CompTIA SecurityX (CAS-005) flashcards
156 free flashcards. Tap a card to flip it.
SIEM Correlation Rules
Flip cardLogic-based expressions within a Security Information and Event Management (SIEM) system that analyze multiple security events from different sources to identify patterns indicative of a threat or security incident.
- Connects disparate events to form a complete picture.
- Reduces false positives and alert fatigue.
- Enhances detection of complex, multi-stage attacks.
Memory trick: Smart SIEMs don't just collect, they connect and prioritize.
netstat
Flip cardThe `netstat` command (network statistics) is a command-line network utility that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics.
- Used for network troubleshooting and performance monitoring.
- Can show listening ports and established connections.
- Various flags (e.g., -t, -u, -l, -n, -p) customize output.
- Crucial for identifying active services during hardening.
Memory trick: Netstat Knows Every Open Port and Process
iptables
Flip cardA command-line utility that allows system administrators to configure the IP packet filter rules of the Linux kernel firewall (Netfilter).
- Manages packet filtering and NAT.
- Uses chains (INPUT, OUTPUT, FORWARD) and tables (filter, nat, mangle, raw).
- Rules are processed sequentially.
Memory trick: iptables Intelligently Protects The Access.
Mutual TLS (mTLS)
Flip cardAn extension of TLS where both the client and the server present digital certificates to each other for mutual authentication, establishing a cryptographically secured and trusted communication channel.
- Provides two-way authentication (client and server).
- Ensures data confidentiality and integrity.
- Foundational for Zero Trust in service meshes.
Memory trick: mTLS: 'Mutual Trust, Layered Security' for your services.
Hardware Security Module (HSM)
Flip cardA Hardware Security Module (HSM) is a physical computing device that safeguards and manages digital keys, performs cryptographic operations, and provides strong authentication within a tamper-resistant environment.
- FIPS 140-2 validated, often Level 3 or higher.
- Protects keys from logical and physical attacks.
- Designed for high-performance, high-volume cryptographic operations.
Memory trick: HSM: high security, high volume, high compliance.
Incident Containment
Flip cardThe phase of incident response focused on limiting the scope and impact of an ongoing security incident. This involves taking immediate actions to stop the attack from spreading or causing further damage, such as isolating systems or blocking malicious traffic.
- Limits incident scope and impact.
- Requires immediate, decisive action.
- Often involves network isolation or blocking.
Memory trick: Contain the threat quickly, don't let it spread.
Domain Generation Algorithm (DGA)
Flip cardA technique used by malware to algorithmically generate a large number of new domain names that can be used as rendezvous points with their command and control (C2) servers. This makes it difficult for security teams to block all potential C2 domains.
- Generates many domains for C2 communication.
- Often results in high NXDOMAIN query rates.
- Used to evade blacklisting of fixed C2 domains.
Memory trick: Malware Generates Domains to Connect and Control.
Just-in-Time (JIT) Access
Flip cardA security principle where users are granted elevated privileges only at the moment they are needed, for a specific task, and for a limited duration.
- Minimizes standing privileges.
- Reduces attack surface.
- Enhances 'least privilege' and 'zero trust' principles.
Memory trick: JIT access gives privileges just for now, not forever.
FIDO2 Authentication
Flip cardFIDO2 is an open authentication standard that uses public-key cryptography to provide strong, phishing-resistant, and passwordless or second-factor authentication. It typically involves a FIDO authenticator (e.g., security key, biometric sensor) and a web browser or application.
- Uses public-key cryptography for strong security.
- Phishing-resistant by design.
- Prevents replay attacks.
- Supports passwordless and second-factor authentication.
Memory trick: For top secrets, prove who you are with your body and your special key.
Fileless Malware Detection (Memory)
Flip cardThe process of identifying malware that operates entirely in memory without writing files to disk, often by injecting malicious code into legitimate processes or running scripts directly in memory.
- Leaves minimal forensic traces on disk.
- Requires memory forensics for detection.
- Often uses living-off-the-land binaries (LOLBins).
- Challenging to detect with traditional antivirus.
