CompTIA SecurityX (CAS-005) flashcards
156 free flashcards. Tap a card to flip it.
Asymmetric Key Cryptography (Public-Key)
Flip cardAsymmetric key cryptography uses a pair of mathematically linked keys: a public key (shared widely) and a private key (kept secret). It enables secure communication, digital signatures, and key exchange without a pre-shared secret.
- Uses distinct public and private keys.
- Public key encrypts data, private key decrypts.
- Private key signs data, public key verifies signature.
- Facilitates secure key exchange (e.g., Diffie-Hellman) and digital identities.
Memory trick: Two keys are better than one for secrets and signatures.
Holistic Risk View
Flip cardAn approach to risk management that considers all types of risks (technical, human, operational, financial, geopolitical, etc.) across the entire organization, recognizing their interdependencies.
- Considers all risk categories.
- Recognizes interdependencies.
- Essential for comprehensive enterprise risk management.
Memory trick: Holistic risk: See the whole picture, not just the tech bits.
HIPAA
Flip cardThe Health Insurance Portability and Accountability Act of 1996 is a U.S. federal law that sets standards for the protection of sensitive patient health information (PHI).
- Protects Protected Health Information (PHI).
- Applies to healthcare providers, plans, and clearinghouses.
- Mandates security and privacy rules for PHI.
Memory trick: HIPAA protects health, PCI protects cards.
Risk Transference
Flip cardA risk management strategy where the potential financial impact or responsibility of a risk is shifted to a third party, typically through insurance or contractual agreements.
- Shifts financial burden.
- Commonly achieved via insurance.
- Does not eliminate the risk, but changes who bears the cost.
Memory trick: A-M-T-A: Avoid, Mitigate, Transfer, Accept.
Hypothesis-Driven Threat Hunting
Flip cardA proactive security activity where analysts develop hypotheses about potential malicious activity that might be present in their environment, then actively search for evidence to prove or disprove those hypotheses using various data sources and analytical techniques. It aims to find unknown threats that evade automated defenses.
- Proactive search for threats.
- Based on specific hypotheses (e.g., 'An attacker is using X technique').
- Leverages behavioral analytics and anomaly detection.
- Aims to find unknown IOCs and novel attack techniques.
Memory trick: Hunt for Threats with Hypotheses, Not Just Alerts.
SSH Hardening
Flip cardThe process of securing the Secure Shell (SSH) service to protect against unauthorized access and attacks.
- Disable root login.
- Use key-based authentication.
- Limit user access and monitor logs.
Memory trick: SSH keys are better than roots and passwords.
Command and Control (C2)
Flip cardCommand and Control (C2 or C&C) refers to the communication channel used by an attacker to remotely control compromised systems (bots or zombies) within a target network.
- Enables attackers to send commands and receive data from compromised machines.
- Often uses covert channels, non-standard ports, or legitimate protocols (e.g., HTTP, DNS) to blend in.
- Detection is crucial for identifying active compromises and preventing further damage.
Memory trick: Compromised servers Communicate Covertly.
Dynamic Malware Analysis
Flip cardThe process of executing a suspicious file in a controlled, isolated environment (e.g., sandbox) to observe its behavior, network communications, file system changes, and process interactions.
- Requires a safe, isolated environment (sandbox).
- Reveals runtime behavior and real-time IOCs.
- Can be time-consuming and requires careful setup.
Memory trick: Static looks at code, Dynamic watches it run.
Botnet Activity Indicators
Flip cardObservable behaviors that suggest a system has been compromised and is acting as part of a botnet. These often include unusual network traffic patterns, C2 communication, and scanning for other vulnerable hosts.
- Unusual outbound connections to diverse IPs/ports.
- Periodic C2 communication patterns.
- Participation in DDoS attacks or spam campaigns.
Memory trick: Compromised Servers Chat and Scan, Not Just Serve.
Centralized HSM and KMS for Multi-Tenant Isolation
Flip cardLeveraging Hardware Security Modules (HSM) and a Key Management System (KMS) to generate, store, and manage unique encryption keys for each tenant, ensuring cryptographic separation of data in a shared multi-tenant environment.
