Free knowledge base

ISC2 Certified in Cybersecurity (CC) — key terms, tricks & tips

Everything from the course in one searchable place: 252 entries. Use it to review before a practice test or look up a word you forgot.

252 results

Key term

ISC2

International Information System Security Certification Consortium.

Getting Started: Your CC Exam Journey

Key term

Certification

Formal recognition of an individual's knowledge and skills.

Getting Started: Your CC Exam Journey

Key term

Entry-level

Positions or certifications for individuals starting a career.

Getting Started: Your CC Exam Journey

Key term

Domain

A specific area of knowledge covered by an exam or curriculum.

Getting Started: Your CC Exam Journey

Key term

Credential

A qualification, achievement, or quality indicating competence.

Getting Started: Your CC Exam Journey

Key term

Foundational

Basic or fundamental knowledge upon which other concepts build.

Getting Started: Your CC Exam Journey

Key term

Cybersecurity

Protecting systems, networks, and data from digital attacks.

Getting Started: Your CC Exam Journey

Memory trick

Understanding the ISC2 CC Certification

To remember the CC is for 'Cybersecurity Career,' think: 'CC = Cybersecurity Commencement!'

Getting Started: Your CC Exam Journey

Exam tip

Understanding the ISC2 CC Certification

The exam tests your understanding of the *purpose* and *target audience* of the CC certification. Be prepared to identify who benefits most from obtaining it and why it's considered an entry-level credential. Keywords like 'foundational,' 'beginner,' and 'career changer' are important.

Getting Started: Your CC Exam Journey

Common mistake

Understanding the ISC2 CC Certification

Mistaking the CC for an advanced technical certification; it's foundational.

Getting Started: Your CC Exam Journey

Common mistake

Understanding the ISC2 CC Certification

Believing prior cybersecurity work experience is required; it is not.

Getting Started: Your CC Exam Journey

Common mistake

Understanding the ISC2 CC Certification

Underestimating the value of the ISC2 brand for entry-level roles.

Getting Started: Your CC Exam Journey

Key term

Scaled Score

A raw score converted to a standardized scale for fair comparison.

Getting Started: Your CC Exam Journey

Key term

Multiple Choice Question

A question format with several options, only one of which is correct.

Getting Started: Your CC Exam Journey

Key term

Time Management

Strategically allocating time to complete all exam questions efficiently.

Getting Started: Your CC Exam Journey

Key term

Endorsement Process

The final step to become certified after passing an ISC2 exam.

Getting Started: Your CC Exam Journey

Key term

Code of Ethics

Professional conduct standards all ISC2 members must adhere to.

Getting Started: Your CC Exam Journey

Key term

Psychometrics

The science of measuring mental capacities and processes, used in exam design.

Getting Started: Your CC Exam Journey

Memory trick

Navigating the Exam: Structure and Strategy

To remember the exam details: '100 Questions, 120 Minutes, 700 to Win it!'

Getting Started: Your CC Exam Journey

Exam tip

Navigating the Exam: Structure and Strategy

The ISC2 CC exam consists of 100 multiple-choice questions. You have 120 minutes to complete it, and a scaled score of 700 out of 1000 is required to pass. Memorize these exact numbers.

Getting Started: Your CC Exam Journey

Common mistake

Navigating the Exam: Structure and Strategy

Spending too much time on a single difficult question, leading to not finishing the exam.

Getting Started: Your CC Exam Journey

Common mistake

Navigating the Exam: Structure and Strategy

Not reading all answer options carefully before selecting one, missing the 'best' answer.

Getting Started: Your CC Exam Journey

Common mistake

Navigating the Exam: Structure and Strategy

Failing to review marked questions at the end if time permits, missing easy corrections.

Getting Started: Your CC Exam Journey

Key term

Confidentiality

Protecting information from unauthorized disclosure.

Foundations of Security Principles

Key term

Integrity

Ensuring information is accurate, complete, and unaltered.

Foundations of Security Principles

Key term

Availability

Ensuring authorized users can access information when needed.

Foundations of Security Principles

Key term

CIA Triad

Foundational model of information security: Confidentiality, Integrity, Availability.

Foundations of Security Principles

Key term

Breach

An incident where security controls are circumvented, leading to compromise.

Foundations of Security Principles

Key term

Encryption

Converting data into a code to prevent unauthorized access.

Foundations of Security Principles

Key term

Access Controls

Mechanisms that restrict who can access what resources.

Foundations of Security Principles

Key term

Hashing

Generating a fixed-size value from data to detect changes.

Foundations of Security Principles

Memory trick

CIA Triad: Confidentiality, Integrity, Availability

To remember CIA, think of a secret agent: they keep secrets (Confidentiality), ensure their mission plans are accurate (Integrity), and are always ready for action (Availability).