Memory trick: To find the ghost in the machine's mind, you must look directly at its thoughts.
Micro-segmentation
Flip cardA network security technique that creates secure zones to isolate individual workloads, applying granular security policies to each, rather than relying on broad network perimeters.
- Creates granular security zones
- Isolates individual workloads/services
- Enforces fine-grained policies
- Key component of Zero Trust
Memory trick: Micro-segmentation: Tiny walls for ultimate trust.
Outcome-Based Compliance Metrics
Flip cardMetrics that measure the achievement of a desired security state or regulatory objective, rather than just the implementation of controls.
- Focuses on effectiveness and results.
- Helps align disparate interpretations of requirements.
- Provides a more accurate picture of true compliance posture.
Memory trick: Outcomes show you the real score, not just the game plan.
Malware Reverse Engineering
Flip cardThe process of analyzing malicious software to understand its functionality, origin, potential impact, and how it exploits systems. This often involves disassembling code, debugging, and observing its behavior in a controlled environment.
- Deconstructs malicious code.
- Reveals exploit mechanisms and C2 protocols.
- Essential for understanding zero-day attacks.
Memory trick: To Dissect a Zero-Day, You Must Reverse Engineer the Code.
ISO 27001
Flip cardAn international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) within the context of the organization's overall business risks.
- Provides a framework for an ISMS.
- Focuses on risk management and regulatory compliance.
- Internationally recognized and certifiable.
Memory trick: ISO-late your risks with a certified ISMS.
Linux Auditd
Flip cardThe Linux Audit System (auditd) provides a way to track security-relevant information on a system. It can log system calls, file access, process execution, and network activity with high granularity, making it invaluable for forensic analysis and compliance.
- Tracks system calls and file access.
- Records user, process, and command details.
- Crucial for forensic investigations on Linux.
Memory trick: Auditd Logs the Actions, Syslog Logs the Status.
AI Accountability & Transparency
Flip cardAccountability ensures clear responsibility for AI system outcomes and failures. Transparency requires AI systems to be understandable and their decision-making processes explainable.
- Addresses legal and ethical responsibility.
- Mitigates 'black box' problem.
- Crucial for trust and regulatory compliance.
Memory trick: AI: Be Accountable and Transparent, especially in healthcare.
Multi-Factor Authentication (MFA)
Flip cardA security system that requires users to provide two or more verification factors to gain access to a resource, such as an application, online account, or VPN. This adds an extra layer of security beyond just a password.
- Uses factors from different categories: knowledge, possession, inherence.
- Significantly reduces risk of credential theft.
- Essential for protecting against phishing and brute-force attacks.
Memory trick: To keep keys safe, add more locks.
AI Ethics and Fairness
Flip cardA critical aspect of AI governance focused on ensuring AI systems are developed and used responsibly, without perpetuating biases, discriminating against groups, or making decisions that are opaque or unjust.
- Addresses bias, discrimination, transparency, and accountability.
- Crucial for sensitive applications (e.g., hiring, law enforcement).
- Aims to build trust and ensure societal benefit.
Memory trick: E-R-P-S: Ethics, Robustness, Privacy, Security.
Network Segmentation
Flip cardThe practice of dividing a computer network into multiple smaller network segments or subnets, often to improve security, performance, and manageability.
- Limits lateral movement of attackers.
- Contains breaches to smaller areas.
- Enables granular access control policies.
Memory trick: Old systems need a strong, isolated castle.
OS Audit Logs
Flip cardSystem-level logs generated by an operating system that record security-relevant events, such as user logins, file access attempts, privilege escalation, and process execution. They are critical for forensic analysis and compliance.
- Records user actions on files and resources.
- Includes timestamps, user IDs, and action types.
- Essential for insider threat and forensic investigations.
Memory trick: For File Forensics, OS Audit Logs are the Gold Standard.
Virtual Private Cloud (VPC)
Flip cardA logically isolated section of a public cloud, allowing users to provision and launch resources within a virtual network that they define, with full control over IP addresses, subnets, route tables, and network gateways.
