Cisco CyberOps Associate (CBROPS) 200-201 flashcards
179 free flashcards. Tap a card to flip it.
Integrity (CIA Triad)
Flip cardThe security principle that ensures data and systems are protected from unauthorized modification or destruction, and that data is accurate, consistent, and trustworthy.
- Prevents tampering and unauthorized changes.
- Maintained through access controls, hashing, digital signatures.
- Aims for accuracy and completeness of data.
Memory trick: Confidentiality: Keep secrets. Integrity: Keep things true. Availability: Keep things working.
Incident Response Lifecycle (NIST)
Flip cardA structured approach to managing the aftermath of a security breach or cyberattack, typically involving phases like preparation, detection, containment, eradication, recovery, and post-incident analysis.
- Developed by NIST (National Institute of Standards and Technology).
- Provides a systematic framework for handling security incidents.
- Aims to minimize damage and recovery time.
- Includes proactive and reactive stages.
Memory trick: IR is a cycle: Prepare, Detect, Contain, Eradicate, Recover, then learn.
DNS Amplification Attack
Flip cardA DNS amplification attack is a type of Distributed Denial of Service (DDoS) attack that uses public DNS servers to overwhelm a target server with a large volume of UDP traffic.
- Attackers send small DNS queries with a spoofed source IP (the target's IP) to many open DNS resolvers.
- The DNS resolvers respond with much larger replies to the spoofed IP, amplifying the attack traffic.
- Often uses internal compromised machines or botnets to initiate the spoofed queries.
Memory trick: DDoS: Flooding the Network with Unwanted Traffic.
Patch Management Failure
Flip cardA breakdown in the process of acquiring, testing, and applying software updates (patches) to systems, leading to unpatched vulnerabilities.
- Can result from poor planning, insufficient resources, or technical issues.
- Increases exposure to known exploits.
- Often a compliance issue.
Memory trick: Missing the patch deadline is like a 'broken clock' for security updates.
Incident Response - Containment
Flip cardThe phase in incident response aimed at stopping the spread of an incident, preventing further damage, and isolating affected systems.
- Immediate action after detection and analysis.
- Goal is to limit the scope and impact of the breach.
- Methods include network segmentation, system shutdown, or service disabling.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Learn – that’s the IR journey!
Resource Hogging Malware
Flip cardResource hogging malware is malicious software designed to consume excessive system resources (CPU, memory, disk I/O, network bandwidth), leading to severe performance degradation or system crashes.
- Symptoms: high CPU/memory usage, slow system, unresponsiveness.
- Often associated with cryptocurrency miners (cryptojacking).
- Can also be used for self-DoS or to mask other activities.
- Detection via process monitoring, resource utilization tools.
Memory trick: Resource anomalies are like your computer suddenly 'running a marathon' with no warning.
Homomorphic Encryption
Flip cardAn advanced form of encryption that allows computation to be performed on ciphertext, generating an encrypted result which, when decrypted, matches the result of operations performed on the plaintext. This enables data to remain encrypted even while being processed or analyzed.
- Enables computation on encrypted data.
- Data remains encrypted 'in use'.
- Crucial for privacy in cloud computing.
- Still computationally intensive.
Memory trick: Homomorphic encryption is like a magic box where you can work on things without opening it.
Confidentiality
Flip cardThe security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.
- Prevents unauthorized disclosure.
- Achieved through encryption, access control, authentication.
- Part of the 'CIA Triad' (Confidentiality, Integrity, Availability).
Memory trick: CIA: Confidentiality is keeping secrets, Integrity is keeping it true, Availability is keeping it there.
User Education
Flip cardThe security principle focused on training and informing individuals about security policies, best practices, and common threats to enhance their role in an organization's security posture.
- Crucial for mitigating social engineering attacks.
- Includes training on phishing, password hygiene, and policy adherence.
- Empowers employees as a first line of defense.
Memory trick: People are the Pillars of Protection.
IP Fragmentation Attack
Flip cardAn IP fragmentation attack is a type of Denial-of-Service (DoS) attack that exploits the IP fragmentation and reassembly process by sending a large number of overlapping, malformed, or oversized IP fragments to a target.
