CompTIA Security+ (SY0-701) flashcards
212 free flashcards. Tap a card to flip it.
Insecure Deserialization
Flip cardA vulnerability where an application deserializes untrusted data without validation, allowing attackers to manipulate serialized objects to execute code or alter logic.
- Common in Java, PHP, and .NET applications using object serialization
- Can lead to remote code execution, denial of service, or privilege escalation
- Mitigated by avoiding native serialization for untrusted data and using integrity checks
Memory trick: Deserialization: unwrapping a gift box that's rigged to explode.
Supply Chain Attack
Flip cardAn attack that compromises a trusted third-party vendor, supplier, or software update mechanism to distribute malicious code to downstream customers.
- Exploits trust in legitimate vendors/updates
- Can affect many organizations simultaneously
- Mitigated by code signing verification, vendor risk assessments, and SBOM review
Memory trick: Poison the well at the source and everyone downstream drinks it.
Residual Risk
Flip cardThe risk that remains after security controls have been implemented to reduce the inherent risk level.
- Inherent risk = risk before controls; residual risk = risk after controls
- Organizations compare residual risk to risk appetite to decide if further action is needed
- Cannot be reduced to zero — some risk always remains
Memory trick: Inherent is 'in the beginning'; residual is what's 'left over.'
Change Management
Flip cardA formal process requiring review, approval, testing, and documentation before changes are made to production systems, reducing the risk of unintended outages.
- Includes a Change Advisory Board (CAB) in many orgs
- Requires rollback plans for failed changes
- Bypassing it is a common root cause of outages
Memory trick: Skipping change management is like performing surgery without checking the chart first.
Risk Acceptance
Flip cardA risk response strategy where an organization decides to take no action to reduce a risk because the cost of treatment exceeds the potential impact.
- Often used for low-probability, low-impact risks
- Requires formal sign-off and documentation in the risk register
- Different from ignoring risk—it is a deliberate, documented decision
Memory trick: Accept, Avoid, Transfer, Mitigate—the four risk response verbs
Rollback Plan
Flip cardA documented procedure to revert a system to its prior state if a change causes unexpected issues.
- Required component of formal change management process
- Reduces risk of prolonged outages from failed changes
- Should be tested prior to change implementation when possible
Memory trick: No rollback, no go-back
IaC Security Scanning
Flip cardThe practice of statically analyzing Infrastructure as Code templates (e.g., Terraform, CloudFormation) for security misconfigurations before they are deployed.
- Also called 'shift-left' security testing
- Catches issues like public buckets, open security groups, missing encryption
- Integrated into CI/CD pipelines to block insecure deployments
Memory trick: 'Scan the blueprint before you build the house.'
Zero Trust Architecture
Flip cardA security model that assumes no implicit trust for any user or device, requiring continuous verification and least-privilege access to individual resources regardless of network location.
- Core principle: 'never trust, always verify'
- Relies on strong identity, device posture, and microsegmentation
- Eliminates the traditional trusted internal network concept
Memory trick: Trust nobody, verify everybody, every time.
Container Image Scanning
Flip cardA CI/CD pipeline security control that inspects container image layers and installed packages for known vulnerabilities (CVEs) before deployment.
- Shift-left security practice integrated into build pipelines
- Often blocks promotion of images above a risk threshold
- Complements image signing and least-privilege runtime configs
Memory trick: Scan the box before you ship it.
Data Sanitization / Media Destruction
Flip cardThe process of permanently destroying or erasing data from storage media so it cannot be recovered, ranging from overwriting to physical destruction.
- Clear: logical overwrite; Purge: degaussing/cryptographic erase; Destroy: shredding/incineration
- Highly sensitive data typically requires physical destruction
- NIST SP 800-88 defines sanitization methods and assurance levels
Memory trick: Shred it to confetti so no data ghost remains.
Hacktivist
Flip cardA threat actor who attacks systems to promote a political, social, or ideological cause rather than for financial gain.
- Often defaces websites or leaks data to embarrass targets
- Publicly claims responsibility to gain attention
- Motivation is ideology, not profit
Memory trick: Hacktivists shout their cause, not their bank account.
Incident Containment Strategies
Flip cardTechniques used during incident response to stop threat propagation while balancing the need to preserve evidence and business continuity.
- Segmentation isolates traffic without shutting systems down
- Isolation/quarantine removes single hosts from the network
- Full shutdown destroys volatile evidence
- Strategy choice depends on scope, evidence needs, and business impact
Memory trick: Segment the sick ward, don't shut off the hospital
Write Blocker
Flip cardA hardware or software tool that prevents any write operations to a storage device during forensic acquisition, preserving evidence integrity.
