Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) flashcards
136 free flashcards. Tap a card to flip it.
Shadow IT Mitigation
Flip cardShadow IT refers to the use of IT systems, devices, software, applications, and services without explicit organizational approval. Mitigating it involves gaining visibility and control over all cloud services used by employees.
- CASBs are primary tools for discovering and managing shadow IT.
- Shadow IT poses risks like data leakage, compliance violations, and security vulnerabilities.
- Visibility and policy enforcement are key to mitigation.
Memory trick: CASB is the 'C'loud 'A'ccess 'S'ecurity 'B'ouncer that catches shadow IT.
Web Application Firewall (WAF)
Flip cardA security solution that monitors, filters, and blocks HTTP traffic to and from a web application, protecting against common web-based attacks like SQL injection and XSS.
- Operates at the application layer (Layer 7)
- Protects against specific web exploits
- Deployed at the edge of the network
Memory trick: WAF is your web app's personal bodyguard.
Cloud Workload Protection Platform (CWPP)
Flip cardA security solution that provides comprehensive protection for server workloads (virtual machines, containers, and serverless functions) across hybrid and multi-cloud environments, covering vulnerability management, runtime protection, and network segmentation.
- Secures workloads throughout their lifecycle.
- Includes vulnerability scanning, malware detection, behavioral monitoring.
- Supports various workload types like containers and VMs.
Memory trick: CWPP 'wraps' your workloads in a 'protective bubble' from build to run.
Shadow IT
Flip cardThe use of IT systems, devices, software, applications, and services without explicit organizational approval or oversight from the IT department.
- Introduces unmanaged security risks
- Can lead to compliance violations
- Often driven by ease of access and user convenience
Memory trick: Shadow IT: Unseen services, unseen dangers.
Private Cloud
Flip cardA cloud computing environment dedicated exclusively to a single organization, offering enhanced control, security, and isolation.
- Single-tenant architecture
- High level of control and customization
- Can be on-premises or hosted externally
Memory trick: Private Clouds are like your own private island for data.
Least Privilege
Flip cardA security principle requiring that a user or system be given only the minimum levels of access or permissions needed to perform its job function.
- Reduces the attack surface
- Limits damage from compromised accounts
- Essential for strong access control
Memory trick: Don't Give Too Much, Just Enough Privilege.
AWS IAM Least Privilege
Flip cardThe security principle of granting users, roles, or services only the minimum permissions necessary to perform their intended tasks in AWS. This minimizes the potential blast radius of a security incident.
- Achieved through carefully crafted IAM policies.
- Reduces risk by limiting unauthorized access.
- Essential for secure cloud operations, especially with serverless functions.
Memory trick: IAM is the 'I'dentity 'A'nd 'M'aster key for AWS resources.
Cloud Security Posture Management (CSPM)
Flip cardA cloud security technology that continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation.
- Identifies security gaps in cloud infrastructure.
- Ensures compliance with regulatory standards.
- Automates remediation of misconfigurations.
Memory trick: CSPM checks your cloud's 'posture' for good 'health' and 'compliance'.
Public Cloud
Flip cardA cloud deployment model where computing services are delivered over the internet by a third-party provider, offering shared infrastructure and global availability.
- Owned and operated by a third-party cloud service provider.
- Resources are shared among multiple organizations.
- Offers high scalability, elasticity, and global reach.
Memory trick: Public clouds are like a global utility, always on, everywhere.
Network Access Control List (NACL)
Flip cardA stateless packet filtering firewall that controls traffic in and out of one or more subnets within a Virtual Private Cloud (VPC). It operates at the subnet level.
- Stateless: must explicitly allow both inbound and outbound traffic.
- Operates at the subnet level.
- Rules are evaluated in order, from lowest to highest.
Memory trick: NACLs are like 'N'etwork 'A'ir 'C'ontrol 'L'anes for your subnets.
Identity and Access Management (IAM)
Flip cardA framework of policies and technologies that controls who can access what resources under which circumstances in a cloud environment.
- Manages users, groups, and roles
- Defines granular permissions to cloud resources
- Crucial for enforcing the principle of least privilege
Memory trick: IAM: I Am Allowed What I Need.
Data at Rest Encryption
Flip cardThe cryptographic protection of data that is stored on any persistent storage media, ensuring its confidentiality even if the storage medium or underlying infrastructure is compromised.
- Applies to data on hard drives, SSDs, object storage, databases.
- Renders data unreadable without the decryption key.
- Crucial for compliance and data breach prevention.
Memory trick: Data 'at rest' should be 'resting' in an encrypted bed.
