Bucket List 1 Flashcards
What are some types of key escrow?
Dual knowledge, split key, dual key
What is OCSP?
Online certificate status protocol
What is the access controls NIST policy?
800-192
What is Public/private key, slow, subject to mitm, can provide CI/A
Asymmetric Encryption
What does a detective security control do?
Aids in discovery
What is a CA with PKI?
Certificate Authority, trusted third party, root authority
What is an unauthorized wireless router?
Rogue AP
Name the wireless authentication types and their encryption standards
WEP+RC4, WPA1+TKIP, WPA2+AES-CCMP
How do you secure DNS?
DNSSEC
Integrity, detects changes, non-reversible
Hashing
What is often the biggest threat?
Disgruntled employee, personnel
What is a non-water fire suppression chemical?
FM-200
What is the certificate standard
X.509v3
Who creates data, is accountable for the data?
Data owner
What is the credential management NIST policy?
800-63
In risk, what is AV?
Asset value
What is the formula for a single loss?
AV * EF, asset value times exposure factor
What security control will stop an event?
Preventative
What does AUP stand for?
Acceptable use policy
What does JOA stand for?
Joint operating agreement
In risk, what is ALE?
Annual loss expectancy
What is multiple defenses called
Defense in depth
What type of testing is external and potentially harmful
penetration testing
What are the SNMP passwords and what are they called?
Public/Private and community strings