- Provides network isolation and segmentation within a public cloud.
- Enables granular control over network access and security.
- Essential for multi-tenant environments and compliance requirements.
Memory trick: Cloud network isolation is like having 'private rooms' in a big hotel, each with its own 'locked door'.
Service Mesh (mTLS)
Flip cardA service mesh is a dedicated infrastructure layer for handling service-to-service communication. It typically provides features like traffic management, observability, and security features such as mutual TLS (mTLS) for identity-based encryption and authentication.
- Enables transparent, identity-based mutual authentication (mTLS).
- Encrypts all inter-service communication.
- Provides fine-grained authorization policies based on workload identity.
- Decouples networking and security from application code, transparent to developers.
Memory trick: Service Mesh Makes Zero Trust Seamless
Kernel-Level Memory Forensics
Flip cardThe analysis of a raw memory dump (RAM image) from a compromised system, specifically focusing on kernel data structures and memory regions. This technique is crucial for detecting sophisticated malware like rootkits that hide processes, files, or network connections by subverting the operating system kernel.
- Analyzes raw RAM dumps.
- Examines kernel data structures.
- Detects hidden processes and rootkits.
- Requires specialized tools (e.g., Volatility Framework).
Memory trick: To Catch a Hidden Rootkit, You Need Kernel Memory Forensics.
Message Authentication Code (MAC)
Flip cardA short piece of information used to authenticate a message and provide integrity and authenticity assurances. It is generated using a secret key and a cryptographic hash function.
- Requires a shared secret key between sender and receiver.
- Provides both data integrity and message authenticity.
- Protects against replay attacks when combined with nonces/timestamps.
Memory trick: MACs Authenticate Critical Systems.
Redundancy and Fault Tolerance
Flip cardThe architectural principle of duplicating critical components or functions to ensure system availability and resilience against failures.
- Ensures continuous operation despite component or system failures.
- Achieved through duplication of hardware, software, or data.
- Key for high availability and disaster recovery planning.
Memory trick: Resilience is like a backup plan for when things go wrong, keeping the gears turning.
Harmonized Compliance
Flip cardA strategy to meet multiple regulatory requirements through a single, integrated set of controls and policies.
- Reduces complexity and cost in multi-jurisdictional environments.
- Focuses on identifying commonalities across regulations.
- Requires thorough understanding of all applicable laws.
Memory trick: Harmonize to simplify, don't individualize to multiply.
Policy Enforcement Mechanisms
Flip cardThe processes, tools, and procedures used to ensure that security policies and controls are consistently implemented, monitored, and maintained across an organization.
- Ensures consistent application of controls.
- Involves monitoring, auditing, and review.
- Crucial for effective governance and compliance.
Memory trick: Controls without enforcement are just good intentions.
OpenID Connect (OIDC)
Flip cardAn identity layer built on top of the OAuth 2.0 protocol, allowing clients to verify the identity of an end-user based on the authentication performed by an authorization server, and to obtain basic profile information about the end-user.
- Enables Single Sign-On (SSO)
- Works across multiple identity providers (IdPs)
- Provides identity verification and profile information
- Built on OAuth 2.0
Memory trick: OIDC opens doors to seamless identity across clouds.
Memory Injection Forensics
Flip cardA memory forensics technique used to detect malicious code (e.g., from RATs or rootkits) that has been injected into the memory space of legitimate processes, often to evade traditional endpoint detection.
- Uses tools like Volatility to analyze memory dumps.
- Identifies code sections with unusual permissions or origin.
- Crucial for detecting advanced malware that operates in memory.
Memory trick: RATs hide in memory, so deep dives reveal their tricks.
Incident Response Plan (IRP)
Flip cardA documented set of procedures and guidelines that an organization follows to prepare for, detect, respond to, and recover from security incidents.
- Structured approach to incidents.
- Minimizes damage and recovery time.
- Includes preparation, detection, containment, eradication, recovery, and post-incident activities.
Memory trick: P-D-C-E-R-P: Prepare, Detect, Contain, Eradicate, Recover, Post-Incident.
