Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET) flashcards
136 free flashcards. Tap a card to flip it.
Defense in Depth
Flip cardDefense in depth is a cybersecurity strategy that employs a layered approach to security, using multiple, overlapping security controls to protect information and systems.
- Inspired by military strategy of layered defenses.
- Aims to slow down attackers, not just block them.
- Combines administrative, physical, and technical controls.
Memory trick: Defense in Depth is like an onion, layers protect the core.
Incident Eradication
Flip cardThe phase of incident response focused on removing the root cause of the incident and all traces of the attacker's presence from affected systems.
- Follows containment and often analysis.
- Involves cleaning compromised systems.
- Aims to prevent re-infection.
Memory trick: After you contain, you eradicate!
Vulnerability Exploitation
Flip cardThe act of taking advantage of a security flaw or weakness in a system, application, or network to achieve an unauthorized outcome.
- Requires a pre-existing vulnerability (e.g., unpatched software, misconfiguration).
- Often uses an 'exploit code' designed to trigger the vulnerability.
- Can lead to unauthorized access, privilege escalation, or data compromise.
- Patch management is a key defense against this attack method.
Memory trick: Attack vectors are like different paths a burglar can take to get into a house.
Hybrid SIEM Deployment
Flip cardA SIEM deployment model that integrates security data collection, analysis, and management across both on-premise infrastructure and cloud-based environments.
- Suitable for organizations with mixed IT landscapes.
- Provides unified visibility across cloud and on-premise.
- Combines benefits of both traditional and cloud SIEMs.
Memory trick: On-cloud, off-cloud, or both-cloud?
Microsegmentation
Flip cardA network security technique that divides an organization's data center or cloud network into distinct, isolated segments down to the individual workload level.
- Applies granular security policies between workloads.
- Restricts lateral movement of threats (east-west traffic).
- Improves security posture in virtualized and cloud environments.
Memory trick: In the cloud, build tiny fences around every sheep, not just a big one around the field.
System Hardening
Flip cardThe process of securing a system by reducing its attack surface and improving its overall security posture.
- Involves removing unnecessary software, services, and accounts.
- Includes applying security patches and updates regularly.
- Focuses on configuring secure settings like strong passwords and access controls.
Memory trick: Hardening builds strong walls against attackers.
Technical Threat Intelligence
Flip cardActionable, machine-readable information about specific Indicators of Compromise (IoCs) and attacker Tactics, Techniques, and Procedures (TTPs) that can be directly fed into security tools for detection and prevention.
- Includes IoCs: IP addresses, domains, file hashes, URLs.
- Directly usable by security devices (firewalls, SIEM, EDR).
- Aids in immediate detection and blocking of threats.
- Often derived from forensic analysis of incidents.
Memory trick: So Many Tiny Treasures
DNS Tunneling
Flip cardA technique that abuses the DNS protocol to create a covert communication channel, often used to bypass firewalls or exfiltrate data.
- Encodes data within DNS queries and responses.
- Can be used for command and control or data exfiltration.
- Often difficult to detect by traditional firewalls as DNS traffic is usually allowed.
Memory trick: DNS Tunnel: Data hidden in plain sight, through the DNS road.
Volatile Data Forensics
Flip cardThe process of collecting data from a live system that will be lost once the system is powered off or rebooted.
- Includes RAM, CPU registers, network connections, and running processes.
- Must be collected in a specific order of volatility (least volatile last).
- Crucial for understanding attacker activity on a live system.
Memory trick: Volatile data is like a ghost, gone if you turn off the lights.
Incident Response Framework
Flip cardAn Incident Response (IR) Framework is a structured set of policies, procedures, and guidelines that dictate how an organization prepares for, detects, analyzes, contains, eradicates, recovers from, and learns from security incidents.
- Provides a systematic approach to incidents.
- Defines roles, responsibilities, and communication.
- Ensures consistent and effective incident handling.
