CompTIA CySA+ (CS0-003) flashcards
190 free flashcards. Tap a card to flip it.
Credential Stuffing
Flip cardAn attack that uses large sets of previously breached username:password pairs against a login portal, relying on password reuse across sites to gain unauthorized access.
- Each username is typically tried with its known specific password, not many guesses
- High volume of distinct accounts attempted, low attempts per account
- Mitigated with MFA, breach password screening, and rate limiting
Memory trick: 'Stuffing shoves stolen key-lock pairs into every door until one fits.'
STIX/TAXII
Flip cardSTIX is a standardized language for representing cyber threat intelligence; TAXII is the protocol used to exchange STIX data between organizations automatically.
- STIX = data format (JSON-based)
- TAXII = transport protocol (REST API-based)
- Enables automated, machine-to-machine threat intel sharing
Memory trick: STIX writes the letter, TAXII delivers the mail.
Mean Time To Recover (MTTR)
Flip cardThe average time it takes to fully restore systems, applications, and services to normal operating conditions after a failure or incident.
- Crucial for business continuity and disaster recovery.
- Lower MTTR indicates effective recovery processes and resources.
- Often a key metric in incident response reporting to management.
Memory trick: Recovery is all about 'Getting Back to Business, Fast'.
Least Privilege Metric
Flip cardA quantitative measure used to assess the extent to which user and system accounts are granted only the minimum necessary permissions to perform their authorized functions.
- Reduces the attack surface.
- Limits potential damage from compromised accounts.
- Often tracked by auditing administrative access levels.
Memory trick: Least privilege: count who has MORE, not who's trying to get in.
SOC Alert Quality Metrics
Flip cardMetrics that assess the accuracy and relevance of security alerts generated by monitoring systems, crucial for SOC efficiency and avoiding alert fatigue.
- Includes false positive rates and true positive rates.
- Helps justify SIEM tuning and rule refinement.
- Directly impacts analyst workload and ability to detect real threats.
Memory trick: More alerts, same acknowledge time? Are these alerts even REAL?
Recovery Phase
Flip cardThe incident response phase focused on restoring affected systems and services to normal operation, ensuring they are clean, hardened, and ready for production.
- Occurs after containment and eradication.
- Includes restoring data, patching, and hardening systems.
- Aims to return to business as usual securely.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-act.
NIST CSF Protect Function
Flip cardThe 'Protect' function of the NIST Cybersecurity Framework outlines safeguards to ensure the delivery of critical infrastructure services, encompassing identity management, access control, data security, and protective technology.
- Focuses on preventing cybersecurity incidents.
- Includes access control, awareness training, data security, information protection processes, and maintenance.
- PAM solutions directly contribute to access control and data security within this function.
Memory trick: I Protect, Detect, Respond, and Recover from cyber threats.
SOAR Automation vs Orchestration
Flip cardOrchestration coordinates multiple tools/data sources into a unified workflow, while automation executes tasks within that workflow without human intervention.
- Orchestration = connecting tools together (integration layer)
- Automation = machine-executed actions with no analyst input
- Playbooks often combine both concepts in a single response
Memory trick: Orchestration connects the band; Automation plays the song without a conductor.
SYN Flood
Flip cardA DoS attack that sends a high volume of SYN packets without completing the TCP three-way handshake, exhausting server connection state tables.
- Half-open connections consume server resources
- Identified by many SYN/SYN-ACK with few final ACKs
- Mitigated with SYN cookies and rate limiting
Memory trick: Flood of SYNs, drought of ACKs = SYN flood.
CVSS Environmental Metrics
Flip cardOptional CVSS metrics (Modified Base metrics plus Security Requirements: CR, IR, AR) that let organizations tailor the score to reflect the criticality of the affected asset.
- Can raise or lower the Base Score
- CR/IR/AR = Confidentiality/Integrity/Availability Requirement
- Produces the Environmental Score used for internal risk-based prioritization
Memory trick: Base is generic, Temporal ages it, Environmental makes it personal.
Masquerading (Defense Evasion)
Flip cardA defense evasion technique where an adversary renames or relocates legitimate system utilities or uses legitimate process names for malicious executables to avoid detection.
