SSCP Systems Security Certified Practitioner flashcards
162 free flashcards. Tap a card to flip it.
Firewall Rule Least Privilege
Flip cardConfiguring firewall rules to grant only the minimum necessary access required for functionality, specifying exact sources, destinations, ports, and protocols.
- Restricts access to only what is needed.
- Minimizes the attack surface.
- Requires specific source, destination, port, and protocol definitions.
Memory trick: Firewall Rules Must Be Precise.
Network Segmentation
Flip cardThe practice of dividing a computer network into smaller subnetworks, each acting as its own broadcast domain.
- Improves network security by limiting lateral movement of threats.
- Enhances network performance by reducing broadcast traffic.
- Uses technologies like VLANs, firewalls, and subnets.
Memory trick: Secure networks Need Good Architecture, always Segment.
Client-to-Site VPN with RADIUS
Flip cardA remote access solution that creates an encrypted tunnel from a single user's device to the corporate network, leveraging a RADIUS server for centralized authentication and granular authorization.
- Provides strong encryption for data in transit.
- Enables remote users to securely access internal resources.
- RADIUS integration allows for centralized user management and granular access control.
Memory trick: Remote Access Needs Strong Control.
Global Server Load Balancing (GSLB)
Flip cardA traffic management technique that distributes user requests across multiple servers located in different geographic regions or data centers.
- Provides high availability and disaster recovery.
- Directs users to the closest or best-performing server.
- Often uses DNS to direct clients to the appropriate data center.
Memory trick: High Availability Requires Good Load Balancing, especially Globally.
Need-to-Know
Flip cardA security principle that restricts access to information to only those individuals or systems whose jobs require them to have that access.
- A refinement of the principle of least privilege.
- Focuses on limiting access to specific data or information.
- Crucial for protecting sensitive and classified information.
Memory trick: Need-to-Know: Only see what you absolutely must to do your job, nothing more.
WPA2-Enterprise
Flip cardA robust wireless security protocol that uses 802.1X for centralized authentication and dynamic encryption keys.
- Requires an authentication server (e.g., RADIUS).
- Provides per-user, per-session encryption keys.
- Offers stronger security than WPA-Personal (PSK).
Memory trick: WEP is Weak, WPA is Better, WPA2 is Best, WPA3 is Next.
Destination NAT (DNAT)
Flip cardA form of Network Address Translation used to change the destination IP address of incoming packets, typically from a public IP to a private IP.
- Enables external hosts to initiate connections to internal servers.
- Often used for servers in a DMZ or internal network.
- Also known as port forwarding when combined with port translation.
Memory trick: Network Address Translation: DHCP gives, DNS resolves, ARP maps, NAT translates.
Differentiated Services Code Point (DSCP)
Flip cardA 6-bit field in the IP header used to classify and manage network traffic, enabling Quality of Service (QoS) by assigning different service levels.
- Operates at Layer 3 (IP header).
- Provides granular traffic classification.
- Widely used for prioritizing real-time traffic like VoIP.
Memory trick: Quality Services Deliver Clear Prizing.
Guest Network Isolation
Flip cardThe practice of creating a separate, logically isolated network segment for guest users to prevent their access to internal corporate resources.
- Typically uses VLANs for logical separation.
- Traffic is routed through a firewall to restrict access.
- Ensures guests only have internet access.
Memory trick: Isolation is Key: VLANs Separate, Firewalls Filter, SSIDs Don't Isolate.
SSL/TLS VPN
Flip cardA Virtual Private Network (VPN) solution that uses the SSL/TLS protocol to create secure, encrypted tunnels over public networks.
- Often accessed via a web browser (clientless) or lightweight client.
- Provides secure remote access to corporate resources.
- Widely compatible with various operating systems.
Memory trick: VPN Choices: IPsec needs Install, SSL is Browser, PPTP is Poor, L2TP needs IPsec.
SNMPv3
Flip cardThe third and most secure version of the Simple Network Management Protocol, providing authentication, integrity, and encryption.
- Uses User-Based Security Model (USM).
- Supports MD5/SHA for authentication and DES/AES for encryption.
- Addresses critical security flaws present in SNMPv1 and SNMPv2c.
