ISC2 Certified in Cybersecurity (CC) flashcards
133 free flashcards. Tap a card to flip it.
Network Segmentation
Flip cardThe practice of dividing a computer network into multiple smaller network segments, each acting as its own small network.
- Reduces the attack surface by isolating critical assets.
- Limits lateral movement of attackers within the network.
- Improves network performance and security posture.
Memory trick: Segment Safely, Passwords Protect, Training Teaches, Antivirus Acts.
IPsec (Internet Protocol Security)
Flip cardA suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet in a data stream.
- Operates at the network layer (Layer 3) of the OSI model.
- Provides confidentiality, integrity, and authenticity.
- Commonly used to implement VPNs (Virtual Private Networks).
Memory trick: IPsec Secures IP, FTP Forgets Files, SMTP Sends Mail, SNMP Sees Networks.
Always-On VPN
Flip cardA type of Virtual Private Network that automatically establishes and maintains a secure connection to a corporate network whenever the device has internet connectivity, without requiring manual user initiation.
- Ensures continuous security and policy enforcement for remote devices.
- Enhances compliance and reduces security risks for mobile users.
- Can be configured to enforce full tunnel or split tunnel depending on policy.
Memory trick: Always-On Auto-Connects, Split Tunnels Separate, Site-to-Site Joins Offices, Clientless Browses.
Virtual Private Network (VPN)
Flip cardA technology that creates a secure, encrypted connection over a less secure network, such as the internet, allowing remote users to access private network resources.
- Encrypts data between the client and the VPN server.
- Creates a 'tunnel' for secure communication.
- Allows remote users to appear as if they are physically on the corporate network.
Memory trick: VPN Vaults Vital, RDP Runs Remote, SSH Secures Shells, FTP Fetches Files.
Endpoint Detection and Response (EDR)
Flip cardA cybersecurity solution that continuously monitors and collects data from endpoint devices, enabling the detection, investigation, and response to advanced threats.
- Provides deep visibility into endpoint activities (processes, file changes, network connections).
- Uses behavioral analytics and machine learning to detect anomalies.
- Facilitates rapid incident response and threat hunting.
Memory trick: EDR Examines Endpoints, SIEM Scans Systems, NIDS Networks Notice, AV Attacks Avert.
TCP (Transmission Control Protocol)
Flip cardA core protocol of the Internet protocol suite that provides reliable, ordered, and error-checked delivery of a stream of bytes between applications running on hosts communicating over an IP network.
- Connection-oriented (three-way handshake).
- Guarantees delivery and order of packets.
- Performs error checking and retransmission.
- Uses flow control and congestion control.
Memory trick: TCP is like a 'meticulous mailman' who confirms every letter arrived, in order, and undamaged.
Intrusion Prevention System (IPS)
Flip cardA network security device that monitors network traffic for malicious activity and automatically takes actions to prevent detected threats in real-time.
- Actively blocks or drops malicious traffic.
- Operates inline with network traffic.
- Can use signature-based, anomaly-based, or policy-based detection.
Memory trick: IPS Prevents, IDS Detects, NAC Controls, Filters Block Content.
Mobile Device Management (MDM)
Flip cardSoftware that allows organizations to securely manage, monitor, and configure mobile devices, such as smartphones and tablets, used by employees.
- Enforces security policies (e.g., passcodes, encryption).
- Manages applications (installation, removal, updates).
- Enables remote actions (e.g., locate, lock, wipe).
- Supports BYOD (Bring Your Own Device) and corporate-owned devices.
Memory trick: MDM Manages Mobiles, NAC Notifies Networks, SIEM Sees Software, DLP Doesn't Leak Data.
Security Information and Event Management (SIEM)
Flip cardA security solution that centralizes the collection, storage, and analysis of security logs and events from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.
- Aggregates logs from various sources (servers, firewalls, applications).
- Correlates security events to identify patterns and potential incidents.
- Provides real-time monitoring and alerting.