Infrastructure as a Service (IaaS)
Flip cardA cloud computing service model where consumers are provided with virtualized computing resources (VMs, storage, networks) over the internet. The customer manages the operating systems and applications.
- Provides fundamental computing resources.
- Customer has control over OS, applications, and data.
- Cloud provider manages virtualization, servers, storage, and networking hardware.
Memory trick: Remember 'I' for Infrastructure, 'P' for Platform, 'S' for Software.
Secure Hybrid Cloud Connectivity
Flip cardThe practice of establishing secure and reliable network connections between on-premises infrastructure and cloud environments, typically using VPNs or dedicated links.
- Ensures data privacy and integrity during transit
- Extends on-premises security controls to the cloud
- Facilitates consistent policy enforcement
Memory trick: Connect your cloud and on-premise securely, like a fortified bridge.
S3 Public Access Best Practice
Flip cardA fundamental security best practice for Amazon S3 (and similar object storage services) is to block all public access to buckets, especially those containing sensitive data, unless explicitly required and carefully controlled.
- Default S3 buckets are private
- Public access can be granted via bucket policies or ACLs
- Tools like S3 Block Public Access can enforce this organization-wide
Memory trick: S3: Secure Storage, Block Public Paths.
Cloud Access Security Broker (CASB)
Flip cardA security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud resources are accessed.
- Addresses shadow IT, data security, threat protection, and compliance
- Can enforce policies on sanctioned and unsanctioned cloud apps
- Operates as a proxy, API integration, or log-based
Memory trick: CASB: Controls All Shadowy Business.
Secure Software Development Lifecycle (SSDLC)
Flip cardIntegrating security practices and considerations into every phase of the software development lifecycle, from requirements gathering to deployment and maintenance.
- Includes threat modeling, secure coding, security testing.
- Aims to minimize vulnerabilities from the start.
- Prevents common security flaws like hardcoded credentials.
Memory trick: SSDLC builds security 'into' the code, not just 'around' it.
Data in Transit Encryption
Flip cardThe process of encrypting data as it moves across networks, such as between a client application and a cloud service, to protect its confidentiality and integrity from eavesdropping or tampering.
- Typically achieved using HTTPS/TLS.
- Protects data during communication.
- Complements data at rest encryption for comprehensive security.
Memory trick: For data 'T'ransport, 'T'LS is 'T'he 'L'ogical 'S'olution.
Federated Identity Management
Flip cardA system that allows users to use a single set of login credentials to access multiple applications and services across different security domains, often involving an on-premises identity provider and cloud services through a trusted relationship.
- Enables Single Sign-On (SSO).
- Relies on trusted relationships between identity providers.
- Commonly uses protocols like SAML or OIDC.
Memory trick: Federated Identity is like a trusted 'passport' for all your cloud travels.
Platform as a Service (PaaS)
Flip cardA cloud service model that provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure.
- Focus on application development and deployment
- Provider manages OS, runtime, middleware
- Scalable and flexible development environment
Memory trick: PaaS is your ready-made workshop for coding.
Cloud Resilience
Flip cardThe ability of a cloud system to withstand failures, adapt to changing conditions, and recover quickly from disruptions while maintaining acceptable levels of service.
- Achieved through redundancy, fault tolerance, and disaster recovery
- Often involves multi-region deployments
- Ensures business continuity
Memory trick: Resilience: Recover, Rebuild, React.
Serverless Least Privilege
Flip cardApplying the principle of least privilege to serverless functions by granting only the essential permissions required for each function to perform its specific task.
- Minimizes potential damage from compromised functions
- Reduces the attack surface
- Requires careful design of IAM policies
Memory trick: Give each serverless function its own tiny, specific key.
Data Encryption at Rest
Flip cardThe process of encoding data while it is stored on a persistent storage medium, protecting it from unauthorized access even if the storage infrastructure is compromised.
- Protects data confidentiality on disk or in storage.
- Uses cryptographic algorithms to scramble data.
- Requires a key for decryption and access.
Memory trick: Encrypt data at rest, so even if it rests in the wrong hands, it's still secret.
Cloud Dedicated Connection
Flip cardA dedicated, private network connection established between an organization's on-premises infrastructure and a cloud provider's network, bypassing the public internet.
- Examples: AWS Direct Connect, Azure ExpressRoute, Google Cloud Interconnect.
- Offers higher bandwidth, lower latency, and enhanced security compared to VPN over internet.
- Used for hybrid cloud architectures and large data transfers.
Memory trick: Direct Connect is like building a 'private highway' to the cloud.
