SSCP Systems Security Certified Practitioner flashcards
162 free flashcards. Tap a card to flip it.
Separation of Duties
Flip cardAn access control principle that divides critical functions and responsibilities among multiple individuals to prevent any single person from controlling an entire sensitive process end-to-end.
- Reduces the risk of fraud, error, or malicious acts.
- Requires multiple parties to complete a critical task.
- Often implemented with dual control or two-person rules.
Memory trick: Separate duties, share the power, secure the tower.
AES-ECB Weakness
Flip cardElectronic Codebook (ECB) mode for block ciphers encrypts each block independently, leading to identical plaintext blocks producing identical ciphertext blocks, thus revealing data patterns.
- Not suitable for encrypting large amounts of data or data with repeating patterns.
- Often illustrated with the 'Tux' penguin example, where the outline of the penguin remains visible after encryption.
- Should generally be avoided in favor of modes like CBC, CTR, or GCM for most applications.
Memory trick: Modes: ECB repeats, CBC chains, CTR counts, GCM authenticates!
Certificate Authority (CA)
Flip cardA trusted entity in a PKI that issues, revokes, and manages digital certificates.
- Root of trust in a PKI.
- Digitally signs certificates it issues.
- Maintains Certificate Revocation Lists (CRLs).
Memory trick: PKI is like a government for digital identities, with different departments.
Diffie-Hellman Key Exchange
Flip cardA cryptographic protocol that allows two parties to establish a shared secret key over an insecure communication channel.
- Does not provide authentication by itself.
- Vulnerable to man-in-the-middle attacks without authentication.
- Based on the mathematical difficulty of the discrete logarithm problem.
Memory trick: Need to share a key? Diffie-Hellman's the secret handshake.
Multi-Factor Authentication (MFA)
Flip cardAn authentication method that requires users to provide two or more distinct verification factors to gain access to a resource.
- Significantly enhances security over single-factor authentication.
- Combines different types of factors (knowledge, possession, inherence).
- Commonly used in sensitive applications like banking.
Memory trick: MFA: Many Factors make it harder to crack.
Stream Cipher
Flip cardA symmetric key cipher that encrypts plaintext digits (bits or bytes) one at a time, and whose transformation of successive digits depends on the internal state of the cipher.
- Encrypts data bit by bit or byte by byte.
- Ideal for streaming data, real-time communication, and data of unknown length.
- Requires a keystream generator to produce a pseudo-random sequence.
Memory trick: Stream flows like a river, bit by bit.
ECB Mode Vulnerability
Flip cardThe vulnerability of Electronic Codebook (ECB) mode where identical plaintext blocks are encrypted into identical ciphertext blocks, revealing patterns in the encrypted data and compromising confidentiality.
- Encrypts each block independently.
- No chaining or initialization vector (IV).
- Suitable only for very short, random data (e.g., encrypting other keys).
Memory trick: ECB Repeats, CBC Chains.
Attribute-Based Access Control (ABAC)
Flip cardAn authorization mechanism that grants or denies access to resources based on policies that evaluate attributes of the subject, object, action, and environmental conditions.
- Provides highly granular and dynamic access control.
- Scales well for complex environments with many users, resources, and conditions.
- Policies are expressed as 'If-Then' rules based on attribute values.
Memory trick: ABAC: All By Attributes, Always Complex.
Federated Identity Management
Flip cardA system that allows for the portability of identity information across multiple, independent domains, enabling users to authenticate once and access various services without re-authentication.
- Uses trusted identity providers (IdPs).
- Enhances user convenience (single sign-on).
- Reduces administrative burden for service providers.
Memory trick: Federated Friends help you log in everywhere.
Role-Based Access Control (RBAC)
Flip cardAn access control model where permissions are associated with roles, and users are assigned to appropriate roles based on their job functions.
- Simplifies access management in large organizations.
- Reduces administrative overhead compared to DAC.
- Roles can be hierarchical or constrained.
Memory trick: Role-play Rules: Groups get permissions, users get groups.