Memory trick: Plan, Detect, Respond, Improve.
Distributed Denial of Service (DDoS)
Flip cardA malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple compromised 'botnet' devices.
- Aims to make a service unavailable to legitimate users.
- Common types include volumetric, protocol, and application layer attacks.
- SYN flood is a common protocol-layer DDoS attack.
Memory trick: DoS is like a thousand people trying to cram through a single doorway at once, blocking everyone.
Containment (Credentials)
Flip cardImmediate actions to prevent further unauthorized use of compromised user or service account credentials.
- Prioritize disabling or revoking access for compromised accounts.
- Prevents attackers from using stolen credentials elsewhere.
- Often combined with network isolation or blocking for comprehensive containment.
Memory trick: When the key is stolen, first change the lock, then secure the door.
Next-Generation Firewall (NGFW)
Flip cardAn advanced firewall that combines traditional firewall capabilities with deep packet inspection, intrusion prevention, application awareness, and identity awareness.
- Inspects traffic beyond port and protocol, up to the application layer.
- Integrates intrusion prevention system (IPS) functionality.
- Provides granular control over applications and user identities.
Memory trick: Next-Gen firewalls are smart, seeing beyond the surface.
Software Vulnerability
Flip cardA flaw or weakness in software code, design, or implementation that can be exploited by an attacker to cause harm or gain unauthorized access.
- Often due to coding errors, design flaws, or outdated versions.
- Can be exploited to gain control, execute arbitrary code, or cause denial of service.
- Mitigated by patching, secure coding practices, and regular updates.
Memory trick: Software has bugs, hardware can fail, configs can be wrong, people make mistakes.
Packet Sniffer
Flip cardA tool (software or hardware) used to intercept and log traffic passing over a digital network or part of a network.
- Allows for deep inspection of individual packets.
- Useful for network troubleshooting, security analysis, and protocol development.
- Examples include Wireshark, tcpdump.
Memory trick: Different tools for different insights into network health and security.
SIEM Core Function
Flip cardA Security Information and Event Management (SIEM) system's core function is to collect, aggregate, and analyze log data and security events from various sources across an organization's IT infrastructure.
- Centralizes security data.
- Enables real-time monitoring and correlation.
- Aids in compliance reporting and incident detection.
Memory trick: SIEM: See Insights, Every Minute.
Cyber Kill Chain: Exploitation
Flip cardThe Exploitation phase of the cyber kill chain involves an attacker leveraging a vulnerability or stolen credentials to gain unauthorized access to a target system or network.
- Direct action against a target.
- Gaining initial access.
- Often follows 'Delivery'.
Memory trick: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control, Actions on Objectives.
Vulnerability Management
Flip cardVulnerability Management is the continuous, cyclical process of identifying, assessing, prioritizing, and remediating security weaknesses (vulnerabilities) in an organization's systems and applications to reduce their attack surface.
- Proactive security process.
- Involves scanning, assessment, and remediation.
- Aims to reduce attack surface.
Memory trick: Prevent, Detect, Respond, Recover.
Distributed SOC Model
Flip cardA Distributed SOC model consists of multiple Security Operations Centers (SOCs) located in different geographical regions or business units, each handling local security operations, while reporting and coordinating with a central SOC for overall strategy and oversight.
- Multiple regional SOCs.
- Centralized coordination/reporting.
- Leverages local expertise, global consistency.
Memory trick: Centralized, Distributed, Co-managed, Virtual: Choose Your SOC's Structure Wisely.
Confidentiality (CIA Triad)
Flip cardThe principle that information should not be disclosed to unauthorized individuals, entities, or processes.
- Ensured through encryption, access controls, and data classification.
- Prevents unauthorized reading or viewing of data.
- A core component of information security.
Memory trick: CIA: Keep it Secret, Safe, and Always On.
Network Broadcast Domain
Flip cardA logical division of a computer network where all nodes can reach each other by broadcast at the data link layer.