- Allows read-only access to original media
- Essential for maintaining evidentiary integrity
- Used before imaging a drive
Memory trick: A write blocker is a one-way mirror: you can look in, but nothing can get out or change.
Data at Rest
Flip cardData that is stored on a disk, database, or backup media and not currently being transmitted or processed.
- Protected primarily with encryption (e.g., AES-256, BitLocker, TDE)
- Contrasts with data in transit (TLS/IPsec) and data in use (memory encryption)
- Loss of encryption keys can still expose data even if encrypted
Memory trick: 'Resting data needs a locked box' - encrypt it where it sits.
Typosquatting
Flip cardA technique where attackers register domain names similar to legitimate ones (misspellings, transpositions) to deceive users, often for phishing or fraud.
- Often combined with BEC or phishing emails
- Relies on visual similarity to trick recipients
- Mitigated by defensive domain registration and email domain monitoring
Memory trick: Swap two letters and slip past the eye — typo becomes trap.
Policy Decision Point (PDP)
Flip cardIn zero trust architecture, the control-plane component that evaluates access requests against policy and decides whether to allow them.
- Works with policy enforcement point (PEP)
- Part of the control plane, not data plane
- Central to NIST zero trust model (SP 800-207)
Memory trick: Decide first (PDP), then enforce (PEP)
False Positive (Vulnerability Scanning)
Flip cardAn alert indicating a vulnerability exists when, upon verification, it actually does not, often due to outdated scanner signatures or environmental context.
- Wastes analyst time if not verified
- Common with credentialed vs uncredentialed scans
- Manual validation reduces false positive rate
Memory trick: A false positive is a smoke alarm 🚨 going off from toast, not an actual fire.
Acceptable Use Policy (AUP)
Flip cardA policy that defines permitted and prohibited uses of an organization's IT systems and resources by employees or users.
- Typically signed as a condition of network access
- Covers personal use, prohibited software, and data handling
- Violation can result in disciplinary action or termination
Memory trick: AUP = 'Allowed Uses, Please' — the rulebook for using company gear.
Compensating Control
Flip cardAn alternative security measure implemented when a required control cannot be directly applied, providing equivalent risk mitigation.
- Common in compliance frameworks like PCI DSS when a specific requirement can't be met
- Must provide a similar level of protection as the original control
- Combines multiple safeguards (e.g., segmentation + monitoring) to offset the gap
Memory trick: Compensating = 'making up for' what's missing.
Data Masking
Flip cardA technique that obscures or substitutes sensitive data with realistic fictitious values while preserving format, commonly used in non-production environments.
- Preserves data format/usability for testing
- Different from encryption (data remains 'readable' but fake)
- Static masking creates a permanently altered copy
- Dynamic masking obscures data on-the-fly at query time
Memory trick: Masking wears a disguise — same shape, fake face
Vulnerability Assessment vs. Penetration Test
Flip cardA vulnerability assessment identifies and catalogs known weaknesses without exploitation, while a penetration test actively exploits vulnerabilities to demonstrate real-world impact.
- Vulnerability assessments are typically automated and broader in scope
- Penetration tests are more targeted and require exploitation authorization
- Both support the overall risk management process
Memory trick: Assess finds the door is unlocked; a pen test walks through it.
Differential Backup Restore
Flip cardA backup strategy where each differential backup contains all changes since the last full backup, so restoration requires only the full backup plus the latest differential.
- Differential size grows each day until next full backup
- Restore = full backup + most recent differential (2 sets)
- Contrasts with incremental, which requires full + every incremental since
Memory trick: Differential remembers everything since Sunday.
Tokenization
Flip cardA data protection technique that replaces sensitive data with a non-sensitive placeholder (token) that maps back to the original value only within a secure tokenization vault.
- Reduces compliance scope (e.g., PCI DSS) by removing sensitive data from most systems
- Tokens have no mathematical relationship to the original data, unlike encryption
- Different from masking, which only obscures display, not storage
Memory trick: 'Swap the real card for a claim ticket — the ticket means nothing outside the vault.'
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable length of time a system or service can be down after a disruption before it must be restored.
- Set by business requirements/SLAs
- Drives DR site selection (hot/warm/cold)
- Measured in downtime duration, not data loss
Memory trick: RTO = Time to Turn it back On.
Incident Response Lifecycle
Flip cardA structured process for handling security incidents consisting of preparation, identification, containment, eradication, recovery, and lessons learned.
