CompTIA CySA+ (CS0-003) flashcards
190 free flashcards. Tap a card to flip it.
Linux User Command History
Flip cardFiles maintained by command-line shells (e.g., Bash, Zsh) that record commands executed by individual users, providing a direct audit trail of user activity.
- Typically stored in a hidden file in the user's home directory (e.g., ~/.bash_history).
- Can be modified or cleared by attackers.
- Crucial for identifying unauthorized user actions.
Memory trick: Bash History Shows User's True Intent
Evidence Integrity
Flip cardEnsuring that digital evidence remains complete, accurate, and unaltered from the moment of collection until its presentation.
- Crucial for admissibility in legal proceedings.
- Verified through cryptographic hashing.
- Part of a robust chain of custody.
Memory trick: Collect, Preserve, Analyze, Present, maintain Chain of Custody and Integrity.
Lessons Learned Report Purpose
Flip cardA section or standalone report following an incident to identify contributing factors, evaluate response effectiveness, and recommend improvements.
- Aims to prevent recurrence of similar incidents.
- Focuses on actionable recommendations.
- Part of continuous security improvement.
Memory trick: Lessons Learned mean 'What's NEXT to make it BETTER?'
Containment
Flip cardThe phase of incident response focused on stopping the incident from spreading and causing further damage.
- Prevents further compromise.
- Limits the scope of the incident.
- Can be short-term or long-term.
Memory trick: Prepare and Detect, then Respond with Containment, Eradication, Recovery, and Post-Incident Review.
Financial Impact Assessment
Flip cardQuantifying the monetary costs associated with a cybersecurity incident, including direct costs (e.g., recovery, legal) and indirect costs (e.g., lost revenue, reputational damage).
- Crucial for executive decision-making.
- Includes both tangible and intangible costs.
- Often involves business continuity and disaster recovery metrics.
Memory trick: For executives, impact means money lost, not just tech details.
NIST CSF Recover Metrics
Flip cardMetrics used to evaluate the effectiveness of an organization's capabilities to restore services and data impaired by a cybersecurity incident.
- Focus on resilience and business continuity.
- Includes recovery time objectives (RTO) and recovery point objectives (RPO).
- MTTR is a key indicator of recovery efficiency.
Memory trick: Recover = Restore, so measure recovery time.
Memory-Safe Languages
Flip cardProgramming languages (e.g., Rust, Go, Java) that enforce automatic bounds checking and memory management, structurally preventing buffer overflow and use-after-free vulnerabilities common in C/C++.
- Eliminates entire vulnerability class rather than patching instances
- Contrasts with manual memory management languages like C/C++
- Recommended by CISA/NSA for high-risk new development
Memory trick: Match the defense to the flaw: memory bugs need memory-safe languages, not filters
Input Validation
Flip cardVerifying that user-supplied data conforms to expected format, type, length, or character set before it is processed.
- Allow-listing is stronger than deny-listing
- Prevents injection, buffer overflow, and malformed data issues
- Should be enforced server-side, not just client-side
Memory trick: Validate in, Encode out, Parameterize queries, Handle errors gracefully.
Evil Twin Attack
Flip cardA wireless attack where a rogue access point impersonates a legitimate AP's SSID, often paired with deauthentication attacks, to lure clients into connecting so traffic can be intercepted.
- Duplicate SSID with different BSSID/MAC
- Deauth frames force clients off the legitimate AP
- Stronger signal encourages client reassociation to rogue AP
Memory trick: Two APs, same name, one is an imposter twin.
Diamond Model: Capability
Flip cardOne of the four core facets of the Diamond Model of Intrusion Analysis, representing the adversary's tools, techniques, and methodologies used to execute an intrusion.
- Includes exploits, malware, custom scripts, and specific attack procedures.
- Answers the question: 'How did the adversary perform the attack?'
- Focuses on the means of the attack.
Memory trick: Adversary, Capability, Infrastructure, Victim – The 'ACIV' of every attack!
Credentialed vs Non-Credentialed Scanning
Flip cardCredentialed scans authenticate to the target to gather detailed patch/config data; non-credentialed scans only see what's visible externally.
- Credentialed scans reduce false positives
- Non-credentialed scans mimic an outside attacker's view
- Credentials must have least-privilege but sufficient read access
Memory trick: Credentials unlock the inside story.
