CompTIA Security+ (SY0-701) flashcards
212 free flashcards. Tap a card to flip it.
Confidentiality
Flip cardOne of the three pillars of the CIA triad; ensures that information is disclosed only to authorized individuals or systems.
- Achieved through encryption, access controls, and classification.
- Breaches of confidentiality result in unauthorized data disclosure.
- Encryption at rest and in transit are common confidentiality controls.
Memory trick: Confidentiality = keep it Closed to outsiders
Brute-Force Attack
Flip cardAn attack method that systematically tries all possible password or key combinations until the correct one is found.
- Can be online (against a live service) or offline (against stolen hashes)
- Mitigated by account lockout, rate limiting, and MFA
- Differs from credential stuffing, which uses known leaked credentials
Memory trick: Brute force hammers through every combination until one fits.
Integer Overflow
Flip cardA vulnerability that occurs when an arithmetic operation produces a value outside the range representable by the allocated integer type, causing it to wrap around unexpectedly.
- Signed 32-bit max is 2,147,483,647
- Wraparound can flip a large positive number to negative
- Mitigated by input validation and using appropriately sized/unsigned data types
Memory trick: Push past the max and the number flips to the negative side.
Passive Reconnaissance
Flip cardInformation gathering about a target using publicly available sources without directly interacting with the target's systems.
- Includes OSINT sources like WHOIS, DNS, and social media
- Does not generate traffic or logs on the target's systems
- Contrasts with active reconnaissance, which involves direct probing
Memory trick: Passive = peeking from a distance; Active = knocking on the door.
Kerberoasting
Flip cardAn attack where a low-privilege user requests Kerberos service tickets for SPNs and cracks them offline to recover service account passwords.
- Targets service accounts with weak passwords
- Ticket is encrypted with the service account's NTLM hash
- Mitigated by strong/long service account passwords and managed service accounts
Memory trick: Kerberoasting roasts service tickets over an offline cracking fire.
RAID 5
Flip cardA RAID level that stripes data with distributed parity across all disks, tolerating a single disk failure while using the equivalent of one disk's capacity for parity.
- Usable capacity = (n-1) x disk size, where n = number of disks.
- Tolerates exactly 1 simultaneous disk failure.
- RAID 6 adds a second parity set to tolerate 2 disk failures.
Memory trick: RAID 5: lose one disk of space, survive one disk of failure.
Non-Disclosure Agreement (NDA)
Flip cardA legally binding contract that requires one or more parties to keep specified information confidential and not disclose it to unauthorized parties.
- Commonly used before sharing proprietary code, trade secrets, or sensitive data
- Can be unilateral (one party discloses) or mutual (both parties disclose)
- Breach of an NDA can result in legal and financial consequences
Memory trick: NDA = 'No Disclosure Allowed' for secrets
Honeynet
Flip cardA network of multiple honeypots designed to appear as a realistic production environment, used to study attacker behavior in depth.
- Composed of multiple interconnected honeypots
- Provides broader attacker behavior analysis than a single honeypot
- Used for threat intelligence gathering
Memory trick: One honeypot is a trap; a honeynet is a whole fake town.
DNS Poisoning
Flip cardAn attack that corrupts DNS cache or records so that a domain name resolves to an attacker-controlled IP address instead of the legitimate one.
- Also called DNS cache poisoning
- Redirects even correctly typed URLs
- Mitigated by DNSSEC and secure resolver configuration
Memory trick: Poison the map, and everyone walks to the wrong destination.
System Hardening
Flip cardThe process of reducing a system's attack surface by removing or disabling unnecessary features, services, ports, and default accounts.
- Disable unused services/ports
- Remove default accounts/credentials
- Apply security patches and baselines
- Use least functionality principle
Memory trick: Less running = less to attack.
Accounting (AAA)
Flip cardThe AAA component that logs and tracks user activities for auditing, billing, or forensic purposes.
- Provides audit trails
- Supports non-repudiation
- Often implemented via RADIUS/TACACS+ logging
Memory trick: Accounting = Actions on record
Registration Authority (RA)
Flip cardA PKI component that verifies the identity of certificate requesters and forwards validated requests to the Certificate Authority for signing.
- Offloads identity vetting from the CA.
- Does not itself issue or sign certificates.
- Reduces CA workload and improves scalability of certificate issuance.
Memory trick: RA checks your ID, CA signs your certificate
Buffer Overflow
Flip cardA vulnerability where data written to a fixed-size buffer exceeds its capacity, overwriting adjacent memory and potentially allowing code execution.
