ISC2 CISSP (Certified Information Systems Security Professional) flashcards
186 free flashcards. Tap a card to flip it.
Data Diode
Flip cardA hardware-based network security device that enforces one-way data flow between two networks. It prevents any data from flowing in the reverse direction, providing absolute assurance against data exfiltration or external network intrusion.
- Physically enforces unidirectional data transfer.
- Offers the highest level of network segregation security.
- Commonly used in critical infrastructure (OT/ICS) and classified networks.
- Prevents data leakage and external command injection.
Memory trick: Data Diodes Direct Data Definitely One-Way.
Man-in-the-Middle (MITM) Attack
Flip cardAn attack where the attacker secretly relays and possibly alters the communication between two parties who believe they are directly communicating with each other.
- Requires the attacker to intercept and control the communication path.
- Can be facilitated by ARP spoofing, DNS spoofing, or compromised network devices.
- Compromises confidentiality and integrity.
Memory trick: A 'Compromised Switch' makes the 'Attacker' the 'Man in the Middle'.
WPA3-Personal (SAE)
Flip cardThe latest standard for securing Wi-Fi networks using a pre-shared key, offering enhanced security features over WPA2-Personal. It uses Simultaneous Authentication of Equals (SAE) to provide stronger protection against offline dictionary attacks and introduce forward secrecy.
- Uses Simultaneous Authentication of Equals (SAE) for robust key exchange.
- Protects against offline dictionary attacks.
- Provides forward secrecy, ensuring past session data remains secure.
- Offers opportunistic wireless encryption (OWE) for open networks.
Memory trick: WPA3 Secures All Encrypted Wi-Fi.
IPsec VPN
Flip cardA Virtual Private Network (VPN) solution that uses the IPsec protocol suite to establish secure, encrypted connections over an untrusted network, such as the internet. It provides confidentiality, integrity, and authenticity for data in transit.
- Operates at the network layer (Layer 3).
- Uses Authentication Header (AH) for integrity/authenticity and Encapsulating Security Payload (ESP) for confidentiality/integrity/authenticity.
- Supports two modes: Tunnel mode (for networks) and Transport mode (for hosts).
- Widely used for site-to-site and remote access VPNs.
Memory trick: IPsec Protects Internet Privacy Securely.
IPS Inline Mode
Flip cardAn Intrusion Prevention System deployment where all network traffic passes directly through the IPS, allowing it to actively block or prevent detected threats.
- Acts as a gatekeeper, sits 'in-line' with network traffic.
- Can actively drop malicious packets or reset connections.
- Introduces latency and can be a single point of failure.
Memory trick: Inline IPS is a 'Traffic Cop' that can 'Stop' everything.
SD-WAN Orchestrator
Flip cardThe centralized management and control component of an SD-WAN, responsible for policy enforcement, global network visibility, and intelligent routing decisions.
- Acts as the 'brain' of the SD-WAN.
- Monitors network health and application performance.
- Pushes policies and routing decisions to edge devices.
Memory trick: Orchestrator conducts, Edge executes.
Multiprotocol Label Switching (MPLS)
Flip cardA routing technique in telecommunications networks that directs data from one network node to the next based on short path labels rather than long network addresses.
- Reduces latency by avoiding complex IP header lookups.
- Enables traffic engineering and quality of service (QoS).
- Often used in core networks of service providers and large enterprises.
Memory trick: MPLS: 'My Packet's Lightning Speed' for fast lane delivery.
WPA3
Flip cardThe latest generation of Wi-Fi Protected Access security, offering enhanced cryptographic strength, improved authentication, and better resilience against common wireless attacks.
- Uses Simultaneous Authentication of Equals (SAE) for stronger key establishment.
- Provides Management Frame Protection (MFP) for integrity of management frames.
- Offers WPA3-Personal for home, WPA3-Enterprise for corporate.
- Includes Enhanced Open for public Wi-Fi.
Memory trick: WPA3 is the newest shield for Wi-Fi.
Smurf Attack
Flip cardA DDoS attack in which the attacker sends a large number of ICMP echo requests to an IP broadcast address using a spoofed source IP address that belongs to the victim.
