common malware types, think 'VW-RATS': Virus, Worm, Ransomware, Adware, Trojan, Spyware.
Endpoint Protection and Management
The exam often asks to identify common attack vectors like phishing, social engineering, and exploiting vulnerabilities. Be prepared to differentiate between types of malware based on their behavior (e.g., ransomware encrypts, spyware monitors).
Endpoint Protection and Management
Assuming only servers need strong security; user workstations are equally vulnerable.
Endpoint Protection and Management
Believing antivirus alone is sufficient for endpoint protection.
Endpoint Protection and Management
Underestimating the human element in security; users are often the weakest link.
Endpoint Protection and Management
Software to detect, prevent, and remove malware.
Endpoint Protection and Management
Detects malware by analyzing suspicious behavior.
Endpoint Protection and Management
Monitors endpoint activity for advanced threat detection.
Endpoint Protection and Management
Controls network traffic on an individual device.
Endpoint Protection and Management
Attack leveraging unknown software vulnerabilities.
Endpoint Protection and Management
Observing system actions for malicious patterns.
Endpoint Protection and Management
Proactively searching for signs of compromise.
Endpoint Protection and Management
To remember the three, think 'A.E.F.' — Antivirus (first line), EDR (eyes everywhere), Firewall (traffic cop).
Endpoint Protection and Management
The exam often tests the distinct functions of these tools. Remember: Antivirus for known malware, EDR for deep visibility and advanced threats, and host-based firewalls for network traffic control on the device itself.
Endpoint Protection and Management
Confusing EDR with traditional antivirus: EDR is much broader, focusing on monitoring and response, not just signature-based detection.
Endpoint Protection and Management
Believing one tool is sufficient: A layered approach using all three (antivirus, EDR, host-based firewall) provides the best protection.
Endpoint Protection and Management
Underestimating the importance of host-based firewalls: They are critical for individual device protection, especially for mobile users.
Endpoint Protection and Management
Process of acquiring, testing, and applying software updates.
Endpoint Protection and Management
Securing a system by reducing its attack surface and default settings.
Endpoint Protection and Management
The sum of all points where an unauthorized user can try to enter data.
Endpoint Protection and Management
Granting users only the minimum access needed for their tasks.
Endpoint Protection and Management
A newly discovered flaw with no existing patch or public knowledge.
Endpoint Protection and Management
For Patch Management, remember 'TAP-D': Test, Assess, Plan, Deploy. For Hardening, think 'Less is More': Less services, less open ports, more secure settings.
Endpoint Protection and Management
The exam often tests your understanding of the *purpose* of patch management (to fix known vulnerabilities) and configuration hardening (to reduce the attack surface). Look for questions asking to distinguish between reactive vs. proactive security measures.
Endpoint Protection and Management
Delaying critical security patches, leaving systems vulnerable to known exploits.
Endpoint Protection and Management
Failing to test patches before deployment, leading to system instability or outages.
Endpoint Protection and Management
Leaving default configurations unchanged on new systems, creating easy entry points for attackers.
Endpoint Protection and Management
Software to manage and secure mobile devices in an organization.
Endpoint Protection and Management
Extends MDM to manage all endpoints, including desktops and IoT.
Endpoint Protection and Management
Tools and processes to prevent sensitive data from leaving the organization.
Endpoint Protection and Management
Ability to remotely erase data from a lost or stolen device.
Endpoint Protection and Management
Policy allowing employees to use personal devices for work.
Endpoint Protection and Management
Separating corporate and personal data/apps on a mobile device.
Endpoint Protection and Management
Manages and secures specific applications on mobile devices.
Endpoint Protection and Management
MDM: 'My Device is Managed' – think of it as a remote control for all your company's phones and tablets.
Endpoint Protection and Management
The exam often tests your understanding of MDM/UEM capabilities and how they address mobile security challenges like lost devices or data exfiltration. Keywords to look for include 'remote wipe,' 'policy enforcement,' 'encryption,' and 'data classification' in the context of mobile devices.
Endpoint Protection and Management
Underestimating the risk of personal apps on corporate devices.
Endpoint Protection and Management
Failing to implement strong authentication or device encryption.
Endpoint Protection and Management
Not having a clear policy for lost or stolen mobile devices.
Endpoint Protection and Management
Cyclical process to identify, assess, and fix security weaknesses.
Vulnerability Management Lifecycle
The process of fixing or mitigating identified vulnerabilities.
Vulnerability Management Lifecycle
VULNERABILITY: Very Unlocked Locations Need Everyone's Righteous Awareness Before It's Too Late, You Betcha!