- Aids in compliance reporting and forensic investigations.
Memory trick: SIEM is the 'brain' of security, collecting all the 'eyes and ears' data to spot trouble.
TLS/SSL (Transport Layer Security/Secure Sockets Layer)
Flip cardCryptographic protocols that provide secure communication over a computer network, primarily used for encrypting and authenticating data in transit between a client and a server.
- Encrypts data to ensure confidentiality.
- Provides authentication to verify identities.
- Protects data integrity during transmission.
- Widely used for web (HTTPS), email, and VPNs.
Memory trick: TLS/SSL is like a 'secure envelope' for all your data, ensuring it's private and authentic on its journey.
Common Network Ports
Flip cardStandardized port numbers used by various network protocols to identify specific services running on a server.
- Port 80: HTTP (Hypertext Transfer Protocol) for unencrypted web traffic.
- Port 443: HTTPS (Hypertext Transfer Protocol Secure) for encrypted web traffic.
- Firewalls use port numbers to filter traffic and enhance security.
Memory trick: 80 Web Wonders, 443 Safe Sites, 21 Files Fly, 22 SSH Secrets.
Demilitarized Zone (DMZ)
Flip cardA physical or logical subnetwork that separates an organization's local area network (LAN) from an untrusted network, usually the internet.
- Provides an additional layer of security for the internal network.
- Hosts public-facing servers (e.g., web, email, DNS).
- Typically located between two firewalls (a screened subnet DMZ).
Memory trick: DMZ Defends, Firewalls Filter, Routers Route, IDS Detects.
Wireless Router
Flip cardA network device that combines the functions of a router, a switch, a wireless access point, and often a basic firewall to connect multiple devices to a local network and the internet.
- Connects local devices to the internet.
- Assigns IP addresses using DHCP.
- Provides Wi-Fi connectivity.
- Often includes basic firewall features.
Memory trick: The router is the 'Swiss Army Knife' for a small office network.
WPA3 (Wi-Fi Protected Access 3)
Flip cardThe latest security protocol for Wi-Fi networks, offering robust encryption and improved protection against common attacks compared to older standards.
- Uses 192-bit cryptographic strength in Enterprise mode.
- Provides 'Simultaneous Authentication of Equals' (SAE) for stronger password-based authentication.
- Offers enhanced privacy in open networks with 'Opportunistic Wireless Encryption' (OWE).
- Protects against offline dictionary attacks.
Memory trick: Remember Wi-Fi security like a ladder: WEP fell, WPA wobbled, WPA2 stood firm, but WPA3 is the top rung.
VLAN (Virtual Local Area Network)
Flip cardA logical grouping of network devices that allows them to communicate as if they were on the same physical LAN, regardless of their physical location.
- Segments a single physical switch into multiple virtual switches.
- Improves security by isolating traffic.
- Enhances network performance by reducing broadcast domains.
Memory trick: VLANs Virtually Limit, Physical Topologies Place.
Firewall
Flip cardA network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
- Acts as a barrier between a trusted internal network and untrusted external networks.
- Filters traffic based on IP addresses, port numbers, and protocols.
- Can be hardware, software, or cloud-based.
Memory trick: Firewall Fights Foes, Router Routes Roads, Switch Shares Space, Access Adds Air.
Screened Subnet DMZ (Triple-Homed)
Flip cardA network architecture that uses two firewalls to create a highly secure demilitarized zone (DMZ), completely isolating it from both the external network (internet) and the internal private network.
- Employs two firewalls for enhanced security.
- One firewall faces the internet, the other faces the internal network.
- DMZ hosts are placed between these two firewalls.
- Provides maximum isolation for critical services.
Memory trick: A Screened Subnet DMZ is like a 'double-gated fortress', with guards at both the outer and inner walls.
Firewall Rule Analysis
Flip cardThe process of examining firewall rulesets to identify potential vulnerabilities, misconfigurations, or unintended access permissions that could compromise network security.
- Rules are processed in order.