- Routers define the boundaries of broadcast domains.
- Broadcast storms can severely degrade network performance.
- Switches segment collision domains but typically not broadcast domains (unless using VLANs).
Memory trick: Each device has a job: some just repeat, others direct traffic.
Post-Incident Activity
Flip cardPost-Incident Activity, also known as 'Lessons Learned,' is the final phase of incident response where the organization reviews the incident, identifies what worked and what didn't, and implements improvements to processes, technologies, and training to enhance future security.
- Occurs after incident resolution.
- Aims to improve future readiness.
- Includes documentation, policy updates, and training.
Memory trick: I C E R R L: I See Every Risky, Response-Driven Loop.
SIEM Correlation
Flip cardThe process by which a SIEM system links and analyzes security event data from various sources to identify patterns or sequences indicative of a security incident.
- Combines events that individually might seem benign.
- Uses predefined rules and statistical analysis for anomaly detection.
- Crucial for detecting multi-stage attacks and complex threats.
Memory trick: A SIEM is a master detective, piecing together clues to solve the case.
Port Scan
Flip cardAn attack that involves systematically scanning a server's or host's ports to find open ports and identify potential vulnerabilities.
- Often a precursor to other attacks, used for reconnaissance.
- Can involve various techniques like SYN scan, TCP Connect scan, UDP scan.
- Firewalls and IDS/IPS can detect and block port scans.
Memory trick: Attackers first scout the area before launching an assault.
Patch Management
Flip cardThe process of regularly acquiring, testing, and applying code changes (patches) to software and operating systems to fix bugs, improve performance, and, crucially, address security vulnerabilities.
- Crucial for maintaining a strong security posture.
- Reduces the attack surface by eliminating known exploits.
- Requires a systematic approach to ensure all systems are updated.
Memory trick: Fixing holes before they're exploited is like patching a leaky roof.
Network Segmentation
Flip cardThe practice of dividing a computer network into smaller, isolated sub-networks or segments to improve security, performance, and manageability.
- Limits the blast radius of a breach.
- Enforces granular access control between segments.
- Commonly implemented with firewalls, VLANs, and routers.
Memory trick: Good security is like building a castle with distinct, protected wards.
Cloud Native Security
Flip cardAn approach to securing cloud computing environments that leverages the unique characteristics and services of cloud platforms to build security directly into the application and infrastructure layers.
- Emphasizes automation, API-driven security, and continuous monitoring.
- Utilizes cloud provider's native security services (e.g., security groups, WAFs, IAM).
- Supports micro-segmentation and 'zero trust' principles in the cloud.
- Integrates security into the DevOps pipeline (SecDevOps).
Memory trick: Cloud Native Security is like building a custom, smart security system directly into the cloud house, rather than trying to fit old locks on new doors.
Distributed SOC
Flip cardA Security Operations Center model where security analysts and operations are spread across multiple geographical locations.
- Offers 'follow-the-sun' coverage for 24/7 monitoring.
- Can improve local threat intelligence and compliance.
- May increase communication challenges and infrastructure costs.
Memory trick: A distributed SOC is like having security guards at every gate, around the clock.
Application Control
Flip cardA feature of Next-Generation Firewalls (NGFWs) that allows administrators to identify, classify, and control specific applications running on the network, regardless of the port or protocol they use.
- Goes beyond port-based filtering.
- Enables granular policy enforcement for specific applications (e.g., block Facebook, allow Salesforce).
- Improves security posture by reducing the attack surface and preventing unauthorized application usage.
Memory trick: It's not just about the door (port), but who's coming in and what they're carrying (application/content).
HTTPS Port
Flip cardPort 443 is the standard Transmission Control Protocol (TCP) port used for HTTPS (Hypertext Transfer Protocol Secure) communication.
- Encrypts web traffic using TLS/SSL.
- Ensures data confidentiality and integrity.
- Essential for secure online transactions and sensitive data exchange.