Memory trick: SNMP Versions: 1 is None, 2c is Clear, 3 is Covered.
Identity Governance and Administration (IGA)
Flip cardA framework that manages digital identities and access rights throughout their lifecycle, including provisioning, access requests, role management, and compliance.
- Automates identity and access management processes.
- Ensures compliance with security policies and regulations.
- Provides visibility into who has access to what resources.
Memory trick: IGA is the grand conductor of all identity tasks, from hiring to leaving.
Next-Generation Firewall (NGFW)
Flip cardA deep packet inspection firewall that moves beyond port/protocol inspection to include application-level inspection, intrusion prevention, and threat intelligence.
- Performs deep packet inspection (DPI).
- Offers application awareness and control.
- Integrates intrusion prevention system (IPS) capabilities.
Memory trick: Firewall Evolution: Packet is Basic, Stateful is Smart, Next-Gen is Nifty, Proxy is a PITA.
MAC Address Filtering
Flip cardA security technique that controls access to a network by allowing or denying devices based on their unique Media Access Control (MAC) address.
- Uses hardware addresses for access control.
- Provides a basic layer of security.
- Easily bypassed by MAC spoofing.
Memory trick: MACs Block Bad Connections.
WPA3-Enterprise with EAP-TLS
Flip cardThe most secure wireless encryption and authentication standard, combining WPA3's advanced features with certificate-based EAP-TLS for mutual authentication.
- WPA3 offers enhanced security over WPA2.
- Enterprise mode uses 802.1X for authentication.
- EAP-TLS uses digital certificates for strong mutual authentication (client and server).
- Ideal for highly sensitive environments requiring maximum security.
Memory trick: Wireless Needs Enterprise-Level Trust.
Demilitarized Zone (DMZ)
Flip cardA perimeter network that protects an organization's internal local area network (LAN) from untrusted traffic, typically from the internet.
- Acts as a buffer zone.
- Hosts public-facing servers (e.g., web, email).
- Separated from internal and external networks by firewalls.
Memory trick: Segments Protect Zones.
Layer 2 Security Features
Flip cardSecurity controls implemented on network switches to protect against vulnerabilities specific to the data link layer (Layer 2) of the OSI model.
- Protects against MAC flooding, ARP poisoning, VLAN hopping.
- Includes features like DHCP snooping, Dynamic ARP Inspection (DAI), Port Security.
- Requires managed switches for implementation.
Memory trick: Layers Need Specific Defenses.
Wireless Spectrum Analyzer
Flip cardA device or software that measures and displays the amplitude of signals as a function of frequency within a specific radio frequency (RF) band.
- Identifies sources of RF interference.
- Visualizes channel usage and noise levels.
- Essential for troubleshooting wireless performance issues.
Memory trick: Tools Reveal Wireless Woes.
Distributed Denial of Service (DDoS)
Flip cardAn attack where multiple compromised systems (botnet) target a single system, causing a denial of service for legitimate users.
- Uses multiple sources to launch the attack.
- Aims to exhaust target resources (bandwidth, CPU, memory).
- Makes services unavailable to legitimate users.
Memory trick: Attackers Want Diverse Methods to Disrupt.
SYN Flood Attack
Flip cardA type of denial-of-service (DoS) attack that exploits the TCP three-way handshake by sending a flood of SYN requests to a server, but never sending the final ACK, leaving the connections half-open and exhausting server resources.
- Targets the TCP three-way handshake.
- Leaves connections in a 'half-open' state.
- Exhausts server connection tables and memory.
Memory trick: Symptoms Reveal The Attack, Solutions Provide Relief.
In-band NAC
Flip cardA Network Access Control deployment model where the NAC appliance is placed directly in the network's data path.
- Intercepts and controls all network traffic in real-time.
- Enforces policies before granting full network access.
- Provides strict control over device admission.
Memory trick: NAC Models: In-band is Inline, Out-of-band is Off-path.
SSID Broadcasting Disablement
Flip cardThe act of configuring a wireless access point (WAP) to not publicly advertise its network name (SSID).
- Hides the network from casual scanning.
- Does not prevent discovery by dedicated tools.
- Considered 'security through obscurity'.
