SEC+ Acronyms Flashcards
Learn Acronyms
FIM
File Integrity Monitoring [detects if files have been altered]
NAC
Network Access Control [used to control access based on users and their devices]
SPF
Sender Policy Framework [used to prevent email spoofing and phishing attacks]
MFA
Multi-Factor Authentication [used to protects accounts in case another factor is compromised]
Logic Bomb
[code inserted into app or script set to execute in response to an event]
RAT
Remote Access Trojan [malware that lets an attacker access a system remotely]
Evil Twin Attack
targets Wi-Fi networks by mimicking an existing network
Rootkit
Malware that gives a user administrative access to a system
DMZ
Demilitarized Zone [a screen subnet on a network that contains systems accessible by clients or other networks on the Internet]
LAN
Local Area Network
VPN
Virtual Private Network
Honeynets
Networks meant to distract attackers from legitimate networks
Waterfall
methodology that includes multiple states, all of which feed into each other
Scrum
a daily meeting
ESP
Encapsulating Security Payload [used to provide encryption of data and provide confidentiality]
AH
Authentication Header [allows each of the hosts in the IPSec to authenticate with each other before exchanging data]
IPS
Intrusion Prevention System
Static Code Analysis
testing method in which the app is not run but rather checked line by line.
Fuzz Testing
random characters are input into a computer program to find vulnerabilities
Dynamic Code Analysis
testing program while they’re running
AAA
Authentication, Authorization and Accounting
WPA3
used to encrypt Wi-Fi traffic
WEP
outdated encryption method for Wi-Fi
RADIUS
protocol for authentication, authorization and accounting
EAP-TLS
Extensible Authentication Protocol-Transport Layer Security [widely used authentication protocol in Wi-Fi networks]
Risk Transfer
transferring risk (entirely or partially) to another entity
Risk Mitigation
applying controls for a risk
Risk Acceptance
not taking any additional actions to mitigate a risk
MTTR
Mean Time To Repair [the time needed to repair a failed device]
MTTF
Mean Time To Failure [measure of reliability for devices that can’t be repaired]
ARO
Annual Rate of Occurrence [number of times an incident occurs within a year]