Foundations of Security Principles

Exam tip

CIA Triad: Confidentiality, Integrity, Availability

Memorize the exact definition for each component of the CIA Triad. On the exam, you will encounter scenarios and need to correctly identify which principle is being violated or upheld.

Foundations of Security Principles

Common mistake

CIA Triad: Confidentiality, Integrity, Availability

Confusing integrity with confidentiality: Integrity is about unauthorized modification, while confidentiality is about unauthorized viewing.

Foundations of Security Principles

Common mistake

CIA Triad: Confidentiality, Integrity, Availability

Underestimating the impact of an availability breach: Even if data is secure, if no one can access it, it's useless.

Foundations of Security Principles

Common mistake

CIA Triad: Confidentiality, Integrity, Availability

Forgetting that the three principles are interconnected: A failure in one often negatively impacts the others.

Foundations of Security Principles

Key term

Authentication

Verifying the identity of a user, process, or device.

Foundations of Security Principles

Key term

Authorization

Determining what resources an authenticated user can access.

Foundations of Security Principles

Key term

Accounting

Tracking and logging user activities and resource consumption.

Foundations of Security Principles

Key term

Non-Repudiation

Ensuring a party cannot falsely deny having performed an action.

Foundations of Security Principles

Key term

MFA

Multi-Factor Authentication; using two or more credential types.

Foundations of Security Principles

Key term

Least Privilege

Granting only necessary access rights for a job function.

Foundations of Security Principles

Key term

Digital Signature

Cryptographic method providing authenticity and non-repudiation.

Foundations of Security Principles

Memory trick

Authentication, Authorization, Accounting & Non-Repudiation

Remember 'AAA' as 'Are you who you say you Are? What Are you allowed to do? What did you do?' Non-Repudiation is 'No-Denial'.

Foundations of Security Principles

Exam tip

Authentication, Authorization, Accounting & Non-Repudiation

The exam frequently tests the distinct definitions and order of AAA. Remember that authentication *always* comes before authorization. Non-repudiation is a separate but related concept ensuring accountability.

Foundations of Security Principles

Common mistake

Authentication, Authorization, Accounting & Non-Repudiation

Confusing authentication (who you are) with authorization (what you can do).

Foundations of Security Principles

Common mistake

Authentication, Authorization, Accounting & Non-Repudiation

Forgetting that accounting is about logging and auditing, not just financial records.

Foundations of Security Principles

Common mistake

Authentication, Authorization, Accounting & Non-Repudiation

Underestimating the importance of non-repudiation in legal and business contexts.

Foundations of Security Principles

Key term

Risk

Potential for loss or damage from a threat exploiting a vulnerability.

Foundations of Security Principles

Key term

Threat

Any potential danger that could exploit a vulnerability and cause harm.

Foundations of Security Principles

Key term

Vulnerability

A weakness in a system or control that a threat can exploit.

Foundations of Security Principles

Key term

Impact

The magnitude of harm or damage caused by a security incident.

Foundations of Security Principles

Key term

Likelihood

The probability or frequency of a threat exploiting a vulnerability.

Foundations of Security Principles

Key term

Risk Mitigation

Actions taken to reduce the likelihood or impact of a risk.

Foundations of Security Principles

Key term

Risk Acceptance

Deciding to take no action to reduce a risk due to cost/benefit.

Foundations of Security Principles

Key term

Risk Transfer

Shifting the financial burden of a risk to another party, e.g., insurance.

Foundations of Security Principles

Memory trick

Risk Management: Threats, Vulnerabilities, Impact & Likelihood

TV-IL: Threats, Vulnerabilities, Impact, Likelihood – the four ingredients of Risk!

Foundations of Security Principles

Exam tip

Risk Management: Threats, Vulnerabilities, Impact & Likelihood

The exam often tests your ability to differentiate between threats and vulnerabilities. Remember: a threat is 'what could happen' (e.g., malware), and a vulnerability is 'a weakness that allows it to happen' (e.g., unpatched software). Risk is the combination of both, plus impact and likelihood.

Foundations of Security Principles

Common mistake

Risk Management: Threats, Vulnerabilities, Impact & Likelihood

Confusing a threat with a vulnerability (e.g., saying 'malware' is a vulnerability instead of a threat that exploits a vulnerability).

Foundations of Security Principles

Common mistake

Risk Management: Threats, Vulnerabilities, Impact & Likelihood

Underestimating the 'human element' as both a threat (insider) and a vulnerability (lack of training).

Foundations of Security Principles

Common mistake

Risk Management: Threats, Vulnerabilities, Impact & Likelihood

Failing to consider both impact and likelihood when assessing the true severity of a risk.

Foundations of Security Principles

Key term

Security Control

Safeguard to reduce risk to assets.