Memory trick: Secure web traffic 'forty-four-three' is the key to privacy.
Intrusion Detection System (IDS)
Flip cardA security technology that monitors network or system activities for malicious activity or policy violations and produces reports to a management station.
- Primarily focuses on detection, not prevention (unlike IPS).
- Uses signature-based or anomaly-based detection methods.
- Can operate on network traffic (NIDS) or host activities (HIDS).
Memory trick: Detectives (IDS/IPS) watch for bad guys, while guards (firewall) block doors.
Stateless Firewall
Flip cardA firewall that examines each packet individually, without regard to the state of the connection to which the packet belongs.
- Does not track active connections.
- Requires explicit rules for both inbound and outbound traffic.
- Less resource-intensive but less secure and flexible than stateful firewalls.
Memory trick: Stateless walls see packets, not conversations. Stateful walls remember the chat.
Zombie (Bot)
Flip cardA compromised computer connected to the internet that has been infected with malware and can be controlled remotely by an attacker, typically as part of a botnet.
- Used to perform malicious tasks like DDoS attacks, spamming, or cryptomining.
- Controlled by a command-and-control (C2) server.
- Often unaware of its compromised status.
Memory trick: A botnet is an army of zombies (bots) controlled by a sinister brain (C2).
Incident Recovery
Flip cardThe Recovery phase of incident response involves restoring affected systems and services to normal operation, ensuring that they are clean, fully functional, and secure after an incident has been contained and eradicated.
- Restores normal operations.
- Often involves rebuilding from backups or images.
- Follows eradication and precedes lessons learned.
Memory trick: I C E R R L: I See Every Risky, Response-Driven Loop.
ARP (Address Resolution Protocol)
Flip cardA communication protocol used to discover the MAC address associated with a given IP address on a local area network (LAN).
- Operates at the Data Link Layer (Layer 2) and Network Layer (Layer 3).
- Translates IP addresses to MAC addresses.
- Maintains an ARP cache to store recent mappings.
- Used for local network communication (within the same broadcast domain).
Memory trick: ARP is like asking 'Who has this phone number (IP address)?' and getting the answer 'That's me, here's my physical address (MAC address)!'
Transport Layer Security (TLS)
Flip cardA cryptographic protocol designed to provide communication security over a computer network.
- Successor to Secure Sockets Layer (SSL).
- Used to secure web traffic (HTTPS), email, VPNs, and other data-in-transit.
- Provides authentication, confidentiality (encryption), and integrity.
Memory trick: Different protocols secure different types of conversations.
SIEM Tuning
Flip cardThe process of optimizing a SIEM system to improve the accuracy of its threat detection and reduce alert fatigue.
- Involves refining correlation rules and adjusting alert thresholds.
- Aims to distinguish between true positives and false positives.
- Essential for maintaining analyst efficiency and system effectiveness.
Memory trick: Tune the SIEM like a radio, clear out the static to hear the signal.
Demilitarized Zone (DMZ)
Flip cardA physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted, larger network, usually the Internet.
- Acts as a buffer zone between the internet and the internal network.
- Hosts public-facing servers (web servers, email servers, DNS servers).
- Typically protected by firewalls on both its internet and internal network sides.
- Prevents direct access from the internet to the internal network.
Memory trick: The DMZ is like the castle moat and outer wall, protecting the inner keep (internal network) from direct assault.
OSI Model and Firewall Layers
Flip cardThe Open Systems Interconnection (OSI) model describes seven layers of computer networking, and firewalls operate at different layers depending on their functionality.
- Packet filtering firewalls primarily operate at Layer 3 (Network) and Layer 4 (Transport).
- Next-Generation Firewalls (NGFWs) inspect up to Layer 7 (Application).
- Blocking by IP address occurs at Layer 3.
Memory trick: Firewalls guard gates at different levels of the network castle.
Threat Hunting
Flip cardA proactive cybersecurity activity that involves searching for unknown threats or malicious activity that has bypassed existing security controls.
