SSCP Systems Security Certified Practitioner flashcards
162 free flashcards. Tap a card to flip it.
Incident Recovery
Flip cardThe phase of incident response focused on restoring affected systems and services to full operation after an incident has been contained and eradicated.
- Occurs after containment and eradication.
- Aims to return systems to normal business operations.
- Often involves restoring from backups and verifying functionality.
Memory trick: Prepare, ID, Contain, Eradicate, Recover, Lessons Learned – P.I.C.E.R.L.!
Vulnerability Management
Flip cardThe cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities in systems and applications.
- Includes scanning, assessment, prioritization, patching, and verification.
- A continuous process, not a one-time activity.
- Crucial for reducing an organization's attack surface.
Memory trick: Protect, Detect, Respond, Recover; but first, manage vulnerabilities.
Network Isolation (Containment)
Flip cardA containment strategy that involves segmenting or disconnecting an affected system or network segment from the rest of the network to prevent further spread of an incident.
- Prevents further compromise and data exfiltration.
- Preserves the state of the affected system for forensics.
- Can be implemented quickly and effectively.
Memory trick: Containment: 'Isolate' to 'Investigate'.
Business Continuity Plan (BCP)
Flip cardA comprehensive plan that outlines how an organization will continue to operate its critical business functions and processes during and after a disruptive event.
- Broader than a DRP, includes non-IT aspects.
- Focuses on people, processes, and technology.
- Aims to maintain operations, not just restore IT.
Memory trick: BCP keeps the whole business running, DRP just fixes the tech.
Log Source Prioritization
Flip cardThe process of determining which security-relevant log data to collect and analyze first, based on its value for detecting threats.
- Focus on logs that show user activity, system changes, and network connections.
- High-value logs include operating system, application, network device, and security device logs.
- Aims to maximize detection capabilities with finite resources.
Memory trick: System, Network, Application: the core three for security logs.
Risk Management Process
Flip cardA systematic approach to identifying, assessing, mitigating, and monitoring risks to an organization's assets.
- It is an ongoing, cyclical process.
- Aims to reduce risk to an acceptable level.
- Involves stakeholders from across the organization.
Memory trick: The 'I-A-T-M' cycle: Identify, Analyze, Treat, Monitor.
Business Continuity Plan (BCP) Activation
Flip cardThe formal process of initiating the pre-defined strategies and procedures within a BCP in response to a significant disruption or threat to business operations.
- Triggered by specific criteria or thresholds.
- Involves notifying key personnel and stakeholders.
- Leads to the execution of recovery strategies and resource allocation.
Memory trick: Plan, Test, Activate, Recover, Review.
Recovery Point Objective (RPO)
Flip cardThe maximum acceptable amount of data loss measured in time from the point of failure. It dictates how frequently data backups or replications must occur.
- Measured in time (e.g., 1 hour, 4 hours, 24 hours).
- Determines the frequency of data backups or synchronization.
- A lower RPO means less data loss but typically higher cost and complexity.
Memory trick: RPO is about Point (data), RTO is about Time (downtime).
Static Application Security Testing (SAST)
Flip cardA white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities like SQL injection, buffer overflows, cross-site scripting.
- Effective for finding issues in third-party components and open-source code.
Memory trick: SAST for code, DAST for runtime, IAST for both, Pen Test for real attacks.
Business Impact Analysis (BIA)
Flip cardA systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster or emergency.
- Identifies critical business functions.
- Determines MTD, RTO, and RPO.
- Assesses financial and operational impacts of downtime.
Memory trick: BIA: 'B'usiness 'I'mpact 'A'nalysis, what hurts most, how long can it hurt?
Command and Control (C2) Communication
Flip cardThe communication channel used by an attacker to remotely control compromised systems (bots) within a target network.
- Often uses common protocols (HTTP, HTTPS, DNS) to evade detection.
- Can involve regular 'beaconing' to check for instructions.
- Essential for attackers to maintain persistence and launch further attacks.
Memory trick: Unusual Traffic Patterns Signal Malicious Intents.
Brute-force attack
Flip cardAn attack that attempts to guess credentials (e.g., passwords) by systematically trying every possible combination until the correct one is found.
- Often automated using specialized tools.
- Can be prevented by strong passwords, account lockout policies, and multi-factor authentication.
- Generates many failed login attempts in logs.
Memory trick: Remember the 'door-kicker' trying many keys.
Incident Communication Plan
Flip cardA component of the Incident Response Plan (IRP) that defines how information will be shared with internal and external stakeholders during and after a security incident.
- Includes contact lists and escalation paths.
- Defines who communicates what, when, and to whom.
