CompTIA Security+ (SY0-701) flashcards
212 free flashcards. Tap a card to flip it.
LDAP Injection
Flip cardAn attack that manipulates LDAP (Lightweight Directory Access Protocol) query filters by injecting special characters to alter search logic and bypass access controls.
- Exploits parentheses, asterisks, and boolean operators in filters
- Can bypass authentication or dump directory data
- Mitigated by input sanitization and parameterized LDAP queries
Memory trick: LDAP filters use ()* like SQL uses quotes—same trick, different syntax.
Separation of Duties
Flip cardA control that divides critical tasks among multiple people so no single individual can complete a sensitive process alone.
- Prevents fraud and error by requiring collusion for abuse
- Common in financial approvals and change management
- Different from least privilege, which limits access scope
Memory trick: Two hands must sign the check—no single hand controls it all.
Qualitative Risk Analysis
Flip cardA risk assessment method that uses descriptive, subjective categories (e.g., High/Medium/Low) rather than numeric values to rank likelihood and impact.
- Faster and less resource-intensive than quantitative analysis
- Relies on expert judgment and relative rankings
- Often combined with quantitative methods for a hybrid semi-quantitative approach
Memory trick: Qualitative = quick colors, Quantitative = quantities (numbers).
Asset Management
Flip cardThe process of tracking and managing organizational assets throughout their lifecycle, including acquisition, use, maintenance, and disposal.
- Unique asset tags/IDs enable tracking
- Centralized inventory improves accountability
- Lifecycle includes procurement to decommissioning
- Supports security by knowing what needs protecting
Memory trick: Tag it, track it, retire it.
VLAN Segmentation
Flip cardA method of logically dividing a physical network into separate broadcast domains to isolate traffic between groups of devices.
- Reduces attack surface by limiting broadcast/lateral movement
- Often combined with ACLs or firewalls for inter-VLAN traffic control
- Common segments: guest, voice, data, management
Memory trick: 'Different rooms, same building — VLANs are virtual walls.'
Risk Owner
Flip cardThe individual or role formally accountable for managing a specific identified risk, including monitoring it and executing its response strategy.
- Typically documented in the risk register alongside likelihood and impact
- Ensures accountability so risks don't go unmanaged
- Different from risk appetite, which is set at the organizational level
Memory trick: No owner, no action — every risk needs a name attached.
Memory (Process) Injection
Flip cardA technique where malicious code is injected into and executed within the memory space of a legitimate running process, avoiding disk-based detection.
- No new malicious file typically written to disk
- Inherits the trusted process's privileges/identity
- Common techniques include DLL injection, process hollowing, and reflective DLL loading
Memory trick: Inject the poison straight into a trusted host's bloodstream, no footprints left.
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data loss, measured in time, that an organization can tolerate following a disruption.
- Actual data loss = time since last successful backup to the point of failure
- RPO is satisfied when actual loss ≤ target RPO
- Shorter RPOs require more frequent backups or replication, increasing cost
Memory trick: 'RPO is the loss limit; the clock since last backup is the actual toll.'
White-Box Penetration Test
Flip cardA penetration test in which the tester has full knowledge of the target's internal systems, source code, and credentials before testing begins.
- Also called clear-box or full-knowledge testing
- Provides the most comprehensive test coverage
- Contrasts with black-box (no knowledge) and gray-box (partial knowledge)
Memory trick: White box = wide-open view; black box = blind spot.
Hot Site
Flip cardA fully equipped, continuously running alternate processing facility with real-time or near-real-time data replication, enabling near-immediate failover during a disaster.
- Fastest RTO among site types but most expensive to maintain
- Warm sites have partial readiness and periodic data sync (higher RPO)
- Cold sites have infrastructure only, requiring days/weeks to activate
Memory trick: 'Hot means ready right now; cold means start from scratch.'
Least Privilege (Serverless)
Flip cardThe principle that a function, service, or user should be granted only the minimum permissions required to perform its task.
- Overly broad IAM roles on serverless functions are a top cloud misconfiguration risk
- Scope roles to specific resources/actions (e.g., s3:GetObject on one bucket)
- Reduces blast radius if the function is compromised
Memory trick: 'Give the function a single key, not the master keyring.'
Account Deprovisioning
Flip cardThe process of disabling or removing a user's access rights when they no longer require them, such as at termination.
- Should occur immediately upon termination
- Prevents insider threat from former employees
- Part of the identity lifecycle management process
Memory trick: Last day, lock the door right away.
