CompTIA CySA+ (CS0-003) flashcards
190 free flashcards. Tap a card to flip it.
Attack Surface Reduction KPI
Flip cardAn Attack Surface Reduction KPI measures the organization's success in minimizing the entry points and potential vulnerabilities that an attacker could exploit. It often focuses on vulnerability remediation and asset hardening.
- Directly reflects proactive security posture improvement.
- Often involves vulnerability management metrics.
- Aims to reduce the likelihood of successful attacks.
Memory trick: Reduce the attack surface by patching the holes and shrinking the target.
ISO 27001 Continual Improvement (Incident Management)
Flip cardISO 27001 requires organizations to continually improve the suitability, adequacy, and effectiveness of their Information Security Management System (ISMS), including incident management, often demonstrated through root cause analysis and subsequent control enhancements.
- Aligned with the PDCA (Plan-Do-Check-Act) cycle.
- Focuses on learning from incidents to prevent recurrence.
- Requires documentation of improvements and their impact.
Memory trick: ISO: Improve Security Continuously, Learn from Incidents.
Vulnerability Report for Developers
Flip cardA vulnerability report for developers should contain precise technical details, including reproduction steps, proof-of-concept code, affected code/components, and specific recommendations, to facilitate efficient remediation.
- Focuses on technical 'how-to-fix' information.
- Avoids high-level business jargon.
- Enables developers to quickly identify and patch flaws.
Memory trick: Developers need 'DEBUG' details: Steps to Reproduce, Code, Fix.
GDPR Breach Notification Compliance
Flip cardGDPR mandates strict timelines for notifying supervisory authorities (72 hours) and affected data subjects (without undue delay) about personal data breaches, demonstrating an organization's commitment to data protection and transparency.
- Article 33: Notification to supervisory authority.
- Article 34: Communication to data subject.
- Timeliness is critical for compliance.
Memory trick: GDPR: Get Data Protected, Report Breaches Promptly.
DNS Tunneling Indicators
Flip cardSpecific patterns in DNS traffic that suggest data is being covertly exfiltrated or command-and-control communications are occurring by encoding information within DNS queries and responses.
- Unusually long or malformed DNS queries.
- Queries for non-existent or suspicious subdomains.
- High volume of DNS traffic to specific external domains.
- Data encoded in query names or TXT records.
Memory trick: DNS Tunneling: 'Long, Encoded, NXDOMAIN' queries are the secret path.
Compliance Reporting Metric (Policy Adherence)
Flip cardA quantifiable measure used to demonstrate an organization's adherence to internal security policies and external compliance frameworks, often focusing on foundational controls and documentation.
- Verifies implementation of mandated controls.
- Often relates to asset management, configuration management, or access control policies.
- Shows proactive effort in maintaining a secure state.
Memory trick: Adherence means 'policies are followed' and 'assets are known'.
Threat Intelligence Actionability KPI
Flip cardA Threat Intelligence Actionability KPI measures the degree to which ingested threat intelligence is integrated into security tools and processes, directly enhancing detection, prevention, or response capabilities.
- Focuses on utilization, not just acquisition, of intelligence.
- Demonstrates value by improving security operations.
- Often involves correlation with alerts, blocks, or investigations.
Memory trick: Threat Intel: Get Smart, Get Actionable, Get Protected.
Financial Impact Assessment (Breach)
Flip cardThe process of quantifying the monetary costs associated with a security incident or data breach, including direct expenses, indirect losses, and potential future financial liabilities.
- Includes regulatory fines, legal fees, and litigation costs.
- Covers customer notification and compensation expenses.
- Accounts for reputational damage, lost business, and increased insurance premiums.
Memory trick: Breaches hit the 'wallet' with 'Fines, Fees, and Funds' for customers.
Vulnerability Remediation
Flip cardThe process of eliminating or mitigating a vulnerability to reduce the risk it poses.
- Directly fixes the root cause of the vulnerability.
- Often involves patching, upgrading, or reconfiguring.
- Most effective strategy for known software flaws.
Memory trick: Remediate means to fix the problem, not just cover it up.
Reverse Shell Detection
Flip cardA reverse shell is a type of shell session where the target machine initiates the connection back to the attacker's machine, often used for bypassing firewalls and gaining remote control.
- Attacker listens for incoming connections.
- Victim machine connects out to the attacker.
- Commonly uses utilities like Netcat (nc) or Python/Perl scripts.
Memory trick: The 'Netcat' fish caught the 'Shell' hook from the 'Server' line.