Software Composition Analysis (SCA)
Flip cardSCA identifies and inventories third-party and open-source components within software, matching them against known vulnerability databases (often producing an SBOM).
- Detects vulnerable transitive dependencies
- Often generates a Software Bill of Materials (SBOM)
- Complements SAST/DAST for full application coverage
Memory trick: SCA checks the ingredients label for recalled parts
Linux Package Integrity Check (RPM)
Flip cardA method to verify the integrity of installed software packages on Red Hat-based Linux systems by comparing their current state (including cryptographic hashes) against the original package metadata.
- Uses the 'rpm -Va' command.
- Checks file sizes, permissions, checksums, etc.
- Helps detect unauthorized modification of system binaries.
Memory trick: Packages, Rootkits, Logs
Sysmon
Flip cardSysmon (System Monitor) is a Windows system service and device driver that, once installed on a computer, remains resident across system reboots to monitor and log system activity to the Windows event log. It provides detailed information about process creations, network connections, and changes to file creation time.
- Provides granular visibility into system activities.
- Captures process creation with full command lines.
- Logs network connections, driver loads, and image loads.
Memory trick: Endpoint logs tell the story of what happens inside a machine.
SAST (Static Application Security Testing)
Flip cardSAST analyzes application source code, bytecode, or binaries without executing the program to find security flaws early in development.
- Performed early in SDLC (shift-left)
- Finds issues like hardcoded secrets and insecure API usage
- Complementary to DAST which tests running applications
Memory trick: SAST reads the recipe (code); DAST tastes the dish (running app)
Fileless Malware via Office Macro
Flip cardAn attack technique where a malicious Office document macro spawns PowerShell with encoded/hidden flags to execute payloads in memory, avoiding disk-based detection.
- Office app (WINWORD.EXE/EXCEL.EXE) as parent process of powershell.exe is suspicious
- -enc, -nop, -w hidden flags indicate obfuscation and stealth
- Event ID 4688 logs process creation with command-line auditing enabled
Memory trick: A document that secretly whispers hidden PowerShell commands.
PCI DSS Access Control Metrics
Flip cardMetrics demonstrating compliance with PCI DSS requirements for restricting access to cardholder data and CDE systems.
- Focus on strong authentication, least privilege, and role-based access.
- MFA adoption is a key component.
- Auditing and logging access attempts are also critical.
Memory trick: PCI DSS wants to see that CDE access is locked down with STRONG authentication.
Cyber Kill Chain: Weaponization
Flip cardThe stage where an attacker combines an exploit with a malicious payload to create a deliverable weapon (e.g., malicious document, executable).
- Occurs before Delivery
- Often produces a booby-trapped file (PDF, macro, executable)
- Second phase of Lockheed Martin's Cyber Kill Chain
Memory trick: Recon-Weaponize-Deliver-Exploit-Install-C2-Actions.
Mean Time to Detect (MTTD)
Flip cardAn incident response metric measuring the average time elapsed between when a compromise actually begins and when it is detected by monitoring/alerting systems.
- Calculated as detection time minus actual occurrence time
- Lower MTTD indicates more effective monitoring/detection capability
- Distinct from MTTR (time to respond/resolve after detection)
Memory trick: 'MTTD clocks the sneak-in to the alarm; MTTR clocks the alarm to the all-clear.'
Cyber Kill Chain: Reconnaissance
Flip cardThe first phase of the Lockheed Martin Cyber Kill Chain, where an attacker gathers information about the target such as open ports, exposed files, and personnel details.
- Includes OSINT, scanning, and enumeration
- No payload or exploit is delivered yet
- Precedes Weaponization and Delivery phases
Memory trick: Recon-Weapon-Deliver-Exploit-Install-C2-Act: 'Really Wicked Delivery Exploits Install Control Actions'
Strategic Cybersecurity Metrics
Flip cardKey Performance Indicators (KPIs) that measure the overall effectiveness of a cybersecurity program in meeting organizational objectives, typically presented to executive leadership and boards.
- Focus on business impact, risk posture, and compliance.
- Often expressed in financial terms, percentages of compliance, or high-level risk ratings.
