General Security Flashcards
4 Phases of DITSCAP and NIACAP accreditation
- Definition”
A weakness in a system which might be exploited
Vulnerability
ALE
Annualized Loss Expectancy
Also called a maintenance hook
Trap door
An event that can cause harm to a system and create a loss of C, I , A
Threat
Are SSL and TLS compatible?
no
Are SSL sessions stateful or stateless?
stateful
ARO
Annualized Rate of Occurence
At the Network Interface layer, what is the packet of information placed on the wire known as?
a frame
At what OSI layer (and above) must networked computers share a common protocol?
data link and above
Attack that exploits difference in time when a security control is applied and a service is used
TOC/TOU attack
Biba, Clark Wilson, and Non?Interference models cover what aspect of security
Integrity
Combination of ITSEC, TCSEC, and Canada’s CTCPEC
Common Criteria
Consolidation of power should not be allowed in a secure system, this is called
Separation (or segregation) of duties
Design where a component failure allows the system to continue to function
Fault?tolerant
Design where a failure causes non?critical processes to terminate, and system runs in a degraded state
Fail?soft or Resilient
Design where a failure causes termination of processes to protect the system from compromise
Fail?safe
Design where a failure causes the system to use backup spare components to compensate for failed ones
Fail?over
Do hashing algorithms protect files from unauthorized viewing?
no, only verify files have not been changed
Does DSS use symmetric or asymmetric keys?
asymmetric
Does L2TP require IP connectivity?
no
Does PPTP require IP connectivity?
yes
Does TLS use the same ports for encrypted and unencrypted data?
no
EF
Exposure Factor