- Relies on blending in with normal system activity.
- Often involves common system processes (e.g., svchost.exe, explorer.exe).
- Indicators include unusual paths or parent processes for legitimate-looking executables.
Memory trick: Attackers hide by looking normal or changing behavior.
SQL Injection
Flip cardSQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database. This can enable the attacker to view, modify, or delete data, execute administrative operations, or recover the contents of any file present on the database server.
- Exploits improper input validation in web applications.
- Uses SQL keywords (e.g., UNION, SELECT, AND) in user input.
- Can lead to data compromise, unauthorized access, or remote code execution.
Memory trick: Web app attacks target the weakest links in the chain.
DNS Tunneling
Flip cardA covert channel technique that encodes data within DNS queries/responses (often as subdomain labels) to exfiltrate data or establish C2 while evading traditional network filters.
- Often uses TXT, NULL, or CNAME record types
- Subdomains appear random/high-entropy (base32/hex encoded)
- High query volume to a single domain is a key indicator
Memory trick: DNS tunneling = smuggling data through the mail system nobody inspects.
MITRE ATT&CK: Persistence
Flip cardA tactic covering techniques adversaries use to maintain access to systems across restarts, credential changes, and other interruptions, such as Registry Run keys, scheduled tasks, or startup folder entries.
- T1547.001: Registry Run Keys / Startup Folder is a common sub-technique
- Persistence ensures malware survives reboot or logoff
- Detected via monitoring Registry/startup location changes
Memory trick: Run key = a sticky note that reminds Windows to relaunch the malware every morning.
X-Forwarded-For Header Abuse
Flip cardThe `X-Forwarded-For` (XFF) HTTP header identifies the originating IP address of a client connecting to a web server through an HTTP proxy or load balancer. If not properly validated, attackers can manipulate this header to bypass IP-based access controls, poison web caches, or impersonate other users.
- Indicates client's original IP when behind a proxy.
- Manipulating it can bypass IP-based security controls.
- Requires proper validation by the application or proxy.
Memory trick: Headers are like the envelope information for web requests.
CVSS Qualitative Severity Rating
Flip cardCVSS v3.1 maps numeric base scores to five qualitative labels used for reporting and prioritization.
- None = 0.0
- Low = 0.1–3.9, Medium = 4.0–6.9
- High = 7.0–8.9, Critical = 9.0–10.0
Memory trick: None-Low-Med-High-Crit climbs like a ladder toward 10
Post-Incident Review (Lessons Learned)
Flip cardA critical phase in incident response where the team analyzes the incident, evaluates the effectiveness of the response, and identifies areas for improvement.
- Focuses on 'lessons learned'.
- Aims to improve future incident response capabilities.
- Results in updates to plans, policies, and procedures.
Memory trick: Review, Refine, Relearn
SQL Injection (SQLi)
Flip cardA code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.
- Exploits vulnerabilities in database interaction.
- Can lead to data theft, data manipulation, or system compromise.
- Often uses keywords like UNION, SELECT, OR, AND, etc.
Memory trick: Log entries reveal the attacker's intent, like a detective reading a criminal's notes.
SOAR Playbook
Flip cardA predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes a sequence of investigation and remediation actions in response to a trigger.
- Reduces MTTR by removing manual repetitive steps
- Combines orchestration (integrating tools) with automation (executing actions)
- Common use cases: phishing triage, malware containment, account lockout
Memory trick: SOAR = the robot that reads, checks, and locks the door itself.
KPI Reporting for Executives
Flip cardCommunicating key performance indicators to executive leadership in a clear, concise, and actionable manner, focusing on trends, impact, and proposed solutions.
- Use visualizations for trends.
- Provide context and analysis.
- Offer actionable recommendations.
Memory trick: CISO wants trends, reasons, and remedies, not just raw numbers.
Hypothesis-Driven Threat Hunting
Flip cardA proactive hunting methodology where analysts form a testable hypothesis about adversary behavior or detection gaps, then search data sources for evidence supporting or refuting it.