- The first matching rule is applied.
- Implicit 'deny all' is a common last rule.
- Source, Destination, Port, Protocol are key elements.
Memory trick: A firewall rule with 'any' source is like leaving your front door wide open to the entire world, not just your trusted visitors.
HTTPS and TLS
Flip cardHTTPS is the secure version of HTTP, using TLS (Transport Layer Security) to encrypt communication and verify the identity of the web server.
- HTTPS ensures confidentiality and integrity of web data.
- TLS provides encryption and authentication.
- Essential for protecting sensitive data exchanged over the web.
Memory trick: HTTPS is HTTP wearing its TLS 'security suit'.
Intrusion Detection System (IDS)
Flip cardA security system that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.
- Passively monitors traffic, does not block it.
- Detects anomalies, known attack signatures, or policy violations.
- Can be network-based (NIDS) or host-based (HIDS).
Memory trick: The IDS is a 'silent watcher' at the network's gate.
Technical Control
Flip cardSecurity safeguards implemented through hardware, software, or firmware that enforce security policies.
- Automated and often invisible to the end-user.
- Examples include firewalls, intrusion detection systems, encryption, and access control lists.
- Works in conjunction with administrative and physical controls.
Memory trick: Admin tells you what to do, Physical locks it down, Technical does it automatically.
Unique User Identification
Flip cardThe practice of assigning a distinct and non-reusable identifier to each individual user accessing a system or network resource.
- Essential for accountability and non-repudiation.
- Facilitates auditing and incident response.
- Prevents shared accounts that obscure individual actions.
Memory trick: Each person needs their own key, so we know who opened the door.
Risk Appetite
Flip cardThe amount and type of risk that an organization is willing to pursue or retain in order to achieve its objectives. It's a high-level statement set by senior management and influences strategic decisions.
- Set by senior management/board
- Strategic, high-level decision
- Guides risk management activities
Memory trick: Appetite for risk, Tolerance for its swings.
Privacy by Design (PbD)
Flip cardAn approach to systems engineering that incorporates privacy and data protection into the entire lifecycle of technology, from the initial design phase to deployment and beyond. It emphasizes proactive rather than reactive measures.
- Seven foundational principles
- Proactive, not reactive
- Privacy as the default setting
Memory trick: Design for Privacy, build for Security.
Post-Incident Activity (Incident Response)
Flip cardThe final phase of the incident response process, focused on learning from the incident. It includes documentation, evidence retention, conducting a 'lessons learned' review, and improving policies and procedures.
- Aka 'Lessons Learned' phase
- Aims to prevent recurrence and improve future response
- Involves detailed analysis and reporting
Memory trick: PDRCER: Prepare, Detect, Contain, Eradicate, Recover, Post-incident.
Threat
Flip cardA potential cause of an unwanted incident, which may result in harm to a system or organization. It is an agent or event that could exploit a vulnerability.
- Can be intentional (e.g., cyberattack) or unintentional (e.g., natural disaster)
- Requires a threat agent (e.g., hacker, disgruntled employee, storm)
- Acts on a vulnerability to cause harm
Memory trick: TVIL: Threats exploit Vulnerabilities, causing Impact with a certain Likelihood.
Privacy by Design
Flip cardAn approach to systems engineering that incorporates privacy considerations and data protection into the entire design and operation of information systems, network infrastructure, and business practices from the earliest stages.
- Emphasizes proactive rather than reactive privacy measures.
- Aims to prevent privacy issues before they occur.
- One of its seven foundational principles is 'Proactive, not Reactive; Preventative, not Remedial'.
Memory trick: Privacy is built-in, proactive, protective, full lifecycle, visible, user-centric, and secure.
Compliance
Flip cardThe act of adhering to laws, regulations, standards, and policies relevant to an organization's operations.
- Often involves legal and regulatory requirements.
- Can result in penalties for non-adherence.
- Requires continuous monitoring and auditing.
Memory trick: COMPLY with rules, or you'll pay a fine!