Non-repudiation (Digital Signatures)
Flip cardThe assurance that a party cannot deny the authenticity of their signature on a document or message.
- Achieved by using the signer's unique private key.
- Verifies sender's identity and integrity of data.
- A fundamental security service provided by digital signatures.
Memory trick: Your private key is your unique pen; once you sign, you can't deny it.
Authenticated Encryption with Associated Data (AEAD)
Flip cardA type of encryption that simultaneously provides confidentiality (data privacy), integrity (data hasn't been altered), and authenticity (data comes from the expected source). It can also authenticate 'associated data' that is not encrypted.
- Combines encryption and message authentication.
- Prevents common cryptographic implementation pitfalls.
- Often more efficient than separate encryption and MAC schemes.
Memory trick: AEAD is like a secure, tamper-proof envelope for your IoT messages.
Perfect Forward Secrecy (PFS)
Flip cardA property of key agreement protocols that ensures that if one of the long-term keys is compromised, it does not compromise any past session keys derived from it.
- Each session uses a unique, ephemeral session key.
- Session keys are not derived directly from a master secret that could be compromised later.
- Often implemented using Diffie-Hellman key exchange or elliptic curve Diffie-Hellman (ECDHE).
Memory trick: PFS protects 'past' secrets from 'future' key compromises.
Non-repudiation
Flip cardA cryptographic service that provides undeniable proof of the origin or integrity of data, or the identity of the sender, preventing the sender from falsely denying having sent a message or initiated a transaction.
- Prevents denial of origin or action.
- Typically achieved using digital signatures.
- Crucial for legal and financial transactions.
Memory trick: Non-repudiation is like a digital receipt you can't throw away.
Key Separation (Cryptographic)
Flip cardThe principle that different cryptographic keys should be used for different cryptographic functions (e.g., encryption, signing, MAC generation) to prevent a compromise of one key from undermining the security of other functions.
- Assigns distinct keys for distinct operations.
- Minimizes impact of key compromise.
- Prevents cryptanalytic attacks that exploit multi-use keys.
Memory trick: Separate Keys for Separate Security.
Password Hashing with Salt
Flip cardA cryptographic technique for securely storing passwords by transforming them into irreversible hash values, combined with a unique, random string (salt) for each password.
- Protects against rainbow table attacks.
- Ensures two identical passwords yield different hash values.
- Makes brute-force attacks more computationally intensive.
Memory trick: Passwords: Hash it, Salt it, Secure it!
Bell-LaPadula Model: *-Property (Star Property)
Flip cardA security property within the Bell-LaPadula confidentiality model that prevents a subject from writing to an object that has a lower security classification (no write-down).
- Aims to prevent information from flowing downwards to lower security levels.
- Part of Mandatory Access Control (MAC).
- Crucial for maintaining confidentiality in multi-level security systems.
Memory trick: Bell-LaPadula: Don't write down secrets, don't read up gossip.
Authenticated Encryption (AEAD)
Flip cardA type of encryption that simultaneously provides confidentiality, integrity, and authenticity for data. If any part of the ciphertext or associated authenticated data is modified, decryption and verification will fail.
- Combines encryption with a Message Authentication Code (MAC).
- Protects against tampering, decryption, and replay attacks.
- Examples include AES-GCM and ChaCha20-Poly1305.
Memory trick: Crypto Primitives: Confidentiality, Integrity, Authentication, Non-repudiation!
Online Certificate Status Protocol (OCSP)
Flip cardA protocol used to obtain the revocation status of an X.509 digital certificate in real-time. Clients query an OCSP responder for the status of a specific certificate, receiving a signed response.
- Provides real-time certificate revocation status.
- More efficient than CRLs for single certificate checks.
- Reduces network overhead compared to downloading large CRLs.
Memory trick: OCSP is like asking a quick 'Is this ID still valid?' instead of reading a whole 'invalid IDs' book.
Bell-LaPadula *-Property (Star Property)
Flip cardA rule in the Bell-LaPadula access control model that states a subject at a given security level cannot write to an object at a lower security level (also known as 'no write down').
