CompTIA Security+ (SY0-701) flashcards
212 free flashcards. Tap a card to flip it.
Risk-Based Vulnerability Prioritization
Flip cardAn approach to remediation that considers CVSS score alongside exploit availability, asset criticality, and exposure rather than score alone.
- A lower CVSS score with active exploitation can be higher risk
- Asset exposure (internet-facing) increases real-world risk
- Frameworks like EPSS incorporate exploit likelihood into prioritization
Memory trick: Score alone doesn't tell the whole story—context is king.
Vendor Risk Monitoring
Flip cardThe ongoing process of reassessing a third-party vendor's security posture throughout the life of the business relationship, distinct from one-time pre-contract due diligence.
- Due diligence happens before signing; monitoring happens continuously after
- May include periodic questionnaires, updated reports, and audits
- Reduces risk from a vendor's security posture degrading over time
Memory trick: Due diligence before the deal, monitoring for the whole relationship.
SIEM Rule Tuning
Flip cardThe process of adjusting correlation rules and alert thresholds in a SIEM to reduce false positives and alert fatigue while preserving detection of real threats.
- Alert fatigue leads to missed true positives
- Tuning reduces noise, improves signal-to-noise ratio
- Correlation rules combine multiple log events
- Ongoing tuning is a ongoing SOC maintenance task
Memory trick: Tune the noise, catch the signal.
Risk Register
Flip cardA document that catalogs identified risks along with their likelihood, impact, owner, and treatment status for ongoing tracking.
- Central repository for all identified organizational risks
- Includes risk owner, likelihood, impact, and mitigation status
- Reviewed and updated regularly as part of risk management lifecycle
Memory trick: A register keeps a running list — like a ledger of every risk.
Birthday Attack / Hash Collision
Flip cardA cryptographic attack that exploits the mathematical probability of two different inputs producing the same hash output, undermining hash integrity guarantees.
- Named after the birthday paradox in probability
- Risk increases with smaller hash digest sizes (e.g., MD5, SHA-1)
- Mitigated by using strong, collision-resistant algorithms like SHA-256
Memory trick: Just like shared birthdays in a room, hash collisions happen sooner than expected.
Legal Hold
Flip cardA directive that suspends normal data deletion and retention schedules to preserve information relevant to anticipated or ongoing legal proceedings.
- Overrides automated retention/deletion policies
- Failure to comply can result in spoliation sanctions
- Typically issued by legal counsel
Memory trick: Hold the data hostage until the case is closed.
Cost-Benefit Analysis of Controls
Flip cardComparing the reduction in ALE achieved by a control against the annual cost of that control determines whether implementation is financially justified.
- ALE = SLE × ARO
- Net benefit = (ALE before − ALE after) − control cost
- Positive net benefit justifies implementing the control
Memory trick: Savings Minus Spending Equals Sensible Decision
Credentialed Vulnerability Scan
Flip cardA vulnerability scan performed using valid login credentials to inspect the internal state of a system.
- Provides deeper visibility than non-credentialed scans
- Reduces false positives/negatives
- Requires proper account permissions and secure credential storage
Memory trick: Credentials unlock the inside view.
Due Care
Flip cardThe ongoing, reasonable actions an organization takes to protect assets and maintain an acceptable security posture, often exceeding minimum policy requirements.
- Due care is continual/operational; due diligence is investigative/pre-decision
- Failure to exercise due care can result in legal liability for negligence
- Example: patching faster than required, enforcing strong access controls
Memory trick: Diligence = research before, Care = action during
3-2-1 Backup Rule
Flip cardA best-practice backup strategy: 3 copies of data, on 2 different media types, with 1 copy stored off-site.
- Protects against media failure, ransomware, and site disasters.
- Off-site copy can be cloud storage or a remote physical location.
- Different media types reduce risk of a single point of failure.
Memory trick: Three copies, two media, one far away.
Air-Gapped Network
Flip cardA network physically isolated from other networks and the internet, requiring manual/offline methods to transfer data.