Confidentiality
Flip cardThe security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes. It protects sensitive data from unauthorized access and viewing.
- Part of the CIA triad
- Achieved through encryption, access controls, data masking
- Crucial for sensitive data like PII and intellectual property
Memory trick: CIA: Confidentiality, Integrity, Availability – the core of secure information.
Risk Mitigation
Flip cardThe process of taking actions to reduce the likelihood or impact of a risk.
- Involves implementing controls and safeguards.
- Aims to lessen potential harm.
- Common strategy in cybersecurity.
Memory trick: Always MITIGATE risks to make them LESS of a problem.
Authorization
Flip cardThe process of determining what an authenticated entity (user, program, or process) is permitted to do or access.
- Follows successful authentication.
- Implemented using access control lists (ACLs), role-based access control (RBAC), etc.
- Crucial for enforcing the principle of least privilege.
Memory trick: Authenticate who you are, Authorize what you can do, Account for what you did.
Risk Treatment
Flip cardThe process of selecting and implementing measures to modify risk.
- Includes Avoid, Transfer, Mitigate, and Accept (ATMA).
- Chosen based on risk assessment results and organizational risk appetite/tolerance.
- Aims to bring residual risk to an acceptable level.
Memory trick: ATMA: Avoid, Transfer, Mitigate, Accept – always choose wisely!
Integrity
Flip cardThe principle that data is accurate, complete, and protected from unauthorized modification or destruction.
- Ensures data trustworthiness and reliability.
- Achieved through hashing, digital signatures, and access controls.
- Crucial for critical data like financial or health records.
Memory trick: Confidentiality, Integrity, and Availability: Your CIA agent protects your secrets, keeps your files true, and is always there when you call.
Policy (Security)
Flip cardA high-level statement from senior management that outlines an organization's security objectives and mandatory rules for employees and systems.
- Mandatory and enforceable.
- Driven by legal, regulatory, or business needs.
- Answers the 'what' and 'why'.
Memory trick: Policies rule, standards define, procedures guide, guidelines advise.
Separation of Duties (SoD)
Flip cardA security principle that distributes critical tasks among multiple individuals to prevent fraud, error, or malicious activity by any single person.
- Prevents a single point of failure in critical processes.
- Reduces the risk of insider threat.
- Often implemented with multi-person approval requirements.
Memory trick: Separate duties so no one person is a single point of failure.
Annualized Loss Expectancy (ALE)
Flip cardThe expected financial loss from a specific risk over a one-year period. It is a quantitative measure used in risk management.
- Calculated as SLE x ARO.
- Helps prioritize security investments.
- Expressed in monetary value.
Memory trick: ALE is the annual cost, SLE is a single hit, ARO is how often it happens.
Shift-Left Security
Flip cardAn approach to software development that emphasizes integrating security practices and testing activities earlier in the Software Development Life Cycle (SDLC), rather than at later stages.
- Aims to find and fix vulnerabilities early
- Reduces cost and effort of remediation
- Promotes a security-first mindset among developers
Memory trick: Shift-Left: Move security tasks to the beginning of the SDLC timeline.
Administrative Control
Flip cardSecurity controls implemented through policies, procedures, guidelines, and training to manage security risks.
- Focuses on people and processes.
- Examples include security policies, incident response plans, and security awareness training.
- Forms the foundation for technical and physical controls.
Memory trick: Think of security controls like a house: Administrative is the blueprints, Technical is the alarm system, Physical is the locks and fences.
Impact (Risk)
Flip cardThe magnitude of harm that can be caused by a security incident or the realization of a risk.
- Quantifies the damage in terms of financial loss, reputational damage, operational disruption, etc.
- Used in conjunction with likelihood to determine the overall risk level.
- Can be qualitative (high, medium, low) or quantitative (monetary value).
Memory trick: Threat finds a Vulnerability, causing an Impact, with some Likelihood.