- Often hypothesis-driven, looking for specific patterns or anomalies.
- Requires deep understanding of attacker TTPs and network/endpoint data.
- Aims to find threats before they cause significant damage.
Memory trick: The SOC is a fortress with guards (monitoring), repairmen (vuln mgmt), and scouts (threat hunting).
Network Reliability
Flip cardThe ability of a network to provide continuous and consistent service, even in the presence of component failures.
- Achieved through redundancy (duplicate components) and failover mechanisms.
- Minimizes downtime and ensures business continuity.
- Essential for critical applications and services.
Memory trick: Design goals: RES S (Reliability, Efficiency, Security, Scalability).
Business Continuity and Disaster Recovery (BCDR)
Flip cardA set of processes and procedures to ensure that critical business functions can continue during and after a disaster or disruption.
- Focuses on maintaining availability and minimizing downtime.
- Includes data backups, redundant systems, and recovery plans.
- Essential for organizational resilience against various threats.
Memory trick: Best practices are like a good recipe: follow the steps for a secure outcome.
Routing
Flip cardThe process of forwarding packets between different computer networks based on their IP addresses.
- Operates at Layer 3 (Network Layer) of the OSI model.
- Uses IP addresses to determine the next hop.
- Performed by routers to connect different subnets.
Memory trick: Route traffic right, between networks, using IP.
Port Security
Flip cardA switch feature that restricts input to an interface by limiting and/or identifying MAC addresses allowed on that port.
- Prevents unauthorized devices from connecting to the network.
- Can be configured to shut down, restrict, or protect a port.
- Operates at Layer 2 (Data Link Layer).
Memory trick: Port Security: Secure the door against unknown MACs.
Co-managed SOC Model
Flip cardA hybrid Security Operations Center model where an organization partners with a Managed Security Service Provider (MSSP) to share security monitoring and incident response responsibilities, balancing internal control with external expertise.
- Internal team retains strategic control and advanced response.
- MSSP provides 24/7 monitoring, initial triage, and expertise.
- Ideal for organizations with budget/staffing constraints but desire for control.
Memory trick: Need help but want control? Co-manage!
Incident Analysis & Validation
Flip cardThe process of thoroughly examining collected data to confirm the nature, scope, and impact of a potential security incident before proceeding with containment.
- Aims to reduce false positives.
- Involves reviewing logs, network traffic, system artifacts.
- Crucial before implementing containment measures.
Memory trick: Analyze before you act!
Incident Containment
Flip cardThe phase of incident response aimed at limiting the scope and impact of a security incident.
- Focuses on stopping the spread of the attack.
- Can involve isolating systems, blocking malicious IPs, or disabling accounts.
- Must be balanced with evidence preservation and business continuity.
Memory trick: When the alarm rings, first cut the wires to stop the spread.
Port Scanning
Flip cardA reconnaissance technique used to identify open ports, active services, and potential vulnerabilities on a network host by sending packets and analyzing responses.
- Helps attackers (or security teams) discover potential entry points.
- Can be detected by Intrusion Detection Systems (IDS).
- Common tools include Nmap.
Memory trick: Reconnaissance: Scouting for weak spots.
MITRE ATT&CK Framework
Flip cardA globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used as a foundation for developing specific threat models and methodologies.
- Organizes adversary behaviors into tactics (goals) and techniques (how they achieve them).
- Aids in threat hunting, incident response, and security control mapping.
- Provides common language for describing adversary actions.
Memory trick: STIX share, OpenIOC identifies, ATT&CK maps, CVSS scores.
File System Carving
Flip cardA digital forensic technique used to recover deleted or damaged files and data fragments from unallocated space on a storage medium.
- Searches for file headers and footers.
- Useful when attackers attempt to erase evidence.
- Can recover partial files even without file system metadata.
Memory trick: Memory, Live, Carve, Network – what are you looking for?