- Aims to exhaust target's reassembly buffer or cause crashes.
- Examples include Teardrop and Ping of Death attacks.
- Characterized by fragmented IP packets with unusual offsets.
- Detection involves monitoring for high volumes of fragments and malformed packets.
Memory trick: DoS attacks are like trying to overwhelm a bridge with too many cars, some are subtle, some are outright floods.
Penetration Testing
Flip cardA simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.
- Actively exploits vulnerabilities.
- Provides a real-world perspective of an attacker.
- Requires explicit authorization (Rules of Engagement).
Memory trick: Penetration testing is like a 'practice attack' to find true weaknesses.
Compensating Controls
Flip cardSecurity measures that reduce the risk of a vulnerability when it is not feasible or desirable to eliminate the vulnerability itself.
- Mitigate risk, don't remove the vulnerability.
- Must be documented and regularly reviewed.
- Often used for legacy systems or specific operational needs.
Memory trick: Compensating controls are like a 'safety net' for unavoidable risks.
Policy Non-Compliance (Patch Management)
Flip cardA situation where an organization fails to adhere to its defined patch management policies and procedures, often leading to increased exposure to known security vulnerabilities.
- Indicates a gap between policy and practice.
- Significantly increases organizational risk.
- Can result in audit findings and regulatory penalties.
Memory trick: Policy says 'A', practice does 'B', risk is high for all to see.
Behavioral Analysis
Flip cardA security monitoring technique that establishes a baseline of normal system or user activity and then identifies deviations or anomalies that may indicate malicious activity.
- Focuses on patterns and deviations.
- Uses machine learning and statistical methods.
- Effective at detecting unknown or zero-day threats.
- Requires extensive data collection (processes, network, files).
Memory trick: Monitoring is watching, and behavioral analysis watches how things act.
Lateral Movement via SMB
Flip cardA common technique used by attackers and malware (especially worms and ransomware) to spread from one compromised system to other systems within the same network, often leveraging SMB (Server Message Block) for file sharing and remote execution.
- Relies on SMB vulnerabilities or weak/reused credentials.
- Often seen as unusual outbound SMB from a compromised host.
- Enables rapid propagation across Windows environments.
Memory trick: Malware spreads like a virus, finding new hosts to infect.
Polymorphic Malware
Flip cardMalware that changes its underlying code or signature (e.g., file hash, encryption key, instruction order) each time it replicates or executes, while maintaining its original function. This technique is used to evade detection by signature-based antivirus software and intrusion detection systems.
- Constantly changes its signature.
- Evades signature-based detection.
- Relies on a mutation engine.
- Core functionality remains the same.
Memory trick: Polymorphic malware is like a chameleon, always changing its skin.
Log Filtering/Aggregation
Flip cardThe process of reducing the volume of log data by removing irrelevant entries or combining similar entries before they are ingested by a SIEM.
- Done at the log source or an intermediate collector.
- Improves SIEM performance and reduces storage costs.
- Ensures only relevant data is processed for security analysis.
Memory trick: To make SIEM swift and smart, filter early, play your part!
Rootkit Characteristics
Flip cardA rootkit is a collection of malicious software designed to enable access to a computer or an area of its software that is not otherwise allowed and often masks its existence or the existence of other malware.
- Hides processes, files, network connections, and registry keys.
- Modifies core OS components or kernel modules.
- Subverts standard system utilities (e.g., 'ls', 'ps') to provide false information.
- Difficult to detect and remove, often requiring specialized tools or OS reinstallation.
Memory trick: Malware types are like different criminal roles, each with a specific modus operandi.
Network Flow Data Analysis
Flip cardThe process of collecting, storing, and analyzing network flow records (like NetFlow, IPFIX, sFlow) to gain insights into network traffic patterns, identify anomalies, detect security threats (e.g., C2 communication, data exfiltration), and perform network forensics.
- Provides metadata about network conversations (who, what, where, when, how much).
- Does not typically include packet payload content.
- Crucial for detecting C2, lateral movement, and unusual outbound traffic.
Memory trick: Flow data is like looking at the 'who, what, and where' of network conversations, not the actual words.