- Used for governance, investment decisions, and long-term planning.
Memory trick: The Board cares about 'Strategy, Success, and Spending'.
Fileless Malware Detection (Memory Forensics)
Flip cardThe process of analyzing memory dumps to identify malware that operates solely in RAM, utilizes legitimate system tools (LOLBins), or injects code into benign processes, thereby avoiding disk-based detection.
- Focuses on runtime behavior and memory artifacts.
- Looks for injected code, suspicious process relationships, and unusual API calls.
- Traditional file-based signatures are often ineffective.
Memory trick: Memory Anomalies Reveal Hidden Ghosts
Ingress Tool Transfer (T1105)
Flip cardIngress Tool Transfer (MITRE ATT&CK T1105) describes the adversary's capability to transfer tools or files from an external system into a compromised environment. This is often done to introduce additional malware, utilities, or scripts required for further attack phases.
- Involves bringing files from outside to inside the network.
- Commonly uses HTTP/HTTPS, FTP, or other protocols.
- Often follows initial access and enables further exploitation or persistence.
Memory trick: Attackers follow a map to reach their treasure.
CVSS v3.1 Base Score
Flip cardA 0-10 score computed from exploitability metrics (AV, AC, PR, UI, S) and impact metrics (C, I, A) to rate vulnerability severity.
- AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = 9.8
- Scope Changed (S:C) can push score to 10.0
- Severity ranges: 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical
Memory trick: No privileges, no interaction, full impact = near-perfect danger score.
CVSS Attack Complexity (AC)
Flip cardA CVSS base metric describing conditions beyond the attacker's control that must be present for successful exploitation; values are Low (reliable) or High (unreliable, depends on external factors).
- AC:L = attacker can expect reliable success without special conditions
- AC:H = success depends on conditions like timing, configuration, or defeating a protection
- Higher complexity lowers the exploitability sub-score and often the base score
Memory trick: Attack Vector = where, Complexity = how hard, Privileges = what you need, UI = who else must click.
YARA Rule
Flip cardA rule-based language used to identify and classify malware samples by matching strings, byte patterns, and structural conditions within files or memory.
- Rules contain strings section and a condition section
- Used by antivirus, EDR, and sandbox tools for classification
- Different purpose from network IDS signatures (Snort/Suricata)
Memory trick: 'YARA hunts inside files, Snort hunts inside packets.'
Organizational Risk Communication
Flip cardThe process of translating technical cybersecurity findings into terms that articulate potential business consequences, such as financial loss, reputational damage, operational disruption, and regulatory penalties.
- Focuses on 'why it matters' to the business.
- Uses metrics like financial impact, regulatory fines, and CIA triad implications.
- Essential for gaining buy-in and resources from business stakeholders.
Memory trick: Beyond 'CVE numbers', focus on 'Cash, Confidentiality, and Compliance'.
IRC-based C2
Flip cardA Command and Control (C2) channel that leverages the Internet Relay Chat (IRC) protocol for communication between attacker and compromised systems (bots).
- Often uses TCP ports 6667, 6697 (SSL), or other non-standard ports.
- Bots join specific IRC channels to receive commands.
- Traffic can be disguised as other protocols to evade detection.
Memory trick: Bots Talk Securely, Discreetly, and Often Irregularly
Passive Asset Discovery
Flip cardIdentifying hosts and services by observing existing network traffic (e.g., via a tap or SPAN port) rather than sending probes.
- Non-intrusive, safe for fragile/OT devices
- Uses tools like Wireshark, Zeek, or NetFlow analysis
- May miss idle devices that generate no traffic
Memory trick: Passive peeks, Active pokes.
Pyramid of Pain
Flip cardA model ranking indicators of compromise by how much difficulty ('pain') it causes an adversary when defenders detect and block them.
- Bottom: hash values (trivial to change)
- Top: TTPs (very hard to change)
- Higher-level indicators provide more lasting defensive value
Memory trick: Hash is trash, TTPs cause real strife.
Windows Scheduled Tasks
Flip cardA Windows operating system feature that allows users to schedule programs or scripts to run at predetermined times or when a specific system event occurs, often abused by attackers for persistence.
- Managed via Task Scheduler (taskschd.msc) or 'schtasks' command.