- Used for highly classified or critical control systems
- Eliminates remote network-based attack vectors
- Data moved via approved removable media
Memory trick: No wires, no waves, no way in.
Pass-the-Hash
Flip cardAn attack technique where a captured password hash is used to authenticate to systems without decrypting it into plaintext.
- Exploits NTLM authentication weaknesses
- No need to crack the password
- Mitigated by Credential Guard and reducing hash caching
Memory trick: Pass the hash like passing a note — no need to read it, just hand it over.
Nation-State Threat Actor
Flip cardA government-sponsored group conducting cyber operations for espionage, sabotage, or strategic advantage.
- Highly resourced and patient
- Often targets government, defense, and critical infrastructure
- Goal is typically long-term access, not quick disruption
Memory trick: Spies stay Silent and Slow for Secrets.
Just-in-Time (JIT) Access
Flip cardA privileged access management technique that grants elevated permissions only for the time needed to complete a task, then revokes them automatically.
- Reduces standing privileged account risk
- Common in PAM solutions
- Often paired with approval workflows
Memory trick: Access ticks away like a timer.
Technical Threat Intelligence
Flip cardActionable, low-level data points (Indicators of Compromise - IOCs) that can be used to detect and block specific threats, such as malicious IP addresses, domain names, file hashes, or URLs.
- Focuses on specific IOCs.
- Easily integrated into security tools (firewalls, SIEM).
- Often short-lived as attackers change infrastructure.
Memory trick: For 'Technical' details like an IP, think 'T' for 'Tiny' factual pieces.
Security Orchestration, Automation, and Response (SOAR)
Flip cardA platform that integrates security tools, automates security tasks, and orchestrates incident response workflows to improve efficiency and speed.
- Connects disparate security solutions.
- Automates repetitive tasks, reducing manual effort.
- Enables faster and more consistent incident response.
Memory trick: SOAR is the 'Orchestra Conductor' for security tools.
Next-Generation Antivirus (NGAV)
Flip cardAn advanced endpoint protection solution that uses behavioral analysis, machine learning, and AI to detect and prevent both known and unknown threats, often without relying solely on signatures.
- Goes beyond signature-based detection.
- Focuses on behavioral analysis and machine learning.
- Designed to protect against fileless malware and zero-day exploits.
Memory trick: NGAV is like AV's smarter, future-ready kid.
Zero Trust Principle: Verify Explicitly
Flip cardA core principle of Zero Trust that requires all access requests to be authenticated and authorized based on all available data points (user, device, location, service, data sensitivity) and continuously re-evaluated.
- Never trust, always verify.
- Access is not granted implicitly.
- Verification is continuous, not a one-time event.
Memory trick: VERIFY, LEAST, ASSUME: Verify everything, give least privilege, assume breach.
Application Whitelisting
Flip cardA security approach that allows only an explicitly approved list of applications to execute on a system, blocking all others by default.
- Highly effective against malware
- Reduces attack surface
- Can be complex to manage in dynamic environments
Memory trick: Only good apps get a green light.
Operational Threat Intelligence
Flip cardThreat intelligence that provides information about specific threats, campaigns, and the TTPs of threat actors, directly aiding security operations.
- Focuses on current, active threats and threat actor methods.
- Helps security teams understand 'how' and 'who' is attacking.
- Directly supports detection, analysis, and response activities.
Memory trick: Operational TI is 'On the Ground' intel for active defense.
Firewall with Integrated Threat Intelligence
Flip cardA network firewall that automatically consumes and applies external threat intelligence feeds to block traffic from known malicious IP addresses, domains, or other indicators of compromise.
- Automates blocking of known threats.
- Leverages external threat data.
- Enhances network perimeter security in real-time.
Memory trick: A 'Firewall' with 'Intelligence' is like a smart 'Guard' at the gate, knowing who to block.
Data Integrity (Digital Forensics)
Flip cardThe principle that digital evidence must remain complete, accurate, and unaltered from the moment of collection through analysis and presentation.
- Crucial for admissibility of evidence in legal proceedings.
