Memorization Deck Flashcards
What are the contents of an X.509 v3 digital certificate?
Owners public key
Owners distinguished name
CA’s distinguished name
Date issued
Expiration date
Version number of certificate (current version is X.509 v3)
Serial number assigned by CA (no two certs have the same number)
X.509 v2 certs also contain “Issuer Identifier and Subject Identifier”
How does PGP differ from X.509?
PGP relies on a web of trust where anyone can sign and attest to the validity of others’ certificates.
X.509 relies on a hierarchical system of certificate authorities.
What are the secure protocols?
SSH (Symmetric or Asymmetric) SFTP (SSH) FTPS (TLS) NTPsec HTTPS (TLS) S/MIME (TLS) IPsec SSL/TLS LDAPS SRTP (AES & HMAC-SHA1)
What does DNSsec provide?
Authenticates the DNS server and provides data integrity. It does not provide privacy.
What services does a CASB provide?
Security policies and compliance regulations such as:
Visibility (Access only by authorized users)
Compliance (Regulations such as HIPPA, PCI)
Threat Prevention (Access and malware protection)
Data Security (DLP and Encryption)
How do you protect a web applications, API’s and JSON?
Using a Next-Gen Secure Web Gateway
What does a SWG provide? Where does it sit on the network?
URL Filtering Application Control DLP Anti-virus HTTPS Inspection
Edge of the network.
State the Order of Volatility
CPU registers, CPU cache Router table, ARP cache, process table, kernel stats, memory Temporary file systems Disk Remote logging and monitoring Physical configuration, network topology Archival media