- Can execute programs, scripts, or send alerts.
- Attackers use them to ensure malware re-executes after reboots.
Memory trick: Run, Start, Schedule, Inject
Configuration Compliance Scanning
Flip cardA scan type that checks system settings against a security baseline (e.g., CIS Benchmarks, DISA STIGs) using standards like SCAP, rather than searching for software vulnerabilities.
- Validates hardening settings: passwords, auditing, registry keys
- Often automated via SCAP-compliant tools
- Complements, but differs from, CVE-based vulnerability scanning
Memory trick: Compliance checks the rulebook, not the CVE list.
CVSS Temporal Metrics
Flip cardMetrics that reflect the current state of exploit techniques or the availability of remediation and are subject to change over time.
- Exploit Code Maturity (E): Availability of exploit code (U, P, F, H).
- Remediation Level (RL): Availability of a fix (O, T, W, U, N).
- Report Confidence (RC): Confidence in the existence of the vulnerability (U, R, C).
Memory trick: Temporal Score: Exploit, Remediation, Confidence – The 'ERC' of time-sensitive risk!
DAST (Dynamic Application Security Testing)
Flip cardA black-box testing method that probes a running application externally (e.g., via HTTP requests) to find vulnerabilities without needing source code access.
- Also called black-box testing
- Finds runtime issues like injection, auth flaws, XSS
- Contrasts with SAST, which is white-box source code analysis
Memory trick: DAST = Doing it from the Outside; SAST = Seeing All the Source Text.
EDR Logs
Flip cardEndpoint Detection and Response (EDR) logs record activities on an endpoint, such as process execution, file system changes, and network connections, to detect and investigate security incidents.
- Provide deep visibility into endpoint behavior.
- Crucial for detecting post-exploitation activities.
- Collects data like process creation, file hashes, and network flows.
Memory trick: EDR sees all the endpoint's secrets.
SIEM Log Correlation
Flip cardA SIEM aggregates logs from multiple sources so an analyst can correlate related events and detect attack patterns that span systems.
- Centralization enables cross-source correlation
- Correlation reveals multi-stage attacks
- SIEMs do not remediate vulnerabilities automatically
Memory trick: One big picture beats many puzzle pieces.
CVSS Privileges Required (PR)
Flip cardA CVSS Base metric describing the level of privileges an attacker must possess before successfully exploiting a vulnerability.
- Values: None (N), Low (L), High (H)
- PR:N raises severity; PR:H lowers it
- Independent of Attack Vector and User Interaction
Memory trick: AV-AC-PR-UI: Access, Complexity, Privileges, User clicks.
SOAR Case Management
Flip cardThe SOAR capability that automates creation, assignment, and status tracking of incident tickets within an ITSM or case management system.
- Reduces manual ticket handling overhead
- Keeps ticket status synced with playbook progress
- Distinct from enrichment, correlation, and sandboxing functions
Memory trick: SOAR files the paperwork so analysts don't have to.
Lessons Learned Report
Flip cardA document created after an incident to analyze what happened, why it happened, and what can be done to improve future incident response and prevention.
- Focuses on continuous improvement.
- Includes incident overview, analysis, and recommendations.
- Aims to prevent recurrence and strengthen security posture.
Memory trick: Report's plan is where the 'do' list lives.
PCI DSS Requirement 5 Compliance Metric
Flip cardPCI DSS Requirement 5 mandates protecting all systems from malware and regularly updating anti-malware software. Relevant metrics demonstrate the deployment, currency, and effectiveness of these controls.
- Focuses on anti-malware deployment and updates.
- Applies to all systems, especially those in the CDE.
- Crucial for preventing compromise of cardholder data.
Memory trick: Payment Card Industry Demands Security Standards: Protect Systems from Malware.
Data Exfiltration Indicators (Logs)
Flip cardLog entries that, when correlated, suggest unauthorized transfer of data from an organization's network, often characterized by unusual activity, access to unapproved destinations, and significant outbound data volumes.
- Unusual login times or locations.
- Access to unapproved cloud storage or external services.
- Large outbound data transfers (POST requests, high bytes_sent).
- Access to sensitive files followed by external transfer.
Memory trick: Exfiltration is the 'OUT' of data, often at odd 'TIMES' to 'CLOUD' storage.
