Free knowledge base

CompTIA SecurityX (CAS-005) — key terms, tricks & tips

Everything from the course in one searchable place: 240 entries. Use it to review before a practice test or look up a word you forgot.

240 results

Key term

Domain Weighting

Percentage of exam questions allocated to a specific content area.

Getting Started: How the Exam Works

Key term

Multiple-Choice Questions (MCQs)

Standard exam questions with one or more correct options.

Getting Started: How the Exam Works

Key term

Performance-Based Questions (PBQs)

Interactive simulations requiring hands-on problem-solving skills.

Getting Started: How the Exam Works

Key term

Passing Score

Minimum score required to successfully pass the certification exam.

Getting Started: How the Exam Works

Key term

Exam Duration

Total time allotted to complete the certification examination.

Getting Started: How the Exam Works

Key term

CAS-005

The current exam code for the CompTIA SecurityX certification.

Getting Started: How the Exam Works

Key term

Scaled Score

A raw score converted to a standardized scale, not used for CAS-005.

Getting Started: How the Exam Works

Memory trick

CAS-005 Exam Overview & Structure

To remember the exam details: '90 questions in 165 minutes, score 750 to win it!'

Getting Started: How the Exam Works

Exam tip

CAS-005 Exam Overview & Structure

The CAS-005 exam has a maximum of 90 questions and a duration of 165 minutes. The passing score is 750 on a scale of 100-900. Memorize these exact numbers.

Getting Started: How the Exam Works

Common mistake

CAS-005 Exam Overview & Structure

Ignoring domain weightings and spending too much time on low-weighted topics.

Getting Started: How the Exam Works

Common mistake

CAS-005 Exam Overview & Structure

Getting stuck on a single Performance-Based Question (PBQ) and running out of time for others.

Getting Started: How the Exam Works

Common mistake

CAS-005 Exam Overview & Structure

Not practicing time management, leading to unanswered questions at the end of the exam.

Getting Started: How the Exam Works

Key term

Exam Objectives

CompTIA's official list of topics covered on the exam.

Getting Started: How the Exam Works

Key term

Active Learning

Engaging with material through discussion, practice, or teaching.

Getting Started: How the Exam Works

Key term

Spaced Repetition

Reviewing information at increasing intervals to improve retention.

Getting Started: How the Exam Works

Key term

Threat Modeling

Systematic process to identify and mitigate potential threats.

Getting Started: How the Exam Works

Key term

Practice Tests

Simulated exams to assess knowledge and identify weak areas.

Getting Started: How the Exam Works

Key term

NIST SP 800-61

NIST Special Publication on Computer Security Incident Handling Guide.

Getting Started: How the Exam Works

Key term

STRIDE

Threat modeling methodology: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.

Getting Started: How the Exam Works

Memory trick

Study Strategies for SecurityX Success

To remember key study steps: 'OATS' – Objectives, Active Learning, Time Management, Self-Assessment.

Getting Started: How the Exam Works

Exam tip

Study Strategies for SecurityX Success

The CAS-005 exam expects you to not just recall definitions, but to apply concepts to complex scenarios. Look for keywords like 'recommend,' 'evaluate,' 'design,' or 'implement' in questions, as these indicate application-level thinking is required.

Getting Started: How the Exam Works

Common mistake

Study Strategies for SecurityX Success

Relying solely on memorization without understanding the underlying concepts.

Getting Started: How the Exam Works

Common mistake

Study Strategies for SecurityX Success

Neglecting practice tests until the last minute, missing opportunities to identify weaknesses.

Getting Started: How the Exam Works

Common mistake

Study Strategies for SecurityX Success

Underestimating the importance of hands-on experience and practical application.

Getting Started: How the Exam Works

Key term

IT Governance

Ensuring IT aligns with business goals, manages risk, and delivers value.

Governance, Risk and Compliance

Key term

COBIT

Framework for governing and managing enterprise IT, focusing on objectives.

Governance, Risk and Compliance

Key term

ITIL

Framework for IT service management, focusing on best practices.

Governance, Risk and Compliance

Key term

Policy

High-level statement of management's intent and direction.

Governance, Risk and Compliance

Key term

Standard

Mandatory requirements for specific technologies or processes.