- Prevents information flow from higher to lower classification levels.
- Crucial for maintaining confidentiality in multi-level security systems.
- Works in conjunction with the Simple Security Property ('no read up').
Memory trick: Bell-LaPadula: Don't read up, don't write down.
Key Separation
Flip cardThe cryptographic principle of storing encryption keys separately from the data they protect to prevent unauthorized access to both simultaneously.
- Enhances security by creating multiple points of failure for an attacker.
- Often involves hardware security modules (HSMs) or separate key management systems.
- Crucial for data at rest and data in transit encryption.
Memory trick: Keys and locks, never in the same box!
Digital Signature
Flip cardA cryptographic mechanism that uses asymmetric cryptography to bind an identity to a piece of information, ensuring authenticity, integrity, and non-repudiation.
- Created by hashing data and encrypting the hash with the sender's private key.
- Verified by decrypting the hash with the sender's public key and comparing it to a newly computed hash of the data.
- Crucial for legal and financial transactions.
Memory trick: CIA+NN: Confidentiality, Integrity, Availability, Non-repudiation, Authentication!
TLS Key Exchange
Flip cardA critical phase in the TLS handshake where the client and server securely establish a shared symmetric encryption key for subsequent data transmission.
- Uses asymmetric cryptography (e.g., RSA, Diffie-Hellman) to establish a symmetric key.
- Ensures that eavesdroppers cannot determine the symmetric key.
- Modern implementations prioritize Perfect Forward Secrecy (PFS) using ephemeral keys.
Memory trick: TLS Handshake: Hello, Cert, Key, Change!
Least Privilege
Flip cardA security principle where users and processes are granted only the minimum necessary access rights to perform their job functions or tasks.
- Limits potential damage from errors or malicious acts.
- Reduces the attack surface.
- Requires regular review of user permissions.
Memory trick: Principle Power: Only open doors you need to enter.
Initialization Vector (IV)
Flip cardA random or pseudo-random non-secret value used with a symmetric cipher to ensure that when the same plaintext is encrypted multiple times with the same key, it produces different ciphertexts. It prevents pattern recognition and replay attacks.
- Adds randomness to ciphertext.
- Must be unique for each encryption with the same key.
- Typically transmitted with ciphertext, but not necessarily secret.
Memory trick: The IV is like adding a unique 'secret sauce' to each encryption meal.
Mandatory Access Control (MAC)
Flip cardAn access control model where a central authority enforces access decisions based on security labels assigned to subjects (users) and objects (resources).
- Strictly enforced, often used in high-security environments.
- Users cannot alter access permissions.
- Commonly implements 'no write down' and 'no read up' rules (e.g., Bell-LaPadula).
Memory trick: Models Manage Access: Decide who sees what.
Hardware Random Number Generator (HRNG)
Flip cardA physical device that generates random numbers from a physical process, such as thermal noise or quantum phenomena, providing high-quality entropy suitable for cryptographic applications.
- Produces 'true' random numbers, unlike software PRNGs.
- Essential for generating strong cryptographic keys and nonces.
- Less predictable and therefore more secure than software-based random number generators.
Memory trick: Randomness: Hardware is True, Software is Pseudotrue!
Authentication Strength
Flip cardThe level of assurance that an asserted identity is genuine, determined by the robustness of the authentication factors and methods used.
- Increased by combining multiple, distinct authentication factors.
- Reduces the likelihood of unauthorized access.
- Crucial for protecting sensitive systems and data.
Memory trick: Strong Auth: Know, Have, Are, to be sure!
Discretionary Access Control (DAC)
Flip cardAn access control model where the owner of a resource determines who has access to it and what privileges they possess. Access decisions are at the discretion of the resource owner.
- Owners have full control over their resources.
- Common in many operating systems (e.g., file permissions).
- Can lead to complex permission sets and potential security vulnerabilities if not managed well.
Memory trick: DAC: Discretion is the Owner's Choice.