Vulnerability Management Lifecycle
The exam expects you to know the definition of vulnerability management and its core phases. Look for questions that ask about the 'lifecycle' or 'process' of managing vulnerabilities. Remember that it's continuous, not a one-time task.
Vulnerability Management Lifecycle
Confusing a vulnerability (the weakness) with an exploit (the attack using the weakness).
Vulnerability Management Lifecycle
Believing vulnerability management is a one-time project, rather than an ongoing process.
Vulnerability Management Lifecycle
Skipping the verification step after remediation, assuming a fix was successful.
Vulnerability Management Lifecycle
Automated process to identify known security weaknesses.
Vulnerability Management Lifecycle
Simulated cyberattack to find and exploit vulnerabilities.
Vulnerability Management Lifecycle
A popular commercial vulnerability scanner.
Vulnerability Management Lifecycle
Free and open-source vulnerability scanning software.
Vulnerability Management Lifecycle
Linux distribution with pre-installed penetration testing tools.
Vulnerability Management Lifecycle
A framework for developing and executing exploit code.
Vulnerability Management Lifecycle
The act of taking advantage of a vulnerability.
Vulnerability Management Lifecycle
Gathering information about a target system or network.
Vulnerability Management Lifecycle
SCAN for what you KNOW, PEN-test for what you can EXPLOIT.
Vulnerability Management Lifecycle
The exam expects you to clearly distinguish between 'vulnerability scanning' and 'penetration testing' based on their purpose, methodology (automated vs. manual), and outcome (identification vs. exploitation). Look for keywords like 'known vulnerabilities' for scanning and 'simulated attack' or 'exploit' for pen testing.
Vulnerability Management Lifecycle
Confusing the purpose: Scanning identifies, pen testing exploits.
Vulnerability Management Lifecycle
Believing a scan proves a system is secure; it only checks for known issues.
Vulnerability Management Lifecycle
Using pen testing for frequent, broad checks when scanning is more appropriate and cost-effective.
Vulnerability Management Lifecycle
Ranking vulnerabilities based on risk and impact.
Vulnerability Management Lifecycle
Standardized system for scoring vulnerability severity.
Vulnerability Management Lifecycle
Applying software updates to fix vulnerabilities.
Vulnerability Management Lifecycle
Security measure reducing risk when direct fix isn't possible.
Vulnerability Management Lifecycle
Temporary solution to mitigate a vulnerability.
Vulnerability Management Lifecycle
Formal decision to not fix a vulnerability, with documented risk.
Vulnerability Management Lifecycle
Confirming a vulnerability has been successfully fixed.
Vulnerability Management Lifecycle
To remember the remediation steps: 'P-R-V' - Prioritize, Remediate, Verify. Like 'Prove' it's fixed!
Vulnerability Management Lifecycle
Memorize the key steps in the vulnerability management lifecycle: Identification, Prioritization, Remediation, and Verification. The exam often tests the order and purpose of each phase.
Vulnerability Management Lifecycle
Ignoring the business context: Focusing solely on CVSS scores without considering the criticality of the affected asset or potential business impact.
Vulnerability Management Lifecycle
Skipping verification: Assuming a patch fixed the issue without re-scanning or testing, potentially leaving systems vulnerable.
Vulnerability Management Lifecycle
Poor communication: Failing to inform stakeholders about remediation plans, leading to unexpected downtime or resistance.
Vulnerability Management Lifecycle
Ongoing observation and analysis of systems for security weaknesses.
Vulnerability Management Lifecycle
Security Information and Event Management; aggregates and analyzes logs.
Vulnerability Management Lifecycle
Intrusion Detection/Prevention System; monitors network for threats.
Vulnerability Management Lifecycle
Endpoint Detection and Response; monitors and responds to endpoint threats.
Vulnerability Management Lifecycle
Average time taken to fix a detected vulnerability.
Vulnerability Management Lifecycle
Reports demonstrating adherence to regulations and security policies.
Vulnerability Management Lifecycle
Overall security status and resilience of an organization's systems.
Vulnerability Management Lifecycle
To remember the importance of Continuous Monitoring, think: 'Always Be Watching' (ABW) – like a security guard who never takes a break, because threats never do!
Vulnerability Management Lifecycle
The exam expects you to know that continuous monitoring is an ongoing process, not a one-time event. Look for keywords like 'real-time,' 'ongoing,' or 'dynamic' in questions about this topic. Remember that reporting metrics like MTTR are key to measuring program effectiveness.
Vulnerability Management Lifecycle
Assuming that a one-time vulnerability scan is sufficient for ongoing security.
Vulnerability Management Lifecycle
Failing to establish clear reporting metrics or understanding what they mean.