Governance, Risk and Compliance

Key term

Procedure

Detailed, step-by-step instructions for performing a task.

Governance, Risk and Compliance

Key term

Baseline

Minimum security configurations for systems or applications.

Governance, Risk and Compliance

Key term

Guideline

Recommended actions or best practices, not mandatory.

Governance, Risk and Compliance

Memory trick

Governance Frameworks & Policy Structures

P-S-B-G-P: Policies Set Baselines, Guidelines Provide Procedures. (Think of it as a clear path from high-level rules to detailed steps!)

Governance, Risk and Compliance

Exam tip

Governance Frameworks & Policy Structures

The CAS-005 exam often tests your ability to distinguish between policies, standards, guidelines, and procedures. Remember their hierarchical relationship and mandatory nature.

Governance, Risk and Compliance

Common mistake

Governance Frameworks & Policy Structures

Confusing COBIT (governance 'what') with ITIL (service management 'how').

Governance, Risk and Compliance

Common mistake

Governance Frameworks & Policy Structures

Treating guidelines as mandatory requirements instead of recommendations.

Governance, Risk and Compliance

Common mistake

Governance Frameworks & Policy Structures

Failing to involve all stakeholders (e.g., legal, HR) when developing or updating policies.

Governance, Risk and Compliance

Key term

Enterprise Risk Management (ERM)

Holistic approach to managing all risks across an organization.

Governance, Risk and Compliance

Key term

Qualitative Risk Analysis

Subjective assessment of risk likelihood and impact using descriptive scales.

Governance, Risk and Compliance

Key term

Quantitative Risk Analysis

Objective, numerical assessment of risk using data and statistical methods.

Governance, Risk and Compliance

Key term

Risk Avoidance

Eliminating a risk by discontinuing the activity that causes it.

Governance, Risk and Compliance

Key term

Risk Mitigation

Reducing the likelihood or impact of a risk through controls.

Governance, Risk and Compliance

Key term

Risk Transfer

Shifting the financial burden of a risk to a third party, e.g., insurance.

Governance, Risk and Compliance

Key term

Risk Acceptance

Consciously deciding to take no action against an identified risk.

Governance, Risk and Compliance

Key term

Key Risk Indicators (KRIs)

Metrics used to monitor and track the level of risk exposure.

Governance, Risk and Compliance

Memory trick

Enterprise Risk Management Strategies

To remember the four risk treatment strategies, think of 'AMAT': Avoid, Mitigate, Accept, Transfer.

Governance, Risk and Compliance

Exam tip

Enterprise Risk Management Strategies

The CAS-005 exam expects you to understand the ERM process as a continuous cycle and to distinguish clearly between the four risk treatment strategies. Pay close attention to the nuances of qualitative vs. quantitative analysis.

Governance, Risk and Compliance

Common mistake

Enterprise Risk Management Strategies

Confusing risk mitigation with risk avoidance; mitigation reduces impact/likelihood, avoidance eliminates the risk entirely.

Governance, Risk and Compliance

Common mistake

Enterprise Risk Management Strategies

Failing to understand that ERM is a continuous process, not a one-time assessment.

Governance, Risk and Compliance

Common mistake

Enterprise Risk Management Strategies

Not documenting risk acceptance decisions; all risk treatment decisions, especially acceptance, must be formally recorded.

Governance, Risk and Compliance

Key term

GDPR

EU law for data protection and privacy for all individuals within the EU.

Governance, Risk and Compliance

Key term

HIPAA

US law protecting sensitive patient health information from disclosure.

Governance, Risk and Compliance

Key term

CCPA

California law granting consumers rights over their personal data.

Governance, Risk and Compliance

Key term

Data Sovereignty

Data is subject to the laws of the country where it is stored.

Governance, Risk and Compliance

Key term

Jurisdiction

The official power to make legal decisions and judgments.

Governance, Risk and Compliance

Key term

Compliance Framework

A structured set of guidelines for meeting security standards.

Governance, Risk and Compliance

Key term

Audit

An official inspection of an organization's accounts or systems.

Governance, Risk and Compliance

Memory trick

Compliance, Regulations & Legal Considerations

To remember key data privacy laws: 'G-H-C-P-L' for GDPR, HIPAA, CCPA, PIPEDA, LGPD. Imagine a 'Grand Hippo Chasing Purple Lizards' across the globe!