- Common in languages without automatic bounds checking (C/C++)
- Can overwrite the stack return address
- Mitigated by input validation, bounds checking, ASLR, and stack canaries
Memory trick: Overflow the cup and it spills onto the return address.
Resource Exhaustion (Memory Leak)
Flip cardA condition where a system's resources, such as memory, are gradually consumed without being released, eventually causing degraded performance or a crash.
- Often caused by application bugs that fail to free allocated memory
- Can be exploited intentionally as a denial-of-service vector
- Mitigated through code reviews, memory profiling, and resource limits
Memory trick: A leaky bucket of memory eventually runs dry and the app collapses.
Dynamic Malware Analysis (Sandboxing)
Flip cardA technique where suspicious files are executed in an isolated environment to observe real-time behavior, such as file system, registry, and network activity, without risking production systems.
- Detects behavior-based indicators, not just signatures
- Runs in isolated VM or dedicated sandbox appliance
- Complements static analysis for comprehensive malware research
Memory trick: Sandboxing lets the malware play in a locked sandbox while defenders watch every move.
Honeytoken
Flip cardA piece of fake data (credentials, files, database entries) planted to detect unauthorized access when the data is used.
- Part of deception technology alongside honeypots and honeynets
- Triggers alerts on any use since no legitimate reason exists
- Cheap, low-maintenance detection mechanism
Memory trick: Token = bait, not a whole network
Data in Use
Flip cardProtection applied to data while it is actively being processed in CPU/memory, typically via hardware-based trusted execution environments.
- Complements data-at-rest and data-in-transit protections
- Uses secure enclaves (e.g., trusted execution environments)
- Protects against compromised hosts, hypervisors, or insiders
Memory trick: Rest, Transit, Use — three states, three shields.
Threat Hunting
Flip cardA proactive, analyst-driven process of searching networks and endpoints for signs of compromise that automated tools have not detected.
- Starts with a hypothesis based on threat intelligence or TTPs
- Uses log analysis, EDR data, and behavioral baselines
- Differs from incident response, which reacts to known alerts
Memory trick: The hunter stalks silently before the alarm ever rings.
Tabletop Exercise
Flip cardA discussion-based simulation where team members review and practice their roles in a hypothetical incident scenario.
- Low-cost, low-risk training method
- Identifies gaps in IR plans and communication
- Does not involve technical system changes
Memory trick: Talk it through at the table first.
Directory Traversal
Flip cardA vulnerability that allows attackers to access files and directories outside the intended web root by manipulating file path input.
- Uses '../' or encoded equivalents to escape restricted directories
- Mitigated by input sanitization and least-privilege file permissions
- Can expose sensitive OS files like /etc/passwd
Memory trick: Dots and slashes ('../') are the crowbar prying open forbidden folders.
Certificate Revocation (CRL/OCSP)
Flip cardA mechanism allowing a certificate authority to invalidate a certificate before its expiration date, published via a Certificate Revocation List (CRL) or checked in real time via OCSP.
- CRL: periodically published list of revoked certificate serial numbers
- OCSP: real-time query protocol to check a single certificate's status
- Used when a private key is compromised or certificate details change
Memory trick: A revoked certificate gets blacklisted before its natural death (expiration).
Security Automation Benefits
Flip cardUsing scripts or orchestration tools to perform repetitive security tasks automatically, improving speed and consistency of detection and response.
- Reduces mean time to detect (MTTD) and respond (MTTR)
- Frees analysts for higher-value investigative work
- Requires reliable data sources and defined logic to avoid errors
Memory trick: Automation speeds detection, doesn't replace defenders.
API Gateway
Flip cardA managed entry point for microservices that handles authentication, rate limiting, request routing, and monitoring for API traffic.
- Centralizes cross-cutting concerns (auth, logging, throttling) so individual services don't duplicate them
- Common in microservices architectures to hide internal service topology
- Can enforce API keys, OAuth tokens, and quota limits
Memory trick: 'One gate, many rooms — the API gateway guards them all.'
Hardware Security Module (HSM)
Flip cardA dedicated, tamper-resistant hardware device used to generate, store, and manage cryptographic keys and perform cryptographic operations without exposing private keys in plaintext.
- Keys never leave the HSM in unencrypted form.
- Often used for PKI, payment processing, and regulatory compliance.
- Different from TPM, which secures individual endpoint devices, not enterprise-scale key management.