Ubiquitous Data Encryption
Flip cardThe security concept of encrypting data at every point in its lifecycle: when it is stored (at rest), when it is moving across networks (in transit), and ideally, while it is being processed (in use).
- Provides end-to-end data protection
- Crucial for highly sensitive data and compliance
- Involves multiple encryption mechanisms
Memory trick: Ubiquitous Encryption: Everywhere, Always Encrypted.
Federated Identity Management (FIM)
Flip cardA system that allows users to authenticate once and gain access to services and applications across multiple, independent domains using a single set of credentials.
- Enables Single Sign-On (SSO)
- Centralizes identity management across disparate systems
- Commonly used in multi-cloud and hybrid cloud environments
Memory trick: FIM is your universal passport for all clouds.
Incident Identification
Flip cardThe initial phase of incident response focused on detecting security events, determining if they are incidents, and gathering critical information about their nature and scope.
- First phase of incident response.
- Involves monitoring, analysis, and validation.
- Aims to understand 'what happened'.
Memory trick: I Can't Eat Raw Carrots, Post-incident.
Spyware
Flip cardA type of malware that secretly observes the user's activities on a computer without their knowledge or permission, often collecting sensitive information.
- Collects user data (e.g., keystrokes, browsing history).
- Operates stealthily in the background.
- Can be used for identity theft or targeted advertising.
Memory trick: Ransom, Root, Spy, Worm: each does a distinct bad thing.
Well-Known Port 443
Flip cardThe standard port number designated for HTTPS (Hypertext Transfer Protocol Secure) traffic, which provides encrypted communication over a computer network.
- Used by HTTPS for secure web browsing.
- Encrypts data using SSL/TLS.
- Essential for secure online transactions and data transfer.
Memory trick: 443 is secure web, 80 is old web, 21 is files, 3389 is remote control.
Multi-Factor Authentication (MFA)
Flip cardMulti-Factor Authentication (MFA) is a security system that requires a user to provide two or more verification factors to gain access to a resource such as an application, online account, or VPN.
- Combines different types of authentication factors.
- Common factors: knowledge (password), possession (token), inherence (biometrics).
- Significantly reduces the risk of unauthorized access.
Memory trick: Authentication can be Single, Multi, or Identity-based.
Integrity (Cybersecurity)
Flip cardThe assurance that information is accurate, complete, and has not been modified by unauthorized entities or in an unauthorized manner.
- Prevents unauthorized data alteration.
- Ensures data accuracy and completeness.
- Often involves mechanisms like hashing, digital signatures, and access controls.
Memory trick: CIA: Keep it Secret, Safe, and Always Ready.
Implicit Deny
Flip cardA fundamental security principle in firewalls and access control lists (ACLs) where any traffic or access not explicitly permitted by a rule is automatically blocked.
- Considered a security best practice.
- Reduces the attack surface by only allowing necessary traffic.
- Often the last rule in a firewall's rule set.
Memory trick: What's not allowed, is denied by default.
Security by Design
Flip cardAn approach to software and system development where security is considered and integrated into every stage of the development lifecycle, from initial design to deployment and maintenance.
- Also known as 'shift left security'.
- Aims to prevent vulnerabilities rather than remediate them later.
- Reduces costs and risks associated with security flaws.
Memory trick: Design means building it right from the start, not fixing it later.
Firewall Rule Components
Flip cardFirewall rules are sets of instructions that specify what traffic is allowed or denied based on various criteria, including source, destination, application, and service.
- Evaluate traffic against defined criteria.
- Typically processed in order from top to bottom.
- An implicit 'deny all' is often the last rule.
Memory trick: Firewalls use zones, addresses, apps, and services to direct traffic.
Role-Based Access Control (RBAC)
Flip cardAn access control model where permissions are associated with specific roles, and users are granted access by being assigned to those roles.
- Simplifies access management for large organizations.
- Ensures least privilege by default based on job function.
- Commonly used in enterprise environments.
Memory trick: RBAC: Roles get permissions, users get roles. Simple!
Explicit Allow Rule
Flip cardA firewall rule that specifically permits traffic that matches defined criteria, often used in conjunction with an implicit deny-all policy.
- Specifically grants access.
- Overrides implicit deny rules.
- Crucial for controlled network access.
Memory trick: Rules are either explicitly allowed or implicitly denied.
Confidentiality
Flip cardThe information security principle that protects data from unauthorized disclosure. It ensures that only authorized individuals can access sensitive information.
- Part of the CIA triad (Confidentiality, Integrity, Availability).