- Verified using cryptographic hashing (e.g., MD5, SHA-256).
- Any change to the data will result in a different hash value.
Memory trick: Hashing ensures data 'Integrity' – it's Intact!
Forensic Write Blocker
Flip cardA hardware or software tool used in digital forensics to prevent any data from being written to a source drive, thus preserving the integrity of the original evidence during acquisition.
- Crucial for maintaining chain of custody and evidence admissibility.
- Can be hardware-based (physical device) or software-based.
- Ensures the original data remains unaltered.
Memory trick: Write Blocker: 'Block' any 'writes' to protect the evidence.
Vulnerability Management
Flip cardThe cyclical process of identifying, assessing, prioritizing, remediating, and mitigating software and system vulnerabilities.
- Includes patching and configuration management
- Aims to reduce attack surface
- Ongoing process, not a one-time event
Memory trick: Operations build and guard the security structure.
Simulated Phishing Campaign
Flip cardA controlled exercise where fake phishing emails are sent to employees to test their awareness and identify training needs.
- Measures employee susceptibility to social engineering.
- Identifies individuals needing more training.
- Provides metrics for security awareness program effectiveness.
Memory trick: To CATCH a phish, you have to GO FISHING, but with a FAKE WORM.
Indicator of Compromise (IOC)
Flip cardA piece of forensic data found on a network or operating system that indicates a potential intrusion or malicious activity.
- Specific, observable artifact of an attack.
- Examples include malicious IP addresses, domains, file hashes, registry keys.
- Used to detect, investigate, and prevent future attacks.
Memory trick: An 'IOC' is an 'Individual Observable Clue' of a breach.
Vulnerability Scanner Tuning
Flip cardThe process of adjusting the configuration and parameters of a vulnerability scanner to optimize its performance, reduce false positives, and ensure relevant results.
- Reduces 'noise' in scan reports.
- Customizes scans to organizational context.
- Improves accuracy and actionability of findings.
Memory trick: To make the scanner 'sing' a clearer tune, you need to 'tune' its settings.
Next-Generation Firewall (NGFW)
Flip cardA deep-packet inspection firewall that moves beyond port/protocol inspection and blocking to add application-level inspection, intrusion prevention, and intelligence from outside the firewall.
- Combines traditional firewall with IPS and application awareness.
- Often integrates threat intelligence feeds.
- Provides deeper inspection for web attacks and malware.
Memory trick: For 'Next-Gen' threats, you need a 'Next-Gen' firewall that does it 'All'.
False Positive Tuning (Vulnerability Management)
Flip cardThe process of refining vulnerability scanner configurations, adding exclusions, or providing contextual information to reduce the number of erroneous alerts that are not true vulnerabilities.
- Reduces alert fatigue and wasted effort for security teams.
- Involves understanding compensating controls or environmental factors.
- Can include adjusting scan policies, creating custom checks, or using exceptions.
Memory trick: To tune out false positives, you need 'Fine-Tuning' of the scanner.
Zero Trust (Continuous Verification)
Flip cardA security model that requires strict identity verification for every person and device attempting to access resources on a private network, regardless of whether they are inside or outside the network perimeter. Continuous verification is a core principle.
- Never trust, always verify
- Microsegmentation is key
- Dynamic, context-aware access decisions
Memory trick: Zero trust: Verify everything, always, everywhere.
Continuous Verification (Zero Trust)
Flip cardA core principle of Zero Trust that requires every access request to be authenticated, authorized, and continuously validated based on policy, context, and risk, regardless of location.
- Trust is never granted implicitly; it must be explicitly established and maintained.
- Access decisions are dynamic and adaptable.
- Applies to users, devices, applications, and data.
Memory trick: Zero Trust means 'Verify Every Access' always.
Preventative Control
Flip cardA type of security control designed to stop an incident from occurring by actively blocking or mitigating threats.
- Acts proactively to prevent security breaches.
- Examples include firewalls, access control lists, and encryption.
- Part of an organization's defense-in-depth strategy.
Memory trick: Preventing problems before they pop up is always preferred.