ACRONYMS Flashcards

1
Q

CIFS

A

Common Internet File System = Samba

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

111/tcp

A

RPC port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

LLMNR

A

Link Local Multicast Name Resolution = host name to IP resolution Windows

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BPDU

A

Bridge Protocol Data Unit = update frames multicast between switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

TTY

A

terminal shell

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

WAF

A

Web Application Firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SET

A

Social Engineering Toolkit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

BeEF

A

Browser Exploitation Framework = social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

XOR

A

Exclusive OR = encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

TKIP

A

Temporal Key Integrity Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

OSINT

A

open source intelligence gathering –> method of searching public records, social media, google etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

WAF

A

web application firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

ICS

A

industrial control systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

DAR

A

data at rest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SAST

A

static application security testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ICS

A

Industrial Control System

17
Q

CAPEC

A

MITRE’s Common Attack Pattern Enumeration & Classification

provides a dictionary of known patterns of attack

capec.mitre.org

18
Q

NVD

A

National Vulnerability Database

Maintained by NIST

Full Disclosure is a public forum.

19
Q

SoW

A

Statement of Work

plans the project-specific work to be done.

identifies the cope of work and testing to be completed.

20
Q

OSINT

A

collection and analysis of data gathered from open sources

21
Q

SCADA

A

Supervisory Control And Data Acquisition (SCADA) systems

22
Q

DAR

A

data at rest

23
Q

SAST

A

static application security testing

Static application security testing can be embedded directly within the development environment. This allows developers to track their code continuously. Scrum masters and product owners will also regulate secure coding best practices. This leads to rapid vulnerability reduction and improved code integrity and security.

24
Q

DAST

A

Dynamic Application Security Testing

focuses on testing the application in run-time, and this is usually done using vulnerability scanners. While SAST focuses on creating and writing secure code, DAST focuses more on finding security flaws in the deployed application.

25
Q

SOAP

A

Simple Object Access Protocol

a Connection or an interface between the web services or a client and web service. SOAP is operated with application layer protocols like HTTP, SMTP or even with the TCP for message transmission.

created from WSDL

26
Q

WSDL

A

Web Service Description Language

XML based.

SOAP.

27
Q

REST

A

representational state transfer

replacing SOAP in web applications

28
Q

WADL

A

web application description language

XML based.

REST

29
Q

XSD

A

XLM schema definition

30
Q

LSASS

A

Local Security Authority Subsystem Service

windows security policy enforcement
verifies users at login

31
Q

SPN

A

service principle names

are used to uniquely identify each instance of a Windows service

32
Q

MSA

A

master service agreement - addresses high-level requirements for contract