- Often grounded in known TTPs (e.g., MITRE ATT&CK) or intel about detection blind spots
- Differs from IOC-based hunting, which searches for specific known indicators
- Requires iterative refinement as evidence is gathered
Memory trick: Hypothesis-driven = a detective forming a theory first, then hunting for clues to prove it.
Brute-Force Attack
Flip cardAn attack method that involves systematically trying every possible combination of characters or words to guess a password, encryption key, or find a hidden web page.
- Often targets authentication mechanisms.
- Can use dictionaries or generate all possible combinations.
- Indicators include numerous failed login attempts from a single source or to a single account.
Memory trick: Web apps face many attack types; brute-force is about guessing.
Root Cause Remediation (Recovery Phase)
Flip cardThe process of identifying and fixing the fundamental reason for an incident, ensuring that the vulnerability exploited is fully closed before systems are returned to operation.
- Crucial for preventing recurrence.
- Often involves patching, configuration changes, or process improvements.
- Must be confirmed before full system restoration.
Memory trick: Don't just fix the wound, cure the disease before you send the patient home.
PowerShell Obfuscation Indicator
Flip cardMalicious PowerShell often combines Base64-encoded commands (-EncodedCommand), hidden windows, and network download cradles to evade detection while retrieving/executing payloads.
- -Enc/-EncodedCommand obscures the actual command from casual view
- -W Hidden suppresses the console window from the user
- Net.WebClient.DownloadString is a common fileless download technique
Memory trick: Encoded + Hidden + Download = a masked burglar sneaking in through a hidden window.
Long-Term Containment
Flip cardStrategies implemented to prevent recurrence or further spread of an incident over an extended period.
- Goes beyond immediate isolation.
- Often involves policy changes, new security controls.
- Aims to address root causes.
Memory trick: Short-term is 'Block and Isolate', Long-term is 'Build a Wall' (DLP, NAC, Segmentation).
Board-Level Security KPIs
Flip cardHigh-level metrics that demonstrate the overall effectiveness of the security program and the value of security investments to the Board of Directors.
- Focus on risk reduction, strategic impact, and program maturity.
- Avoid excessive technical detail.
- Examples include incident response times, compliance status, and overall risk posture.
Memory trick: The BOARD wants big picture, fast response, and secure investments.
HTTP/HTTPS Tunneling
Flip cardA technique where non-HTTP/S traffic or data is encapsulated within HTTP/HTTPS requests and responses to bypass network security controls.
- Bypasses firewalls/proxies by blending with legitimate web traffic.
- Often uses non-standard ports or obfuscated data in headers/payloads.
- Commonly used for C2 communication or data exfiltration.
Memory trick: Data leaves through disguised tunnels.
Admiralty Code
Flip cardA two-part rating system used to evaluate intelligence: a letter (A-F) rates source reliability, and a number (1-6) rates the credibility of the information itself.
- A=Completely reliable through F=Reliability cannot be judged
- 1=Confirmed through 6=Cannot be judged
- Widely used in military and cyber threat intelligence to grade feeds
Memory trick: 'Admiralty grades intel like a report card: letter for source, number for truth.'
Timing-Based Sandbox Evasion
Flip cardA technique where malware measures elapsed execution time (e.g., via GetTickCount or sleep calls) and withholds malicious behavior if the runtime appears too short, suspecting an automated sandbox.
- Sandboxes often have limited analysis windows (seconds to minutes)
- Malware may sleep or check timers to outlast automated analysis
- Extended/dynamic sandbox timeouts help counter this evasion
Memory trick: GetTickCount = malware peeking at its watch before deciding to 'perform.'
Order of Volatility
Flip cardA hierarchy of digital evidence based on how quickly it can be lost or altered, guiding collection priorities.
- Most volatile data collected first.
- RAM is typically the most volatile.
- Disk data is less volatile than RAM.
Memory trick: R-C-N-D: RAM, Cache, Network, Disk. Get the 'Airy' data first!
Business Impact Communication
Flip cardTranslating technical security findings into understandable business risks and consequences for non-technical stakeholders, enabling informed decision-making.