Governance, Risk and Compliance

Exam tip

Compliance, Regulations & Legal Considerations

Memorize the core principles of GDPR (e.g., lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability) as they are frequently referenced in exam questions about global data privacy.

Governance, Risk and Compliance

Common mistake

Compliance, Regulations & Legal Considerations

Assuming compliance with one regulation automatically covers others; many regulations have unique requirements.

Governance, Risk and Compliance

Common mistake

Compliance, Regulations & Legal Considerations

Neglecting to update compliance posture as laws and regulations evolve or as the business expands into new jurisdictions.

Governance, Risk and Compliance

Common mistake

Compliance, Regulations & Legal Considerations

Viewing compliance as a one-time project rather than an ongoing process requiring continuous monitoring and auditing.

Governance, Risk and Compliance

Key term

AI Governance

Framework of policies ensuring responsible, ethical, and legal AI development and use.

Governance, Risk and Compliance

Key term

Adversarial Attack

Malicious input designed to trick or compromise an AI model.

Governance, Risk and Compliance

Key term

Data Poisoning

Injecting malicious data into an AI model's training set.

Governance, Risk and Compliance

Key term

Model Inversion

Attack to reconstruct sensitive training data from an AI model's output.

Governance, Risk and Compliance

Key term

Evasion Attack

Crafting inputs that cause an AI model to misclassify or fail.

Governance, Risk and Compliance

Memory trick

Threat Modeling & AI Governance Essentials

To remember STRIDE: 'STRong IDentity Ensures Data security.' (Spoofing, Tampering, Repudiation, Info Disclosure, DoS, EoP)

Governance, Risk and Compliance

Exam tip

Threat Modeling & AI Governance Essentials

For the CAS-005 exam, understand the core purpose of threat modeling and be able to identify the components of common methodologies like STRIDE and DREAD. Also, recognize the unique security and ethical challenges of AI systems and the role of governance.

Governance, Risk and Compliance

Common mistake

Threat Modeling & AI Governance Essentials

Treating threat modeling as a one-time event, rather than an iterative process throughout the system lifecycle.

Governance, Risk and Compliance

Common mistake

Threat Modeling & AI Governance Essentials

Focusing only on technical vulnerabilities and neglecting business logic or human element threats.

Governance, Risk and Compliance

Common mistake

Threat Modeling & AI Governance Essentials

Ignoring the unique security challenges of AI systems, assuming traditional cybersecurity is sufficient.

Governance, Risk and Compliance

Key term

Resilience

Ability of a system to recover from failures and continue functioning.

Security Architecture

Key term

Fault Tolerance

System's ability to operate despite the failure of one or more components.

Security Architecture

Key term

High Availability

Maximizing system uptime and minimizing service interruptions.

Security Architecture

Key term

Scalability

Ability of a system to handle increased workload or demand.

Security Architecture

Key term

Redundancy

Duplication of critical components to prevent single points of failure.

Security Architecture

Key term

Recoverability

Speed and ease with which a system can be restored after a disruption.

Security Architecture

Key term

Diversification

Using different technologies or vendors to avoid common mode failures.

Security Architecture

Memory trick

Resilient Architecture Design Principles

Remember 'FRAS': Fault tolerance, Recoverability, Availability, Scalability – the pillars of resilience.

Security Architecture

Exam tip

Resilient Architecture Design Principles

The CAS-005 exam frequently tests your understanding of the differences and overlaps between security, resilience, and availability. Look for keywords like 'maintain service during disruption' or 'recover quickly' to identify resilience-focused questions.

Security Architecture

Common mistake

Resilient Architecture Design Principles

Confusing resilience solely with security; they are distinct but complementary.

Security Architecture

Common mistake

Resilient Architecture Design Principles

Designing for resilience only after a system is built, instead of from the ground up.

Security Architecture

Common mistake

Resilient Architecture Design Principles

Failing to regularly test resilience mechanisms, leading to false confidence.

Security Architecture

Key term

Secure Design Pattern

Reusable, proven solution to common security problems in system architecture.

Security Architecture

Key term

Least Privilege

Granting minimum necessary permissions to a user or system component.

Security Architecture

Key term

Defense in Depth

Layering multiple security controls to protect resources.