- Relies on ICMP and IP broadcast addresses.
- Amplifies traffic, causing a denial of service to the victim.
- Mitigated by disabling IP directed broadcasts on routers.
Memory trick: DOS: 'D'o 'O'ver 'S'ervice.
Integrity (CIA Triad)
Flip cardThe assurance that information is accurate and complete, and has not been subjected to unauthorized modification or destruction.
- Achieved through hashing, digital signatures, access controls.
- Compromised by data tampering, unauthorized changes, or replay attacks.
- Ensures trustworthiness and reliability of data.
Memory trick: CIA: 'C'onfidential, 'I'ntegrity, 'A'vailable.
MAC Flooding
Flip cardA network attack that overwhelms a switch's Content Addressable Memory (CAM) table by sending a large number of frames with different source MAC addresses. This forces the switch to broadcast all incoming traffic to all ports, effectively turning it into a hub.
- Targets Layer 2 switches.
- Overwhelms the switch's CAM table.
- Causes the switch to enter fail-open mode, broadcasting all traffic.
- Can lead to network performance degradation and traffic interception.
Memory trick: MACs And ARPs Poison Networks Easily.
Firewall
Flip cardA network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
- Can be hardware, software, or cloud-based.
- Operates at various layers of the OSI model.
- Essential for network segmentation and perimeter defense.
Memory trick: A 'Firewall' 'Walls' off 'Traffic' between zones.
IPsec
Flip cardA suite of protocols used to secure IP communications by providing authentication, integrity, and confidentiality services.
- Operates at the network layer (Layer 3) of the OSI model.
- Commonly used for Virtual Private Networks (VPNs).
- Includes Authentication Header (AH) and Encapsulating Security Payload (ESP) protocols.
Memory trick: IPsec is the 'Secure' way to 'Connect' 'Packets'.
Transport Layer Security (TLS)
Flip cardA cryptographic protocol designed to provide communication security over a computer network, widely used for encrypting web traffic and other application-layer data.
- Operates at the transport layer of the OSI model.
- Provides confidentiality, integrity, and authentication.
- Successor to SSL (Secure Sockets Layer).
Memory trick: TLS 'Secures' the 'Talk' between 'Apps'.
Virtual Local Area Network (VLAN)
Flip cardA logical grouping of network devices that allows for segmentation of a local area network (LAN) into multiple broadcast domains, even if devices are on the same physical switch.
- Operates at Layer 2 of the OSI model.
- Enhances security by isolating traffic.
- Improves network performance by reducing broadcast traffic.
Memory trick: VLANs are 'Virtual Lanes' for traffic, keeping projects separated.
SDN Control Plane
Flip cardThe 'brain' of Software-Defined Networking (SDN), responsible for making forwarding decisions, managing network state, and translating high-level policies into data plane instructions.
- Centralized intelligence for the network.
- Communicates with the data plane via protocols like OpenFlow.
- Enforces policies defined in the management plane.
Memory trick: The 'Control Plane' is the conductor, directing the network orchestra.
Intrusion Detection System (IDS)
Flip cardA security device that monitors network or system activities for malicious activity or policy violations and produces reports or alerts.
- Monitors traffic for signatures or anomalies.
- Primarily a detection and alerting tool.
- Does not actively block traffic (unlike IPS).
Memory trick: IDS spots danger, IPS stops it cold.
WPA3-Enterprise
Flip cardThe latest and most secure Wi-Fi Protected Access standard designed for enterprise environments, providing enhanced authentication and encryption.
- Uses 802.1X for authentication, typically with RADIUS/EAP.
- Supports 192-bit cryptographic strength for CNSA compliance.
- Offers stronger protection against dictionary attacks and improved key management.
Memory trick: WPA3-Enterprise: The 'Gold Standard' for serious network defense.
Port Security
Flip cardA switch feature that restricts input to an interface by limiting and identifying MAC addresses of stations allowed to access the port.
- Prevents MAC address spoofing and MAC flooding attacks.
- Allows static configuration of MAC addresses or dynamic learning up to a limit.