Foundations of Security Principles

Key term

Policy

High-level statement of security objectives.

Foundations of Security Principles

Key term

Standard

Specific, mandatory requirements for implementing policies.

Foundations of Security Principles

Key term

Compliance

Adherence to rules, laws, regulations, and policies.

Foundations of Security Principles

Key term

Preventative Control

Stops an incident before it occurs.

Foundations of Security Principles

Key term

Detective Control

Identifies an incident during or after occurrence.

Foundations of Security Principles

Key term

Corrective Control

Mitigates impact and restores systems after an incident.

Foundations of Security Principles

Key term

GDPR

General Data Protection Regulation for data privacy.

Foundations of Security Principles

Memory trick

Security Controls, Policies, Standards & Compliance

P-S-C: Policies Set the rules, Standards Specify how, Controls Carry them out. Compliance Checks everything.

Foundations of Security Principles

Exam tip

Security Controls, Policies, Standards & Compliance

The exam often tests your ability to distinguish between policies (what to do), standards (how to do it), and controls (the actual implementation). Look for keywords like 'management directive' for policy, 'specific requirement' for standard, and 'mechanism' or 'safeguard' for control.

Foundations of Security Principles

Common mistake

Security Controls, Policies, Standards & Compliance

Confusing a policy (high-level 'what') with a standard (specific 'how').

Foundations of Security Principles

Common mistake

Security Controls, Policies, Standards & Compliance

Thinking all controls are technical; remember administrative and physical controls.

Foundations of Security Principles

Common mistake

Security Controls, Policies, Standards & Compliance

Underestimating the importance of compliance; it's not just about avoiding fines, but also trust and reputation.

Foundations of Security Principles

Key term

Business Continuity (BC)

Maintaining essential business functions during disruptions.

Resilience: BC, DR & IR Concepts

Key term

Disaster Recovery (DR)

Restoring IT systems after a disaster.

Resilience: BC, DR & IR Concepts

Key term

Recovery Time Objective (RTO)

Maximum acceptable downtime for a system/process.

Resilience: BC, DR & IR Concepts

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss measured in time.

Resilience: BC, DR & IR Concepts

Key term

Business Impact Analysis (BIA)

Identifies critical functions and their recovery needs.

Resilience: BC, DR & IR Concepts

Key term

Redundancy

Duplication of critical components to ensure availability.

Resilience: BC, DR & IR Concepts

Key term

Alternate Site

A secondary location for operations during a disaster.

Resilience: BC, DR & IR Concepts

Memory trick

Business Continuity & Disaster Recovery Planning

BC is for 'Business Continues', DR is for 'Data Restores'.

Resilience: BC, DR & IR Concepts

Exam tip

Business Continuity & Disaster Recovery Planning

The exam often tests the distinction between BC and DR. Remember: BC is about the business continuing, DR is about the IT recovering. Keywords like 'overall organizational resilience' point to BC, while 'restoring servers' points to DR.

Resilience: BC, DR & IR Concepts

Common mistake

Business Continuity & Disaster Recovery Planning

Confusing Business Continuity (BC) with Disaster Recovery (DR) and using the terms interchangeably.

Resilience: BC, DR & IR Concepts

Common mistake

Business Continuity & Disaster Recovery Planning

Developing a DR plan without first conducting a Business Impact Analysis (BIA) to prioritize systems.

Resilience: BC, DR & IR Concepts

Common mistake

Business Continuity & Disaster Recovery Planning

Creating BC/DR plans but failing to regularly test and update them, rendering them ineffective.

Resilience: BC, DR & IR Concepts

Key term

Incident Response (IR)

Structured approach to manage cybersecurity incidents.

Resilience: BC, DR & IR Concepts

Key term

NIST SP 800-61

A widely recognized guideline for computer security incident handling.

Resilience: BC, DR & IR Concepts

Key term

Containment

Limiting the scope and impact of an incident.

Resilience: BC, DR & IR Concepts

Key term

Eradication

Removing the root cause of an incident.

Resilience: BC, DR & IR Concepts

Key term

Recovery

Restoring systems and data to normal operation.

Resilience: BC, DR & IR Concepts

Key term

Lessons Learned

Post-incident review for continuous improvement.

Resilience: BC, DR & IR Concepts

Key term

Playbook

Detailed, step-by-step instructions for specific incident types.

Resilience: BC, DR & IR Concepts

Memory trick

Incident Response: Handling, Management & Planning

PRIDE: **P**reparation, **R**ecognition (Detection & Analysis), **I**solation (Containment), **D**econtamination (Eradication & Recovery), **E**valuation (Post-Incident Activity).