Memory trick: Hiding the Name is a Simple Game.
Implicit Deny
Flip cardImplicit deny is a firewall rule that states if a packet does not match any 'allow' rules, it will be automatically denied. This provides a secure default posture.
- Last rule in a firewall's access control list (ACL).
- Enhances security by blocking unapproved traffic.
- Often represented as 'deny any any' at the end of a rule set.
Memory trick: If it's not on the guest list, it's not coming in the club.
Anomaly-Based IDS
Flip cardAn Intrusion Detection System that establishes a baseline of normal network or system behavior and identifies activity that deviates significantly from this baseline as anomalous and potentially malicious.
- Detects unknown attacks (zero-day).
- Can have higher false positive rates initially.
- Requires a learning phase to establish a baseline.
- Focuses on deviations from 'normal'.
Memory trick: Signatures are known, Anomalies are new, Heuristics are smart rules.
Incident Response - Detection and Analysis
Flip cardThe phase of incident response focused on identifying potential security events, determining if they are actual incidents, assessing their scope and impact, and prioritizing them for further action.
- Involves monitoring logs and alerts.
- Requires verifying the legitimacy of an incident.
- Includes initial damage assessment and prioritization.
Memory trick: Prepare, Detect, Contain, Eradicate, Recover, Post-mortem.
Security Awareness Program Metrics
Flip cardQuantifiable measures used to evaluate the effectiveness of security awareness training programs, focusing on changes in employee knowledge, attitudes, and behaviors related to cybersecurity.
- Should measure behavioral change.
- Examples: phishing click rates, incident reporting rates.
- Tracked over time to show trends.
- Helps justify program investment.
Memory trick: Behavioral change is the true test of learning.
Password Spraying
Flip cardAn attack where a single common password is tried against many different user accounts to avoid account lockout policies, often followed by trying another password against the same set of accounts.
- Targets multiple user accounts.
- Uses a small set of common passwords.
- Aims to bypass account lockout mechanisms.
Memory trick: Spray many locks with one key, then switch keys.
EDR False Positive Reduction
Flip cardThe process of tuning Endpoint Detection and Response (EDR) rules, baselines, and thresholds to minimize the generation of benign alerts, thereby improving the signal-to-noise ratio and reducing alert fatigue for security analysts.
- Crucial for operational efficiency.
- Involves continuous tuning and learning.
- Reduces alert fatigue.
- Improves focus on actual threats.
Memory trick: Tune the noise, so the real alarms are heard.
WORM Log Management
Flip cardWrite-Once, Read-Many (WORM) log management systems ensure that log data, once recorded, cannot be altered or deleted, providing an immutable audit trail for security investigations.
- Ensures log integrity and immutability.
- Crucial for forensic investigations and compliance.
- Prevents attackers from covering their tracks.
- Often involves centralized storage.
Memory trick: Immutable logs are the bedrock of reliable investigations.
Mobile Application Management (MAM)
Flip cardMAM is a type of software that enables IT administrators to manage and protect corporate applications and data on mobile devices, often used in BYOD environments to separate business and personal data.
- Manages specific applications, not the entire device.
- Ideal for BYOD scenarios to respect user privacy.
- Enforces policies like data encryption, copy/paste restrictions within corporate apps.
- Complements or can be used instead of MDM.
Memory trick: BYOD is about balancing corporate security with personal device freedom.
Virtual Patching (WAF)
Flip cardVirtual patching, often implemented via a Web Application Firewall (WAF), is a security measure that shields a vulnerable application from attacks by intercepting and inspecting traffic, blocking malicious requests without modifying the application's source code.
- Provides immediate protection for known vulnerabilities.
- Does not require changes to the application code.
- Acts as an interim solution until a permanent fix is deployed.
- Effective against common web application attacks like SQL Injection and XSS.
Memory trick: When a critical vulnerability is found, patch it fast, then fix it right.
Black-Box Penetration Test
Flip cardA black-box penetration test is an authorized cyberattack simulation where the testers have no prior knowledge of the target system's internal structure or code, mimicking an external attacker.
- Simulates an unprivileged attacker.
- Focuses on external vulnerabilities.
- Provides a realistic view of external attack surfaces.