- HSMs provide tamper-resistant hardware for key protection.
- Unique keys per tenant prevent cross-tenant data access.
- KMS manages the lifecycle of these tenant-specific keys.
Memory trick: HSM & KMS: 'Hardware Shields Keys' for each tenant's 'Kingdom'.
PCI DSS Scope Reduction
Flip cardStrategies and controls implemented by organizations to limit the number of systems, networks, and processes that come into contact with cardholder data, thereby reducing the overhead and complexity of achieving and maintaining PCI DSS compliance.
- Reduces systems subject to PCI DSS.
- Simplifies compliance efforts.
- Common methods include tokenization and outsourcing.
Memory trick: Scope-out the card data, then secure it.
API Gateway
Flip cardAn API Gateway is a server that acts as an API front-end, taking requests from clients, routing them to the appropriate microservice, and often performing functions like authentication, authorization, rate limiting, and data transformation.
- Single entry point for client requests to microservices.
- Centralizes security policies (authN/authZ).
- Provides observability (logging, metrics, tracing).
- Reduces complexity for clients and individual microservices.
Memory trick: Gateway guards the city, routes traffic, and checks IDs.
HSM with CMEK
Flip cardHardware Security Modules (HSMs) provide a tamper-resistant environment for cryptographic key generation, storage, and operations. When used with Customer-Managed Encryption Keys (CMEK), it allows cloud customers to control their encryption keys while benefiting from the hardware-backed security of the HSM.
- Keys are generated and stored in a secure hardware module.
- Customers retain control over their encryption keys.
- Provides strong cryptographic assurances for data at rest.
Memory trick: HSM with CMEK: Hardware secures my Cloud Encryption Keys.
Identity Federation
Flip cardA system that allows users to use the same digital identity across multiple, independent application systems or organizations, enabling single sign-on (SSO).
- Enables single sign-on (SSO)
- Reduces administrative burden
- Improves user experience across disparate systems
Memory trick: Federation is like a universal passport for your digital identity.
Key Management Service (KMS)
Flip cardA cloud service that helps you create and control the encryption keys used to encrypt your data. It provides a centralized, secure, and auditable way to manage the lifecycle of cryptographic keys.
- Centralized key generation, storage, and usage.
- Integration with other cloud services for encryption.
- Provides auditing and access control for keys.
Memory trick: KMS keeps the keys in a central, secure cloud vault.
Service Mesh
Flip cardA dedicated infrastructure layer that handles service-to-service communication within a microservices architecture, providing features like traffic management, security, and observability.
- Decouples communication logic from application code.
- Often implemented with a 'sidecar proxy' pattern.
- Provides security features like mTLS, authorization, and traffic encryption.
Memory trick: Mesh your services for secure, resilient, and observable connections.
Post-Quantum Cryptography (PQC) for Key Management
Flip cardThe use of cryptographic algorithms designed to be secure against attacks by quantum computers, specifically applied to key exchange and digital signatures to protect long-term data confidentiality.
- Mitigates the threat of quantum computers breaking current public-key crypto
- Essential for 'harvest now, decrypt later' scenarios
- Focuses on securing key establishment and authentication in a quantum future
Memory trick: PQC protects keys from Quantum Computers.
SAML 2.0 (Security Assertion Markup Language)
Flip cardAn XML-based open standard for exchanging authentication and authorization data between an identity provider (IdP) and a service provider (SP) in enterprise federation scenarios.
- Widely adopted for enterprise SSO and federation
- Supports rich attribute exchange and complex scenarios
- XML-based for secure data assertions
Memory trick: SAML 2.0: Securely Asserting Multi-domain Login!
Geographic Redundancy with Synchronous Replication
Flip cardAn architecture where identical systems and data are deployed in multiple, distinct geographical regions, with data synchronized in real-time to ensure zero data loss and continuous operation during a regional outage.
- Provides the highest level of disaster recovery and business continuity.
- Achieves RPO (Recovery Point Objective) of zero and near-zero RTO (Recovery Time Objective).
- Requires significant network bandwidth and can introduce latency due to synchronous data commits across distances.