Forward Secrecy (Perfect Forward Secrecy - PFS)
Flip cardA property of a key agreement protocol that ensures that a compromise of long-term secret keys does not compromise past session keys.
- Achieved by generating ephemeral (temporary) session keys.
- Commonly implemented with Ephemeral Diffie-Hellman (DHE or ECDHE).
- Crucial for protecting the confidentiality of past communications.
Memory trick: Ephemeral keys are like disposable locks: once used, they're gone, so past secrets stay safe.
Access Control List (ACL) Best Practices
Flip cardGuidelines for effectively managing permissions on resources to ensure security, maintainability, and adherence to principles like least privilege.
- Use security groups instead of individual users for permissions.
- Apply the principle of least privilege.
- Regularly review and audit ACL entries.
- Avoid excessive or overly broad permissions.
Memory trick: ACL: Groups are great, individuals are chaos.
Key Stretching
Flip cardA technique used to increase the strength of a weak key, typically derived from a password or passphrase, by making it computationally more expensive to brute-force or guess.
- Transforms weak passwords into stronger keys.
- Uses iterative hashing or PBKDFs.
- Slows down brute-force attacks significantly.
Memory trick: Stretch the Key, Secure the Secret.
Collision Resistance
Flip cardA property of a cryptographic hash function making it computationally infeasible to find two distinct inputs that hash to the same output.
- Essential for data integrity and password security.
- Protects against birthday attacks.
- Weak collision resistance can lead to vulnerabilities.
Memory trick: Hashes are like unique fingerprints; collisions are when two people have the same print.
Digital Certificate
Flip cardAn electronic document used to prove ownership of a public key, binding it to an individual or organization, and is signed by a trusted Certificate Authority.
- Binds a public key to an identity.
- Signed by a Certificate Authority (CA) for trust.
- Used for authentication, integrity, and non-repudiation.
Memory trick: Certificates Verify Servers Authentically.
Key Management
Flip cardThe set of processes and procedures for generating, distributing, storing, rotating, and revoking cryptographic keys.
- Crucial for the overall security of cryptographic systems.
- Poor key management can undermine strong algorithms.
- Involves the entire lifecycle of keys.
Memory trick: A single key is like a single point of failure; it breaks the whole key management chain.
Quantum-Resistant Hashing
Flip cardCryptographic hash functions designed to remain secure against attacks by quantum computers, particularly those leveraging Grover's algorithm.
- Grover's algorithm can halve the effective security strength of a hash function.
- Requires significantly larger hash output sizes compared to classical hashes for equivalent security.
- Post-quantum cryptography research is actively developing and standardizing these algorithms.
Memory trick: Quantum attacks: Shor breaks keys, Grover finds hashes!
Cryptographically Secure Random Number Generator (CSRNG)
Flip cardA random number generator suitable for cryptographic applications, where the output is computationally indistinguishable from true randomness, especially in terms of unpredictability.
- Outputs are unpredictable, even if internal state is known.
- Must withstand malicious attempts to predict future values.
- Often seeded with high-entropy sources from the environment.
Memory trick: CSRNGs are like secret dice, you can never guess the next roll.
Block Cipher Modes of Operation
Flip cardMethods that specify how a block cipher should be applied to encrypt data blocks, influencing properties like security, error propagation, and performance (e.g., parallelization).
- Transform fixed-size blocks of plaintext into ciphertext.
- Different modes offer varying security and performance characteristics.
- Some modes allow for parallel processing, others require sequential.
Memory trick: To speed up encryption, think of counters counting up independently.
Rule-Based Access Control
Flip cardAn access control mechanism that grants or denies access to resources based on a set of predefined rules or policies. These rules often incorporate conditions like time of day, location, or protocol.
- Highly flexible and dynamic.
- Rules are typically defined by administrators.
- Can be used in conjunction with other models like RBAC or ABAC.
Memory trick: Rules Rule! Time, Place, Action are key.
Context-Based Access Control (CBAC)
Flip cardAn access control model where decisions are made based on the context of the access request, including factors like user identity, time, location, data sensitivity, and the operation being performed.