- Crucial for coordinated and effective response.
Memory trick: The IRP is a playbook; communication is the huddle.
Operational Risk
Flip cardThe risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.
- Includes risks related to IT system failures, human error, and process breakdowns.
- Distinguished from strategic, financial, or reputational risks.
- A key area for security management as many security failures stem from operational issues.
Memory trick: Strategic for goals, Operational for daily work, Financial for money, Compliance for rules, Reputational for image.
Vulnerability Prioritization
Flip cardThe process of ranking identified vulnerabilities based on their severity, exploitability, asset criticality, and potential impact to guide remediation efforts.
- Essential for efficient and effective vulnerability management.
- Considers CVSS scores, threat intelligence, and business context.
- Helps allocate limited resources to the most critical risks first.
Memory trick: Identify, Assess, Prioritize, Remediate, Verify, Monitor.
MITRE ATT&CK Tactics
Flip cardThe top-level categories in the MITRE ATT&CK framework that represent an adversary's tactical goals or 'why' they perform certain actions during an attack.
- Examples include Initial Access, Execution, Persistence, Privilege Escalation, Lateral Movement, Exfiltration.
- Each tactic contains multiple techniques.
- Provides a common language for describing adversary behavior.
Memory trick: TTP: Tactics (why), Techniques (how), Procedures (what exactly).
Vulnerability
Flip cardA weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source.
- Can be exploited by a threat.
- Often results from design flaws, misconfigurations, or software bugs.
- Requires a threat to materialize into an incident.
Memory trick: Threats Exploit Vulnerabilities, causing Impact.
Malware Infection Indicators
Flip cardObservable signs that a system has been compromised by malicious software.
- Includes unusual network traffic, system performance degradation, unexpected pop-ups, and unauthorized file modifications.
- Often initiated through phishing, malicious downloads, or exploiting vulnerabilities.
- Requires prompt detection and remediation to prevent further damage.
Memory trick: Look for the 'digital symptoms' to diagnose the problem.
Continuous Data Protection (CDP)
Flip cardA backup and recovery strategy that continuously tracks and stores changes to data, allowing for restoration to any previous point in time.
- Offers the lowest Recovery Point Objective (RPO).
- Enables restoration to virtually any point in time.
- Often involves higher storage and network overhead.
Memory trick: CDP is the 'always-on' data guardian.
Indicators of Compromise (IoCs)
Flip cardForensic data found on a network or operating system that indicates a computer intrusion or malicious activity.
- Examples include malicious IP addresses, domain names, file hashes, registry keys, and unusual traffic patterns.
- Used to detect, identify, and prevent future attacks.
- Often shared within the cybersecurity community to enhance defenses.
Memory trick: IoCs are the 'clues' left behind at the crime scene.
Risk Acceptance
Flip cardA risk response strategy where an organization decides to take no action to reduce the likelihood or impact of a risk, typically because the cost of mitigation outweighs the potential loss, or the risk is within acceptable limits.
- Often for low-probability, low-impact risks.
- Can be conscious (formal decision) or unconscious.
- Always involves some level of remaining or 'residual' risk.
Memory trick: Avoid, Transfer, Mitigate, Accept - ATM-A for Risk.
RTO and RPO Alignment
Flip cardThe process of selecting appropriate disaster recovery strategies (backup types, recovery sites) that align with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO).
- Lower RTO/RPO require more expensive solutions.
- Hot sites and continuous replication support aggressive RTO/RPO.
- Trade-offs between cost, speed, and data loss.
Memory trick: Aggressive RTO/RPO needs 'Hot' and 'Frequent' solutions.
Lessons Learned (Incident Response)
Flip cardThe final phase of incident response, focused on reviewing the incident, documenting findings, and identifying improvements to prevent future incidents and enhance response capabilities.
- Occurs after recovery.
- Involves a post-incident review meeting.
- Aims to improve policies, procedures, and training.
Memory trick: Learn from mistakes, get better next time!
Annualized Loss Expectancy (ALE)
Flip cardThe expected monetary loss from a risk over a one-year period.
- Calculated as SLE × ARO.
- Used in quantitative risk assessment to prioritize risks.
- Represents the long-term average loss.
Memory trick: SLE for one, ARO for annual frequency, ALE is their product.
Supply Chain Risk
Flip cardThe risk of disruption to the flow of goods or services caused by vulnerabilities or incidents within the network of organizations that supply components or services.
- Extends beyond direct suppliers to their suppliers (N-tier risk).
- Includes risks from software, hardware, and service providers.
- Requires due diligence and continuous monitoring of third parties.
Memory trick: Vendor risks ripple through the Supply Chain.