- Can be configured to shut down the port, restrict traffic, or protect against violations.
Memory trick: Port Security 'Locks' the 'Port' by 'MAC' address.
Virtual Extensible LAN (VXLAN)
Flip cardA network virtualization technology that encapsulates Layer 2 Ethernet frames in Layer 3 IP packets, creating a logical Layer 2 network over an existing Layer 3 infrastructure. It enables scalable multi-tenancy and larger virtual network segments in cloud data centers.
- Extends Layer 2 networks over Layer 3 (referred to as an overlay network).
- Uses a 24-bit VXLAN Network Identifier (VNI) for up to 16 million logical networks.
- Solves the scalability limitations of traditional VLANs (4096 IDs).
- Enables flexible, isolated multi-tenant environments in cloud data centers.
Memory trick: VXLAN Virtually eXtends LANs for All Tenants.
Datagram Transport Layer Security (DTLS)
Flip cardA communication protocol that provides security for datagram-based applications by allowing them to communicate in a way that prevents eavesdropping, tampering, or message forgery. It is based on TLS but adapted for unreliable transport protocols like UDP.
- Provides security similar to TLS but over UDP.
- Designed for applications sensitive to latency and packet loss (e.g., VoIP, gaming, IoT).
- Handles packet reordering and loss inherent in UDP.
- Lower overhead than TCP-based TLS for certain use cases.
Memory trick: DTLS Delivers Tiny Links Securely.
Intrusion Prevention System (IPS) Inline Mode
Flip cardA deployment method for an IPS where the device is placed directly in the network's traffic path. This allows the IPS to actively inspect all passing traffic and take immediate action, such as blocking or dropping malicious packets, before they reach their intended target.
- Acts as a gatekeeper, inspecting all traffic.
- Enables real-time prevention and active blocking of threats.
- Can introduce a single point of failure if not properly designed with bypass mechanisms.
- Requires careful tuning to minimize false positives and latency.
Memory trick: Inline IPS Injects Instant Protection.
Software-Defined Networking (SDN)
Flip cardAn architectural approach that decouples the network control and forwarding functions, enabling network control to become directly programmable and the underlying infrastructure to be abstracted from applications and network services.
- Separates control plane from data plane.
- Centralized network management and orchestration.
- Enables network programmability and automation.
- Improves network agility, resilience, and scalability.
Memory trick: SDN: Smartly Designed Networks.
802.1X Port-Based Authentication
Flip cardAn IEEE standard for port-based network access control that provides an authentication mechanism to devices wishing to attach to a LAN port or to establish a wireless connection.
- Requires authentication before network access is granted.
- Often integrates with RADIUS servers.
- Can dynamically assign VLANs or apply policies post-authentication.
Memory trick: 802.1X asks 'Who are you?' before connecting.
WPA2-Enterprise (EAP-TLS)
Flip cardAn enterprise-grade wireless security standard utilizing 802.1X for centralized authentication and EAP-TLS for strong mutual authentication with digital certificates, coupled with AES encryption.
- Uses 802.1X for centralized authentication (RADIUS).
- EAP-TLS provides strongest mutual authentication (certificates).
- Encrypts traffic with AES (CCMP).
Memory trick: WEP is weak, WPA2-Enterprise is strong.
Web Application Firewall (WAF)
Flip cardA security solution that protects web applications from common web-based attacks by filtering, monitoring, and blocking malicious HTTP traffic to and from a web application. It operates at Layer 7 of the OSI model.
- Protects against application-layer attacks (e.g., SQL injection, XSS, application DDoS).
- Inspects HTTP/HTTPS traffic content.
- Can be network-based, host-based, or cloud-based.
- Provides granular control over web traffic.
Memory trick: WAFs Guard Web Apps Fiercely.
SDN Controller
Flip cardThe central component of a Software-Defined Network (SDN) that acts as the 'brain,' separating the control plane from the data plane, providing a centralized view and programmatic control of the network.
- Centralizes network intelligence.
- Communicates with data plane via Southbound APIs (e.g., OpenFlow).
- Provides Northbound APIs for applications.
Memory trick: Controller thinks, Switch acts.