Lessons Learned Report: Root Cause Analysis
Flip cardThe Root Cause Analysis section in a lessons learned report identifies the fundamental, underlying reasons for an incident, moving beyond immediate symptoms to uncover systemic issues across processes, people, and technology.
- Goes beyond 'what happened' to 'why it happened'.
- Includes analysis of human error, process failures, and technical vulnerabilities.
- Forms the basis for effective recommendations.
Memory trick: Lessons Learned: Executive Summary, Timeline, Root Cause, Recommendations.
Least Privilege and Account Deactivation
Flip cardThe principle of least privilege dictates that users should only have the minimum necessary access rights to perform their job functions. Prompt deactivation of terminated employee accounts is critical to enforce this principle and prevent unauthorized access.
- Minimizes potential damage from compromised accounts.
- Reduces the attack surface.
- Requires robust offboarding processes.
Memory trick: Access control: Least privilege is key, only what you need.
Security Awareness Training Effectiveness KPI
Flip cardA metric used to evaluate the success of security awareness programs in changing employee behavior and improving their ability to identify and resist cyber threats, particularly social engineering attacks.
- Measures behavioral changes, not just completion rates.
- Often uses simulated attacks (e.g., phishing) to test effectiveness.
- Aims to reduce employee susceptibility to common attack vectors.
Memory trick: Awareness means fewer 'clicks' on the 'phishing' hook.
PCI DSS 11.2 Compliance Metric
Flip cardA metric used to demonstrate adherence to PCI DSS Requirement 11.2, which specifies regular internal and external vulnerability scanning for all systems in the cardholder data environment.
- Mandates quarterly internal vulnerability scans.
- Requires annual external vulnerability scans conducted by an Approved Scanning Vendor (ASV).
- Focuses on coverage and frequency of scanning for in-scope systems.
Memory trick: PCI scans cover all cards every quarter and year.
Vulnerability Remediation Efficiency KPI
Flip cardA metric used to assess how quickly and effectively security teams address and resolve identified vulnerabilities, often focusing on critical or high-severity issues.
- Measures the speed of patching or fixing vulnerabilities.
- Often tracked for different severity levels (e.g., critical, high).
- Helps demonstrate the responsiveness of the security team.
Memory trick: Speedy patches protect the kingdom.
GDPR Breach Notification Requirements
Flip cardSpecific information that must be provided to the relevant supervisory authority and, in some cases, to affected data subjects, following a personal data breach under the General Data Protection Regulation.
- Notification to supervisory authority within 72 hours (where feasible).
- Includes nature of breach, categories of data, DPO contact, likely consequences, and mitigation measures.
- Does not explicitly require reporting the organization's financial cost of the breach.
Memory trick: GDPR wants 'Who, What, How, and DPO' for a breach, not your 'wallet' size.
Mean Time To Exfiltrate (MTTE)
Flip cardMTTE measures the average time it takes for an attacker, or insider, to exfiltrate sensitive data after gaining initial access to it.
- Focuses on data movement off the network.
- Critical for assessing data loss prevention effectiveness.
- Calculated from initial data access to confirmed exfiltration.
Memory trick: Many Times The Exfiltration timer starts when data is touched.
GDPR Article 33 Notification
Flip cardGDPR Article 33 outlines the mandatory information required when notifying a supervisory authority of a personal data breach, focusing on the breach's nature, impact, and remediation.
- Mandatory information for supervisory authority notification.
- Must be provided without undue delay, within 72 hours.
- Focuses on data subjects, consequences, and mitigation measures.
Memory trick: GDPR 33: Tell the 'What, Who, Why, How-to-Fix' but not the 'Cost'.
Technical Vulnerability Communication
Flip cardThe process of effectively conveying detailed information about security vulnerabilities, including their nature, impact, and specific remediation steps, to technical audiences like development teams.
- Requires precision and clarity.
- Should include proof-of-concept and affected code where possible.
- Best delivered through structured, trackable systems (e.g., ticketing).
Memory trick: Developers need 'Code, Proof, Fix' in a 'Ticket', not just 'Talk'.
PCI DSS Requirement 10
Flip cardA PCI DSS requirement mandating the tracking and monitoring of all access to network resources and cardholder data, ensuring that all actions are logged, reviewed, and retained.