Watering Hole Attack
Flip cardAn attack strategy where adversaries compromise a website known to be frequented by a specific target group, infecting visitors from that group.
- Targets are identified by common online behavior/interests
- Malicious payload often filtered by IP range or user agent
- Mitigated by web filtering, endpoint protection, and network segmentation
Memory trick: Poison the watering hole and wait for the herd to drink.
Risk Appetite vs Risk Tolerance
Flip cardRisk appetite is the general amount of risk an organization is willing to accept, while risk tolerance is the specific, quantifiable acceptable variation from that appetite.
- Appetite = broad, qualitative statement
- Tolerance = specific, measurable threshold
- Both guide risk-based decision making
Memory trick: Appetite is the Mood, Tolerance is the Number
Black-Box Penetration Test
Flip cardA penetration test conducted with no prior internal knowledge of the target system, simulating an external attacker.
- Tester relies entirely on external reconnaissance
- Most realistic simulation of an outside attacker
- Contrasts with white-box (full knowledge) and gray-box (partial knowledge)
Memory trick: Black = blind, White = wide-open, Gray = a little of both.
Log Retention Policy
Flip cardA documented policy defining how long log data must be preserved and how it is stored, often driven by regulatory or legal requirements.
- Active SIEM storage is typically short-term for fast search
- Long-term retention often uses cheaper cold/archive storage
- Retention periods driven by regulations like PCI DSS, HIPAA, or legal hold
Memory trick: Old logs don't die, they retire to the archive vault.
Access Control Vestibule
Flip cardA physical security mechanism with two interlocking doors that only allows one person to pass through at a time after authentication, preventing tailgating.
- Formerly known as a mantrap
- Only one door opens at a time
- Effective anti-tailgating/piggybacking control
Memory trick: One door closes before the next opens — no tailgaters allowed.
Integrity via Hashing
Flip cardHashing produces a fixed-length fingerprint of data used to detect unauthorized changes.
- Same input always produces the same hash output
- Any change in data produces a different hash
- Common algorithms: SHA-256, SHA-3
Memory trick: Hash matches mean nothing was touched.
Evil Twin
Flip cardA rogue wireless access point disguised as a legitimate one to intercept user traffic or credentials.
- Mimics legitimate SSID
- Often has stronger signal to lure victims
- Enables on-path attacks over Wi-Fi
Memory trick: Evil twin looks just like the real one, but it's rotten inside.
Salting
Flip cardAdding a unique random value to a password before hashing to prevent precomputed hash (rainbow table) attacks and ensure identical passwords produce different hashes.
- Salt is stored alongside the hash, not secret
- Makes each hash unique even for identical passwords
- Often combined with key-stretching algorithms like bcrypt or PBKDF2
Memory trick: Salt spoils the rainbow (table)
Vishing (Voice Phishing)
Flip cardA social engineering attack conducted over phone calls, increasingly enhanced with AI voice-cloning (deepfake) technology to impersonate trusted individuals.
- Uses urgency and authority to pressure victims
- AI deepfakes can convincingly mimic real voices
- Common target: finance staff for fraudulent wire transfers
Memory trick: Vishing = voice + phishing; deepfakes make the lie sound like the boss.
Role-Based Access Control (RBAC)
Flip cardAn access control model where permissions are assigned to roles (job functions), and users inherit access rights by being assigned to a role.
- Simplifies administration for large user bases
- Access changes automatically when role changes
- Contrasts with ABAC, which uses multiple dynamic attributes
Memory trick: RBAC hands out a uniform (role) — everyone wearing it gets the same keys.
Risk Transference
Flip cardA risk treatment strategy that shifts the financial or operational impact of a risk to a third party, commonly through insurance or outsourcing.
- Common example: purchasing cyber insurance
- Does not reduce likelihood or impact directly
- Differs from acceptance, which retains the risk internally
Memory trick: Transfer the Bill to an Insurance Firm
Shadow IT
Flip cardThe use of unauthorized applications, devices, or services within an organization without the knowledge or approval of the IT department.
- Creates visibility gaps for security teams
- Often driven by convenience or perceived inefficiency of approved tools
- Mitigated by CASB solutions, policy enforcement, and user education
Memory trick: Shadows hide in the cloud where IT can't see.
Single Loss Expectancy (SLE)
Flip cardThe monetary loss expected from a single occurrence of a risk, calculated as Asset Value multiplied by Exposure Factor (AV × EF).
