security Flashcards

1
Q

IDS

A
intrusion detection system
PASSIVE
Signature based, statistics!!!!
reports issues to user
doesn't block user
GuardDuty intrusion detection system on 
WORKLOAD
ACCOUNTS
DATA
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

IPS

A
Intrusion prevention system
ACTION PORTION
Put in quarantine, or drop it. 
can log text, and send report.
IDS(guardduty) , cloudwatch, lambda
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Asymmetric encryption

A

have public and private data
Public (ENCRYPT)
Private (PRIVATE)

Exchange Public key, use another’s public key to sign and encrypt a message, this others key will encrypt it. original sender will send the encrypted message to receiver. only receiver can decrypt

HTTPS
BITCOIN
SSH
PTP emails

“sample”

public key is location of mailbox, people can use public key to place mail into the box, the mail is then locked away and can only be accessed by the owners private key. Allows people to deposit information without being able to access it, allows owner to retain exclusive access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Symmetric encryption

A

Same key is used to unlock and lock key, very simple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

WAF

A
normal firewall is layer 4, blocks ports
waf defends against
ddos - RATE LIMITING ON IP ADDRESS
IP SPOOFING?
SQL injection - get data, place data
Cross scripting CSS- inject code or scripts into application of website
malware etc
How well did you know this?
1
Not at all
2
3
4
5
Perfectly