- Focus on financial, reputational, and legal implications.
- Use clear, concise language.
- Tie findings to organizational goals and regulatory compliance.
Memory trick: Management wants to know the BUSINESS hit, not just the tech trick.
Blind SQL Injection
Flip cardBlind SQL Injection (SQLi) is a type of SQL injection where the attacker cannot see the results of their malicious query directly within the application's response. Instead, they infer information by observing the application's behavior (e.g., response times, error messages, or subtle differences in content) to determine if a condition is true or false.
- No direct data retrieval in the response.
- Relies on server behavior (time delays, error messages, boolean logic).
- Includes Boolean-based, Error-based, and Time-based variants.
Memory trick: SQL injection attacks are like secretly talking to the database.
Active Asset Discovery
Flip cardA discovery method that sends probe traffic (ping sweeps, port scans) directly to hosts to identify live systems and services.
- Uses tools like Nmap, Masscan
- Generates network traffic that can be detected by IDS
- More thorough than passive but can disrupt fragile systems like ICS
Memory trick: PAAL: Passive listens, Active probes, Agent installs, Logs correlate.
Technical Communication
Flip cardThe process of conveying complex security details, findings, or recommendations to technical stakeholders to enable informed decision-making and action.
- Requires precision and supporting evidence.
- Should facilitate clear understanding and actionable steps.
- Often uses ticketing systems or formal reports for tracking.
Memory trick: For technical action, use a structured ticket, not just talk.
False Positive
Flip cardA false positive occurs when a scanner reports a vulnerability that does not actually exist on the target system.
- Common with version-banner-based detection
- Backported patches often cause false positives
- Manual verification reduces wasted remediation effort
Memory trick: Positive = flagged, Negative = clear; True = correct, False = wrong
SQL Injection Indicator
Flip cardAn attack technique where malicious SQL syntax is inserted into an input field to manipulate backend database queries.
- UNION SELECT combines results from an injected query
- Trailing -- or # comments out remaining original SQL
- Often targets parameters like id, search, or login fields
Memory trick: UNION SELECT unions the attacker with your data.
ISO 27001 Incident Management Metrics
Flip cardMetrics used to measure an organization's performance in handling information security incidents according to ISO 27001 guidelines.
- Focus on incident detection, response, and resolution.
- Examples include MTTR, incident backlog, and incident recurrence rates.
- Helps demonstrate compliance and continuous improvement.
Memory trick: ISO 27001 is about managing incidents, so measure how fast you RESOLVE them.
Diamond Model of Intrusion Analysis
Flip cardAn analytic framework describing an intrusion event through four core features: Adversary, Capability, Infrastructure, and Victim.
- Adversary = the threat actor/group
- Capability = tools, malware, exploits used
- Infrastructure = IPs, domains, servers used by attacker
- Victim = targeted person, system, or organization
Memory trick: A-C-I-V: Adversary Casts Infrastructure at Victim.
Patch Management System
Flip cardA Patch Management System is a software solution that automates the process of managing and deploying software updates and security patches across an organization's network.
- Streamlines the patching process from discovery to deployment.
- Helps ensure systems are up-to-date with the latest security fixes.
- Often includes features for scheduling, testing, and reporting on patch status.
Memory trick: Patch System: AUTOMATICALLY 'patches' up your security holes.
Diamond Model: Infrastructure
Flip cardOne of the four core Diamond Model features, representing the physical/logical communication resources (domains, IPs, servers) an adversary uses to deliver capabilities.
- Four core features: Adversary, Capability, Infrastructure, Victim
- Infrastructure includes C2 domains, IPs, and relay/proxy servers
- Connects Adversary to Victim in the intrusion event
Memory trick: An Adversary uses Capability over Infrastructure against a Victim — AC-IV, like a diamond's four points
MITRE ATT&CK Framework
Flip cardA globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to categorize and communicate attacker behavior (TTPs).
- Organized into tactics (the 'why') and techniques (the 'how')
- Covers Initial Access, Execution, Persistence, Lateral Movement, etc.