Security Architecture

Key term

Fail Secure

System failure defaults to denial of access or unauthorized operations.

Security Architecture

Key term

Separation of Duties

Requiring multiple individuals to complete a critical task.

Security Architecture

Key term

Integrated Security

Combining security technologies into a cohesive, centrally managed system.

Security Architecture

Key term

Shift-Left Security

Embedding security early in the SDLC to identify vulnerabilities sooner.

Security Architecture

Memory trick

Secure Design Patterns & Integrated Security

To remember key secure design patterns: 'L.D.F.S.S.' - Least Privilege, Defense in Depth, Fail Secure, Separation of Duties, Secure Defaults.

Security Architecture

Exam tip

Secure Design Patterns & Integrated Security

The CAS-005 exam expects you to differentiate between various secure design patterns and understand their application in real-world scenarios. Pay close attention to the benefits of integrated security solutions and how security is woven into every stage of the SDLC, not just at the end.

Security Architecture

Common mistake

Secure Design Patterns & Integrated Security

Treating security as an afterthought, only addressing it at the end of development.

Security Architecture

Common mistake

Secure Design Patterns & Integrated Security

Granting overly broad permissions instead of adhering to the Principle of Least Privilege.

Security Architecture

Common mistake

Secure Design Patterns & Integrated Security

Implementing disparate security tools that don't communicate or share intelligence.

Security Architecture

Key term

Zero Trust

Security model: never trust, always verify every access request.

Security Architecture

Key term

Policy Enforcement Point (PEP)

System that grants, denies, or revokes access to resources.

Security Architecture

Key term

Policy Decision Point (PDP)

System that evaluates policies to make access decisions.

Security Architecture

Key term

Microsegmentation

Dividing networks into small, isolated segments for granular control.

Security Architecture

Key term

Device Posture

Security state and compliance of an endpoint device.

Security Architecture

Key term

Implicit Trust

Automatic trust based on network location (traditional security).

Security Architecture

Memory trick

Zero Trust Architecture Implementation

V.E.R.I.F.Y.: Verify explicitly, Enforce least privilege, Rely on context, Isolate segments, Focus on data, Yield to continuous monitoring.

Security Architecture

Exam tip

Zero Trust Architecture Implementation

The CAS-005 exam heavily emphasizes the core principles and components of Zero Trust. Be prepared to differentiate Zero Trust from traditional perimeter security and identify key implementation steps. Keywords like 'never trust, always verify,' 'microsegmentation,' 'least privilege,' and 'continuous verification' are critical.

Security Architecture

Common mistake

Zero Trust Architecture Implementation

Believing Zero Trust is a product you can buy, rather than an architectural approach and philosophy.

Security Architecture

Common mistake

Zero Trust Architecture Implementation

Attempting to implement Zero Trust all at once instead of through a phased, iterative process.

Security Architecture

Common mistake

Zero Trust Architecture Implementation

Neglecting the importance of identity and device posture in a Zero Trust model, focusing only on network segmentation.

Security Architecture

Key term

Shared Responsibility Model

Defines security duties between CSP and customer.

Security Architecture

Key term

Cloud Security Posture Management (CSPM)

Tools to identify cloud misconfigurations and compliance issues.

Security Architecture

Key term

Cloud Access Security Broker (CASB)

Enforces security policies between cloud users and providers.

Security Architecture

Key term

Hybrid Cloud

Combines on-premise with public/private cloud services.

Security Architecture

Key term

Infrastructure as a Service (IaaS)

Cloud model offering virtualized computing resources.

Security Architecture

Key term

Platform as a Service (PaaS)

Cloud model offering platform for developing, running, managing apps.

Security Architecture

Key term

Software as a Service (SaaS)

Cloud model offering ready-to-use applications over the internet.

Security Architecture

Memory trick

Cloud & Hybrid Infrastructure Security

C-S-P: 'Cloud Secures Platform' (CSP) for the Provider, 'Customer Secures Payload' (CSP) for the Customer. Helps remember the split!

Security Architecture

Exam tip

Cloud & Hybrid Infrastructure Security

The CAS-005 exam heavily emphasizes the shared responsibility model. Memorize the division of responsibilities for IaaS, PaaS, and SaaS, as questions often test your understanding of who is accountable for specific security controls in each model.