- Provides highly granular and dynamic access control.
- Considers environmental and situational attributes.
- Often used in environments with complex, changing access requirements.
Memory trick: Contextual Chameleon: Access changes color with the situation.
Single Sign-On (SSO)
Flip cardAn authentication process that allows a user to access multiple independent software systems using a single set of login credentials.
- Enhances user convenience by eliminating repeated logins.
- Can improve security by centralizing authentication and reducing password fatigue.
- Often implemented using protocols like SAML or OAuth.
Memory trick: IAM's goal: One key opens many doors.
Post-Quantum Cryptography (PQC)
Flip cardCryptographic algorithms designed to be secure against attacks from quantum computers, which could break many of the currently used public-key cryptographic algorithms.
- Aims to replace current public-key cryptography.
- Focuses on algorithms resistant to Shor's and Grover's algorithms.
- Includes lattice-based, code-based, hash-based, and multivariate polynomial cryptography.
Memory trick: Quantum hashes are like super-strong locks, even quantum computers can't pick them.
Web of Trust (WoT)
Flip cardA decentralized trust model where individuals directly attest to the authenticity of other users' public keys, rather than relying on a single Certificate Authority.
- Users sign each other's public keys.
- No central root of trust.
- Used by PGP (Pretty Good Privacy) and GPG.
Memory trick: Trust can be a pyramid (PKI) or a spiderweb (Web of Trust).
Digital Certificates
Flip cardAn electronic document used to prove the ownership of a public key. It is issued by a Certificate Authority (CA) and contains the public key, the owner's identity, the CA's digital signature, and validity dates.
- Binds a public key to an identity.
- Verifies sender's authenticity and data integrity.
- Issued by trusted Certificate Authorities (CAs).
Memory trick: Certificates are like digital passports for secure online meetings.
Kerberos Authentication Protocol
Flip cardA network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another in a secure manner.
- Uses symmetric-key cryptography.
- Provides mutual authentication.
- Resistant to replay attacks through timestamps.
- Requires a Key Distribution Center (KDC).
Memory trick: Kerberos: The K-9 guard dog of network authentication.
Key Derivation Function (KDF) Attack
Flip cardAn attack against a Key Derivation Function, typically a brute-force or dictionary attack, aimed at recovering the original low-entropy secret (like a password or passphrase) used to derive a high-entropy cryptographic key.
- Exploits the fact that the derived key is directly dependent on the input passphrase.
- KDFs like PBKDF2, bcrypt, and scrypt are designed to be computationally expensive to slow down such attacks.
- The strength of the KDF against brute-force depends on its iteration count and memory hardness.
Memory trick: Key Attacks: Guess the password, not the cipher!
Access Control Matrix
Flip cardA table that defines the permissions that each subject (user or process) has over each object (file, resource) in a system.
- Rows represent subjects, columns represent objects.
- Cells contain the access rights (e.g., read, write, execute).
- A conceptual model often implemented using access control lists (ACLs) or capability lists.
Memory trick: Matrix Magic: Every cell is a permission, owner's decision.
Password-Based Key Derivation Function (PBKDF)
Flip cardA function that derives cryptographic keys from a password or passphrase, designed to be computationally expensive to deter brute-force attacks.
- Makes password cracking computationally intensive.
- Incorporates salting to prevent rainbow table attacks.
- Examples include PBKDF2, Bcrypt, Scrypt.
Memory trick: PBKDF Protects Passwords.
Hardware Security Module (HSM)
Flip cardA physical computing device that safeguards and manages digital keys for strong authentication and provides cryptoprocessing. Keys are generated, stored, and used within the HSM and never leave it in plain text.
- Provides a tamper-resistant environment for cryptographic operations.
- Protects against logical and physical attacks on keys.
- Commonly used for Certificate Authorities, database encryption, and secure key storage.
Memory trick: Keys: Hardware for Hardcore Security!
Advanced Encryption Standard (AES)
Flip cardA symmetric block cipher adopted by the U.S. government and widely used worldwide for secure data encryption.