- Widely used for threat hunting, detection engineering, and reporting
Memory trick: ATT&CK = the attacker's 'playbook map' of tactics and techniques.
Static Application Security Testing (SAST)
Flip cardSAST is a white-box testing methodology that analyzes an application's source code, bytecode, or binary code for vulnerabilities without executing the application.
- Identifies flaws early in the Software Development Lifecycle (SDLC).
- Can find issues like injection flaws, hardcoded credentials, and insecure configurations.
- Does not require a running application, making it suitable for developers.
Memory trick: SAST: Static, Analyze Source – looks at the 'static' code, not running 'app'.
Post-Incident Activity
Flip cardThe final phase of incident response focused on improving security posture and response capabilities based on lessons learned from an incident.
- Includes lessons learned meetings.
- Updates incident response plans.
- Aims for continuous improvement.
Memory trick: After the storm, we 'Review' the damage and 'Improve' our defenses.
Microsegmentation
Flip cardA security architecture technique that isolates individual workloads or applications with granular policies to limit lateral movement, even within the same network segment.
- Goes beyond VLAN/subnet-level isolation
- Commonly implemented via software-defined networking (SDN)
- Reduces blast radius of a compromised workload
Memory trick: Micro means each workload gets its own tiny fence.
Executive Stakeholder Communication
Flip cardThe process of informing and engaging senior management and business owners about cybersecurity risks, incidents, and remediation efforts, focusing on business impact and strategic decisions.
- Prioritizes business context over technical jargon.
- Aims to secure resources and approval for security initiatives.
- Essential for managing high-impact risks effectively.
Memory trick: Critical issues need C-level attention for 'Cash and Control'.
Risk-Based Prioritization (KEV Catalog)
Flip cardRemediation prioritization approach that factors in real-world exploitation evidence (e.g., CISA KEV catalog) and asset exposure, not just CVSS severity.
- CISA KEV lists vulnerabilities confirmed to be exploited in the wild
- Internet-facing assets carry higher exposure risk than internal-only assets
- Combines exploitability, exposure, and asset value with CVSS for prioritization
Memory trick: CVSS tells severity; KEV tells reality.
Rogue DHCP Server
Flip cardAn unauthorized device on the network that responds to DHCP requests with its own lease information, often redirecting victims' default gateway or DNS server to attacker-controlled infrastructure.
- Detected by seeing multiple DHCPOFFER from unexpected MAC/switch ports
- Mitigated with DHCP snooping on switches
- Often paired with man-in-the-middle attacks
Memory trick: 'Rogue offers a fake key to your door' - a second, unauthorized DHCPOFFER hands out a bad gateway.
Vulnerability Management KPI (Severity Reduction)
Flip cardA metric that tracks the decrease or increase in the number of vulnerabilities categorized by their severity level over time, indicating the effectiveness of remediation efforts.
- Focuses on risk reduction over absolute numbers.
- Prioritizing 'High' and 'Critical' severity is key for immediate impact.
- A decrease in high-severity vulnerabilities indicates positive progress.
Memory trick: Fewer 'Highs' means 'Good Focus, Getting Better'.
CVSS User Interaction (UI)
Flip cardA CVSS Base metric indicating whether successful exploitation requires action by a user other than the attacker.
- Values: None (N) or Required (R)
- UI:R lowers severity relative to UI:N
- Common in phishing/macro-based attacks
Memory trick: UI:R — the victim must Reach out and click.
Ransomware Recovery Metrics
Flip cardMetrics used to evaluate and improve the organization's ability to restore operations and data after a ransomware attack.
- Focus on recovery time objectives (RTO) and recovery point objectives (RPO).
- MTTR is a key indicator of recovery efficiency.
- Essential for business continuity and resilience.
Memory trick: After ransomware, the goal is to RECOVER and get back to NORMAL operation.
CVSS Scope (S)
Flip cardA CVSS v3.1 base metric indicating whether a vulnerability in one security authority (e.g., a VM, sandbox, or application) can impact resources controlled by a different security authority; values are Unchanged (S:U) or Changed (S:C).
