Domain 1 and Test Sudy 1 Flashcards
What are the three levels/types of authentication?
Type 1 - Something you know
Type 2 - Something you have
Type 3 - Something you are
What contract is based upon connecting disparate business networks together?
ISA
Interconnect service agreement.
Which authentication protocol is deprecated because of vulnerabilities?
LEAP
What is the Defined step in CMMI?
Processes characterized for the organization and is proactive.
What part of an SDN is responsible for the routing of data?
Control plane.
What part of an SDN determines how to handle incoming packets?
Data plane.
When discussing platforms, what is SoC?
System on a chip, a sophisticated, embedded system.
What are some regulatory standards?
GDPR, HIPAA, GLBA, SOX, PIPEDA, COPPA, FISMA
What are two advantages of high level programming languages?
Human readable syntax and it is easier to enforce coding standards because there is a specific order to that syntax.
What is PEAP?
A Microsoft favored package protected by TLS
Describe trademark
Trademark is the exclusive right to use symbols, words, colors, etc.
In contracts what is an OLA?
Operating level agreement. This defines the interdependent relationships in support of an SLA. Describes the responsibilities of each support group towards other support groups, and includes timeframes.
What CMMI level focuses on continuous process improvement?
Optimizing
What attack allowed Linux OS command injection?
Shellshock.
What is Initial in CMMI?
Processes are inconsistent, not organized, reactive, poorly managed.
What are the common tenets of privacy law?
NPSLARSD Notification Participation Scope Limitation Accuracy Retention Security Dissemniation
or DRSSLAPN Dissemination Retention Scope Security Limitation Accuracy Participation Notificiation
What is SASL?
Simple authentication and securtiy layer, a directory access protocol that can implement a wide variety of authentication methods.
Which authentication protocol uses a secure tunnel but does not distribute certificates?
EAP-TTLS
What are four industry standards?
ISO, CSA Star, Uptime Institute, SSAE 16
What are STRIDE, VAST, OCTAVE, and Trike?
Threat modeling techniques.
What are three main tenets of Clark-Wilson?
Prevent unauthorized users form making changes, prevent authorized users from making improper changes, and maintaining consistency.
What is Optimizing in CMMI?
Focus on continuous process improvement.
What CMMI level are processes characterized for the organization and is proactive?
Defined.
What CMMI level are processes measured and controlled?
Quantitatively managed.
What is MAD
Maximum allowable downtime - the maximum time until the business is non viable. Also known as MTD
What is an XML based protocol that can provision services and user accounts?
SPML
What is unit testing?
A method by which small, individual units and components are verified.
What is the difference between US Code and Code of Regulations?
Code of regulations is administrative law, where US Code are laws enacted by congress. Code of regulations are based on US Code.
Which directory access can implement a wide variety of authentication methods?
SASL
Simple authentication and security layer
What CMMI level is inconsistent processes, not organized, reactive, and poorly managed?
Initial
What is a fuzzing tool that offers both dumb and intelligent techniques?
Peach Fuzzer
What is EAP-FAST?
LEAP successor using a protected tunnel by Cisco.
What is Heartbleed?
An attack on OpenSSL that allows for the reading of memory.
What is scoping in risk management?
Selecting controls that are applicable to a given asset.
What is an embedded system that is quite sophisticated?
SoC or System on a Chip
What is the difference in cohesion and coupling?
Cohesion refers to methods that are similar and belong together. Coupling refers to the degree to which methods are dependent on other methods or modules.
In contracts, what is an MSA?
Master services agreement. An agreement that will govern future transactions.