Memory trick: Geo-Sync: Global Strength, Zero Loss.
SOAR (Security Orchestration, Automation, and Response)
Flip cardA platform that helps organizations automate and orchestrate security operations tasks, incident response workflows, and threat management processes.
- Automates repetitive security tasks
- Orchestrates workflows across multiple security tools
- Facilitates rapid incident response
Memory trick: SOAR: Security Orchestrates Automated Response.
Synchronous Replication
Flip cardA data replication method where data is written to both the primary and replica storage locations simultaneously, ensuring zero data loss (RPO=0) but potentially introducing latency.
- Guarantees data consistency across replicas.
- Transaction is only committed after confirmation from all replicas.
- Essential for applications with zero RPO (Recovery Point Objective) requirements.
Memory trick: Sync for Zero Loss, Async for Speed, Snap for Point-in-Time.
Regional Data Silos (Data Residency by Design)
Flip cardAn architectural approach where data is intentionally confined to specific geographic regions or countries to comply with local data residency regulations.
- Ensures data remains within defined jurisdictional boundaries.
- Often requires separate infrastructure, databases, and application deployments per region.
- Can increase operational complexity and cost but is necessary for compliance.
Memory trick: Local Laws, Local Data: Silo It!
Web Application Firewall (WAF)
Flip cardA Web Application Firewall (WAF) is a security solution that monitors and filters HTTP/HTTPS traffic between a web application and the Internet. It protects web applications from various attacks, including cross-site scripting (XSS), SQL injection, and other OWASP Top 10 vulnerabilities.
- Operates at the application layer (Layer 7 of OSI model).
- Protects against common web-based attacks.
- Can enforce security policies, perform rate limiting, and provide API security.
- Can be network-based, host-based, or cloud-based.
Memory trick: WAF Watches Web Attacks Fiercely.
Homomorphic Encryption (HE)
Flip cardHomomorphic Encryption (HE) is a form of encryption that allows computations to be performed on encrypted data without requiring decryption. The result of the computation remains encrypted and, when decrypted, is identical to the result of performing the same computation on the plaintext data.
- Enables computation on encrypted data without decryption.
- Preserves data confidentiality during processing in untrusted environments.
- Can be fully homomorphic (FHE) or partially homomorphic (PHE).
- Computationally intensive, but increasingly practical for specific use cases.
Memory trick: Homomorphic Hides Operations on Medical Encrypted Data.
Pod Security Admission (PSA) Levels
Flip cardKubernetes' built-in admission controller for enforcing Pod Security Standards (PSS) at different levels (Privileged, Baseline, Restricted) to control the security posture of pods.
- Enforces PSS at admission time.
- Three levels: Privileged, Baseline, Restricted.
- Applied per namespace with 'enforce', 'audit', 'warn' modes.
Memory trick: PSA: Privileged, BASELINE, RESTRICTED, like security levels.
ValidatingWebhookConfiguration
Flip cardA Kubernetes admission controller that allows custom, external policy engines to validate or mutate API requests (like pod creation) before they are admitted to the cluster.
- Extends Kubernetes policy enforcement
- Integrates with external policy engines (e.g., OPA Gatekeeper)
- Enforces custom rules beyond built-in admission controllers
Memory trick: Validating Webhook: If it's not valid, the webhook will make it sad!
IPsec
Flip cardIPsec (Internet Protocol Security) is a suite of protocols used to secure IP communications by authenticating and encrypting each IP packet of a communication session. It operates at the network layer (Layer 3).
- Provides confidentiality, integrity, and authenticity for IP traffic.
- Used for Virtual Private Networks (VPNs), especially site-to-site.
- Consists of two main protocols: AH (Authentication Header) and ESP (Encapsulating Security Payload).
- Operates in two modes: Transport mode (end-to-end) and Tunnel mode (gateway-to-gateway).
Memory trick: IPsec secures the entire IP journey between sites.
Active-Active Synchronous Replication
Flip cardAn architectural pattern where multiple geographically separated instances of an application or database are simultaneously active and processing requests. Data changes are synchronously replicated between all active instances, ensuring near-zero data loss (RPO) and immediate failover capabilities (RTO).