- S:C applies to sandbox/VM escapes, container breakouts, and cross-privilege-domain impacts
- Changing Scope alters the underlying CVSS formula, typically increasing the base score
- Example: identical metrics with S:U vs S:C can shift a score from 8.8 to 9.9
Memory trick: Scope Changed = the fire jumps over the firewall into the neighbor's house.
Eradication & Recovery Strategy
Flip cardThe approach to removing the threat and restoring systems to a trusted, operational state after an incident.
- Full rebuild/restore is often required for deep compromises.
- Must ensure threat is completely removed.
- Prioritizes trusted sources (clean backups).
Memory trick: When the foundation's cracked, rebuild from scratch, don't just patch the walls.
OT/ICS Security Considerations
Flip cardSecurity considerations unique to Operational Technology (OT) and Industrial Control Systems (ICS) environments, prioritizing safety, availability, and integrity of physical processes.
- Safety and availability often outweigh confidentiality.
- Common protocols: Modbus, DNP3, OPC, EtherNet/IP.
- Unauthorized access can lead to physical damage, environmental harm, or loss of life.
Memory trick: ICS attacks prioritize physical harm and control.
Eradication Strategy: Re-imaging
Flip cardA highly effective eradication method involving wiping the compromised system's disk and reinstalling the operating system and applications from trusted sources, ensuring complete removal of malware and backdoors.
- Provides a 'clean slate' for compromised systems.
- Best for deep or persistent infections.
- Requires backups for data restoration.
Memory trick: Eradication is like clearing out a digital infestation completely.
Parameterized Queries
Flip cardParameterized Queries (or Prepared Statements) are a secure coding practice that separates SQL code from user-supplied data, preventing SQL Injection vulnerabilities.
- The SQL statement is defined first, with placeholders for data.
- User input is then bound to these placeholders as data, not as executable code.
- This ensures that special characters in user input are treated as literal values, not as SQL commands.
Memory trick: Prepared Queries: Prepare your statements to prevent SQL 'injections' of bad code.
False Negative (Vulnerability Scanning)
Flip cardA scan result classification where an actual vulnerability exists on the target but the scan fails to detect or report it, often due to scan scope limitations, credential failures, or evasion.
- Common causes: expired/invalid credentials, firewall blocking, scan scope exclusions
- More dangerous than false positives because risk goes unnoticed
- Credentialed scans that silently degrade to unauthenticated mode are a key false-negative risk
Memory trick: Expired password = the scanner peeked through a locked window and missed what's inside.
Risk-Based Vulnerability Prioritization
Flip cardPrioritizing remediation based on exploitability, asset exposure/criticality, and threat intelligence, not just CVSS base score.
- Consider exposure (internet-facing vs isolated)
- Factor in active exploitation (e.g., EPSS, CISA KEV list)
- Asset criticality to business operations matters
Memory trick: Exposed and exploited beats merely scary-scored.
VLAN Segmentation
Flip cardA Virtual Local Area Network logically divides a physical switch into multiple isolated broadcast domains, restricting traffic between groups of devices without requiring separate physical switches.
- VLANs operate at OSI Layer 2 using tagging (802.1Q)
- Inter-VLAN traffic requires a router or Layer 3 switch
- Reduces attack surface by limiting lateral broadcast/ARP traffic
Memory trick: 'V for Virtual walls' - VLAN builds invisible walls inside one switch.
Mean Time To Remediate Vulnerability (MTTR-V)
Flip cardThe average time an organization takes to fix or mitigate a discovered security vulnerability from its identification to full resolution.
- Measures the efficiency of the vulnerability management program.
- Lower MTTR-V indicates a more agile and effective remediation process.
- Often a key metric for compliance frameworks like PCI DSS.
Memory trick: PCI cares about 'Vulnerabilities Fixed, Fast'.
Impossible Travel
Flip cardA security anomaly detection technique that flags suspicious activity when a user account logs in from two geographically disparate locations within a time window that makes physical travel impossible.
- Strong indicator of compromised credentials or account takeover.
- Relies on correlating login events with IP geolocation data.
- Requires accurate time synchronization across logging sources.
Memory trick: Account anomalies show unusual user behavior.