Port Security
Flip cardA Layer 2 security feature on network switches that restricts input on an interface by limiting and/or identifying the MAC addresses of stations allowed to access the port.
- Binds specific MAC addresses to switch ports.
- Prevents unauthorized devices from connecting.
- Can be configured to shut down or restrict traffic from unauthorized MACs.
Memory trick: Port Security is like a bouncer checking IDs at each port's door.
Non-repudiation
Flip cardThe assurance that someone cannot deny the validity of something. It ensures that a party cannot deny having sent a message or performed an action.
- Provides proof of origin and integrity.
- Often achieved through digital signatures and logging.
- Crucial for legal and financial accountability.
Memory trick: CIA: Confidentiality, Integrity, Availability. Then Authenticity, Authorization, Accounting, Non-repudiation.
Incident Response (Detection and Analysis)
Flip cardThe phase of incident response where security events are identified, characterized, and assessed to determine if they constitute an incident.
- Involves monitoring systems, logs, and alerts.
- Aims to confirm an incident and gather initial information.
- Leads to subsequent phases like containment and eradication.
Memory trick: PREPARE for an incident, DETECT and ANALYZE it, CONTAIN its spread, ERADICATE the cause, RECOVER systems, and then POST-INCIDENT lessons learn.
Incident Response
Flip cardA structured approach to managing the aftermath of a security breach or cyberattack, including detection, analysis, containment, and recovery.
- Aims to minimize damage and recovery time.
- Involves predefined steps and roles.
- Includes communication and reporting obligations.
Memory trick: Respond to incidents, recover from disasters, continue the business.
Security Audit
Flip cardA systematic evaluation of the security of a company's information system by measuring how well it conforms to a set of established criteria.
- Identifies vulnerabilities and policy violations.
- Can be internal or external.
- Verifies compliance with standards and regulations.
Memory trick: Audits inspect, training instructs, planning protects, appetite accepts.
Disaster Recovery (DR)
Flip cardThe process of restoring IT systems, infrastructure, and data after a disaster or major disruptive event.
- Focuses specifically on the recovery of technology assets.
- Often a component of a broader Business Continuity Plan (BCP).
- Involves backups, replication, and alternate sites.
Memory trick: IR handles the crisis, DR recovers the tech, BC keeps the business running.
Load Balancer
Flip cardA device or software that distributes network traffic efficiently across multiple servers to improve responsiveness, availability, and reliability of applications.
- Distributes traffic across a 'farm' of servers.
- Enhances application performance and prevents server overload.
- Provides high availability by redirecting traffic from failed servers.
Memory trick: The Load Balancer is the 'traffic cop' for server farms.
Risk Treatment (Mitigation)
Flip cardThe process of modifying risk by reducing the likelihood of an event, the impact of an event, or both, often through implementing controls.
- One of four common risk treatment strategies (mitigate, accept, transfer, avoid).
- Aims to reduce risk to an acceptable level.
- Examples include implementing security controls, patching vulnerabilities, and employee training.
Memory trick: MAAT: Mitigate (shield it), Accept (live with it), Avoid (don't do it), Transfer (share it).
Return on Investment (ROI) for Security
Flip cardA financial metric used to evaluate the efficiency of a security investment, calculated as the benefit of the investment minus its cost, divided by its cost.
- ROI = (Annualized Savings - Cost of Control) / Cost of Control.
- Annualized Savings (Benefit) = (Original ALE - New ALE).
- Helps justify security spending and prioritize controls.
Memory trick: ALE is total annual loss, ROI is profit from security.
Accounting (Security)
Flip cardThe process of tracking user activities, system events, and resource consumption for auditing, billing, and accountability purposes.
- Often referred to as auditing.
- Records who did what, when, and from where.
- Crucial for forensics, compliance, and identifying malicious activity.
Memory trick: Authenticate who you are, Authorize what you can do, Account for what you did.
Virtual Local Area Network (VLAN)
Flip cardA logical grouping of network devices that allows them to communicate as if they were on the same physical network, regardless of their actual physical location, while isolating them from other VLANs.