Least Privilege (Network)
Flip cardA security principle applied to networks that dictates granting only the minimum necessary access rights (e.g., open ports, allowed protocols) required for a system or user to perform its function.
- Reduces attack surface by limiting exposure.
- Minimizes potential damage from compromise.
- Applies to users, processes, and network resources.
Memory trick: Least Privilege: Just enough, no more.
Client-Side Encryption (CSE)
Flip cardA method where data is encrypted by the client's application or system before it is transmitted to and stored by a cloud service provider, ensuring the client retains full control over the encryption keys and process.
- Data is encrypted before leaving the client's control.
- CSP never has access to unencrypted data or encryption keys.
- Provides the highest level of client control over data confidentiality in the cloud.
Memory trick: Client's hand encrypts before cloud land.
Data Classification Objectives
Flip cardClearly defined goals for a data classification program, including scope, purpose, and stakeholders, serving as the foundation for the entire scheme.
- Establishes 'why' and 'what' of classification.
- Aligns with business needs and risk tolerance.
- Guides subsequent steps in scheme development.
Memory trick: Goals first, then rules, then find the data, label, protect, and teach.
Technical Controls
Flip cardSecurity controls implemented through hardware or software to enforce security policies and protect systems and data.
- Automate security functions.
- Examples: firewalls, IDS, encryption, access control systems.
- Directly protect assets.
Memory trick: Admin's Rules, Physical's Walls, Technical's Code, Operational's Calls.
Information Classification
Flip cardThe process of categorizing information based on its sensitivity, value, and criticality to an organization, often determining its protection requirements.
- Assigns sensitivity labels (e.g., Top Secret, Confidential).
- Prerequisite for Mandatory Access Control (MAC).
- Helps determine appropriate security controls.
Memory trick: Classify to Control, Label to Govern All.
Data Owner
Flip cardThe individual or entity with ultimate responsibility for the protection, integrity, and usage of specific data assets, making decisions on classification and access.
- Accountable for data's lifecycle, not just its technical aspects.
- Often a business unit head who understands the data's value.
- Works with data custodians and other stakeholders to implement controls.
Memory trick: Owner knows data's worth, Custodian protects its birth.
Administrative Controls (Data Handling)
Flip cardPolicies, procedures, and guidelines established by management to govern the behavior of personnel and the management of information assets, ensuring adherence to security objectives.
- Define 'how' data should be handled and protected.
- Provide the framework for technical and physical controls.
- Examples include security policies, standards, and awareness training.
Memory trick: Admin tells, Tech does, Phys secures.
Non-repudiation
Flip cardA security objective that ensures an individual or entity cannot deny the authenticity of their signature on a document or the sending of a message.
- Often achieved using digital signatures.
- Proves origin and integrity of data/action.
- Prevents false denials of involvement.
Memory trick: CIA Protects, Non-Repudiation Connects.
Client-Side Encryption
Flip cardEncryption performed by the client application or system before data is transmitted to or stored by a third party (e.g., cloud provider).
- Ensures data is encrypted before leaving client control.
- Prevents cloud provider from accessing plaintext data.
- Provides highest level of data confidentiality in cloud.
Memory trick: Client First, Cloud Never Sees; Server Second, Cloud Can Please.
Data Retention Policy Ownership
Flip cardDesignating specific data owners who are accountable for defining and enforcing retention schedules for their respective data types, especially crucial in complex regulatory environments.
- Assigns responsibility for retention decisions.
- Ensures compliance with legal and business needs.
- Foundation for automated retention processes.
Memory trick: Owner's Watch, Data's Clock, Compliance's Lock.
Data Security Controls
Flip cardMeasures, both technical and administrative, implemented to protect the confidentiality, integrity, and availability of data throughout its lifecycle.
- Encompasses encryption, access controls, monitoring, and policies.
- Designed to enforce data classification and handling requirements.
- Aims to prevent unauthorized access, modification, or disclosure.
Memory trick: An accidental move skips the security guard.
Client-Managed Keys (BYOK)
Flip cardA cloud key management model where the client generates, stores, and manages their own cryptographic keys, typically using on-premises HSMs, and provides them to the CSP for data encryption.