- Preparation: policies, tools, training in place beforehand
- Identification: detect and confirm the incident
- Containment: isolate affected systems to stop spread
- Eradication/Recovery: remove threat, restore systems
Memory trick: Prepare, ID, Contain, Eradicate, Recover, Learn.
Intrusion Prevention System (IPS)
Flip cardAn inline network security device that detects and actively blocks malicious traffic in real time, unlike a passive IDS that only alerts.
- Deployed inline (in the traffic path)
- Can drop packets or reset connections
- Uses signature and/or anomaly-based detection
Memory trick: IPS is a security guard who physically stops the intruder; IDS just shouts an alarm.
On-Path (Man-in-the-Middle) Attack
Flip cardAn attack where the threat actor secretly intercepts and possibly alters communication between two parties who believe they are directly communicating.
- Often involves forged certificates or ARP spoofing to position the attacker
- Common on unsecured public Wi-Fi networks
- Mitigated with HTTPS/TLS validation, VPNs, and certificate pinning
Memory trick: The attacker stands 'on the path' between you and your bank.
SOC 2 Type II Report
Flip cardAn independent audit report evaluating the design and operating effectiveness of a service organization's security controls over a specified period, typically shared privately with customers.
- SOC 1 = financial reporting controls
- SOC 2 Type I = design only, at a point in time
- SOC 2 Type II = design AND operating effectiveness over time
Memory trick: SOC 2 Type Two Tests Time, Not Just a Snapshot
ALE Calculation
Flip cardAnnualized Loss Expectancy (ALE) represents the expected yearly monetary loss from a risk, calculated as SLE multiplied by ARO.
- SLE = Single Loss Expectancy (cost per incident)
- ARO = Annualized Rate of Occurrence (frequency per year)
- ALE = SLE × ARO
Memory trick: Annual Loss = Single Loss times how Often it Recurs
Chain of Custody
Flip cardA documented record tracking the handling, transfer, and storage of evidence from collection to presentation in court.
- Establishes evidence authenticity and integrity
- Records who, what, when, where, and why for each transfer
- Break in chain can render evidence inadmissible
Memory trick: Every hand that touches it must sign the chain.
Script Kiddie
Flip cardA low-skill attacker who uses pre-made hacking tools or scripts without understanding the underlying mechanics.
- Motivated by curiosity, notoriety, or thrill-seeking
- Relies on publicly available exploit kits
- Low sophistication but can still cause real damage
Memory trick: Script kiddie: 'copy-paste hacker' with a rented toolkit.
Attestation of Compliance (AOC)
Flip cardA formal document certifying that an organization has met the requirements of a specific compliance standard, often signed by an assessor.
- Common in PCI DSS assessments
- Signed by a Qualified Security Assessor (QSA) or self-assessed
- Provides evidence to partners/regulators of compliance status
Memory trick: AOC = 'Assessor's Official Certificate' of compliance.
Zero-Day Vulnerability
Flip cardA software flaw that is unknown to or unaddressed by the vendor, often exploited before a patch is available.
- No official patch exists at time of exploitation
- High risk due to lack of defenses
- Often sold/traded on underground markets before disclosure
Memory trick: Zero-day means zero days of warning before it's used against you.
Standard Change
Flip cardA low-risk, pre-approved, repeatable change that follows an established procedure without requiring individual CAB review.
- Pre-approved and well-documented
- Low risk and repeatable
- Contrasts with normal changes (require CAB approval) and emergency changes (urgent, expedited)
Memory trick: Standard = stamped in advance, no need to ask again.
Network ACL (NACL)
Flip cardA stateless, subnet-level firewall in cloud networking that evaluates inbound and outbound rules for every packet, requiring explicit rules for both request and return traffic.
- Stateless: return traffic must be explicitly allowed
- Operates at the subnet level, not per-instance
- Contrasts with stateful security groups
Memory trick: NACL checks every packet, coming and going.
SLA Uptime Calculation
Flip cardA Service Level Agreement (SLA) specifies a guaranteed availability percentage; allowed downtime is calculated as total time multiplied by (1 - availability).
- Total hours in a year = 8,760
- 99.9% uptime allows ~8.76 hours downtime/year
- Higher 'nines' of availability mean exponentially less allowed downtime
Memory trick: Each extra 'nine' shrinks downtime by 10x — the Rule of Nines.
Pretexting
Flip cardA social engineering technique where an attacker fabricates a believable false scenario or identity to manipulate a victim into revealing information or performing an action.
- Often combined with vishing, phishing, or impersonation
- Relies on establishing false trust or authority
- Common pretexts include IT support, auditors, or executives
Memory trick: Pretexting is the script; vishing is the stage (the phone call).