- Both sites are active and serve traffic.
- Data is written to all sites concurrently (synchronously).
- Provides RPO (Recovery Point Objective) of zero or near-zero.
- Enables RTO (Recovery Time Objective) of near-zero, ensuring continuous operation.
Memory trick: Always on, always synced, always ready for disaster.
Private Subnet for Databases
Flip cardA network segmentation strategy where sensitive resources like databases are placed in a private subnet (or network segment) that is not directly routable from the public internet. Access is typically restricted to specific internal resources, such as application servers.
- Prevents direct internet exposure of databases.
- Reduces the attack surface significantly.
- Forces traffic through controlled intermediaries (e.g., application servers).
- A fundamental principle in securing multi-tier applications.
Memory trick: Keep the vault in the back, behind the trusted guards.
Unified CSPM and CWPP (Cloud Native Application Protection Platform - CNAPP)
Flip cardAn integrated security solution that combines Cloud Security Posture Management (CSPM) for configuration and compliance with Cloud Workload Protection Platform (CWPP) for runtime threat detection and protection across hybrid and multi-cloud environments.
- Provides end-to-end security for applications and infrastructure in cloud environments.
- Offers continuous monitoring, vulnerability management, and threat detection.
- Aims to reduce complexity and provide consistent security policy enforcement across hybrid setups.
Memory trick: CSPM+CWPP: Comprehensive Protection for Cloud and On-Premises.
Zero Trust - Verify Explicitly
Flip cardThe 'Verify explicitly' principle of Zero Trust mandates that all access requests, whether from inside or outside the network, must be explicitly authenticated and authorized based on all available data points, rather than implicit trust from network location.
- Authentication and authorization are continuous, not one-time.
- Considers user identity, device health, location, service identity, and data sensitivity.
- Moves away from perimeter-based security to identity-based security.
- Crucial for microservices where network boundaries are fluid.
Memory trick: Don't trust, always check: 'V'erify 'E'verything 'E'xplicitly.
Bring Your Own Key (BYOK) with Cloud HSM
Flip cardA cloud encryption key management strategy where customers generate their own keys on-premises and securely transfer them to a dedicated Hardware Security Module (HSM) managed by the cloud provider but controlled by the customer.
- Customer retains full control over key generation and lifecycle.
- Keys are stored in a tamper-resistant hardware module (HSM) in the cloud.
- Prevents cloud provider from accessing unencrypted keys or customer data without explicit customer action.
Memory trick: BYOK + HSM = Your Keys, Your Rules, Hardware Secure.
SIEM
Flip cardSecurity Information and Event Management (SIEM) systems combine security information management (SIM) and security event management (SEM) functions into one security management system.
- Collects logs and security alerts from various sources.
- Aggregates and normalizes data for analysis.
- Identifies and alerts on security incidents and policy violations.
Memory trick: SIEM Sees Everything, Instantly Alerts.
STRIDE Threat Model
Flip cardA systematic approach to identifying and classifying threats to software, developed by Microsoft, using six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
- Used during the design phase of software development.
- Helps analyze security properties of system components and data flows.
- Each category helps identify specific types of vulnerabilities.
Memory trick: STRIDE Systematically Spots Software's Structural Risks.
SSL/TLS VPN
Flip cardA Virtual Private Network (VPN) solution that uses the Secure Sockets Layer (SSL) or Transport Layer Security (TLS) protocol to create a secure, encrypted connection over an untrusted network.
- Operates at the application layer (OSI Layer 6/7).
- Often uses a web browser as the client, simplifying deployment.
- Provides strong encryption, authentication, and data integrity.
Memory trick: Very Prudent VPNs Secure Virtual Paths.
Web Server Access Logs
Flip cardFiles maintained by a web server that record every request processed by the server, providing detailed information about client interactions.
- Contain client IP address, request method, URL, status code, user agent, and timestamp.
- Crucial for website analytics, security monitoring, and incident response.
- Directly show web application-level interactions like login attempts.
Memory trick: Logs Lead to Logical Learnings.