- Achieved through encryption, access control, and data handling policies.
- Prevents unauthorized viewing or access to data.
Memory trick: CIA ensures your data is Safe, Sound, and always On.
Digital Signature
Flip cardA mathematical scheme for verifying the authenticity and integrity of digital messages or documents.
- Uses asymmetric cryptography.
- Provides sender authentication, data integrity, and non-repudiation.
- Does not directly provide confidentiality (encryption must be added separately).
Memory trick: Sign, Seal, and Deliver, ensuring it's really from the sender and hasn't changed.
Advanced Persistent Threat (APT)
Flip cardA stealthy and continuous computer hacking process, often orchestrated by nation-states or highly organized groups, targeting organizations for a specific objective, typically data exfiltration.
- Highly skilled and well-funded attackers.
- Long-term, targeted campaigns.
- Focus on stealth and data exfiltration.
- Often uses multiple attack vectors.
Memory trick: APT is Advanced, Persistent, and Targeted.
Threat Assessment Goal
Flip cardThe primary objective of a threat assessment is to systematically identify and evaluate potential threats, vulnerabilities, and their potential impact on an organization's assets or systems.
- Focuses on understanding attack vectors and consequences.
- Helps prioritize security controls.
- Informs risk management decisions.
Memory trick: Threat assessment is like 'scouting the enemy' to see how they might attack and what damage they could do.
DDoS Attack
Flip cardA Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple sources.
- Utilizes multiple compromised systems (botnet).
- Aims to make services unavailable to legitimate users.
- Can target various layers of the network stack.
Memory trick: Attacks can be Social, Data-focused, or simply Overwhelming.
Data Classification (Restricted)
Flip cardA category of data classification for information that, if disclosed, altered, or destroyed, would cause severe damage to the organization, requiring the highest level of protection.
- Highest level of sensitivity and impact.
- Often includes PII, financial data, trade secrets, and national security information.
- Requires stringent access controls, encryption, and audit trails.
Memory trick: Restricted is like a 'top secret' vault, only for the most damaging data.
Encryption and Confidentiality
Flip cardEncryption is the process of converting information or data into a code, preventing unauthorized access. It is a fundamental tool for achieving confidentiality, ensuring only authorized parties can understand the data.
- Transforms plaintext into ciphertext.
- Requires a key to decrypt and access original data.
- Protects data both 'at rest' (stored) and 'in transit' (communicated).
Memory trick: Protecting data means keeping it Secret, Sound, and always On-call.
Brute-force Attack
Flip cardA brute-force attack is a trial-and-error method used to obtain information such as user passwords or cryptographic keys. An attacker systematically tries every possible combination until the correct one is found.
- Involves guessing credentials repeatedly.
- Can be time-consuming but effective if no lockout policies are in place.
- Often detected by multiple failed login attempts from a single source.
Memory trick: Access attacks can be about Guessing, Tricking, or Stealing.
Asymmetric-key Cryptography
Flip cardA cryptographic system that uses a pair of mathematically related keys: a public key for encryption and a private key for decryption, or vice-versa, allowing secure communication without sharing a secret key.
- Uses distinct public and private keys.
- Public key can be shared, private key kept secret.
- Used for encryption, digital signatures, key exchange.
Memory trick: Asymmetric is like a lock with two different keys.
Cyber Kill Chain: Installation
Flip cardThe Installation phase of the Lockheed Martin Cyber Kill Chain describes the attacker's actions to establish a persistent foothold on the compromised system, often through the use of backdoors, rootkits, or other mechanisms.
- Occurs after initial exploitation and delivery.
- Focuses on maintaining access for future operations.
- Examples include installing web shells, rootkits, or creating new user accounts.
Memory trick: R-W-D-E-I-C-A: Really Wicked Dogs Eat Icy Cold Apples.
Mandatory Access Control (MAC)
Flip cardAn access control model where the operating system or security kernel enforces access rules based on security labels (sensitivity levels) assigned to subjects (users/processes) and objects (files/resources).
- Non-discretionary: Users cannot override access rules.
- Commonly used in highly secure environments (e.g., military, government).
- Employs a lattice-based model for security clearances/classifications.
Memory trick: The system mandates access, not the user.
Hashing (Cryptographic)
Flip cardA one-way mathematical function that converts an arbitrary-length input (data) into a fixed-length output (hash value or message digest).
- Primarily used for data integrity verification.
- Even a tiny change in input data results in a vastly different hash.
- Considered one-way: computationally infeasible to reverse the process.
- Used in digital signatures for integrity and non-repudiation.