Memory trick: HSM is the vault where keys are born and die, never leaving.
MAC(E) Timestamps
Flip cardFile system metadata timestamps—Modified, Accessed, Created, and (on NTFS) Entry Modified—used by forensic examiners to reconstruct file activity timelines.
- Modified = content was changed
- Accessed = file was opened/read
- Created = file was first created
- Entry Modified (NTFS) = MFT metadata record changed
Memory trick: MACE: Modified=content edited, Accessed=file opened, Created=born, Entry=paperwork updated.
Right-to-Audit Clause
Flip cardA contractual provision that allows an organization to inspect and verify a third party's security controls and compliance during the business relationship.
- Key third-party risk management control
- Should be negotiated before contract signing
- Complements SLAs and vendor due diligence
Memory trick: Trust but Verify—Right to Audit Lets You Check
Vendor Due Diligence
Flip cardThe process of evaluating a third party's security, financial, and compliance posture before entering into a business relationship.
- Performed before contract signing, unlike ongoing audits
- Includes reviewing certifications (e.g., SOC 2), financials, and questionnaires
- Reduces third-party and supply chain risk
Memory trick: Due diligence is 'doing your homework' before the deal.
Patch Management Testing Phase
Flip cardThe stage where patches are validated in a staging environment to confirm compatibility and stability before production deployment.
- Occurs after identification and prioritization
- Reduces risk of outages from bad patches
- Precedes full production deployment
Memory trick: A doctor tests medicine on a dummy patient before giving it to real ones.
Load Balancer
Flip cardA network device or service that distributes incoming traffic across multiple servers, improving performance, scalability, and availability through health monitoring.
- Supports high availability by rerouting around failed nodes
- Common algorithms: round robin, least connections, weighted
- Can operate at Layer 4 (transport) or Layer 7 (application)
Memory trick: Load balancer = traffic cop directing cars to open lanes.
Incremental Backup Restoration
Flip cardA backup strategy that captures only data changed since the last backup (full or incremental); restoration requires the last full backup plus every incremental in sequence.
- Incremental: smaller, faster backups but slower, multi-step restore
- Differential: backs up changes since last full backup; restore needs only full + latest differential
- Full backup captures entire dataset every time, largest but simplest restore
Memory trick: Incremental = climbing every stair one at a time to reach the top.
Warm Site
Flip cardA backup facility with some hardware and software pre-installed and data updated periodically, offering a middle ground between hot and cold sites.
- Recovery typically hours to a day
- Cheaper than hot site, faster than cold site
- Data may be somewhat stale at failover time
Memory trick: Hot=instant, Warm=hours, Cold=days.
Authentication Factors
Flip cardCategories of evidence used to verify identity, combined to strengthen authentication beyond a single method.
- Knowledge = password/PIN
- Possession = token/phone/smart card
- Inherence = biometric trait
- True MFA requires factors from different categories
Memory trick: Know it, Have it, Are it — mix two to lock it tight
Availability
Flip cardThe CIA triad pillar ensuring authorized users have reliable and timely access to information and systems.
- Achieved through redundancy, failover, and backups
- Threatened by DoS attacks and hardware failure
- Measured by uptime/SLA metrics
Memory trick: Availability = Always accessible
GDPR Fine Tiers
Flip cardGDPR authorizes fines up to the greater of a fixed amount or a percentage of a company's annual global revenue, depending on the severity of the violation.
- Higher tier: up to 4% of global annual revenue or €20 million, whichever is greater
- Lower tier: up to 2% of global annual revenue or €10 million
- Applies regardless of company location if EU residents' data is involved
Memory trick: GDPR bites 4% for the big violations, 2% for the smaller ones.
Risk Avoidance
Flip cardA risk response strategy that eliminates the risk by discontinuing the activity, process, or asset that creates it.
- Removes the risk source entirely, not just its impact
- Often used when mitigation costs exceed the value of the activity
- Contrasts with acceptance, mitigation, and transference
Memory trick: Avoid it, Accept it, Transfer it, Mitigate it — AATM your risk.
Data Classification Levels
Flip cardA tiered labeling system (commonly Public, Internal, Confidential, Restricted) used to determine required handling and access controls based on data sensitivity.
- Higher tiers require stricter access controls and encryption
- Regulated data (PII, PHI, PCI) typically requires the highest classification
- Mislabeling data can lead to compliance violations and breaches
Memory trick: 'The more it can hurt if leaked, the higher the label goes.'