False Positive (Vulnerability Scan)
Flip cardA vulnerability scan result that indicates a security flaw when, in reality, no such flaw exists in the target system or is not exploitable in that specific context.
- Can waste time and resources in remediation efforts.
- Often due to incomplete scanner knowledge or environmental factors.
- Requires manual validation to differentiate from true positives.
Memory trick: Positive means found, False means wrong.
Command and Control (C2) Traffic
Flip cardCommunication between compromised systems (bots) and an attacker's C2 server, used for issuing commands, receiving updates, and exfiltrating data.
- Often uses common ports (80, 443, 53) to blend with legitimate traffic.
- Can be detected by unusual volume, destination patterns, or protocol anomalies.
- A key indicator of an active compromise.
Memory trick: When traffic acts strange, danger's in range!
Process Masquerading
Flip cardA technique used by malware to hide its presence by naming its executable or process after a legitimate system process, often placing it in an unusual directory, to evade detection.
- Malware uses legitimate process names (e.g., svchost.exe, explorer.exe).
- Executables are often unsigned or have invalid signatures.
- Files are typically found in non-standard system directories.
Memory trick: Look for the fake ID, not just the face, in the wrong place.
Memory Forensics
Flip cardThe process of analyzing a computer's volatile memory (RAM) to identify and extract artifacts of malicious activity or system state.
- Captures running processes, open network connections, loaded modules, and user activity.
- Crucial for detecting fileless malware or sophisticated attacks that reside only in memory.
- Tools like Volatility Framework are commonly used.
Memory trick: Host forensics: Where the digital clues are found on the machine itself!
Credentialed Scan
Flip cardA vulnerability scan performed with authenticated access to target systems, allowing for deeper and more accurate vulnerability identification.
- Provides a more thorough assessment than uncredentialed scans.
- Can uncover misconfigurations and patch levels not visible externally.
- Requires valid login credentials for target systems.
Memory trick: Credentialed scans are like 'unlocking the door' to see inside.
Governance, Risk, and Compliance (GRC)
Flip cardA comprehensive approach to managing an organization's overall governance, enterprise risk management, and compliance with regulations.
- Integrates various aspects of organizational management.
- Helps achieve objectives while managing risks and adhering to laws.
- Critical for complex regulatory environments.
Memory trick: GRC: The company's 'GPS' for laws, risks, and good practice.
Regular Expressions (Regex) for Log Analysis
Flip cardA sequence of characters that defines a search pattern, primarily for use in pattern matching with strings, or string searching and 'find and replace' operations. Essential for parsing and filtering unstructured log data.
- Powerful for complex pattern matching in text.
- Used to extract specific fields or identify particular event types.
- Common in SIEMs, scripting, and command-line tools (e.g., grep).
Memory trick: To find the right needle in the haystack, you need a precise magnet.
Password Spraying
Flip cardAn attack technique where a threat actor attempts a small number of common passwords against a large list of user accounts to avoid account lockout policies, rather than repeatedly trying many passwords against a single account.
- Targets many usernames with a few common passwords.
- Designed to evade account lockout thresholds.
- Often uses common defaults like 'Password1!' or 'Summer2023'.
Memory trick: Spray paints many targets with one color, while brute force hammers one target with many tools.
Process Hollowing
Flip cardA stealthy malware injection technique where a legitimate process is created in a suspended state, its memory is unmapped, malicious code is written into its place, and the process is then resumed.
- Allows malware to run under the identity of a trusted process.
- Evades traditional signature-based detection.
- Often involves modifying the legitimate process's entry point.
Memory trick: Malware hides on the host, playing tricks to avoid being lost!
Nmap Scripting Engine (NSE)
Flip cardA powerful feature of the Nmap network scanner that allows users to write and share scripts to automate a wide variety of networking tasks, including network discovery, vulnerability detection, and exploitation.
- Extends Nmap's capabilities beyond port scanning.
- Scripts can detect vulnerabilities, enumerate services, or even exploit weaknesses.
- Often leaves 'Nmap Scripting Engine' in User-Agent or other headers.
Memory trick: The User-Agent is like a name tag, revealing who's knocking.
Vulnerability Scanning
Flip cardAn automated process of identifying security weaknesses and misconfigurations in a network, system, or application using specialized software.