Container Image Signing
Flip cardThe process of cryptographically signing a container image to assert its origin and ensure its integrity, allowing for verification that the image has not been tampered with.
- Verifies image origin (authenticity)
- Ensures image integrity (no tampering)
- Uses digital signatures
- Crucial for supply chain security in containers
Memory trick: Sign your images, trust your code.
Linux Shell History
Flip cardLinux shell history files (e.g., ~/.bash_history) store commands executed by a user in their shell, providing a chronological record of their actions.
- Specific to each user and their shell.
- Can be manipulated or cleared by an attacker.
- Crucial for forensic analysis of user activity.
Memory trick: Audit Records History of Commands.
Service Mesh with mTLS
Flip cardA dedicated infrastructure layer for handling service-to-service communication within a microservices architecture, using mutual Transport Layer Security (mTLS) for strong authentication and encryption.
- Provides mutual authentication between services
- Encrypts all service-to-service communication
- Enhances observability and traffic management
- Key component of Zero Trust for microservices
Memory trick: Service Mesh with mTLS: The Zero Trust guard for microservices.
Security Groups (Cloud)
Flip cardIn cloud environments (e.g., AWS, Azure), Security Groups act as virtual firewalls that control inbound and outbound traffic for one or more instances. They are stateful and implicitly deny all traffic unless explicitly allowed.
- Operate at the instance level.
- Stateful (return traffic is automatically allowed).
- Implicitly deny all inbound traffic unless allowed.
- Allow granular control based on IP addresses, other security groups, and ports.
Memory trick: Security Groups are like a bouncer for each database server, only letting in specific, pre-approved guests.
DNS Exfiltration
Flip cardA technique where attackers encode data within DNS queries and responses to bypass security controls and transfer sensitive information out of a network. It leverages the legitimate and often unrestricted nature of DNS traffic.
- Uses DNS queries/responses for data transfer.
- Operates on TCP/UDP port 53.
- Often bypasses firewalls due to DNS whitelist rules.
Memory trick: Exfiltrate Data by Hiding It in Plain Sight.
Principle of Least Privilege
Flip cardA security principle that requires that a subject (user, process, program, or function) be given only the minimum set of permissions necessary to perform its legitimate tasks. This limits the potential damage if that subject is compromised.
- Grants only essential permissions.
- Limits impact of compromise.
- Crucial for sensitive data and serverless environments.
Memory trick: Serverless Functions Need the Least Privilege to Shine.
FIDO2
Flip cardFIDO2 is an open authentication standard that enables users to leverage common devices to easily and securely authenticate to online services in place of passwords, offering phishing-resistant authentication.
- Uses public-key cryptography for strong authentication.
- Supports passwordless authentication.
- Highly resistant to phishing and credential stuffing attacks.
- Comprises WebAuthn (for browsers/platforms) and CTAP2 (for authenticators).
Memory trick: FIDO's Fast Identity Defeats Phishing Online
Endpoint Audit Logs
Flip cardRecords generated by an operating system or security agent on an endpoint (workstation, server) that detail user activities, system events, file access, and device connections.
- Crucial for forensic investigations.
- Logs user logins/logouts, process execution, file operations.
- Includes removable media connections.
- Examples: Windows Event Logs, Linux auditd.
Memory trick: To solve the mystery, gather clues from the most direct source.
SAML (Security Assertion Markup Language)
Flip cardAn XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- XML-based protocol.
- Used for federated identity management.
- Enables Single Sign-On (SSO) across different security domains.
Memory trick: Federation's many standards, SAML for enterprise, OIDC for web, OAuth for access.
HTTP C2 for Data Exfiltration
Flip cardA technique where attackers use HTTP/HTTPS for command and control (C2) communication and to exfiltrate data from a compromised system, often disguised as legitimate web traffic.
- Leverages common web ports (80, 443) to evade detection.
- Often uses HTTP GET for commands, HTTP POST for data exfiltration.
- May employ unusual User-Agent strings, dynamic IPs/domains, or encrypted payloads.
- Difficult to distinguish from legitimate web traffic without deep packet inspection.