Shared Responsibility Model
Flip cardA cloud security framework defining which security tasks belong to the cloud provider versus the customer, varying by service model (IaaS, PaaS, SaaS).
- IaaS: provider secures hardware/hypervisor; customer secures OS, apps, data.
- SaaS: provider secures almost everything except data and access management.
- Misunderstanding this model is a leading cause of cloud misconfigurations.
Memory trick: Provider builds the house, customer locks the doors.
Bollards
Flip cardSturdy vertical posts placed around building entrances to prevent vehicle intrusion while allowing pedestrian access.
- Common at data centers, government buildings, and retail entrances
- Can be fixed or retractable
- A physical, preventive control
Memory trick: Bollards block bumpers
Beaconing
Flip cardPeriodic, low-volume network communication from a compromised host to an external command-and-control (C2) server, used to check in for instructions or exfiltrate data.
- Occurs at regular time intervals ('heartbeat')
- Often uses encrypted or obfuscated traffic
- Continues even when the host is idle, distinguishing it from user-driven traffic
Memory trick: Beaconing = a lighthouse blinking every 60 seconds, calling home to its master.
Business Email Compromise (BEC)
Flip cardA social engineering attack where an attacker impersonates an executive or trusted vendor via email to trick an employee into transferring funds or sensitive data.
- Often uses lookalike domains or compromised accounts
- Relies on urgency and authority to bypass scrutiny
- Commonly targets finance/accounts payable staff
Memory trick: BEC: Boss Emails Cash-request, but it's fake.
Supply Chain Risk
Flip cardThe risk that disruptions, failures, or compromises within an organization's supplier or vendor network will adversely affect its operations, products, or security.
- Often heightened by single-source or sole-supplier dependencies
- Includes geopolitical, financial, and cybersecurity risks from third parties
- Mitigated through vendor diversification, due diligence, and contractual controls
Memory trick: One supplier, one point of failure—diversify the chain
Annualized Rate of Occurrence (ARO)
Flip cardThe estimated number of times a specific threat event is expected to occur within a one-year period.
- ARO is expressed as a decimal or frequency (e.g., 0.2 = once every 5 years)
- Used with SLE to calculate ALE: ALE = SLE x ARO
- Derived from historical data, industry statistics, or expert judgment
Memory trick: ARO = how often, SLE = how much, ALE = both combined
Spear Phishing
Flip cardA targeted phishing attack directed at a specific individual or organization, using personal or contextual details to increase credibility.
- More targeted than mass phishing
- Uses personal info like name, role, or recent activity
- Often precursor to BEC or credential theft
Memory trick: Spear = aimed at ONE fish with a personalized hook.
Cold Site
Flip cardA backup facility with basic infrastructure (space, power, cooling) but no pre-installed systems or current data, requiring extensive setup before use.
- Cheapest but slowest recovery option
- Requires procuring hardware and restoring backups
- Longest RTO among site types
Memory trick: Hot is ready, warm is waiting, cold is empty.
ARP Poisoning
Flip cardAn attack where forged ARP replies associate the attacker's MAC address with a legitimate IP (often the gateway), redirecting local traffic to the attacker.
- Enables on-path (MITM) attacks on LANs
- Exploits lack of ARP authentication
- Mitigated by dynamic ARP inspection and static ARP entries
Memory trick: ARP poisoning hijacks the address book so mail goes to the wrong desk.
Authorization (AAA)
Flip cardThe AAA function that determines what resources or actions an authenticated identity is permitted to access.
- Occurs after authentication succeeds.
- Often implemented via RBAC, ACLs, or group policies.
- Answers 'what can this user do?' not 'who is this user?'
Memory trick: Authenticate who you are, then Authorize what you can do
Privilege Escalation
Flip cardThe act of exploiting a bug, misconfiguration, or design flaw to gain elevated access to resources beyond what was originally granted.
- Vertical escalation gains higher privileges (user to admin/root)
- Horizontal escalation gains access to peer accounts at the same level
- Common vectors include insecure file permissions, unpatched kernel exploits, and misconfigured services
Memory trick: Climbing the ladder from user to root via a weak rung (bad permissions).
Digital Signature
Flip cardA cryptographic mechanism where a hash of data is encrypted with the sender's private key to provide authenticity, integrity, and non-repudiation.
- Uses sender's private key to sign, public key to verify
- Provides non-repudiation unlike a simple MAC
- Common in code signing and secure email (S/MIME)
Memory trick: Sign with private, verify with public — proof it's really you.