- Automated and scalable.
- Identifies known vulnerabilities.
- Less expensive than manual testing.
Memory trick: Start smart, scan for quick wins.
Vulnerability Remediation
Flip cardThe process of eliminating or reducing the risk posed by a vulnerability.
- Often involves applying patches or configuration changes.
- Prioritization is crucial based on risk.
- Verification after remediation is essential.
Memory trick: Patching outdated software is like putting a fresh bandage on a wound, upgrading its defenses.
GDPR: Integrity and Confidentiality
Flip cardOne of the seven key principles of the General Data Protection Regulation (GDPR), which mandates that personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
- Focuses on data security.
- Protects against unauthorized access, loss, destruction.
- Requires technical and organizational measures.
- Article 5(1)(f) of GDPR.
Memory trick: GDPR principles are like the 7 commandments for data.
SQL Injection Analysis
Flip cardThe process of examining web server and application logs to identify and confirm attempts to exploit SQL injection vulnerabilities.
- Look for SQL keywords (e.g., UNION, SELECT, OR, AND) in URL parameters or POST data.
- Analyze HTTP response codes for unusual errors or data leakage.
- Correlate with database logs for unauthorized queries.
Memory trick: To confirm an attack, look at the host's track!
Confidentiality (CIA Triad)
Flip cardThe principle of the CIA triad that ensures that sensitive information is kept secret and is only accessible to authorized individuals or systems. It protects against unauthorized disclosure of information.
- Protects privacy and secrecy.
- Achieved through encryption, access control, data classification.
- Compromised by data breaches, unauthorized access, eavesdropping.
Memory trick: CIA: Confidentiality (secrets), Integrity (truth), Availability (always there).
White-box Scan
Flip cardA vulnerability scan performed with full knowledge of the target system's internal structure, configuration, and often, administrator-level credentials.
- Provides the most comprehensive view of vulnerabilities.
- Requires credentials for deeper inspection.
- Identifies misconfigurations and patch deficiencies.
Memory trick: Box colors show how much you know.
TCP Connect Scan
Flip cardA type of port scan that attempts to complete the full TCP three-way handshake with each probed port on a target system.
- Also known as a 'Full Connect Scan'.
- Most detectable type of scan as it leaves full connection records in logs.
- Used when stealth is not a primary concern or when a SYN scan is blocked.
Memory trick: Scans reveal open doors, some loud, some quiet, some just explore!
User and Entity Behavior Analytics (UEBA)
Flip cardUEBA is a cybersecurity process that leverages machine learning and statistical analysis to detect anomalous activities by users and other entities (e.g., hosts, applications) that may indicate a security threat.
- Establishes a baseline of normal behavior.
- Detects deviations from this baseline (e.g., unusual login times, data access patterns).
- Effective for insider threat detection and compromised accounts.
- Requires continuous data collection and sophisticated algorithms.
Memory trick: SIEM analysis techniques are like different lenses to view your security data.
Penetration Test Scope Limitations
Flip cardExplicit rules and boundaries defined in the 'Rules of Engagement' for a penetration test, outlining what is and is not permitted, often including restrictions on exploitation impact.
- Crucial for ethical and legal compliance.
- Must be strictly adhered to by testers.
- Often includes 'no disruption' or 'no data modification' clauses for critical systems.
Memory trick: Scope is king, avoid the fling.
Impossible Travel Detection
Flip cardA security monitoring technique, often implemented in SIEMs or UEBA systems, that detects suspicious user activity where a user account is accessed from two geographically distant locations within an impossibly short time frame, indicating compromised credentials.
- Compares login/access locations and timestamps.
- Requires baseline understanding of user login patterns.
- Strong indicator of compromised credentials or account takeover.
Memory trick: A user can't be in two places at once, if they are, someone else is moving.
GDPR Storage Limitation
Flip cardA principle under GDPR requiring personal data to be kept for no longer than is necessary for the purposes for which it is processed.
- Requires defining clear data retention periods.
- Mandates deletion or anonymization of data past its retention period.
- Reduces the risk of data breaches and non-compliance.
Memory trick: Lawfulness, Fairness, Transparency, Purpose, Minimization, Accuracy, Storage, Integrity, Accountability.