Memory trick: Look for the ghost in the machine, whispering secrets through normal channels.
Loose Coupling & Bounded Contexts
Flip cardLoose coupling in software design means components are independent and have minimal dependencies on each other. Bounded contexts define explicit boundaries within a domain where a particular model is consistent, preventing unintended side effects.
- Reduces interdependencies between services.
- Limits the scope of data and functionality within a service.
- Enhances system resilience by preventing cascading failures.
- Improves security by isolating data and functionality.
Memory trick: Microservices thrive when they are like independent islands with clear shores.
Reverse Proxy
Flip cardA reverse proxy is a server that sits in front of web servers and forwards client requests to those web servers. It acts as an intermediary, providing a single point of contact for external clients while protecting and abstracting the backend services.
- Protects backend servers from direct exposure.
- Can provide load balancing, SSL termination, caching, and security features.
- Acts as a centralized entry point for an application or microservices.
Memory trick: Think of a Reverse Proxy as the 'bouncer' at the club: it checks IDs, manages the queue, and directs you inside, protecting the VIPs.
ISO/IEC 27001
Flip cardAn international standard that provides requirements for an Information Security Management System (ISMS).
- Establishes, implements, operates, monitors, reviews, maintains, and improves an ISMS.
- Widely recognized globally for information security best practices.
- Focuses on managing information security risks systematically.
Memory trick: ISO-late your risks with a global standard.
Risk Assessment (Quantitative)
Flip cardThe process of identifying, analyzing, and evaluating risks. Quantitative risk assessment assigns numerical values to risk components (asset value, exposure factor, ARO) to calculate potential financial loss.
- Identifies and evaluates risks.
- Determines likelihood and impact.
- Informs prioritization of mitigation efforts.
Memory trick: I-A-R-M-M: Identify, Assess, Respond, Monitor, Maintain.
Kernel Rootkit Detection
Flip cardThe process of identifying malicious software (rootkits) that operates at the kernel level of an operating system to hide its presence and activities from detection tools.
- Requires kernel-level visibility (e.g., memory forensics).
- Often involves comparing active kernel structures to a known good state.
- Can hide processes, files, network connections.
- Challenges traditional OS-level detection methods.
Memory trick: To find the ghost in the machine's brain, you need to look at its core components.
STRIDE Threat Modeling
Flip cardA mnemonic used to categorize and identify threats to applications and systems.
- Developed by Microsoft.
- Helps ensure a comprehensive approach to threat identification.
- Each letter represents a specific threat category.
Memory trick: STRIDE through threats to find their core.
SOC 2 Type II Report
Flip cardA report on the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a specified period of time, issued by an independent auditor.
- Assesses controls over a period (e.g., 6-12 months).
- Provides assurance on security, availability, processing integrity, confidentiality, or privacy (Trust Services Criteria).
- Issued by an independent auditor.
Memory trick: Trust but verify with SOC 2 Type II.
DDoS Attack
Flip cardA malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple sources (bots/botnet)
- Aims to exhaust resources (bandwidth, CPU, memory)
- Prevents legitimate users from accessing services
Memory trick: Many different attacks, each with a distinct footprint.
Lateral Movement Forensics
Flip cardThe process of identifying and analyzing forensic artifacts that indicate an attacker's attempts to move from an initially compromised system to other systems within a network, often involving credential use and remote execution.
- Looks for signs of authentication to other hosts.
- Examines network connections and remote command execution.
- Key artifacts include logon events, network flows, and remote service logs.
Memory trick: To see where they went, check their logins and network trails.
Data Encryption & Integrity
Flip cardData encryption is the process of converting data into a coded format to prevent unauthorized access. Data integrity ensures that data has not been altered or corrupted and remains accurate and complete.
- Encryption protects confidentiality for data at rest and in transit.
- Integrity controls (e.g., hashing) detect unauthorized modifications.
- Both are crucial for protecting data throughout its lifecycle.
- Often implemented together for comprehensive data protection.
Memory trick: Keep your secrets locked and verify they haven't been touched.