Symmetric Key Scalability
Flip cardThe number of unique pairwise symmetric keys needed for n parties equals n(n-1)/2, illustrating symmetric encryption's key management challenge at scale.
- Formula: n(n-1)/2 unique keys for n users
- Grows quadratically as users increase
- Asymmetric cryptography avoids this scaling issue via key pairs per user, not per pair
Memory trick: Pairs, not squares: n(n-1)/2
Governance Document Hierarchy
Flip cardPolicies set high-level intent, standards define mandatory requirements, procedures give step-by-step instructions, and guidelines offer recommendations.
- Policies are approved by executive leadership
- Standards support policies with specific requirements
- Procedures are the most detailed, task-level documents
Memory trick: Policies Say What, Standards Set Specs, Procedures Push Steps, Guidelines Give Suggestions
Immutable Infrastructure
Flip cardAn architecture approach where deployed servers/containers are never modified after creation; changes are made by deploying new replacement images instead of patching in place.
- Reduces configuration drift and inconsistency
- Common in containerized/cloud-native environments
- Simplifies rollback: redeploy the prior known-good image
Memory trick: Don't fix it, replace it—immutable means untouched after birth.
Organized Crime (Threat Actor)
Flip cardA financially motivated threat actor group operating with business-like structure, often specializing in ransomware, fraud, or data theft for profit.
- Primary motivation is financial gain
- Often highly resourced with specialized roles (developers, negotiators, money launderers)
- Common tactic: ransomware-as-a-service
Memory trick: 'Organized crime' = organized like a company, chasing cash.
SOAR Orchestration
Flip cardThe coordination of multiple different security tools and systems to work together within a single automated workflow, as opposed to automating just one task.
- Orchestration = coordinating many tools together
- Automation = executing one repetitive task
- Together they form the core of SOAR platforms
Memory trick: Orchestration is a conductor 🎼 directing many instruments (tools) to play together; automation is one instrument playing on autopilot.
Federation / SSO
Flip cardFederation allows identity providers to share authentication assertions with multiple service providers, enabling single sign-on (SSO) across organizational boundaries.
- SAML and OAuth/OIDC are common federation protocols
- One login grants access to multiple trusted apps
- Reduces password fatigue and reuse
- Relies on trust relationship between IdP and SP
Memory trick: Log in once, roam everywhere trusted.
Screened Subnet (DMZ)
Flip cardA network segment positioned between external and internal firewalls that hosts public-facing services, isolating them from the trusted internal network.
- Also called demilitarized zone
- Typically bounded by two firewalls or one firewall with three interfaces
- Limits blast radius if a public server is compromised
Memory trick: DMZ is the buffer zone between enemy (internet) and home (LAN).
Chain of Trust
Flip cardThe hierarchical validation path from an end-entity certificate through intermediate CAs up to a trusted root CA that establishes certificate legitimacy.
- Root CA certificates are self-signed and trusted by default
- Intermediate CAs bridge trust between root and end-entity certs
- A missing or misconfigured intermediate cert breaks the chain
Memory trick: No unbroken links, no trust to the top.
SQL Injection
Flip cardAn attack that inserts malicious SQL code into input fields to manipulate or bypass database queries.
- Common payload: ' OR '1'='1
- Mitigated with parameterized queries/prepared statements
- Can lead to data theft, authentication bypass, or database modification
Memory trick: Inject truth into the query and the door swings open.
Lessons Learned (Post-Incident Review)
Flip cardThe final phase of incident response where the team reviews the incident, documents findings, and updates policies, playbooks, and controls to prevent recurrence.
- Occurs after recovery is complete
- Produces a formal after-action report
- Feeds improvements back into preparation phase
Memory trick: After the fire is out, the team writes the report so it burns less next time.
Reflected XSS
Flip cardA cross-site scripting attack where malicious script is embedded in a request (like a URL) and immediately reflected back by the server into the response, executing in the victim's browser.
- Requires victim to click a crafted malicious link
- Not stored on the server (unlike stored XSS)
- Mitigated by output encoding and input validation
Memory trick: Reflect the script like a mirror bouncing malice back at you.
Rules of Engagement (RoE)
Flip cardA document that defines the scope, methods, timing, and communication procedures authorized for a penetration test.
- Prevents legal issues by defining authorization boundaries
- Includes emergency stop/contact procedures
- Distinct from SOW, which focuses on deliverables/cost
Memory trick: Rules of Engagement Set the Battlefield Boundaries