Tactics, Techniques, and Procedures (TTPs)
Flip cardDescribes how adversaries operate, including their high-level goals (tactics), specific methods (techniques), and particular implementations (procedures).
- Provides a behavioral understanding of threats.
- Helps in predicting future adversary actions.
- Used for threat hunting, incident response, and defense-in-depth planning.
Memory trick: TTPs are the 'story' that connects the clues.
Threat Intelligence Utilization
Flip cardThe process of integrating and acting upon threat intelligence to enhance an organization's security posture and incident response capabilities.
- Requires context to be effective (e.g., does it apply to my systems?).
- Involves assessing relevance, impact, and actionable steps.
- Supports proactive defense and faster incident response.
Memory trick: First, 'is it me?', then 'what to do?'.
Technical Threat Intelligence
Flip cardActionable, low-level indicators of compromise (IoCs) that can be directly applied to security controls for detection and prevention.
- Includes IP addresses, domains, file hashes, URLs, registry keys.
- Shortest shelf life, highly specific.
- Used by security devices and analysts for immediate detection and blocking.
Memory trick: Strategic for leaders, Operational for campaigns, Tactical for TTPs, Technical for IoCs.
Operational Threat Intelligence
Flip cardInformation about the specific methods, tools, and processes (TTPs) used by adversaries in their campaigns. It helps understand how attacks are being executed.
- Focuses on 'how' attacks are conducted.
- Includes TTPs, campaign details, C2 patterns.
- Useful for incident responders and security analysts.
Memory trick: STOP! Strategic, Tactical, Operational, Technical.
Chain of Custody
Flip cardA documented process that tracks the handling and storage of evidence from the moment it is collected until its final disposition, ensuring its integrity and authenticity.
- Essential for legal admissibility of evidence.
- Documents who handled the evidence, when, and why.
- Prevents tampering and maintains integrity.
Memory trick: Evidence needs a clear chain to be trusted.
Black-box Testing
Flip cardA type of security assessment where the tester has no prior knowledge of the internal workings, architecture, or source code of the system being tested.
- Simulates an external attacker.
- Relies on publicly available information and reconnaissance.
- Focuses on identifying vulnerabilities exploitable from an external perspective.
Memory trick: Box colors tell you how much you see inside.
NetFlow Analysis
Flip cardA network protocol developed by Cisco for collecting IP traffic information and monitoring network flow statistics.
- Captures metadata about network conversations (who, what, when, how much).
- Does not capture the actual payload content.
- Crucial for network visibility, anomaly detection, and incident response, especially with encrypted traffic.
Memory trick: Flows for metadata, PCAP for full details, IDS for signatures, EDR for endpoints.
Cold Site
Flip cardA disaster recovery site that provides basic infrastructure (e.g., office space, power, cooling, network) but lacks IT equipment and data, requiring significant time to become operational.
- Lowest cost among alternate sites.
- Requires the longest Recovery Time Objective (RTO).
- Needs all hardware and data to be transported and installed.
Memory trick: Cold Site: Just a cold, empty room.
Hardcoded Credential Remediation
Flip cardStrategies to mitigate the risk posed by sensitive authentication information (credentials) embedded directly into application source code or configuration files, making them easily discoverable and exploitable.
- Immediate risk: discovered credentials can be used directly.
- Long-term fix: externalize secrets using secrets management.
- Interim fix: change the actual credentials on target systems.
Memory trick: Hardcoded secrets are a ticking bomb; change the locks before they come.
HTTPS
Flip cardHypertext Transfer Protocol Secure (HTTPS) is an extension of the Hypertext Transfer Protocol (HTTP) for secure communication over a computer network. In HTTPS, the communication protocol is encrypted using Transport Layer Security (TLS), or its predecessor, Secure Sockets Layer (SSL).
- Provides confidentiality (encryption), integrity, and authenticity.
- Uses TLS/SSL to secure HTTP traffic.
- Requires server certificates to establish trust.
Memory trick: Secure connections need layers of trust and encryption.
Secure SDLC (Security by Design)
Flip cardAn approach to software development that integrates security considerations and practices into every phase of the Software Development Life Cycle (SDLC), from initial design and requirements gathering through to deployment and maintenance.
- Shifts security 'left' in the development process.
- Aims to prevent vulnerabilities rather than just detect them late.
- Involves threat modeling, secure coding, security testing, and secure deployment.
Memory trick: Build security in from the start, not just a patch at the end.
Cloud VM Hardening
Flip cardThe process of securing virtual machines in a cloud environment by reducing their attack surface, implementing strong configurations, and applying security best practices to protect against vulnerabilities and attacks.