- Formula: SLE = AV × EF
- Exposure Factor is the percentage of asset value lost in one event
- SLE feeds into ALE when multiplied by Annualized Rate of Occurrence (ARO)
Memory trick: SLE = Single hit, so multiply Asset Value by the damage Percentage.
Contractual vs Regulatory Compliance
Flip cardContractual compliance obligations arise from agreements between private parties (e.g., PCI DSS), while regulatory/statutory compliance arises from government law.
- PCI DSS = industry/contractual standard
- GDPR/HIPAA = regulatory/statutory law
- Both carry penalties but differ in enforcement source
Memory trick: Contracts Come from Companies, Regulations Come from Government
Memorandum of Understanding (MOU)
Flip cardA document expressing mutual intent and understanding between two or more parties without creating a legally binding, enforceable contract.
- Less formal and generally not legally enforceable, unlike an MSA or BPA
- Often used between government agencies or non-commercial partners
- Commonly used to outline general cooperation goals or information sharing
Memory trick: MOU = 'Mostly Optional Understanding' — friendly, not binding.
Deterrent Control
Flip cardA control designed to discourage a threat actor from attempting an attack by increasing perceived risk or effort.
- Examples: warning signs, visible guards, lighting
- Does not stop or detect the attack itself
- Works on psychology of the attacker
Memory trick: Deter = discourage before it happens
SIEM Correlation Rule Thresholds
Flip cardA rule that aggregates related events (e.g., failed logins) over a defined time window and triggers an alert once a cumulative threshold is met, rather than evaluating single events in isolation.
- Uses sliding time windows to sum related events
- Reduces noise compared to alerting on every single event
- Threshold tuning balances detection speed vs false positives
Memory trick: The SIEM keeps a running tally in a moving 5-minute basket — once it's full (10), the alarm rings.
Hashing for Evidence Integrity
Flip cardCryptographic hashing (e.g., SHA-256) creates a unique digest of forensic evidence used to verify that a copy is identical to the original and has not been altered.
- Matching hash values confirm image integrity
- Part of maintaining chain of custody documentation
- Common algorithms: SHA-256, MD5 (legacy)
- Any evidence alteration changes the hash completely
Memory trick: Same hash, same evidence—no tampering.
Business Impact Analysis (BIA)
Flip cardA process that identifies and evaluates the potential effects of disruptions to critical business operations, establishing priorities like RTO and MTD.
- Outputs include Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
- Forms the foundation for business continuity and disaster recovery planning
- Focuses on business processes, not technical vulnerabilities
Memory trick: BIA = 'Before Impact, Analyze' priorities and downtime limits
Cross-Site Request Forgery (CSRF)
Flip cardAn attack that forces an authenticated user's browser to send unwanted requests to a web application in which the user is currently logged in.
- Exploits trust a site has in the user's browser
- Mitigated with anti-CSRF tokens and SameSite cookies
- Requires the victim to be actively authenticated
Memory trick: CSRF = 'Con the Session, Request Forged' using your own cookie against you.
Policy Enforcement Point (PEP)
Flip cardThe zero trust component that enforces the access decision by allowing, denying, or terminating a connection between subject and resource.
- Works together with the Policy Decision Point (PDP)
- Sits inline in the data path
- Defined in NIST SP 800-207 zero trust architecture
Memory trick: PDP decides, PEP does.
SOAR Playbook
Flip cardA predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes multiple response actions in sequence when triggered by an alert.
- Orchestrates actions across multiple security tools
- Reduces mean time to respond (MTTR)
- Can isolate hosts, disable accounts, create tickets automatically
- Requires integration APIs between tools
Memory trick: SOAR lets the system fly the response itself.
User and Entity Behavior Analytics (UEBA)
Flip cardA security analytics approach that establishes baselines of normal user/entity behavior and detects anomalies that may indicate compromise or insider threats.
- Uses machine learning/statistical modeling
- Detects anomalies without relying on known signatures
- Often integrated into SIEM platforms
Memory trick: UEBA is a nosy neighbor who notices when you leave the house at an unusual hour.
Parameterized Queries
Flip cardA secure coding technique that uses precompiled SQL statements with placeholders for user input, preventing the input from being interpreted as executable SQL code.
- Also called prepared statements
- Separates SQL logic from data
- Primary defense against SQL injection, along with input validation and stored procedures
Memory trick: Parameterized queries build a fence: data stays data, code stays code.