Memory trick: Transforming data into a unique fingerprint for verification.
Cross-Site Scripting (XSS)
Flip cardCross-Site Scripting (XSS) is a type of security vulnerability typically found in web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users.
- Relies on improper input validation by the web application.
- Malicious scripts execute in the victim's browser.
- Can steal session cookies, deface websites, or redirect users.
Memory trick: Web apps can be attacked by injecting Code, Forging requests, or Traversing paths.
Zero Trust Model
Flip cardA security concept centered on the belief that organizations should not automatically trust anything inside or outside its perimeters and instead must verify anything and everything trying to connect to its systems before granting access.
- Never trust, always verify.
- Requires strict identity verification for every user and device.
- Assumes breach and minimizes the attack surface.
Memory trick: Zero trust means verifying everyone, not just keeping them out.
Exploit
Flip cardA piece of software, data, or sequence of commands that takes advantage of a bug or vulnerability to cause unintended or unanticipated behavior on computer software, hardware, or something else electronic (usually computer-related).
- Leverages specific vulnerabilities.
- Aims to gain unauthorized access, elevate privileges, or cause system compromise.
- Often a component within a larger attack chain.
Memory trick: Knowing the enemy's tactics helps defend the castle.
Integrity
Flip cardThe information security principle that ensures data is accurate, complete, and authentic, and has not been subjected to unauthorized modification or destruction.
- Part of the CIA triad (Confidentiality, Integrity, Availability).
- Achieved through hashing, digital signatures, access control, and version control.
- Focuses on preventing and detecting unauthorized data alteration.
Memory trick: CIA: Keep secrets, stay accurate, always available.
Mobile Device Management (MDM)
Flip cardSoftware that enables organizations to securely manage and monitor mobile devices, often including features for data separation, application management, and remote wiping.
- Manages and secures smartphones, tablets, laptops.
- Key for BYOD policies.
- Can enforce policies, encrypt data, remote wipe.
Memory trick: MDM manages devices, DLP prevents loss.
SQL Injection
Flip cardA code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g., to dump database content to the attacker).
- Exploits improper input validation in web applications.
- Allows attackers to manipulate database queries.
- Can lead to data theft, alteration, or complete system compromise.
Memory trick: SQL Injection is like 'talking directly to the database' through a sneaky message.
Broken Access Control
Flip cardA common web application vulnerability where restrictions on what authenticated users are allowed to do are not properly enforced, leading to unauthorized access to functionality or data.
- Users can access unauthorized resources/functions.
- Often due to incorrect permission checks.
- A top vulnerability in OWASP Top 10.
Memory trick: Access control can be broken, not just scripts or requests.
Symmetric Encryption
Flip cardA type of encryption where the same secret key is used for both encrypting plaintext into ciphertext and decrypting ciphertext back into plaintext.
- Uses a single, shared secret key.
- Faster than asymmetric encryption, ideal for bulk data.
- Key distribution is a challenge.
Memory trick: Symmetric: Same key for both sides, like a single lock.
Phishing
Flip cardA social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (e.g., usernames, passwords, credit card details) or downloading malware by impersonating a trustworthy entity.
- Often delivered via email, SMS (smishing), or voice (vishing).
- Relies on deception and urgency.
- Aims to exploit human trust and curiosity.
Memory trick: Don't fall for the bait, verify the sender!
Phishing Attack
Flip cardA type of social engineering attack where an attacker attempts to trick individuals into revealing sensitive information (e.g., usernames, passwords, credit card details) or clicking malicious links, often via deceptive emails or messages.
- Relies on deception and urgency.
- Often mimics legitimate entities.
- A common vector for malware delivery and credential theft.
Memory trick: Phishing is like 'fishing' for your info with a tricky bait email.
Non-repudiation
Flip cardNon-repudiation is the assurance that someone cannot deny the validity of something. In cybersecurity, it refers to the ability to ensure that a party to a contract or a communication cannot deny the authenticity of their signature on a document or the sending of a message that they originated.
- Provides undeniable proof of sender/receiver identity.
- Often achieved using digital signatures and logging.
- Crucial for legal and financial transactions.
Memory trick: Beyond CIA, we need Accountability and Proof.
Actions on Objectives
Flip cardThe final stage of the Cyber Kill Chain where an attacker achieves their primary goals, such as data exfiltration, destruction, or denial of service.
- Represents the attacker's ultimate goal.
- Can include data theft, corruption, or system disruption.
- Often the most visible and damaging stage for the victim.
Memory trick: Remember 'RED' for Recon, Exploitation, and Data theft (Actions on Objectives).