- Involves disabling unnecessary services, strong passwords, least privilege.
- Includes regular patching and security updates.
- Often guided by security benchmarks (e.g., CIS Benchmarks).
Memory trick: Harden the system, lock it down, make it strong throughout the town.
Session ID Management
Flip cardThe process of securely creating, transmitting, and validating session identifiers to maintain stateful communication between a user and a web application.
- Session IDs should be long, random, and unpredictable.
- Never transmit session IDs in URLs (query strings).
- Use HTTPS and HTTP-only, secure, and samesite cookies for session IDs.
Memory trick: Web sessions need a secret handshake, not a shouted password.
Attack Surface Reduction
Flip cardThe process of identifying and reducing the number of possible attack vectors on a system or application.
- Minimize open ports and services.
- Disable unnecessary features and components.
- Remove unused code or functionalities.
Memory trick: Hardening systems is like fortifying a castle: close all unnecessary gates.
Data Execution Prevention (DEP)
Flip cardA system-level memory protection feature that marks certain memory areas as non-executable, preventing code from running from data-only memory regions. This helps prevent certain types of malware and buffer overflow attacks.
- Prevents code execution from data segments of memory.
- Mitigates buffer overflow and similar memory corruption attacks.
- Implemented by hardware (NX bit) and/or software.
Memory trick: Memory needs guards to keep data from running wild.
Cross-Site Scripting (XSS) Prevention
Flip cardTechniques used to prevent attackers from injecting malicious client-side scripts into web pages viewed by other users, typically by validating, sanitizing, or encoding user input.
- Primarily targets client-side browsers.
- Defenses include input validation, output encoding, and content security policies.
- Can lead to session hijacking, defacement, or malware distribution.
Memory trick: Input must be clean, or scripts will run unseen.
Path Traversal
Flip cardA web security vulnerability that allows an attacker to read arbitrary files on the server that is running an application, or to write arbitrary files to the server, by manipulating file paths.
- Also known as directory traversal.
- Exploits insufficient validation of user-supplied file paths.
- Often uses '../' sequences to navigate directory structures.
Memory trick: Web paths lead to hidden files, if not secured tightly.
SQL Injection Prevention
Flip cardTechniques used to prevent malicious SQL code from being inserted into data-driven input fields, thereby altering or compromising SQL queries.
- Parameterized queries are the primary defense.
- Input validation (server-side) is crucial.
- Least privilege for database accounts.
Memory trick: To stop SQLi, build a strong wall between data and commands.
Data at Rest Encryption
Flip cardThe cryptographic protection of data when it is stored on any non-volatile storage medium, such as hard drives, solid-state drives, databases, and backup tapes.
- Protects data when not actively being used or transmitted.
- Ensures data remains unreadable if storage is compromised.
- Commonly implemented via full disk encryption, database encryption, or file-level encryption.
Memory trick: Data sleeps, data moves, data works; each state needs its own security perks.
Secure Password Storage
Flip cardThe practice of storing user passwords in a way that prevents them from being easily recovered or used by attackers, even if the storage system is compromised.
- Never store passwords in plaintext or encrypted form.
- Always use strong, one-way hashing algorithms.
- Passwords must be 'salted' to prevent rainbow table attacks.
- Use adaptive (slow) hashing functions (e.g., bcrypt, scrypt, Argon2).
Memory trick: Store passwords like precious jewels, not in plain sight.
Buffer Overflow Prevention
Flip cardTechniques used in software development to prevent a program from writing data beyond the boundaries of an allocated buffer, which can lead to crashes, incorrect program behavior, or execution of malicious code.
- Perform bounds checking on all input.
- Use safe string handling functions (e.g., `strlcpy` instead of `strcpy`).
- Employ memory-safe languages or language features.
Memory trick: Secure coding is like building a house with strong foundations and walls.
Message Authentication Code (MAC)
Flip cardA short piece of information used to authenticate a message and provide integrity and authenticity assurances for data. A MAC algorithm, sometimes called a keyed hash function, accepts a secret key and an arbitrary-length message as input and outputs a MAC.
- Provides data integrity and authenticity.
- Uses a secret key.
- Prevents both accidental and malicious alteration of data.
Memory trick: Cryptography has many tools, pick the right one for your rules.
Authentication Factors
Flip cardCategories of credentials used to verify a user's identity. There are typically three main types: knowledge, possession, and inherence.
- Something you know (e.g., password, PIN).
- Something you have (e.g., smart card, token, phone).
- Something you are (e.g., fingerprint, retina scan, voice).
Memory trick: MFA is like needing multiple keys of different types to open a secure door.