Vulnerability Management Lifecycle
Not integrating continuous monitoring results into the remediation process.
Vulnerability Management Lifecycle
Ignoring the importance of compliance reporting for legal and business reasons.
Vulnerability Management Lifecycle
Anything of value to an organization that needs protection.
Risk Management Essentials
Any potential danger that could exploit a vulnerability.
Risk Management Essentials
The potential for loss or damage from a security incident.
Risk Management Essentials
The magnitude of harm if a risk materializes.
Risk Management Essentials
The probability that a threat will exploit a vulnerability.
Risk Management Essentials
Remember 'ATL' for Asset, Threat, Likelihood! No, wait, that's not right. How about 'ATV' for Asset, Threat, Vulnerability! That's the core. Then add 'IRL' for Impact, Risk, Likelihood.
Risk Management Essentials
The exam often tests your ability to distinguish between an asset, threat, and vulnerability. Look for keywords like 'what needs protection' (asset), 'potential danger' (threat), and 'weakness' (vulnerability).
Risk Management Essentials
Confusing a threat with a vulnerability (e.g., thinking 'malware' is a vulnerability when it's a threat that exploits a vulnerability).
Risk Management Essentials
Failing to identify all three components (asset, threat, vulnerability) when defining a specific risk.
Risk Management Essentials
Underestimating the importance of intangible assets like reputation or intellectual property.
Risk Management Essentials
Systematic process to identify, analyze, and evaluate risks.
Risk Management Essentials
Uses descriptive terms for risk assessment (e.g., high, medium, low).
Risk Management Essentials
Uses numerical values and monetary terms for risk assessment.
Risk Management Essentials
A document to record and track identified risks and their details.
Risk Management Essentials
L-I-R-A-M: Likelihood and Impact determine Risk, which is then Analyzed and Managed. Remember LIRA for your risk analysis!
Risk Management Essentials
The exam often tests your understanding of the risk assessment lifecycle. Memorize the core steps: Identify, Analyze, Evaluate, Treat, Monitor. Also, distinguish clearly between qualitative (subjective, descriptive) and quantitative (objective, numerical) analysis.
Risk Management Essentials
Confusing likelihood with impact; they are distinct components of risk.
Risk Management Essentials
Skipping the documentation phase (risk register) which is vital for tracking and ongoing management.
Risk Management Essentials
Failing to consider all types of assets, not just technical ones (e.g., reputation, intellectual property).
Risk Management Essentials
Actions to reduce likelihood or impact of a risk.
Risk Management Essentials
Deliberate decision to take no action on a risk.
Risk Management Essentials
Layered security approach with multiple controls.
Risk Management Essentials
Measure to prevent, detect, or reduce a risk.
Risk Management Essentials
Risk remaining after mitigation efforts.
Risk Management Essentials
To remember the four main strategies: 'MAAT' (Mitigate, Accept, Avoid, Transfer). Think of a 'MAAT' of options for handling risks!
Risk Management Essentials
The exam often presents scenarios and asks you to identify the best risk treatment strategy. Look for keywords like 'reduce,' 'prevent,' 'implement controls' for mitigation, and 'accept,' 'monitor,' 'document decision' for acceptance. Understand that 'defense in depth' is a mitigation strategy.
Risk Management Essentials
Confusing risk acceptance with ignoring a risk; acceptance is a conscious, documented decision.
Risk Management Essentials
Believing that mitigation eliminates all risk; it only reduces it to an acceptable level.
Risk Management Essentials
Underestimating the importance of a layered security approach (defense in depth).
Risk Management Essentials
Maintaining essential functions during disruption.
Risk Management Essentials
Restoring IT systems after a disaster.
Risk Management Essentials
Comprehensive plan for ongoing operations.
Risk Management Essentials
Detailed steps to restore IT infrastructure.
Risk Management Essentials
Max tolerable downtime for systems.
Risk Management Essentials
Max tolerable data loss from an incident.
Risk Management Essentials
Identifies critical processes and their impact.
Risk Management Essentials
Think of BCP as 'Business Continues Planning' – keeping the whole business going. DRP is 'Data Recovery Planning' – specifically getting the tech back.
Risk Management Essentials
The exam often tests your ability to distinguish between RTO (how quickly you need to be back up) and RPO (how much data you can afford to lose). Know these definitions precisely.
Risk Management Essentials
Confusing BCP and DRP as interchangeable terms; BCP is broader, DRP is IT-specific.
Risk Management Essentials
Failing to regularly test recovery plans, leading to outdated or ineffective procedures.
Risk Management Essentials
Not performing a thorough Business Impact Analysis (BIA) to identify truly critical assets.