- Client retains full control over keys.
- Keys often generated and stored in client's HSMs.
- Enhances data sovereignty and security posture.
Memory trick: Client's Keys, Client's Control; CSP's Keys, CSP's Role.
Data Sanitization Methods (NIST SP 800-88)
Flip cardTechniques to render data inaccessible for a given level of effort, ranging from simple deletion to physical destruction, ensuring data is removed from storage media.
- Clear: Logical deletion or simple overwrite, data may be recoverable with advanced tools.
- Purge: Overwriting multiple times, degaussing, or cryptographic erase; renders data unrecoverable by state-of-the-art lab techniques.
- Destroy: Physical destruction (shredding, pulverizing); renders data recovery impossible.
Memory trick: Clear for casual, Purge for private, Destroy for critical.
Physical Destruction (Data Sanitization)
Flip cardA data sanitization method that physically destroys the storage media, rendering the data completely unrecoverable.
- Highest level of data sanitization assurance.
- Methods include shredding, pulverizing, incineration.
- Applicable to all media types.
Memory trick: Destroy to be Sure, Overwrite to Obscure.
Client-Managed Encryption Keys
Flip cardA security model where the customer, not the cloud service provider, controls the encryption keys used to protect their data in the cloud.
- Enhances data confidentiality and integrity in the cloud.
- Mitigates risks from CSP breaches or insider threats.
- Increases customer control over data security.
Memory trick: Key control is king for cloud confidentiality.
Data Masking
Flip cardA technique used to create a structurally similar but inauthentic version of sensitive data, used primarily in non-production environments (e.g., development, testing) to protect real PII while maintaining data utility.
- Replaces sensitive data with fictitious data.
- Preserves data format and type for application compatibility.
- Used to protect PII in non-production environments.
Memory trick: Mask for tests, Encrypt for rest.
Data Owner Responsibility
Flip cardThe individual or entity accountable for specific data assets, making decisions regarding their classification, protection, and usage throughout their lifecycle.
- Responsible for data classification and access rights.
- Ultimately accountable for the data's integrity, confidentiality, and availability.
- Often a business unit head or senior manager.
Memory trick: Classify, then Owner, then Protect.
Purpose Limitation
Flip cardA privacy principle stating that personal data should be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Data usage must align with the initial stated purpose.
- Requires explicit consent for new, incompatible purposes.
- A core principle in regulations like GDPR and HIPAA.
Memory trick: Purpose limits use, like a target's clue.
Purpose Limitation (GDPR)
Flip cardA GDPR principle stating that personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data collected for stated reasons
- No incompatible secondary use
- Core privacy principle
Memory trick: LIMIT your Purpose, Minimize your Data, Store for a short Time, Ensure Accuracy and Integrity, Maintain Lawfulness, and be Accountable.
Data Encryption at Rest
Flip cardThe process of encrypting data while it is stored on any device, such as hard drives, databases, or cloud storage, to protect it from unauthorized access.
- Protects data even if the storage medium is stolen or compromised.
- Essential for sensitive data stored in public or untrusted environments.
- Can be implemented at the file, volume, or database level.
Memory trick: Always Encrypt Sensitive Data, Rest Assured.
Automated Data Retention & Disposal
Flip cardSystematic, automated processes for managing the lifecycle of data, ensuring it is retained for specified periods according to policy and then securely deleted or archived.
- Provides auditable evidence of compliance with retention policies and regulations.
- Reduces human error and ensures consistency.
- Critical for managing large volumes of data and meeting legal obligations.
Memory trick: Automate retention, auditor's satisfaction.
Data Marking & Labeling
Flip cardThe process of applying visual or electronic indicators to data to denote its classification, sensitivity, handling requirements, and regulatory obligations, facilitating consistent protection across an organization.
- Crucial for communicating data's value and handling rules to users and systems.
- Enables automated enforcement of security controls.
- Must be consistently applied across all data storage and processing environments.
Memory trick: Label data first, then rules can last.
