ACRONYMS Flashcards

1
Q

CIFS

A

Common Internet File System = Samba

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

111/tcp

A

RPC port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

LLMNR

A

Link Local Multicast Name Resolution = host name to IP resolution Windows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BPDU

A

Bridge Protocol Data Unit = update frames multicast between switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

TTY

A

terminal shell

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

WAF

A

Web Application Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SET

A

Social Engineering Toolkit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

BeEF

A

Browser Exploitation Framework = social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

XOR

A

Exclusive OR = encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

TKIP

A

Temporal Key Integrity Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

OSINT

A

open source intelligence gathering –> method of searching public records, social media, google etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

WAF

A

web application firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ICS

A

industrial control systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

DAR

A

data at rest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SAST

A

static application security testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ICS

A

Industrial Control System

17
Q

CAPEC

A

MITRE’s Common Attack Pattern Enumeration & Classification

provides a dictionary of known patterns of attack

capec.mitre.org

18
Q

NVD

A

National Vulnerability Database

Maintained by NIST

Full Disclosure is a public forum.

19
Q

SoW

A

Statement of Work

plans the project-specific work to be done.

identifies the cope of work and testing to be completed.

20
Q

OSINT

A

collection and analysis of data gathered from open sources

21
Q

SCADA

A

Supervisory Control And Data Acquisition (SCADA) systems

22
Q

DAR

A

data at rest

23
Q

SAST

A

static application security testing

Static application security testing can be embedded directly within the development environment. This allows developers to track their code continuously. Scrum masters and product owners will also regulate secure coding best practices. This leads to rapid vulnerability reduction and improved code integrity and security.

24
Q

DAST

A

Dynamic Application Security Testing

focuses on testing the application in run-time, and this is usually done using vulnerability scanners. While SAST focuses on creating and writing secure code, DAST focuses more on finding security flaws in the deployed application.

25
SOAP
Simple Object Access Protocol a Connection or an interface between the web services or a client and web service. SOAP is operated with application layer protocols like HTTP, SMTP or even with the TCP for message transmission. created from WSDL
26
WSDL
Web Service Description Language XML based. SOAP.
27
REST
representational state transfer replacing SOAP in web applications
28
WADL
web application description language XML based. REST
29
XSD
XLM schema definition
30
LSASS
Local Security Authority Subsystem Service windows security policy enforcement verifies users at login
31
SPN
service principle names are used to uniquely identify each instance of a Windows service
32
MSA
master service agreement - addresses high-level requirements for contract