Static Malware Analysis
Flip cardExamining a malware sample's code, strings, headers, and structure without executing it, to safely gather indicators of behavior and intent.
- No code execution required
- Includes string extraction, disassembly, and header inspection
- Safer but less revealing than dynamic analysis
- Often performed before dynamic/sandbox analysis
Memory trick: Static stays Still — read the file, never run it
Internal vs. External Audit
Flip cardInternal audits are performed by an organization's own staff for continuous self-assessment, while external audits are performed by independent third parties to provide unbiased assurance to outside stakeholders.
- Internal audits are typically more frequent and operational in focus
- External audits provide independence and credibility to regulators/investors
- Both are components of a mature governance and oversight program
Memory trick: Internal checks yourself; external checks are checked by someone else.
Data in Transit
Flip cardData actively moving across a network, protected primarily through encryption protocols like TLS or IPsec VPNs.
- TLS 1.2/1.3 commonly used for transit protection
- Prevents eavesdropping/man-in-the-middle attacks
- One of three data states: rest, transit, use
Memory trick: Rest=stored, Transit=moving, Use=processing.
Continuous Compliance Monitoring
Flip cardThe ongoing, automated evaluation of systems and configurations against defined security baselines to detect and alert on non-compliance in real time.
- Contrasts with periodic audits by providing near real-time visibility
- Often implemented via cloud security posture management (CSPM) tools
- Helps quickly identify and remediate configuration drift
Memory trick: Continuous = always watching, not just once a year
Agent-Based Vulnerability Scanning
Flip cardA scanning method where software agents are installed on endpoints to collect vulnerability data locally and report it to a central console, independent of network location.
- Ideal for remote/roaming devices
- Provides continuous local visibility
- Requires agent deployment and maintenance overhead
Memory trick: An agent travels with the laptop like a bodyguard, reporting home from anywhere.
Network Access Control (NAC)
Flip cardA security solution that checks device compliance (patches, AV, configuration) before allowing network access, quarantining non-compliant devices.
- Enforces posture assessment at connection time
- Can use 802.1X for authentication
- Non-compliant devices routed to remediation VLAN
Memory trick: NAC is a bouncer checking ID and health papers before letting you into the club.
Rootkit
Flip cardMalware that gains and maintains privileged access to a system while hiding its presence, often by modifying the OS kernel or core utilities.
- Operates at kernel or firmware level for stealth
- Difficult to detect with standard OS tools
- Often requires specialized detection or full OS reinstall to remove
Memory trick: Rootkit digs to the 'root' of the OS to become invisible.
Root Cause Analysis
Flip cardA structured investigation technique used after an incident to identify the fundamental underlying cause, not just the symptoms, to prevent recurrence.
- Often performed during the lessons-learned phase of incident response
- Techniques include the '5 Whys' and fishbone diagrams
- Leads to corrective actions like updated change management controls
Memory trick: Dig past the branches to find the root that caused the tree to fall.
File Integrity Monitoring (FIM)
Flip cardA security control that monitors and alerts on unauthorized changes to critical system or configuration files by comparing current file hashes to a known-good baseline.
- Uses cryptographic hashing to detect changes
- Commonly monitors OS binaries, config files, and logs
- Helps detect rootkits, tampering, and unauthorized changes
Memory trick: FIM fingerprints files so any tampering shows up like a smudge.
N+1 Redundancy
Flip cardA fault-tolerance design where one extra unit of capacity (N+1) is provisioned beyond the minimum required (N) to handle a component failure without service disruption.
- N = required capacity units to meet load
- N+1 adds exactly one spare unit
- Contrasts with 2N (full duplicate) redundancy
Memory trick: Need four to run, keep five to be safe.
Configuration Compliance Scanning
Flip cardAutomated comparison of a system's current settings against an approved secure baseline to detect unauthorized drift.
- Detects configuration drift over time
- Complements vulnerability scanning
- Often tied to hardening standards like CIS benchmarks
Memory trick: Picture a ruler measuring a server against a blueprint every night.
Privileged Access Management (PAM)
Flip cardA solution that centrally stores, rotates, and audits privileged account credentials, granting temporary checkout access instead of persistent knowledge of passwords.
- Automatically rotates privileged passwords
- Logs all checkout and usage sessions
- Reduces standing privileged credential exposure
Memory trick: PAM is a locked key cabinet — check out the key, use it, return it, logged every time.