Resilience: BC, DR & IR Concepts

Exam tip

Incident Response: Handling, Management & Planning

The exam often tests your knowledge of the phases of the incident response lifecycle. Memorize the order and purpose of each phase, especially 'Containment' and 'Eradication' – they are distinct steps.

Resilience: BC, DR & IR Concepts

Common mistake

Incident Response: Handling, Management & Planning

Confusing containment with eradication: Containment stops the spread, eradication removes the threat's cause.

Resilience: BC, DR & IR Concepts

Common mistake

Incident Response: Handling, Management & Planning

Neglecting post-incident review: Skipping this step means missing opportunities to improve defenses.

Resilience: BC, DR & IR Concepts

Common mistake

Incident Response: Handling, Management & Planning

Lack of communication: Failing to inform relevant stakeholders can escalate an incident's impact.

Resilience: BC, DR & IR Concepts

Key term

Critical Business Function

An activity essential for an organization's survival and operations.

Resilience: BC, DR & IR Concepts

Key term

Downtime

Period when a system or service is unavailable.

Resilience: BC, DR & IR Concepts

Key term

Data Loss

Irrecoverable destruction or corruption of data.

Resilience: BC, DR & IR Concepts

Memory trick

Business Impact Analysis & Recovery Objectives

RTO is 'Time' (how long till it's back up?), RPO is 'Point' (how much data did we lose up to this point?).

Resilience: BC, DR & IR Concepts

Exam tip

Business Impact Analysis & Recovery Objectives

The exam often tests your ability to distinguish between RTO and RPO. Remember, RTO is about time to recover functionality, and RPO is about the amount of data lost. The BIA is the foundational step for determining both.

Resilience: BC, DR & IR Concepts

Common mistake

Business Impact Analysis & Recovery Objectives

Confusing RTO with RPO: RTO is about time to recovery, RPO is about data loss.

Resilience: BC, DR & IR Concepts

Common mistake

Business Impact Analysis & Recovery Objectives

Skipping the BIA: Without a proper BIA, RTO and RPO are arbitrary and not aligned with business needs.

Resilience: BC, DR & IR Concepts

Common mistake

Business Impact Analysis & Recovery Objectives

Setting unrealistic RTO/RPO: Very low RTO/RPO targets are expensive and may not be necessary for all systems.

Resilience: BC, DR & IR Concepts

Key term

Backup

A copy of data used to restore original data after loss.

Resilience: BC, DR & IR Concepts

Key term

Full Backup

Copies all selected data, regardless of prior backups.

Resilience: BC, DR & IR Concepts

Key term

Incremental Backup

Copies only data changed since the last full or incremental backup.

Resilience: BC, DR & IR Concepts

Key term

Differential Backup

Copies data changed since the last full backup.

Resilience: BC, DR & IR Concepts

Key term

RAID

Redundant Array of Independent Disks for data redundancy.

Resilience: BC, DR & IR Concepts

Key term

High Availability (HA)

Systems designed to operate continuously without failure.

Resilience: BC, DR & IR Concepts

Key term

Offsite Storage

Storing backups in a location separate from the primary site.

Resilience: BC, DR & IR Concepts

Memory trick

Backup Strategies, Redundancy & Testing Plans

To remember the 3-2-1 backup rule, think of a '3-course meal, 2 different drinks, and 1 dessert to go!'

Resilience: BC, DR & IR Concepts

Exam tip

Backup Strategies, Redundancy & Testing Plans

The exam often tests your understanding of the '3-2-1 rule' for backups. Memorize '3 copies, 2 different media, 1 offsite.' Also, know the difference between incremental and differential backups regarding restore time and storage.

Resilience: BC, DR & IR Concepts

Common mistake

Backup Strategies, Redundancy & Testing Plans

Forgetting to test backups regularly, leading to failed recovery when needed.

Resilience: BC, DR & IR Concepts

Common mistake

Backup Strategies, Redundancy & Testing Plans

Confusing redundancy with backups; redundancy prevents downtime, backups recover data.

Resilience: BC, DR & IR Concepts

Common mistake

Backup Strategies, Redundancy & Testing Plans

Not storing backups offsite, making them vulnerable to site-specific disasters.

Resilience: BC, DR & IR Concepts

Key term

Access Control

Mechanism to regulate who or what can use resources.

Controlling Access to Resources

Key term

Physical Access Control

Restricts direct interaction with physical assets.

Controlling Access to Resources

Key term

Logical Access Control

Restricts access to computer systems, networks, and data.

Controlling Access to Resources

Key term

Defense in Depth

Layered security approach using multiple controls.

Controlling Access to Resources

Key term

Biometric Scanner

Uses unique biological traits for identification.

Controlling Access to Resources

Key term

Access Control List (ACL)

List of permissions attached to an object.