Column-level Encryption
Flip cardA method of encrypting specific data columns within a database, rather than the entire database or disk. This provides granular protection for sensitive data fields.
- Encrypts individual fields or columns.
- Protects data even if an attacker gains database access.
- Requires secure key management for effectiveness.
Memory trick: Encrypting data at rest is like putting a safe around your files.
OAuth 2.0 & OpenID Connect (OIDC)
Flip cardOAuth 2.0 is an authorization framework that enables applications to obtain limited access to user accounts on an HTTP service. OpenID Connect is an authentication layer on top of OAuth 2.0, allowing clients to verify the identity of the end-user based on the authentication performed by an authorization server.
- OAuth provides delegated authorization.
- OIDC provides identity verification (authentication).
- Ideal for microservices and API security.
Memory trick: Securing microservices is like giving each puzzle piece its own guard and ID card.
Secrets Management
Flip cardThe tools and methods used to manage digital authentication credentials (secrets) for applications, services, and users, ensuring they are stored, distributed, and accessed securely.
- Prevents hardcoding of sensitive information.
- Enables centralized control, auditability, and rotation of secrets.
- Essential for modern distributed architectures like microservices.
Memory trick: Secret keys need a vault, not just a lock and key.
Compartmentalization
Flip cardA security principle that involves dividing a system or network into isolated segments or 'compartments' to limit the impact of a security breach to only the compromised segment, preventing lateral movement to other parts of the system.
- Also known as segmentation or isolation.
- Limits the 'blast radius' of an attack.
- Applied to networks, systems, data, and processes.
Memory trick: Good design builds walls and limits access.
EAP-TLS with WPA3
Flip cardA highly secure wireless authentication and encryption combination using client/server certificates for mutual authentication and WPA3's advanced cryptographic features.
- EAP-TLS uses X.509 certificates for both client and server.
- WPA3 mandates CCMP (AES-GCM) for encryption.
- WPA3's SAE (Simultaneous Authentication of Equals) provides forward secrecy.
Memory trick: EAP Methods: MD5 is Messy, LEAP is Leaky, PEAP is Protected, TLS is Top-tier.
SSID Broadcasting Disablement
Flip cardThe act of configuring a wireless access point (WAP) to not publicly advertise its network name (SSID).
- Hides the network from casual scanning.
- Does not prevent discovery by dedicated tools.
- Considered 'security through obscurity'.
Memory trick: Hiding the Name is a Simple Game.
In-band NAC
Flip cardA Network Access Control deployment model where the NAC appliance is placed directly in the network's data path.
- Intercepts and controls all network traffic in real-time.
- Enforces policies before granting full network access.
- Provides strict control over device admission.
Memory trick: NAC Models: In-band is Inline, Out-of-band is Off-path.
SYN Flood Attack
Flip cardA type of denial-of-service (DoS) attack that exploits the TCP three-way handshake by sending a flood of SYN requests to a server, but never sending the final ACK, leaving the connections half-open and exhausting server resources.
- Targets the TCP three-way handshake.
- Leaves connections in a 'half-open' state.
- Exhausts server connection tables and memory.
Memory trick: Symptoms Reveal The Attack, Solutions Provide Relief.
Distributed Denial of Service (DDoS)
Flip cardAn attack where multiple compromised systems (botnet) target a single system, causing a denial of service for legitimate users.
- Uses multiple sources to launch the attack.
- Aims to exhaust target resources (bandwidth, CPU, memory).
- Makes services unavailable to legitimate users.
Memory trick: Attackers Want Diverse Methods to Disrupt.
Wireless Spectrum Analyzer
Flip cardA device or software that measures and displays the amplitude of signals as a function of frequency within a specific radio frequency (RF) band.
- Identifies sources of RF interference.
- Visualizes channel usage and noise levels.
- Essential for troubleshooting wireless performance issues.
Memory trick: Tools Reveal Wireless Woes.
Layer 2 Security Features
Flip cardSecurity controls implemented on network switches to protect against vulnerabilities specific to the data link layer (Layer 2) of the OSI model.
- Protects against MAC flooding, ARP poisoning, VLAN hopping.
- Includes features like DHCP snooping, Dynamic ARP Inspection (DAI), Port Security.
- Requires managed switches for implementation.
Memory trick: Layers Need Specific Defenses.
Demilitarized Zone (DMZ)
Flip cardA perimeter network that protects an organization's internal local area network (LAN) from untrusted traffic, typically from the internet.
- Acts as a buffer zone.
- Hosts public-facing servers (e.g., web, email).
- Separated from internal and external networks by firewalls.
Memory trick: Segments Protect Zones.