Wireshark Follow TCP Stream
Flip cardThe 'Follow TCP Stream' feature in Wireshark allows an analyst to select a packet within a TCP conversation and then view all related packets in that specific session, often reconstructing the application-layer data exchanged.
- Filters all packets for a single TCP session
- Reconstructs the conversation content
- Useful for understanding full data flows
- Accessible via right-click on a TCP packet
Memory trick: Wireshark's 'Stream Follow' is like a detective tracing a single conversation through a crowd.
Business Continuity Planning (BCP)
Flip cardThe process of creating systems of prevention and recovery to deal with potential threats to a company. It ensures that personnel and assets are protected and are able to function quickly in the event of a disaster.
- Focuses on keeping business functions operational during disruptions.
- Includes disaster recovery as a critical component.
- Aims to minimize downtime and data loss.
Memory trick: Resilience is built on a strong plan to bounce back.
IPS Inline Deployment
Flip cardAn Intrusion Prevention System (IPS) deployed in inline mode sits directly in the path of network traffic, actively inspecting and enforcing security policies. It can block or modify malicious traffic in real-time.
- Traffic flows directly through the IPS
- Can block or alter malicious traffic
- Introduces a single point of failure
- Can add latency to network communications
Memory trick: IPS deployments are either 'In-Line' for active blocking or 'Passive' for alerts.
Security Awareness Training
Flip cardPrograms designed to educate employees about cybersecurity threats, organizational policies, and best practices to protect sensitive information and systems.
- Aims to change user behavior to be more security-conscious.
- Covers topics like phishing, malware, password hygiene.
- Is a continuous process, not a one-time event.
Memory trick: Training builds a smart shield against digital dangers.
Botnet C2 Communication
Flip cardThe communication channel between a botnet's command and control (C2) server and its compromised 'bot' clients, often characterized by persistent, low-volume, periodic traffic to suspicious or dynamically generated domains.
- Uses various protocols (HTTP, DNS, IRC)
- Often employs Domain Generation Algorithms (DGAs)
- Periodically 'phones home' for instructions
Memory trick: Bots Talk Quietly, Regularly, Randomly to Control.
Incident Response Maturity
Flip cardThe level of an organization's capability to effectively and efficiently detect, analyze, contain, eradicate, and recover from security incidents.
- Ranges from ad-hoc (low maturity) to optimized (high maturity).
- Characterized by documented plans, skilled teams, and regular practice.
- Assessed using frameworks like CMMI or NIST's IR maturity model.
Memory trick: Maturity shows how well we DO, PLAN, and ADAPT.
Buffer Overflow
Flip cardA condition where a program attempts to write data beyond the boundaries of a fixed-length buffer, overwriting adjacent memory locations.
- Can lead to crashes (DoS) or arbitrary code execution.
- Often exploited by overwriting the return address on the stack.
- Common in languages like C and C++ due to manual memory management.
Memory trick: Memory corruption is like a brain short-circuit.
Security Policy Enforcement
Flip cardThe process of ensuring that security policies are consistently followed through technical controls, administrative procedures, and monitoring mechanisms.
- Involves using tools (e.g., DLP, firewalls) and processes (e.g., audits) to uphold policy rules.
- Crucial for a policy's effectiveness beyond mere documentation.
- Can involve automated checks or manual oversight.
Memory trick: Policies need D.I.E.R.: Develop, Implement, Enforce, Review.
Network Tap
Flip cardA hardware device that intercepts and copies network traffic passing between two points, providing a duplicate stream for monitoring and analysis without introducing delay or affecting the original traffic flow.
- Passive monitoring device
- No impact on network performance
- Essential for full-duplex traffic capture
Memory trick: Passive Monitoring: Tap for Hardware, SPAN for Software.
ARP Spoofing/Poisoning
Flip cardARP spoofing (or ARP poisoning) is a type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network. This results in the attacker's MAC address being linked to the IP address of a legitimate computer or server on the network.
- Manipulates ARP tables on hosts/switches
- Attacker sends forged ARP replies
- Associates attacker's MAC with another IP
- Enables Man-in-the-Middle (MitM) attacks or DoS
Memory trick: Layer 2 attacks are 'Sneaky Tricks' on the local network links.