Controlling Access to Resources

Memory trick

Physical & Logical Access Control Fundamentals

Think 'P' for Physical, 'P' for People and Places. Think 'L' for Logical, 'L' for Login and Laptops.

Controlling Access to Resources

Exam tip

Physical & Logical Access Control Fundamentals

The exam will test your ability to differentiate between physical and logical controls. Look for keywords like 'door,' 'fence,' 'guard' for physical, and 'password,' 'firewall,' 'encryption' for logical. Remember that defense in depth applies to both.

Controlling Access to Resources

Common mistake

Physical & Logical Access Control Fundamentals

Confusing physical and logical controls: Remember physical protects the hardware, logical protects the data/software.

Controlling Access to Resources

Common mistake

Physical & Logical Access Control Fundamentals

Underestimating the importance of physical security: A strong firewall is useless if someone can just walk in and steal the server.

Controlling Access to Resources

Common mistake

Physical & Logical Access Control Fundamentals

Ignoring the need for layered security: Relying on a single control leaves a single point of failure.

Controlling Access to Resources

Key term

Identification

Claiming an identity to a system.

Controlling Access to Resources

Key term

Credentials

Proof of identity, like passwords or tokens.

Controlling Access to Resources

Memory trick

Identification, Authentication & Authorization

Think 'IAA' as 'I Am Allowed' – I (Identify) Am (Authenticate) Allowed (Authorize).

Controlling Access to Resources

Exam tip

Identification, Authentication & Authorization

The exam will test your ability to distinguish between identification, authentication, and authorization. Remember: Identification is 'who you say you are,' Authentication is 'proving you are who you say you are,' and Authorization is 'what you are allowed to do.'

Controlling Access to Resources

Common mistake

Identification, Authentication & Authorization

Confusing authentication with authorization; they are distinct steps.

Controlling Access to Resources

Common mistake

Identification, Authentication & Authorization

Believing that successful identification automatically grants access.

Controlling Access to Resources

Common mistake

Identification, Authentication & Authorization

Underestimating the importance of strong authentication methods.

Controlling Access to Resources

Key term

Multi-Factor Authentication (MFA)

Requires two or more distinct authentication factors for verification.

Controlling Access to Resources

Key term

Authentication Factor

A category of proof used to verify identity (e.g., something you know, have, are).

Controlling Access to Resources

Key term

Something You Know

A secret piece of information only the user should know, like a password or PIN.

Controlling Access to Resources

Key term

Something You Have

A physical item possessed by the user, such as a token or smartphone.

Controlling Access to Resources

Key term

Something You Are

A unique biological characteristic of the user, like a fingerprint or face.

Controlling Access to Resources

Key term

Single Sign-On (SSO)

Allows users to log in once to access multiple independent applications.

Controlling Access to Resources

Key term

Identity Provider (IdP)

The system that authenticates the user and provides identity assertions in SSO.

Controlling Access to Resources

Key term

Service Provider (SP)

An application or service that relies on an IdP for user authentication.

Controlling Access to Resources

Memory trick

Multi-Factor Authentication & Single Sign-On

K-H-A for Know, Have, Are. Think of it like a KHA-p (cap) you wear for security!

Controlling Access to Resources

Exam tip

Multi-Factor Authentication & Single Sign-On

The exam often tests your understanding of the three primary authentication factors: something you know, something you have, and something you are. Be able to provide examples for each. Also, remember that MFA requires at least two *different* factors, not just two pieces of the same factor.

Controlling Access to Resources

Common mistake

Multi-Factor Authentication & Single Sign-On

Confusing MFA with simply using a stronger password. MFA requires *multiple types* of factors.

Controlling Access to Resources

Common mistake

Multi-Factor Authentication & Single Sign-On

Believing SSO is a security measure on its own. SSO enhances convenience; its security depends on the strength of the initial authentication (ideally MFA).

Controlling Access to Resources

Common mistake

Multi-Factor Authentication & Single Sign-On

Thinking 'something you do' (like a specific gesture) is one of the three primary factors. While a factor, it's less common than know, have, or are.

Controlling Access to Resources

Key term

IAM

Framework for managing digital identities and access to resources.

Controlling Access to Resources

Key term

DAC

Resource owner controls access permissions.

Controlling Access to Resources

Key term

RBAC

Permissions are assigned to roles, users are assigned to roles.

Controlling Access to Resources

Key term

MAC

Central authority assigns security labels; strict access rules.

Controlling Access to Resources

Key term

Provisioning

Process of creating and assigning user accounts and permissions.

Controlling Access to Resources

Key term

De-provisioning

Process of revoking access and removing user accounts.

Controlling Access to Resources

Memory trick

IAM, Access Models & Least Privilege

To remember the access models, think 'DR. MAC': Discretionary, Role-Based, Mandatory Access Control.