Security Architecture

Common mistake

Cloud & Hybrid Infrastructure Security

Assuming the cloud provider handles all security; remember the shared responsibility model.

Security Architecture

Common mistake

Cloud & Hybrid Infrastructure Security

Neglecting to apply least privilege principles to cloud IAM roles and policies.

Security Architecture

Common mistake

Cloud & Hybrid Infrastructure Security

Failing to encrypt data both at rest and in transit within cloud and hybrid environments.

Security Architecture

Key term

Data at Rest

Data stored on physical or digital media.

Security Architecture

Key term

Data in Transit

Data moving across a network or between systems.

Security Architecture

Key term

Data in Use

Data actively being processed by a computer system.

Security Architecture

Key term

DLP

Data Loss Prevention; systems to prevent unauthorized data transfer.

Security Architecture

Key term

Data Masking

Replacing sensitive data with realistic, fictitious data.

Security Architecture

Key term

Tokenization

Replacing sensitive data with a non-sensitive surrogate (token).

Security Architecture

Key term

Retention Policy

Rules for how long data must be kept.

Security Architecture

Key term

Cryptographic Erasure

Destroying encryption keys to render data unreadable.

Security Architecture

Memory trick

Data Security & Protection Strategies

Remember 'RAT' for Data States: Rest, At, Transit. Protection for RATs: Encryption, Access Control, TLS.

Security Architecture

Exam tip

Data Security & Protection Strategies

The CAS-005 exam expects you to know the three states of data (at rest, in transit, in use) and the primary protection methods for each. Also, be able to distinguish between data masking and tokenization, and understand the purpose of DLP.

Security Architecture

Common mistake

Data Security & Protection Strategies

Confusing data masking with encryption; masking changes the data for non-production use, while encryption protects it in all states.

Security Architecture

Common mistake

Data Security & Protection Strategies

Assuming DLP is a 'set it and forget it' solution; it requires continuous tuning and policy updates to be effective.

Security Architecture

Common mistake

Data Security & Protection Strategies

Neglecting data destruction. Simply deleting files does not securely remove data; proper methods are crucial.

Security Architecture

Key term

Authentication

Verifying a user's identity.

Security Engineering

Key term

Authorization

Determining what an authenticated user can do.

Security Engineering

Key term

Accounting

Tracking user activities and resource access.

Security Engineering

Key term

Multi-factor Authentication (MFA)

Requiring two or more distinct types of credentials.

Security Engineering

Key term

Role-Based Access Control (RBAC)

Permissions assigned to roles, not individuals.

Security Engineering

Key term

Identity Federation

Using a single identity across multiple security domains.

Security Engineering

Key term

Single Sign-On (SSO)

One authentication event for multiple applications.

Security Engineering

Memory trick

Identity, Access Management & Federation

AAA: Always Authenticate, Always Authorize, Always Account. Remember these three pillars for IAM.

Security Engineering

Exam tip

Identity, Access Management & Federation

For CAS-005, understand the distinctions and use cases for DAC, MAC, RBAC, and ABAC. Be prepared to identify appropriate access control models for various scenarios. Also, know the primary protocols for federation: SAML and OpenID Connect.

Security Engineering

Common mistake

Identity, Access Management & Federation

Confusing authentication with authorization: Authentication proves who you are; authorization determines what you can do.

Security Engineering

Common mistake

Identity, Access Management & Federation

Neglecting deprovisioning processes: Failing to promptly remove access for terminated employees creates orphaned accounts and serious security risks.

Security Engineering

Common mistake

Identity, Access Management & Federation

Over-privileging users: Granting more access than necessary (violating least privilege) significantly increases the attack surface if an account is compromised.

Security Engineering

Key term

Hardening

Process of securing a system by reducing its attack surface and vulnerabilities.

Security Engineering

Key term

Attack Surface

The sum of all points where an unauthorized user can try to enter or extract data from a system.

Security Engineering

Key term

Security Baseline

A set of minimum security configurations and best practices for a system.

Security Engineering

Key term

Patch Management

The process of acquiring, testing, and applying code changes to fix vulnerabilities.

Security Engineering

Key term

Vulnerability Scan

Automated process to identify security weaknesses in systems, networks, or applications.