- Segments a single physical network into multiple logical networks.
- Enhances security by isolating traffic between groups of devices.
- Used for compliance (e.g., PCI DSS) and network management.
Memory trick: VLANs are like invisible walls within a building, separating departments.
Procedure (Security)
Flip cardDetailed, step-by-step instructions on how to perform a specific task or set of tasks to achieve a desired security objective.
- Highly prescriptive and mandatory for compliance.
- Often derived from policies and standards.
- Ensures consistency and repeatability of security operations.
Memory trick: Policy is the law, Standard is the rule, Guideline is advice, Procedure is how-to.
Data Loss Prevention (DLP)
Flip cardA set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
- Monitors, detects, and blocks sensitive data in motion, at rest, and in use.
- Prevents unauthorized data exfiltration.
- Enforces compliance regulations (e.g., GDPR, PCI DSS).
Memory trick: DLP is the 'data bouncer' at the network's exit.
Risk Tolerance
Flip cardThe acceptable deviation from achieving objectives related to risk. It is the specific maximum level of risk an organization is willing to accept after risk treatment.
- Often expressed qualitatively or quantitatively.
- Determined by executive management.
- Differs from risk appetite, which is the overall desired risk level.
Memory trick: Appetite wants, tolerance allows, treatment acts.
Single Loss Expectancy (SLE)
Flip cardThe monetary loss that is expected from a single occurrence of a specific risk event. It includes both tangible (direct) and intangible (indirect) costs associated with the event.
- Expressed in monetary terms
- Focuses on a single incident
- Component of Annualized Loss Expectancy (ALE)
Memory trick: SLE: Sum all Losses from an Event.
Vulnerability
Flip cardA weakness or flaw in a system, design, or implementation that can be exploited by a threat.
- Can be in software, hardware, or human processes.
- Often exploited by threats to cause harm.
- Patching and secure configurations mitigate vulnerabilities.
Memory trick: A THREAT exploits a VULNERABILITY, causing an IMPACT. Think of a storm (threat) hitting a weak roof (vulnerability) and causing water damage (impact).
Availability
Flip cardThe principle that systems and data are accessible and operational to authorized users when needed.
- Crucial for business continuity and critical operations.
- Achieved through redundancy, backups, disaster recovery, and fault tolerance.
- Often prioritized for operational technology (OT) systems like ICS.
Memory trick: Confidentiality, Integrity, and Availability: Your CIA agent protects your secrets, keeps your files true, and is always there when you call.
Legal and Regulatory Requirements
Flip cardMandatory laws, regulations, and standards established by governmental bodies or industry organizations that an entity must comply with.
- Non-compliance can lead to severe penalties, fines, and legal action.
- Examples include GDPR, HIPAA, PCI DSS, SOX.
- Often drive the implementation of specific security controls and practices.
Memory trick: Laws must be followed, Ethics are your compass, Privacy is personal, Data protection is the shield.
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data (measured in time) that an application can afford to lose during a disaster.
- Determines backup frequency.
- Measured in units of time (e.g., 1 hour, 1 day).
- Lower RPO means less data loss but higher cost/complexity.
Memory trick: RPO is about the 'Point' in time for data recovery, how much data you can 'lose'.
Network Routing
Flip cardThe process of selecting a path across one or more networks to send data packets from a source to a destination.
- Routers use routing tables to determine paths.
- Essential for communication between different IP subnets.
- Incorrect or missing routes cause connectivity failures to remote networks.
Memory trick: When the path is blocked, check the map (routing table).
SYN Flood Attack
Flip cardA type of Denial-of-Service (DoS) attack in which an attacker rapidly initiates a connection to a server without completing the three-way handshake, causing the server to exhaust its resources.
- Exploits the TCP three-way handshake.
- Sends many SYN packets but no final ACK.
- Overwhelms server's connection table, denying legitimate users.
Memory trick: SYN Flood is like a traffic jam at the server's entrance.