Risk Management Essentials
A violation of security policies or practices, compromising CIA.
Incident Handling and Response
Any observable occurrence in a system or network.
Incident Handling and Response
A documented strategy for handling security incidents.
Incident Handling and Response
Limiting the scope and impact of an incident.
Incident Handling and Response
Removing the root cause of a security incident.
Incident Handling and Response
Restoring systems and data to normal operation.
Incident Handling and Response
CIA: Confidentiality, Integrity, Availability – the three pillars of information security, often compromised during an incident.
Incident Handling and Response
The exam often tests your ability to differentiate between an 'event' and an 'incident.' Remember: An incident is an event that violates policy or compromises security. Look for keywords like 'violation,' 'unauthorized access,' or 'compromise' to identify incidents.
Incident Handling and Response
Confusing an 'event' with an 'incident.' An event is just an occurrence; an incident is an event that violates security policy.
Incident Handling and Response
Not having a documented Incident Response Plan. Winging it during an incident leads to chaos and greater damage.
Incident Handling and Response
Failing to conduct 'lessons learned' after an incident, missing opportunities to improve security posture.
Incident Handling and Response
Six-phase incident response model: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned.
Incident Handling and Response
Proactive steps taken before an incident occurs, like planning and training.
Incident Handling and Response
Detecting and confirming a security incident and its scope.
Incident Handling and Response
Limiting the damage and preventing the spread of an incident.
Incident Handling and Response
Removing the root cause of an incident and all malicious components.
Incident Handling and Response
Restoring affected systems and services to normal, secure operation.
Incident Handling and Response
Post-incident review to identify improvements for future incident response.
Incident Handling and Response
P-I-C-E-R-L: 'Please Identify Criminals, Eradicate, Recover, Learn!'
Incident Handling and Response
The exam expects you to know the exact order and purpose of each phase in the PICERL model. Pay close attention to the distinct activities performed in each phase.
Incident Handling and Response
Skipping the Preparation phase entirely, leading to chaotic and ineffective responses.
Incident Handling and Response
Moving directly from Identification to Recovery without proper Containment and Eradication, allowing the threat to persist or resurface.
Incident Handling and Response
Neglecting the Lessons Learned phase, which prevents continuous improvement and leaves the organization vulnerable to similar future incidents.
Incident Handling and Response
Captures and analyzes network traffic.
Incident Handling and Response
Systematic collection and analysis of digital evidence.
Incident Handling and Response
Examines malicious software behavior in a safe environment.
Incident Handling and Response
Information about current and emerging threats.
Incident Handling and Response
Identifies security weaknesses in systems or networks.
Incident Handling and Response
Creates copies of data for recovery after loss.
Incident Handling and Response
To remember the key tools and their functions, think 'S.E.C.U.R.E.': SIEM for Seeing events, EDR for Endpoint response, Communication tools for Unity, Recovery systems for Restoring, and Evidence tools for Examining.
Incident Handling and Response
The exam expects you to differentiate between the primary purpose of various tools (e.g., SIEM for detection/analysis, EDR for containment/response, backup for recovery). Keywords like 'log correlation,' 'endpoint isolation,' or 'evidence preservation' often point to specific tools or techniques.
Incident Handling and Response
Confusing the purpose of IDS/IPS (detection/prevention) with EDR (detection/response/containment on endpoints).
Incident Handling and Response
Underestimating the importance of communication and documentation tools; they are as critical as technical tools.
Incident Handling and Response
Failing to understand that tools are only effective when combined with proper techniques and skilled personnel.
Incident Handling and Response
Review of an incident to understand its cause and handling.
Incident Handling and Response
Formal process to identify successes, failures, and improvements.
Incident Handling and Response
Detailed document summarizing an incident, its impact, and resolution.
Incident Handling and Response
Process to identify the fundamental reason for an incident.
Incident Handling and Response
Formal declaration that an incident's response activities are complete.
Incident Handling and Response
After an incident, remember the 3 D's: Document, Discuss, Develop (improvements).
Incident Handling and Response
The exam expects you to know the purpose and key activities of the post-incident phase, including documentation, 'lessons learned' reviews, and how findings lead to policy updates. Look for keywords like 'root cause', 'documentation', 'improvement', and 'prevention'.
Incident Handling and Response
Skipping the 'lessons learned' meeting due to time constraints.
Incident Handling and Response
Failing to document all aspects of the incident thoroughly.
Incident Handling and Response
Not implementing the recommendations from the post-incident review.
Incident Handling and Response
Blaming individuals instead of focusing on process and system improvements.
Incident Handling and Response