Security Engineering

Key term

Host-based Firewall

A software firewall running on an individual endpoint or server to control network traffic.

Security Engineering

Key term

Configuration Drift

When a system's configuration deviates from its intended or baseline security state.

Security Engineering

Memory trick

Endpoint & Server Hardening Techniques

To 'Harden' a system, remember: R.A.P.I.D. — Remove unnecessary, Apply patches, Protect physically, Implement least privilege, Disable defaults.

Security Engineering

Exam tip

Endpoint & Server Hardening Techniques

The CAS-005 exam expects you to differentiate between various hardening techniques for different system types (OS, applications, network, physical) and understand their practical implementation, often referencing industry standards like CIS Benchmarks.

Security Engineering

Common mistake

Endpoint & Server Hardening Techniques

Forgetting that hardening is an ongoing process, not a one-time task; new vulnerabilities emerge daily.

Security Engineering

Common mistake

Endpoint & Server Hardening Techniques

Over-hardening a system to the point where it impacts functionality or user productivity, leading to workarounds.

Security Engineering

Common mistake

Endpoint & Server Hardening Techniques

Relying solely on default vendor security settings without further customization or review.

Security Engineering

Key term

ICS (Industrial Control Systems)

Systems controlling industrial processes, prioritizing safety and availability.

Security Engineering

Key term

OT (Operational Technology)

Hardware/software monitoring and controlling physical processes, e.g., manufacturing.

Security Engineering

Key term

IoT (Internet of Things)

Network of physical objects with sensors, software, connecting to the internet.

Security Engineering

Key term

SCADA (Supervisory Control and Data Acquisition)

Large-scale ICS for monitoring and controlling geographically dispersed facilities.

Security Engineering

Key term

PLC (Programmable Logic Controller)

Industrial computer control system automating specific processes.

Security Engineering

Key term

Purdue Model

Reference model for segmenting ICS/OT networks into logical layers.

Security Engineering

Key term

IIoT (Industrial IoT)

IoT applied to industrial settings, often merging with OT.

Security Engineering

Key term

Air Gap

Physical isolation of a network from other networks, especially the internet.

Security Engineering

Memory trick

Securing ICS/OT and IoT Environments

To secure OT, remember 'S.A.F.E.T.Y.': Segmentation, Authentication, Firmware, Encryption, Training, Yet-to-come (future threats).

Security Engineering

Exam tip

Securing ICS/OT and IoT Environments

The CAS-005 exam expects you to differentiate between IT, OT, and IoT security priorities (confidentiality vs. availability/safety). Know the Purdue Model's layers and their purpose in OT segmentation. Be aware of common OT-specific malware (Stuxnet, Industroyer, Triton) and IoT botnets (Mirai).

Security Engineering

Common mistake

Securing ICS/OT and IoT Environments

Treating OT/IoT security with the same approach as traditional IT security, ignoring their unique priorities (e.g., availability over confidentiality for OT).

Security Engineering

Common mistake

Securing ICS/OT and IoT Environments

Failing to implement proper network segmentation between IT and OT environments, creating a direct path for attacks.

Security Engineering

Common mistake

Securing ICS/OT and IoT Environments

Neglecting to inventory and manage IoT devices, leading to 'shadow IoT' and unpatched vulnerabilities.

Security Engineering

Key term

Automation

Performing tasks with minimal human intervention.

Security Engineering

Key term

Orchestration

Coordinating multiple automated tasks across systems.

Security Engineering

Key term

SOAR

Security Orchestration, Automation, and Response platform.

Security Engineering

Key term

Playbook

Step-by-step guide for incident response actions.

Security Engineering

Key term

Runbook

Detailed instructions for routine operational tasks.

Security Engineering

Key term

Threat Intelligence

Contextualized knowledge about existing or emerging threats.

Security Engineering

Key term

Incident Response

Organized approach to managing and recovering from security breaches.

Security Engineering

Memory trick

Security Automation & Orchestration

SOAR: S-O-A-R, Security Operations Are Rapid with SOAR!

Security Engineering

Exam tip

Security Automation & Orchestration

The CAS-005 exam expects you to differentiate clearly between automation (single task) and orchestration (coordinated workflows). Also, know what SOAR stands for and its primary function in integrating tools and playbooks.