Controlling Access to Resources

Exam tip

IAM, Access Models & Least Privilege

On the exam, understand the core difference: DAC is owner-centric, RBAC is role-centric, and MAC is label-centric (system-wide policy). Least privilege is a fundamental security principle applicable across all models.

Controlling Access to Resources

Common mistake

IAM, Access Models & Least Privilege

Granting 'temporary' administrative access and forgetting to revoke it.

Controlling Access to Resources

Common mistake

IAM, Access Models & Least Privilege

Assigning users to roles with more permissions than their job requires.

Controlling Access to Resources

Common mistake

IAM, Access Models & Least Privilege

Not regularly auditing user permissions to ensure they still align with current job functions.

Controlling Access to Resources

Key term

Topology

Physical or logical arrangement of network devices.

Securing the Network Perimeter

Key term

Switch

Device that forwards data frames to specific ports.

Securing the Network Perimeter

Key term

Router

Device that forwards data packets between different networks.

Securing the Network Perimeter

Key term

Protocol

Set of rules governing data communication.

Securing the Network Perimeter

Key term

TCP/IP

Suite of protocols forming the internet's foundation.

Securing the Network Perimeter

Key term

OSI Model

7-layer conceptual framework for network communication.

Securing the Network Perimeter

Key term

VLAN

Logical network segment created on a switch.

Securing the Network Perimeter

Memory trick

Network Topologies, Devices & Protocols

Please Do Not Throw Sausage Pizza Away (Physical, Data Link, Network, Transport, Session, Presentation, Application)

Securing the Network Perimeter

Exam tip

Network Topologies, Devices & Protocols

Memorize the order of the OSI model layers from 7 (Application) down to 1 (Physical). On the exam, you might be asked to identify which layer a specific device or protocol operates at.

Securing the Network Perimeter

Common mistake

Network Topologies, Devices & Protocols

Confusing a hub with a switch: Hubs broadcast, switches intelligently forward.

Securing the Network Perimeter

Common mistake

Network Topologies, Devices & Protocols

Incorrectly identifying the primary function of a router vs. a switch: Routers connect different networks, switches connect devices within the same network segment.

Securing the Network Perimeter

Common mistake

Network Topologies, Devices & Protocols

Forgetting the OSI model layers or their order: This framework is key to understanding network communication and troubleshooting.

Securing the Network Perimeter

Key term

WPA3

Latest and most secure Wi-Fi Protected Access standard.

Securing the Network Perimeter

Key term

Network Segmentation

Dividing a network into isolated sub-networks.

Securing the Network Perimeter

Key term

VPN

Creates a secure, encrypted connection over a public network.

Securing the Network Perimeter

Key term

Remote-Access VPN

Connects individual users to a private network.

Securing the Network Perimeter

Key term

Site-to-Site VPN

Connects two or more private networks together.

Securing the Network Perimeter

Key term

IPsec

Suite of protocols for securing IP communications.

Securing the Network Perimeter

Key term

AES

Advanced Encryption Standard, a strong symmetric encryption algorithm.

Securing the Network Perimeter

Memory trick

Wireless Security, Segmentation & VPNs

To remember the order of Wi-Fi security: 'WEP Was Pretty Awful, WPA Was Pretty Adequate, WPA2 Was Pretty Good, WPA3 is Pretty Perfect!'

Securing the Network Perimeter

Exam tip

Wireless Security, Segmentation & VPNs

On the exam, recognize WPA3 as the strongest wireless security protocol. Understand that network segmentation (e.g., VLANs) limits the blast radius of a breach. For VPNs, differentiate between Remote-Access and Site-to-Site and know their primary purpose is secure remote connectivity.

Securing the Network Perimeter

Common mistake

Wireless Security, Segmentation & VPNs

Using WEP or WPA (original) for wireless security instead of WPA2 or WPA3, leaving the network vulnerable.

Securing the Network Perimeter

Common mistake

Wireless Security, Segmentation & VPNs

Failing to segment critical systems, allowing an attacker who breaches one part of the network to easily access sensitive data elsewhere.

Securing the Network Perimeter

Common mistake

Wireless Security, Segmentation & VPNs

Assuming a VPN alone is sufficient for remote access security without also implementing strong authentication like MFA.

Securing the Network Perimeter

Key term

Shared Responsibility Model

Defines security duties between cloud provider and customer.

Securing the Network Perimeter

Key term

Endpoint Detection and Response (EDR)

Monitors and responds to threats on endpoints in real-time.

Securing the Network Perimeter

Key term

Data Loss Prevention (DLP)

Prevents sensitive data from leaving the organization's control.

Securing the Network Perimeter

Key term

Mobile Device Management (MDM)

Centrally manages and secures mobile devices.