CVSS Scoring
Flip cardCommon Vulnerability Scoring System rates vulnerability severity from 0.0 to 10.0, guiding remediation prioritization.
- 0.1-3.9 = Low
- 4.0-6.9 = Medium
- 7.0-8.9 = High
- 9.0-10.0 = Critical
Memory trick: Nine and up, fix it right now.
Command Injection
Flip cardA vulnerability where an application passes untrusted user input directly to a system shell, allowing an attacker to execute arbitrary OS commands.
- Often uses shell metacharacters like ; | & to chain commands
- Mitigated by input validation and avoiding shell calls with user input
- Can lead to full system compromise
Memory trick: A semicolon in the input is the attacker's command chain-link.
Time Synchronization (NTP) for Log Correlation
Flip cardThe practice of synchronizing all systems to a common authoritative time source (NTP) to ensure consistent, accurate timestamps for log correlation and forensic analysis.
- Clock drift without NTP can make timelines unreliable during investigations
- Critical for SIEM correlation across multiple log sources
- NTP servers typically sync to a stratum hierarchy rooted in atomic/GPS clocks
Memory trick: Every clock must march to the same drumbeat (NTP) or the story falls apart.
DLL Sideloading (Hijacking)
Flip cardAn attack that exploits an application's insecure DLL search order to load a malicious library instead of the legitimate one, achieving code execution with the app's privileges.
- Exploits Windows library search order precedence
- Malicious DLL is placed in a directory searched before the trusted system path
- Mitigated by using fully qualified library paths and secure search settings
Memory trick: Sideloading swaps in a fake library book before you reach the real shelf.
Web Application Firewall (WAF)
Flip cardA security appliance or service that filters, monitors, and blocks HTTP/HTTPS traffic to protect web applications from application-layer attacks.
- Blocks SQL injection, XSS, and other OWASP Top 10 threats
- Operates at Layer 7 (application layer)
- Can be deployed inline, as a reverse proxy, or cloud-based
- Complements, not replaces, secure coding practices
Memory trick: WAF Watches Application Fields for injected junk
XML External Entity (XXE) Injection
Flip cardA vulnerability where a poorly configured XML parser processes external entity references, allowing attackers to read local files, perform SSRF, or cause denial of service.
- Exploits DOCTYPE and ENTITY declarations in XML input
- Mitigated by disabling external entity processing in parsers
- Can lead to file disclosure, SSRF, or DoS
Memory trick: XXE: eXtra eXternal Entities let attackers peek at your files.
Golden Ticket Attack
Flip cardAn attack that uses the krbtgt account's password hash to forge Kerberos TGTs, granting attackers persistent, domain-wide access.
- Requires krbtgt hash compromise, typically from a domain controller
- Grants access even after user password resets
- Mitigated by resetting krbtgt password (twice) and monitoring ticket lifetimes
Memory trick: The golden ticket is the master key that opens every domain door forever.
Kubernetes Secrets
Flip cardA Kubernetes API object used to store and manage sensitive information such as passwords, tokens, and keys separately from application code and pod specs.
- Can be encrypted at rest when etcd encryption is enabled.
- Access controlled via Kubernetes RBAC.
- Distinct from ConfigMaps, which are meant for non-sensitive data.
Memory trick: Secrets for passwords, ConfigMaps for settings.
Order of Volatility
Flip cardA forensic principle dictating the sequence for collecting evidence, starting with the most volatile (likely to change or disappear) data first.
- Order: CPU registers/cache > RAM > swap/paging > disk > logs > archival media
- RAM captures running processes, network connections, encryption keys
- Volatile data lost on reboot/power-off
- Guides evidence collection priority during live forensics
Memory trick: Grab the ghost (RAM) before it vanishes.
Service Mesh (mTLS)
Flip cardAn infrastructure layer that manages service-to-service communication in microservices architectures, typically using sidecar proxies to enforce mutual TLS and policy without changing application code.
- Sidecar proxies (e.g., Envoy) run alongside each service instance
- Provides mTLS, traffic policy, observability, and retries transparently
- Examples: Istio, Linkerd
Memory trick: 'A mesh of tiny bodyguards encrypts every handshake between services.'
Gray-Box Penetration Test
Flip cardA penetration test in which the tester is given partial knowledge of the target environment, such as limited credentials or network diagrams, but not full internal documentation.