Security Engineering

Common mistake

Security Automation & Orchestration

Confusing automation with orchestration: Automation is a single task; orchestration is coordinating many tasks.

Security Engineering

Common mistake

Security Automation & Orchestration

Believing SOAR replaces human analysts: SOAR augments analysts, handling repetitive tasks so humans can focus on complex problems.

Security Engineering

Common mistake

Security Automation & Orchestration

Implementing automation without clear processes: Automation without well-defined playbooks or runbooks can lead to errors or unexpected outcomes.

Security Engineering

Key term

Post-Quantum Cryptography (PQC)

Algorithms secure against quantum and classical computers.

Security Engineering

Key term

Shor's Algorithm

Quantum algorithm breaking RSA and ECC encryption.

Security Engineering

Key term

Lattice-based Cryptography

PQC type based on hard problems in high-dimensional lattices.

Security Engineering

Key term

CRYSTALS-Kyber

NIST-selected PQC for key encapsulation mechanisms.

Security Engineering

Key term

CRYSTALS-Dilithium

NIST-selected PQC for digital signature algorithms.

Security Engineering

Key term

Hardware Security Module (HSM)

Physical device for secure cryptographic key storage and ops.

Security Engineering

Key term

Key Management System (KMS)

Centralized system for managing crypto keys lifecycle.

Security Engineering

Key term

Key Rotation

Regularly replacing old keys with new ones.

Security Engineering

Memory trick

Advanced Cryptography: PQC & Key Management

Quantum computers are 'SHOR'ing' up trouble, so we need 'LATTICE' work with 'CRYSTALS' to keep our keys 'MANAGED'.

Security Engineering

Exam tip

Advanced Cryptography: PQC & Key Management

The CAS-005 exam expects you to understand the *why* behind PQC – the quantum threat to current crypto. Memorize the names of the NIST-selected PQC algorithms (e.g., CRYSTALS-Kyber, CRYSTALS-Dilithium) and the core phases of the key management lifecycle.

Security Engineering

Common mistake

Advanced Cryptography: PQC & Key Management

Assuming current encryption will always be sufficient; quantum threats are real and require proactive planning.

Security Engineering

Common mistake

Advanced Cryptography: PQC & Key Management

Neglecting the full key lifecycle; key generation is just one part, secure storage and destruction are equally vital.

Security Engineering

Common mistake

Advanced Cryptography: PQC & Key Management

Underestimating the complexity of PQC migration; it's a multi-year effort, not a quick fix.

Security Engineering

Key term

SIEM

System aggregating and analyzing security logs for threat detection.

Security Operations

Key term

EDR

Endpoint Detection and Response; monitors and responds to threats on devices.

Security Operations

Key term

MTTD

Mean Time To Detect; average time from incident start to detection.

Security Operations

Key term

MTTR

Mean Time To Respond; average time from detection to full resolution.

Security Operations

Key term

UEBA

User and Entity Behavior Analytics; detects anomalies in user/system behavior.

Security Operations

Key term

Incident Response Plan

A documented set of procedures for handling security incidents.

Security Operations

Key term

False Positive

An alert indicating a threat when no actual threat exists.

Security Operations

Memory trick

Security Monitoring & Incident Response

To remember the NIST IR phases: 'P.D.C.E.R.P.' – 'Prepared Detectives Contain Every Rogue Perpetrator.'

Security Operations

Exam tip

Security Monitoring & Incident Response

The CAS-005 exam expects you to know the phases of the NIST incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) and differentiate between various security monitoring tools like SIEM, EDR, and UEBA.

Security Operations

Common mistake

Security Monitoring & Incident Response

Confusing IDS (detection only) with IPS (detection and prevention).

Security Operations

Common mistake

Security Monitoring & Incident Response

Skipping the 'lessons learned' phase of incident response, leading to repeated incidents.

Security Operations

Common mistake

Security Monitoring & Incident Response

Over-relying on automated tools without human oversight and tuning, resulting in alert fatigue or missed threats.

Security Operations

Key term

Vulnerability

A weakness in a system that can be exploited by a threat actor.

Security Operations

Key term

Penetration Test

Simulated cyberattack to find exploitable vulnerabilities.

Security Operations

Key term

Exploit

A piece of software or data that takes advantage of a vulnerability.