SIEM Rule Optimization
Flip cardThe process of refining Security Information and Event Management (SIEM) correlation rules to reduce false positives, minimize alert fatigue, and improve the accuracy of threat detection.
- Involves adjusting thresholds and conditions.
- Aims to differentiate between normal and malicious events.
- Crucial for maintaining analyst effectiveness.
Memory trick: Too many alerts? Tune the rules!
Operational Threat Intelligence
Flip cardInformation about adversary Tactics, Techniques, and Procedures (TTPs), infrastructure, and ongoing campaigns.
- Helps understand 'how' an attack might occur.
- Often includes details on specific threat actors or groups.
- Used to develop defensive strategies and strengthen security controls.
Memory trick: Threat intelligence is like getting a scout report on the opposing team's playbook.
IP Security (IPsec)
Flip cardA suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.
- Operates at the Network Layer (Layer 3) of the OSI model.
- Provides confidentiality (encryption), integrity (hashing), and authenticity (digital signatures).
- Can be used in Tunnel mode (for VPNs) or Transport mode (for host-to-host encryption).
Memory trick: Securing internal chats is like whispering secrets in a crowded room.
SIEM Event Correlation
Flip cardSIEM Event Correlation is the process of analyzing multiple security events from various sources to identify relationships, patterns, and sequences that indicate a potential security threat or incident, especially those that individual events might not reveal.
- Links disparate events.
- Identifies complex attack patterns.
- Reduces false positives by increasing context.
Memory trick: Collect, Normalize, Correlate, Alert, Report.
IPsec
Flip cardA suite of protocols that provides cryptographic security for IP communications at the network layer (Layer 3).
- Offers authentication, integrity, and confidentiality.
- Used for Virtual Private Networks (VPNs) and securing host-to-host or network-to-network communication.
- Operates in two modes: Transport mode (host-to-host) and Tunnel mode (network-to-network).
Memory trick: IPsec: Securing IP packets, from network to network.
Inter-VLAN Routing
Flip cardThe process of forwarding network traffic from one Virtual Local Area Network (VLAN) to another through a Layer 3 device, such as a router or a Layer 3 switch.
- VLANs create separate broadcast domains.
- A router or Layer 3 switch is needed to route traffic between VLANs.
- Router-on-a-stick is a common method using one physical interface to route multiple VLANs.
Memory trick: VLANs are like separate rooms; you need a door to go between them.
Network Address Translation (NAT)
Flip cardA method of remapping one IP address space into another by modifying network address information in the IP header of packets while they are in transit.
- Translates private IP addresses to public IP addresses.
- Hides internal network topology from external networks.
- Conserves public IP addresses.
- Enhances network security by preventing direct external access to internal hosts.
Memory trick: NAT is like a Post Office for home addresses – it changes your internal address to a public one for external mail.
HTTP Port
Flip cardThe standard port number used for Hypertext Transfer Protocol (HTTP), which carries unencrypted web traffic.
- Port number is 80.
- Used for communication between web browsers and web servers.
- Traffic is unencrypted, making it vulnerable to eavesdropping.
Memory trick: Ports: Doors to network services.
Incident Response Flow
Flip cardThe structured process followed to manage and resolve a cybersecurity incident, typically starting with preparation and ending with post-incident activities.
- NIST SP 800-61 Rev. 2 defines a common framework.
- Phases: Preparation, Identification, Containment, Eradication, Recovery, Post-Incident Activity.
- Containment is critical after identification to limit impact.
Memory trick: Prepare, ID, Contain, Eradicate, Recover, Post-mortem (PICERL).
Common Network Ports
Flip cardSpecific numerical labels used to identify different services or applications running on a network device, enabling communication between them.
- Ports 0-1023 are well-known ports, assigned to common services.
- Ports 1024-49151 are registered ports, often used by specific applications.
- Ports 49152-65535 are dynamic/private ports, used for client-side connections.
Memory trick: Each application has its own door number to connect.