HTTP Flood (DoS)
Flip cardA type of Denial of Service (DoS) attack that targets web servers by sending a high volume of seemingly legitimate HTTP GET or POST requests, aiming to consume server resources and make it unavailable to legitimate users.
- Operates at the application layer (Layer 7).
- Can be difficult to distinguish from legitimate traffic due to well-formed requests.
- Often uses large POST bodies, slow requests (Slowloris), or complex query parameters.
Memory trick: App layer DoS attacks make websites stop working.
Least Privilege Principle
Flip cardThe practice of granting users only the minimum necessary access rights to perform their job functions, thereby reducing the attack surface and potential damage from a compromise.
- Crucial for access control and authorization.
- Requires regular review and adjustment of permissions.
- Helps prevent insider threats and lateral movement by attackers.
Memory trick: Oversight in access means keys are given out too freely.
Security Awareness Program Effectiveness Metrics
Flip cardQuantifiable measures used to evaluate how well a security awareness program achieves its goals, particularly in changing employee behavior.
- Focus on behavioral changes, not just knowledge acquisition.
- Examples include phishing click rates, incident reporting rates, policy compliance.
- Baseline measurements are crucial for demonstrating improvement.
Memory trick: Measure Behavior, Not Just Knowledge.
Security Procedure
Flip cardA detailed, step-by-step instruction set for performing specific security-related tasks or actions.
- Explains 'how' to implement policies and standards.
- Highly specific and often role-based.
- Ensures consistency and repeatability of security operations.
Memory trick: Policies are high, Procedures are low, Standards are in between, Guidelines just flow.
PSH Flag Abuse (C2)
Flip cardMalware can abuse the TCP PSH (Push) flag to force immediate delivery of small data segments to a command-and-control (C2) server, bypassing buffering delays. This allows for rapid, low-latency communication, which can be harder to detect than larger, more sustained data transfers.
- TCP PSH flag forces immediate data delivery
- Abused by malware for rapid C2 communication
- Often seen with small payloads to C2 servers
- Helps malware minimize connection duration and evade detection
Memory trick: TCP Flags are like 'Traffic Signals', and malware often runs a red light (PSH) to speed past.
Preventative Security Control
Flip cardA security control designed to prevent unauthorized or undesirable actions from occurring.
- Aims to stop incidents before they start.
- Examples include firewalls, access controls, encryption.
- Effectiveness depends on proper implementation and enforcement.
Memory trick: Prevent, Detect, Correct, Deter, Compensate.
Nmap SYN Scan (-sS)
Flip cardA type of port scan (also known as half-open or stealth scan) where the scanner sends a SYN packet and waits for a SYN-ACK (port open) or RST (port closed) reply, without completing the TCP three-way handshake.
- Less noisy than a full TCP connect scan as it doesn't complete the handshake.
- Requires raw packet privileges.
- A SYN-ACK indicates an open port, RST indicates a closed port.
Memory trick: TCP scans knock on doors differently to see if anyone's home.
Domain Generation Algorithm (DGA)
Flip cardAn algorithm used by malware to generate a large number of potential domain names that can be used for command and control (C2) communication.
- Helps malware evade blacklisting by constantly changing C2 domains.
- Often generates domains that appear random or nonsensical.
- Requires the attacker to pre-register some of the generated domains to establish communication.
Memory trick: Malware uses tricks to hide its control center.
Malware Beaconing
Flip cardA technique used by malware where a compromised host periodically sends small, often encrypted, communication packets to its command and control (C2) server.
- Indicates the host is still active and connected to the C2.
- Characterized by regular, fixed intervals and low data volume.
- Often uses common ports (e.g., 80, 443) or DNS to blend in.
Memory trick: Malware calls home like a robot checking in.
Procedure Development
Flip cardThe process of creating detailed, step-by-step instructions that guide individuals or systems in performing a specific task or process in a consistent and secure manner.
- Translates high-level policies into actionable steps.
- Ensures consistency and reduces errors.
- Requires technical expertise for implementation details.
Memory trick: Policy is the goal, procedure is the map to get there.