- Focuses on logging and monitoring.
- Applies to all access to cardholder data and network resources.
- Requires audit trails to be linked to individual users.
Memory trick: PCI 10: Cardholder Data Access Must Be Logged & Tracked.
Lessons Learned - Root Cause Analysis
Flip cardA component of a 'lessons learned' report that systematically investigates and identifies the fundamental reasons, such as control gaps or process failures, that contributed to an incident's occurrence or impact.
- Focuses on 'why' an incident happened.
- Identifies underlying control deficiencies or process breakdowns.
- Distinguishes between symptoms and fundamental causes.
Memory trick: Learned Lessons Reveal Core Problems and Fixes.
Vulnerability Remediation Effectiveness Metric
Flip cardA key metric for vulnerability remediation effectiveness measures the average time elapsed from when a vulnerability is discovered until it is successfully mitigated or patched, particularly focusing on critical assets or high-severity findings.
- Directly reflects the efficiency of the vulnerability management program.
- Crucial for demonstrating risk reduction over time.
- Highlights the impact of prioritization strategies.
Memory trick: Vulnerability Management: Find, Prioritize, Fix, Measure Time.
Root Cause Analysis (Phishing)
Flip cardThe process of identifying the fundamental reason or underlying factor that, if removed or corrected, would prevent a phishing incident from recurring, often pointing to human factors or control gaps.
- Goes beyond immediate symptoms.
- For phishing, often reveals human vulnerability or control failure.
- Aims to implement effective, long-term preventative measures.
Memory trick: Phishing: The 'Human' is the 'Root' when they 'Click' and 'Type'.
Technical Incident Communication
Flip cardTechnical incident communication involves providing granular, actionable data specific to the affected systems, networks, and applications to enable technical teams to understand, diagnose, and remediate incidents effectively.
- Focuses on 'how' the incident occurred technically.
- Includes logs, configurations, network data, forensic findings.
- Aids in root cause analysis and technical remediation.
Memory trick: Technical details: logs, configurations, network traffic, for the tech crew.
False Positive Rate (FPR)
Flip cardA metric representing the proportion of non-malicious events that are incorrectly identified as malicious by a security system, often leading to alert fatigue and wasted resources.
- Calculated as (False Positives) / (False Positives + True Negatives).
- High FPR indicates inefficiency and alert fatigue.
- Crucial for evaluating the effectiveness and tuning of detection systems.
Memory trick: SOC Efficiency: Focus on 'False' alarms, not just 'Total' noise.
Executive Security Metrics
Flip cardHigh-level, business-oriented metrics designed to inform executive leadership about the organization's overall security posture, risk reduction, and the effectiveness of security investments.
- Focus on risk, compliance, and business impact.
- Avoid overly technical jargon.
- Demonstrate progress and value of security initiatives.
Memory trick: Executives want to see the 'big picture' of protection and progress.
Security Resource Allocation Effectiveness KPI
Flip cardA Key Performance Indicator (KPI) that measures how effectively security resources (time, budget, personnel) are being utilized to address and mitigate the most significant security risks and threats to an organization.
- Links resource use to risk reduction.
- Often involves measuring remediation performance against SLAs for critical issues.
- Important for strategic decision-making and budget justification.
Memory trick: Resources are 'Efficient' when 'Critical' risks are 'Fixed on Time'.
Board-Level Strategic Cybersecurity KPI
Flip cardBoard-level strategic cybersecurity KPIs focus on translating security posture into business value, resilience, and risk reduction, aligning with organizational objectives rather than technical operational details.
- Emphasizes business impact, not technical specifics.
- Often relates to availability, continuity, reputation, and financial risk.
- Should be concise and easily understood by non-technical leadership.
Memory trick: Board wants Big picture, Business impact, and Bottom line.
Exploitability Metric
Flip cardA metric that quantifies the proportion of identified vulnerabilities that are confirmed to be exploitable within a given operational environment, providing a more accurate assessment of actual risk.
- Focuses on actual risk, not theoretical.
- Accounts for compensating controls and environmental factors.
- Useful for executive reporting to avoid alarm over non-issues.
Memory trick: Executives need 'Actual Risk' not just 'Raw Count'.