- Supports key sizes of 128, 192, and 256 bits.
- Replaced DES and 3DES as the standard.
- Efficient in both hardware and software implementations.
Memory trick: When it comes to symmetric strength, AES is the champion, leaving old DES in the dust.
Digital Signature Integrity
Flip cardThe property of a digital signature that ensures the signed data has not been altered since it was signed. This is achieved by including a cryptographic hash of the data within the signature.
- Relies on cryptographic hashing.
- Any change to the data invalidates the hash.
- Verifies that the original content remains intact.
Memory trick: Hash Ensures Integrity, Keys Confirm Identity.
Privileged Access Management (PAM)
Flip cardA comprehensive solution for managing, monitoring, and securing privileged accounts and their access to critical systems and data, ensuring adherence to the principle of least privilege.
- Focuses on 'super-user' accounts (administrators, root, service accounts).
- Includes password vaulting, session monitoring, and just-in-time access.
- Crucial for reducing the attack surface and preventing insider threats.
Memory trick: PAM: Protect Admin Masters!
CRL Integrity and Authenticity
Flip cardEnsuring that a Certificate Revocation List (CRL) has not been tampered with and genuinely originates from the issuing Certificate Authority (CA) to prevent clients from accepting revoked certificates.
- CRLs are digitally signed by the CA.
- Signature verification confirms integrity and authenticity.
- Unsecured distribution (e.g., plain HTTP) allows tampering.
Memory trick: CRL's Sign Proves Its Truth.
Need-to-Know Principle
Flip cardA security principle that states that a subject should only have access to the information and resources that are absolutely necessary to perform their assigned duties.
- Minimizes the potential damage from compromised accounts.
- Reduces the attack surface by limiting access.
- Often implemented with granular permissions and temporary access.
Memory trick: Know your Need: only what's necessary, only when needed.
Certificate Revocation List (CRL)
Flip cardA list of digital certificates that have been revoked by the issuing Certificate Authority (CA) before their scheduled expiration date.
- Periodically published by the CA.
- Must be checked by relying parties to confirm certificate validity.
- Can lead to a window of vulnerability between publications.
Memory trick: CRL updates are like slow newspaper deliveries; news of a bad cert can take a full cycle to spread.
Certificate Chain of Trust
Flip cardA hierarchical model in PKI where digital certificates are linked together, starting from an end-entity certificate and leading up to a trusted root Certificate Authority (CA) certificate.
- Each certificate in the chain is signed by the private key of the certificate above it.
- The 'Issuer' field of a child certificate matches the 'Subject' field of its parent certificate.
- Allows clients to verify the authenticity of any certificate by validating the entire chain up to a trusted root.
Memory trick: Certificates: Subject is who, Issuer is who signed!
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data loss measured in time from the point of failure. It dictates how frequently data backups or replications must occur.
- Measured in time (e.g., 1 hour, 4 hours, 24 hours).
- Determines the frequency of data backups or synchronization.
- A lower RPO means less data loss but typically higher cost and complexity.
Memory trick: RPO is about Point (data), RTO is about Time (downtime).
Hot Site
Flip cardA fully equipped, operational alternative facility that can be activated immediately or with very short notice to continue business operations during a disaster.
- Highest cost among alternate sites.
- Offers the lowest Recovery Time Objective (RTO).
- Often involves real-time data replication.
Memory trick: Hot is Ready, Warm is Waiting, Cold is Empty.
Incident Eradication
Flip cardThe phase of incident response focused on removing the root cause of an incident, eliminating the threat, and patching vulnerabilities to prevent recurrence.
- Follows containment.
- Identifies and fixes the vulnerability.
- Prevents future similar incidents.
Memory trick: PICERL - Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned
Recovery Time Objective (RTO)
Flip cardThe maximum acceptable duration of time that a business process or system can be unavailable after an incident or disaster without causing unacceptable consequences.
- Measured in time (hours, days).
- Determined by Business Impact Analysis (BIA).
- Dictates the speed of recovery.
Memory trick: RTO is 'Time' to get 'Online' again.