Security Orchestration, Automation, and Response (SOAR)
Flip cardA software platform that combines incident response, security operations automation, and security orchestration capabilities to help organizations manage and respond to security incidents more efficiently.
- Automates repetitive security tasks.
- Orchestrates workflows across multiple security tools.
- Improves incident response times and consistency.
Memory trick: SOAR Soars Over Security Tasks.
Single Loss Expectancy (SLE)
Flip cardThe expected monetary loss from a single occurrence of a risk event.
- Calculated as Asset Value (AV) * Exposure Factor (EF).
- Represents the financial impact of one incident.
- A component of quantitative risk analysis.
Memory trick: SLE is the single hit, ALE is the yearly sum.
Envelope Encryption
Flip cardA cryptographic technique where data is encrypted with a unique data encryption key (DEK), and the DEK itself is then encrypted with a separate key encryption key (KEK).
- Data encrypted by DEK
- DEK encrypted by KEK
- Enables efficient key rotation (only KEK needs rotation)
- Separates data encryption from key encryption
Memory trick: Envelope: Keys within keys for easy rotation and secure data.
Data Diode
Flip cardA data diode is a hardware device that ensures data can only flow in one direction, preventing any return path.
- Enforces unidirectional data flow physically.
- Used for high-security environments like ICS/SCADA and critical infrastructure.
- Provides absolute segmentation between networks.
Memory trick: OT data flows out, never back in, like a one-way street.
Lateral Movement Risk
Flip cardThe risk that an attacker, after gaining initial access to one system within a network, can then move to other systems within the same network. This is often achieved through exploiting misconfigurations, weak credentials, or additional vulnerabilities on accessible internal hosts.
- Attacker pivots from one compromised host to another.
- Expands foothold and increases impact.
- Often uses RCE, credential theft, or misconfigurations.
Memory trick: RCE on Internal Server Rings the Alarm for Lateral Movement.
Group Managed Service Account (gMSA)
Flip cardA gMSA is a type of Active Directory account for services that provides automatic password management, simplified SPN management, and delegation of management to other administrators.
- Eliminates the need for manual password rotation.
- Suitable for services running on multiple servers.
- Enhances security by reducing static credentials.
Memory trick: Local is just here, Network uses the machine, gMSA manages itself for groups.
Centralized HSM and KMS
Flip cardA combined solution using Hardware Security Modules (HSMs) for secure key generation and storage, and a Key Management System (KMS) for managing the lifecycle and access policies of encryption keys.
- Provides FIPS-compliant hardware protection for cryptographic keys.
- Centralizes key lifecycle management (generation, rotation, revocation).
- Enforces consistent access control and auditability for keys across an enterprise.
Memory trick: To keep data safe, you need a central 'vault' for keys and a 'librarian' to manage them.
MITRE ATT&CK Framework
Flip cardA globally accessible knowledge base of adversary tactics and techniques based on real-world observations. It provides a common language and framework for describing attacker behavior across the attack lifecycle.
- Organized into Tactics (goals) and Techniques (how goals are achieved).
- Used for threat hunting, red teaming, and security control mapping.
- Helps understand adversary behavior beyond just malware signatures.
Memory trick: Hunting needs a map of where the prey might hide.
Asymmetric Key Cryptography (Public-Key)
Flip cardAsymmetric key cryptography uses a pair of mathematically linked keys: a public key (shared widely) and a private key (kept secret). It enables secure communication, digital signatures, and key exchange without a pre-shared secret.
- Uses distinct public and private keys.
- Public key encrypts data, private key decrypts.
- Private key signs data, public key verifies signature.
- Facilitates secure key exchange (e.g., Diffie-Hellman) and digital identities.
Memory trick: Two keys are better than one for secrets and signatures.
Holistic Risk View
Flip cardAn approach to risk management that considers all types of risks (technical, human, operational, financial, geopolitical, etc.) across the entire organization, recognizing their interdependencies.
- Considers all risk categories.
- Recognizes interdependencies.
- Essential for comprehensive enterprise risk management.
Memory trick: Holistic risk: See the whole picture, not just the tech bits.