Data Retention Schedule
Flip cardA documented policy that specifies how long different types of data must be kept, based on legal, regulatory, and business requirements, and how it should be disposed of.
- Essential for legal and regulatory compliance.
- Guides data lifecycle management.
- Must be consistently enforced and auditable.
Memory trick: Show the schedule, prove you follow the law.
NIST SP 800-88 Data Sanitization
Flip cardGuidelines for securely erasing data from storage media, categorizing methods into Clear, Purge, and Destroy, based on the level of protection required.
- Clear: Overwriting, protects against simple recovery.
- Purge: Renders data unrecoverable by laboratory techniques.
- Destroy: Physically renders media unusable, absolute data destruction.
Memory trick: Clear for Casual, Purge for Pro, Destroy for Danger.
Data Labeling (Marking)
Flip cardThe process of applying clear, consistent indicators (labels or markings) to data based on its classification to communicate its sensitivity and required handling procedures.
- Communicates data sensitivity to users and systems.
- Guides appropriate controls for storage, transmission, and access.
- Can be visual (e.g., footers) or programmatic (e.g., metadata tags).
Memory trick: Label it so everyone knows how to handle it.
Storage Limitation (GDPR)
Flip cardA principle under GDPR that requires personal data to be kept for no longer than is necessary for the purposes for which it is processed.
- Prevents indefinite data retention.
- Requires explicit retention periods.
- Reduces risk of data breaches and misuse.
Memory trick: Lawful, Fair, Transparent, Purpose, Minimize, Accurate, Limit, Integrity, Accountability.
Data Ownership in Divestitures
Flip cardThe critical process of clearly defining who is accountable for specific data assets, their protection, and compliance obligations when an organization splits or transfers assets.
- Essential for legal and regulatory compliance.
- Determines responsibility for data protection.
- Impacts privacy obligations and reporting.
Memory trick: When you Split, Ownership's the First Bit.
Client-Side Encryption (Cloud)
Flip cardThe process of encrypting data on the client's local system before it is transmitted to and stored in the cloud, with encryption keys managed by the client.
- Cloud provider never has access to plaintext data or decryption keys.
- Ensures maximum data confidentiality and control.
- Mitigates risks from cloud provider breaches or insider threats.
Memory trick: Keep the keys at home to keep data truly private in the cloud.
NIST SP 800-88 Rev. 1 Destroy Method
Flip cardA data sanitization method that renders data storage media unusable for further data storage and ensures data is completely unrecoverable by any means.
- Highest level of sanitization assurance.
- Methods include shredding, pulverizing, incineration, melting.
- Often required for classified or highly sensitive data.
Memory trick: Clear Erases, Purge Cleans, Destroy Ends All Means.
Availability (CIA Triad)
Flip cardThe principle that information and systems must be accessible and usable by authorized users when needed, ensuring continuous operation.
- Crucial for real-time systems, operational technology (OT), and critical infrastructure.
- Threats include DDoS, power outages, hardware failures.
- Achieved through redundancy, backups, disaster recovery, and fault tolerance.
Memory trick: SCADA's life is always live, Integrity keeps it real.
Memory Protection
Flip cardA mechanism that controls access rights to memory on a computer, preventing processes from accessing unauthorized memory regions.
- Crucial for operating system stability and security in multi-tasking environments.
- Protects against buffer overflows, unauthorized data access, and process interference.
- Implemented by hardware (MMU) and managed by the operating system.
Memory trick: Memory protection walls off processes like rooms in a house.
Cross-Site Scripting (XSS)
Flip cardA web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users.
- Occurs when an application embeds untrusted input into its output without proper sanitization.
- Can lead to session hijacking, defacement, or redirection.
- Mitigated by input validation and output encoding.
Memory trick: Injection is Input's Enemy.
Bell-LaPadula Security Model
Flip cardA state machine model focused on enforcing confidentiality, primarily used in military and government systems.
- Has two core rules: Simple Security Property (no read up) and Star (*) Property (no write down).
- Aims to prevent unauthorized disclosure of information.
- Does not address integrity directly, only confidentiality.
Memory trick: Bell-LaPadula keeps secrets locked down, like a bell in a tower.