Memory trick: Box types: White sees all, Grey sees some, Black sees none.
Adult Learning Principles (Andragogy)
Flip cardAdult learning principles (Andragogy) describe methods and approaches for teaching adults, emphasizing self-direction, relevance, experience, and active participation to maximize engagement and retention.
- Adults are self-directed learners.
- Learning must be relevant to their lives/work.
- They draw on their experiences.
- They prefer active participation in the learning process.
Memory trick: Adults learn by doing, relating, and taking control.
Physical Access Control
Flip cardPhysical access control involves measures to restrict unauthorized individuals from entering specific areas, such as server rooms or data centers.
- It's the first line of defense against physical intrusion.
- Includes barriers, locks, and monitoring systems.
- Essential for protecting hardware and data.
Memory trick: First, lock the door, then watch who knocks.
Network Access Control (NAC)
Flip cardNetwork Access Control (NAC) is a security solution that restricts the availability of network resources to endpoint devices that comply with a defined security policy. It authenticates users and devices and assesses their security posture before granting network access.
- Authenticates users and devices.
- Evaluates device security posture (e.g., AV, patches).
- Grants, denies, or restricts network access based on compliance.
- Crucial for BYOD and remote access security.
Memory trick: NAC: Check your papers before you enter the network party.
Effective Security Awareness Training
Flip cardTraining that actively engages participants, tests their understanding, provides practical application of security principles, and clearly communicates individual roles and responsibilities.
- Must be mandatory and recurrent.
- Should include interactive elements and assessments.
- Tailored to roles and relevant threats.
- Focuses on behavior change and understanding 'why'.
Memory trick: Engage, Test, Apply, Reinforce for true understanding.
Security Policy Standard
Flip cardA mandatory rule or specification that defines the specific use of technology, processes, or configurations to ensure compliance with a high-level organizational security policy.
- Mandatory compliance.
- Specific and technical.
- Supports high-level policies.
- Often includes configuration requirements.
Memory trick: Policy is King, Standards are Laws, Guidelines are Advice, Procedures are Steps.
Volatile Data Forensics
Flip cardVolatile data in forensics refers to information that is present in a computer's memory or running processes and will be lost when the system is powered down or rebooted. Its collection is critical for live incident response.
- Lost upon system shutdown/reboot.
- Includes RAM contents, running processes, network connections, logged-on users.
- Collected first in live forensic investigations.
- Provides insights into current system state and attacker activity.
Memory trick: Memory fades fast, so grab it first!
Penetration Testing
Flip cardPenetration testing (pen testing) is a simulated cyberattack against your computer system to check for exploitable vulnerabilities. It's used to evaluate the security of a system or network by safely trying to exploit weaknesses.
- Actively attempts to exploit vulnerabilities.
- Tests the effectiveness of security controls.
- Provides a realistic view of an organization's security posture.
- Goes beyond identifying vulnerabilities to prove exploitability.
Memory trick: To truly know if your shield works, you must try to pierce it.
Software Composition Analysis (SCA)
Flip cardSoftware Composition Analysis (SCA) is a process and set of tools used to automate the identification of open-source and third-party components in a codebase, along with their associated licenses, known vulnerabilities, and security risks.
- Identifies open-source and commercial third-party components.
- Scans for known vulnerabilities (CVEs) in these components.
- Helps manage licensing compliance.
- Integrated into CI/CD pipelines for continuous monitoring.
Memory trick: Secure your code's ingredients before you bake the cake.
Network-based Firewall
Flip cardA security device or software that monitors and controls incoming and outgoing network traffic based on predetermined security rules, typically operating at the network perimeter or between network segments (subnets).
- Filters traffic based on IP, port, protocol.
- Operates at network layer (mostly).
- Protects network segments.
- Can be stateful or stateless.
Memory trick: Firewall guards the gate, WAF the web, NAC the entry.
Incident Preparation
Flip cardThe Incident Preparation phase involves establishing policies, procedures, and resources to prevent and effectively respond to cybersecurity incidents.
- Includes security awareness training.
- Develops incident response plans.
- Involves vulnerability assessments and patching.
Memory trick: Prepare for the storm before it hits, so you can detect, contain, eradicate, and recover.