Security Operations

Key term

Reconnaissance

Gathering information about a target before an attack or test.

Security Operations

Key term

Enumeration

Extracting information about resources from a target system.

Security Operations

Key term

CVE

Common Vulnerabilities and Exposures, a list of publicly disclosed security flaws.

Security Operations

Memory trick

Vulnerability & Attack Surface Analysis

SCAN finds the 'S-pots,' PENTEST 'P-roves' the breach.

Security Operations

Exam tip

Vulnerability & Attack Surface Analysis

The CAS-005 exam expects you to differentiate between the goals, methodologies, and outcomes of vulnerability scanning versus penetration testing. Pay close attention to the 'active exploitation' aspect of pentesting.

Security Operations

Common mistake

Vulnerability & Attack Surface Analysis

Confusing vulnerability scanning with penetration testing; scanning identifies, pentesting exploits.

Security Operations

Common mistake

Vulnerability & Attack Surface Analysis

Failing to define the scope and rules of engagement before conducting a penetration test.

Security Operations

Common mistake

Vulnerability & Attack Surface Analysis

Not regularly updating vulnerability scanners or their vulnerability databases.

Security Operations

Key term

Threat Hunting

Proactive, human-driven search for hidden threats.

Security Operations

Key term

Dwell Time

Duration an attacker remains undetected in a system.

Security Operations

Key term

Hypothesis-Driven Hunting

Hunting based on a theory about attacker activity.

Security Operations

Key term

Anomaly-Driven Hunting

Hunting by detecting deviations from normal behavior.

Security Operations

Key term

TTPs

Tactics, Techniques, and Procedures of adversaries.

Security Operations

Key term

IOCs

Indicators of Compromise; evidence of a breach.

Security Operations

Memory trick

Proactive Threat Hunting Techniques

Hunters Collect And Discover Actions to Enrich security. (Hypothesis, Collect, Analyze, Discover, Action, Enrich)

Security Operations

Exam tip

Proactive Threat Hunting Techniques

The CAS-005 exam emphasizes proactive security measures. Be prepared to distinguish threat hunting from incident response and vulnerability management. Keywords like 'proactive search,' 'human-driven,' 'unknown threats,' and 'reducing dwell time' are strong indicators for threat hunting questions.

Security Operations

Common mistake

Proactive Threat Hunting Techniques

Confusing threat hunting with incident response; hunting is proactive, IR is reactive.

Security Operations

Common mistake

Proactive Threat Hunting Techniques

Relying solely on automated alerts instead of actively searching for unknown threats.

Security Operations

Common mistake

Proactive Threat Hunting Techniques

Not having sufficient data logging or retention to support effective hunting efforts.

Security Operations

Key term

Incident Analysis

Understanding a security event, its impact, and recovery.

Security Operations

Key term

Digital Forensics

Scientific process of collecting and analyzing digital evidence.

Security Operations

Key term

Chain of Custody

Documented chronological record of evidence handling.

Security Operations

Key term

Disk Imaging

Creating a bit-for-bit copy of a storage medium.

Security Operations

Key term

Memory Forensics

Analysis of RAM to find ephemeral evidence.

Security Operations

Key term

Data Carving

Recovering deleted or fragmented data from storage.

Security Operations

Key term

Hashing

Creating a unique digital fingerprint for data integrity.

Security Operations

Memory trick

Incident Analysis & Digital Forensics

PICAP: Prepare, Identify, Collect, Analyze, Present. Remember it like a 'PICAP' (pickup) truck carrying evidence!

Security Operations

Exam tip

Incident Analysis & Digital Forensics

The CAS-005 exam emphasizes the forensic process steps and the importance of chain of custody. Memorize the order of the forensic phases and understand why each step is critical for evidence admissibility. Look for keywords like 'integrity', 'admissibility', and 'documentation'.

Security Operations

Common mistake

Incident Analysis & Digital Forensics

Failing to maintain a strict chain of custody, which can invalidate evidence.

Security Operations

Common mistake

Incident Analysis & Digital Forensics

Modifying original evidence during collection, leading to loss of integrity.

Security Operations

Common mistake

Incident Analysis & Digital Forensics

Not documenting every step of the forensic process thoroughly.

Security Operations