Microsegmentation
Flip cardA zero trust network security technique that divides a network into small, isolated segments—often per workload—requiring explicit policy approval for any communication between them.
- Core zero trust principle: never trust, always verify, even internally
- Reduces blast radius by limiting lateral movement
- Often implemented via software-defined networking or host-based firewalls
Memory trick: Wall off every room in the house so a burglar can't roam freely.
Bug Bounty Program
Flip cardA crowdsourced security initiative that rewards external researchers for discovering and responsibly disclosing vulnerabilities, usually with payouts scaled to severity.
- Open to a broad pool of independent researchers, unlike contracted pen tests
- Rewards are typically tiered by vulnerability severity/impact
- Often managed via platforms with defined scope and disclosure policies
Memory trick: Bounty = pay per bug found, like a reward poster
Honeypot
Flip cardA decoy system or resource intentionally exposed to attract attackers, allowing defenders to study techniques and divert attention from real assets.
- Contains no real production data
- Used for threat intelligence and early warning
- A honeynet is a network of multiple honeypots
Memory trick: Honey attracts the bear (attacker) away from the hive (real data).
Endpoint Detection and Response (EDR)
Flip cardA security tool that continuously monitors endpoint behavior, detects anomalies, and enables automated response and forensic investigation.
- Goes beyond signature-based detection
- Supports automated isolation/containment
- Provides telemetry for threat hunting and forensics
Memory trick: EDR watches behavior, not just fingerprints.
Security Awareness Metrics
Flip cardEffectiveness of security awareness training is measured by trends such as decreasing phishing click rates and increasing suspicious email reporting rates.
- Lower click-through rate indicates reduced susceptibility
- Higher reporting rate indicates increased vigilance
- Both metrics together provide a fuller picture than either alone
Memory trick: Fewer Bites, More Reports = Awareness Works
OCSP
Flip cardOnline Certificate Status Protocol; allows real-time verification of an individual certificate's revocation status from a CA.
- Faster and lighter than downloading a full CRL
- OCSP stapling lets the web server provide the response, improving privacy and performance
- Response is signed by the CA or an authorized responder
Memory trick: OCSP = On-demand Check, Single Piece
Attribute-Based Access Control (ABAC)
Flip cardAn access control model that grants permissions based on the dynamic evaluation of multiple attributes—such as user, device, environment, and resource—at the time of the access request.
- Evaluated in real time by a policy engine
- Can combine user, device, time, and location attributes
- Offers more granular, context-aware control than RBAC
Memory trick: ABAC checks a checklist of clues (attributes) before opening the door every single time.
Software-Defined Networking (SDN)
Flip cardA network architecture that separates the control plane from the data plane, using a centralized controller to programmatically manage traffic flow across the network.
- Enables dynamic, policy-based network reconfiguration
- Common in cloud data centers and microservice environments
- Controller compromise is a key security risk (single point of control)
Memory trick: SDN = a joystick controlling the whole network from one seat.
Address Space Layout Randomization (ASLR)
Flip cardAn operating system security feature that randomizes the memory locations of key process areas (stack, heap, libraries) on each execution to hinder exploitation of memory-corruption vulnerabilities.
- Randomizes memory layout at each program launch
- Often paired with DEP/NX for stronger protection
- Increases difficulty of reliably locating shellcode or return addresses
Memory trick: ASLR shuffles the deck every time the program deals memory addresses.
TOCTOU Race Condition
Flip cardA vulnerability where a resource's state changes between the time it is checked and the time it is used, allowing an attacker to substitute a different resource.
- Common in file-system operations
- Also called a 'check-then-act' flaw
- Mitigated by atomic operations or file locking
Memory trick: Check now, swap fast, use later — the race is won in the gap.
Active/Passive Failover Clustering
Flip cardA high-availability configuration where a standby node automatically assumes the workload of a failed active node to minimize downtime.
- Passive node stays idle until failover is triggered.
- Failover is typically automatic, not manual.
- Contrasts with active/active, where both nodes process traffic simultaneously.
Memory trick: One works, one waits, ready to jump in.
Key Escrow
Flip cardThe practice of storing a copy of a cryptographic private key with a trusted third party for recovery in case the original key is lost, damaged, or unavailable.
- Enables data recovery for lost/inaccessible keys
- Introduces a single point of trust/risk with the escrow agent
- Often required in regulated or government environments
Memory trick: Escrow keeps a spare key locked in a trusted vault.