Securing the Network Perimeter

Key term

Mobile Application Management (MAM)

Secures and manages specific applications on mobile devices.

Securing the Network Perimeter

Key term

Cloud Access Security Broker (CASB)

Enforces security policies across multiple cloud services.

Securing the Network Perimeter

Memory trick

Cloud, Endpoint & Mobile Device Security

CEM: Cloud, Endpoint, Mobile. Remember to secure all three parts of your digital world!

Securing the Network Perimeter

Exam tip

Cloud, Endpoint & Mobile Device Security

The exam often tests the Shared Responsibility Model for cloud security. Remember that the cloud provider is generally responsible for 'security OF the cloud' (physical infrastructure, virtualization), while the customer is responsible for 'security IN the cloud' (data, applications, network configuration, IAM). Keywords to look for are 'customer's responsibility' or 'provider's responsibility' in cloud scenarios.

Securing the Network Perimeter

Common mistake

Cloud, Endpoint & Mobile Device Security

Assuming the cloud provider handles all security aspects in a SaaS model.

Securing the Network Perimeter

Common mistake

Cloud, Endpoint & Mobile Device Security

Neglecting to implement strong authentication (MFA) for cloud services and mobile access.

Securing the Network Perimeter

Common mistake

Cloud, Endpoint & Mobile Device Security

Failing to regularly patch and update endpoint operating systems and applications.

Securing the Network Perimeter

Key term

Phishing

Deceptive emails to trick users into revealing info.

Securing the Network Perimeter

Key term

SPF (Sender Policy Framework)

Email authentication to prevent sender spoofing.

Securing the Network Perimeter

Key term

WAF (Web Application Firewall)

Protects web applications from common attacks.

Securing the Network Perimeter

Key term

SSL/TLS

Protocols for encrypting web communication.

Securing the Network Perimeter

Key term

SIEM (Security Information and Event Management)

Collects, aggregates, analyzes security logs.

Securing the Network Perimeter

Key term

Correlation

Linking disparate events to identify patterns.

Securing the Network Perimeter

Key term

BEC (Business Email Compromise)

Impersonating executives for financial fraud.

Securing the Network Perimeter

Memory trick

Email, Web Security & SIEM Fundamentals

For SIEM functions, remember 'CAN-DO': Collect, Aggregate, Normalize, Detect (Correlate), Output (Reports/Alerts).

Securing the Network Perimeter

Exam tip

Email, Web Security & SIEM Fundamentals

The exam often tests the purpose of SPF, DKIM, and DMARC in preventing email spoofing. Remember that a WAF protects web applications, not the network layer. For SIEM, focus on its ability to centralize logs, correlate events, and provide real-time alerts for incident detection.

Securing the Network Perimeter

Common mistake

Email, Web Security & SIEM Fundamentals

Confusing a WAF with a traditional network firewall; a WAF operates at the application layer (Layer 7).

Securing the Network Perimeter

Common mistake

Email, Web Security & SIEM Fundamentals

Underestimating the importance of user training in preventing phishing and web-based attacks; technology alone isn't enough.

Securing the Network Perimeter

Common mistake

Email, Web Security & SIEM Fundamentals

Believing a SIEM automatically fixes problems; it detects and alerts, but human analysts are still needed for investigation and response.

Securing the Network Perimeter

Key term

Vulnerability Scan

Automated process to identify known security weaknesses.

Operational Security Practices

Key term

Penetration Test

Simulated cyberattack to find exploitable vulnerabilities.

Operational Security Practices

Key term

Security Audit

Systematic evaluation of controls against standards/policies.

Operational Security Practices

Key term

CVE

Common Vulnerabilities and Exposures database of known flaws.

Operational Security Practices

Key term

Ethical Hacking

Authorized hacking to test system security.

Operational Security Practices

Key term

Black Box Test

Pen test with no prior knowledge of the target system.

Operational Security Practices

Memory trick

Security Assessments: Scans, Tests & Audits

To remember the differences: 'V' is for 'Vulnerabilities', 'P' is for 'Penetrating' (exploiting), 'A' is for 'Auditing' (compliance).

Operational Security Practices

Exam tip

Security Assessments: Scans, Tests & Audits

The exam often distinguishes between 'finding' vulnerabilities (scans) and 'exploiting' them (pen tests). Remember that audits are about 'verifying compliance' and 'control effectiveness.'

Operational Security Practices

Common mistake

Security Assessments: Scans, Tests & Audits

Confusing a vulnerability scan with a penetration test; scans identify, pen tests exploit.

Operational Security Practices

Common mistake

Security Assessments: Scans, Tests & Audits

Believing that passing a vulnerability scan means a system is perfectly secure.