- Simulates an attacker with insider-level but limited access
- Balances the realism of black-box with the efficiency of white-box testing
- Contrast with black-box (no knowledge) and white-box (full knowledge)
Memory trick: Black=blind, White=full view, Gray=partial peek
Data Sovereignty
Flip cardThe concept that data is subject to the laws of the country or jurisdiction where it is physically located or collected, affecting where it can legally be stored or processed.
- Relevant to regulations like GDPR for EU citizen data
- May require data residency within specific borders
- Cloud providers often offer region-specific data centers to comply
Memory trick: Data obeys the laws of the land it lives on.
Data Loss Prevention (DLP)
Flip cardA security tool that identifies and blocks unauthorized transmission of sensitive data such as PII, PCI, or intellectual property.
- Monitors data in motion, at rest, and in use
- Can block, quarantine, or alert on policy violations
- Uses pattern matching (e.g., credit card regex)
- Deployed at email gateways, endpoints, and network egress
Memory trick: DLP = Don't Leak Private data.
Mobile Device Management (MDM)
Flip cardA platform that centrally enforces security policies, deploys applications, and can remotely wipe or lock managed mobile devices.
- Supports remote wipe and lock for lost/stolen devices
- Enforces encryption, PIN, and app whitelisting policies
- Often paired with BYOD or corporate-owned device programs
Memory trick: MDM is the remote control for every company phone.
Malicious Insider
Flip cardAn employee, contractor, or partner who intentionally misuses authorized access to harm the organization or benefit themselves.
- Already has legitimate credentials, bypassing perimeter defenses
- Motivated by financial gain, revenge, or ideology
- Detected mainly through behavior analytics and audit logging
Memory trick: The insider already has the keys—no need to pick the lock.
Credential Stuffing
Flip cardAn attack that uses username/password pairs stolen from one breach to attempt logins on other, unrelated services, exploiting password reuse.
- Relies on breached credential dumps
- Effective because many users reuse passwords
- Mitigated with MFA and breach-monitoring services
Memory trick: Stuffing = 'shove the same old keys into every door on the street.'
Logic Bomb
Flip cardMalicious code deliberately planted within a program that remains inactive until a specific trigger condition is met, then executes a harmful action.
- Often planted by insiders with legitimate access
- Triggered by dates, events, or account changes
- Detected through code reviews and change monitoring
Memory trick: A logic bomb waits like a landmine for the right footstep (trigger).
Jump Server (Bastion Host)
Flip cardA hardened, monitored system that administrators must connect through to reach internal network resources, reducing direct exposure of internal hosts.
- Centralizes and logs administrative access
- Reduces attack surface of internal servers
- Often placed in a DMZ or management network
Memory trick: One door in, watched by a guard.
Lateral Movement Indicators
Flip cardNetwork behavior patterns, such as unusual ports and internal connection spikes following external C2 communication, that suggest an attacker is spreading through a network.
- Port 4444 is a common default for Metasploit reverse shells
- NetFlow analysis helps identify anomalous traffic patterns
- Spike in internal connections after external contact suggests pivoting
Memory trick: Port 4444 knocking, then spreading like a spider.
End-of-Life (EOL) / End-of-Support (EOS) Software
Flip cardSoftware or hardware that a vendor no longer maintains or patches, creating unmitigated security exposure over time.
- No further security patches after EOS date
- Common target for exploit development
- Should be tracked in asset management/CMDB
- Mitigations include upgrading, isolation, or compensating controls
Memory trick: When support Ends, patches Leave — that's EOL's real risk
Risk Matrix (Heat Map)
Flip cardA visual tool that plots risks based on likelihood and impact, often using color coding, to help prioritize which risks require the most attention.
- Commonly uses a grid with likelihood on one axis and impact on the other
- Color coding (green/yellow/red) communicates severity at a glance
- Complements the risk register by visualizing qualitative risk data
Memory trick: Matrix = map of likelihood x impact, colored like a traffic light
Account Lockout Duration
Flip cardThe length of time an account stays locked after exceeding the allowed number of failed login attempts before it automatically unlocks.
- Works with lockout threshold (max failed attempts)
- Reduces brute-force success without permanent lockout
- Balances security with user convenience
Memory trick: Think of a timed vault door: it locks after too many wrong tries and reopens itself after the timer runs out.
Geographic Dispersion
Flip cardA resilience strategy that distributes systems, data, and infrastructure across physically separate locations to reduce the risk that a single regional event causes total outage or data loss.
- Mitigates regional disasters (earthquakes, power grid failures)
- Often paired with synchronous or asynchronous replication
- Key design factor in multi-region cloud architectures
Memory trick: Don't put all your servers in one region's basket.