Operational Security Practices

Common mistake

Security Assessments: Scans, Tests & Audits

Assuming a security audit is a technical test; it's primarily a compliance and control review.

Operational Security Practices

Key term

Security Monitoring

Continuous observation of systems and networks for security incidents.

Operational Security Practices

Key term

Log Management

Process of collecting, storing, analyzing, and disposing of system logs.

Operational Security Practices

Key term

IDS (Intrusion Detection System)

Monitors network or system activity for malicious patterns or policy violations.

Operational Security Practices

Key term

Security Awareness Training

Educating employees about security risks, policies, and best practices.

Operational Security Practices

Key term

Retention Policy

Rules defining how long data, including logs, must be kept.

Operational Security Practices

Key term

Anomaly Detection

Identifying patterns in data that deviate significantly from expected behavior.

Operational Security Practices

Memory trick

Monitoring, Log Management & Awareness Training

To remember the key aspects: 'MAL' for Monitoring, Awareness, and Logs. MALware is bad, but MAL security practices are good!

Operational Security Practices

Exam tip

Monitoring, Log Management & Awareness Training

The exam emphasizes the 'why' behind these practices. Know that monitoring detects, log management records, and awareness training prevents. Keywords like 'proactive defense,' 'forensic analysis,' and 'human element' are important.

Operational Security Practices

Common mistake

Monitoring, Log Management & Awareness Training

Treating logs as mere storage; they must be actively analyzed.

Operational Security Practices

Common mistake

Monitoring, Log Management & Awareness Training

Conducting security awareness training only once a year instead of ongoing.

Operational Security Practices

Common mistake

Monitoring, Log Management & Awareness Training

Failing to integrate monitoring alerts with incident response procedures.

Operational Security Practices

Key term

Patch Management

Process of applying updates to software to fix bugs and security vulnerabilities.

Operational Security Practices

Key term

Configuration Management

Ensuring systems adhere to secure baselines and consistent settings.

Operational Security Practices

Key term

Asset Management

Identifying, tracking, and managing all IT assets throughout their lifecycle.

Operational Security Practices

Key term

Security Baseline

A minimum set of security configurations for a system or application.

Operational Security Practices

Key term

Exploit

Software or data that takes advantage of a vulnerability to cause unintended behavior.

Operational Security Practices

Key term

Lifecycle

The entire lifespan of an asset, from acquisition to disposal.

Operational Security Practices

Memory trick

Patch, Configuration & Asset Management

To remember the three, think 'PAC Man': P-atch, A-sset, C-onfiguration. PAC Man eats up security threats!

Operational Security Practices

Exam tip

Patch, Configuration & Asset Management

The exam often tests your understanding of the *purpose* and *benefits* of each management practice. Keywords like 'reduce attack surface' for configuration management, 'address known vulnerabilities' for patch management, and 'maintain inventory' for asset management are key.

Operational Security Practices

Common mistake

Patch, Configuration & Asset Management

Confusing configuration management with change management (configuration is about *state*, change is about *process*).

Operational Security Practices

Common mistake

Patch, Configuration & Asset Management

Forgetting that patch management includes testing, not just deployment.

Operational Security Practices

Common mistake

Patch, Configuration & Asset Management

Underestimating the importance of asset disposal in asset management.

Operational Security Practices

Key term

Data Classification

Categorizing data by sensitivity to apply appropriate security controls.

Operational Security Practices

Key term

Data at Rest

Data stored on a physical or digital storage medium.

Operational Security Practices

Key term

Data in Transit

Data actively moving across a network or between systems.

Operational Security Practices

Key term

Physical Security

Protection of physical assets from threats like theft and unauthorized access.

Operational Security Practices

Key term

Personnel Security

Measures to ensure employees are trustworthy and follow security policies.

Operational Security Practices

Key term

Degaussing

Using a magnetic field to erase data from magnetic storage media.

Operational Security Practices

Key term

Principle of Least Privilege

Granting users only the minimum access needed to perform their job.

Operational Security Practices

Memory trick

Data Handling, Physical & Personnel Security

Remember 'APP' for the three types of security: Assets (Physical), People (Personnel), and Processes (Data Handling).

Operational Security Practices

Exam tip

Data Handling, Physical & Personnel Security

Memorize the three states of data (at rest, in transit, in process) and the primary control for each. The exam often asks to match a data state with its most effective security measure.

Operational Security Practices

Common mistake

Data Handling, Physical & Personnel Security

Underestimating the importance of physical security in a digital world.

Operational Security Practices

Common mistake

Data Handling, Physical & Personnel Security

Failing to classify data, leading to over- or under-protection.

Operational Security Practices

Common mistake

Data Handling, Physical & Personnel Security

Neglecting proper employee offboarding procedures, creating insider threats.

Operational Security Practices