Stuff from Exams I don't knw #4 Flashcards
Serverless Architecture
serverless architecture refers to a cloud computing model where the cloud provider manages the infrastructure, automatically scaling resources as needed. In this model, users don’t need to manage or provision servers; instead, they focus on writing code and deploying functions.
Risk Management Components
Risk assessment, risk response.
VXLAN
Virtual Extensible LAN - encapsulation protocol enabling switch created network segments to be stretched across subnets and geographical space.
Which component of IPSec allows multiple concurrent vpns?
ISAKMP
Familiarity
AKA ‘liking’ used as a social engineering principle. Attempts to exploit native trust in something familiar.
Temporal Protections - encryption
Process that marks encrypted traffic as valid for only a limited amount of time.
Used to prevent replay attacks.
Is Security Governance related to Acquisitions, divestitures, and governance committees?
Yes
RFC 6749
OAuth
Scoping
Removing controls from a suggested baseline of controls.
Service Ticket
In Kerberos authentication, a service ticket is a time-limited credential provided by the Ticket Granting Server (TGS) after a user presents a valid Ticket Granting Ticket (TGT). This service ticket allows the user to access a specific network service, serving as proof of the user’s authenticated identity for the requested service.
What is a Ticket Granting Ticket?
Kerberos ticket that allows authenticated users to request access to network services.
What is a Ticket Granting Server?
A Kerberos Ticket Granting Server (TGS) is a component in the Kerberos authentication system that issues service tickets to users after they have successfully obtained a Ticket Granting Ticket (TGT) from the Authentication Server (AS). The TGS plays a key role in facilitating secure access to various services within a network by providing users with tickets that authenticate their identity to those servic
Randomized masking
An anonymization technique. When done correctly cannot be reversed.
What best describes a Service Account?
Used to run applications.
Wired Extension
A single added WAP used to extend a wired network.
Enterprise Extension
Topology where wireless network is designed to support large envioronment with one SSID, numerous APs. Ofeten used to extend a wired network.
What port is used for SQL
1433
IR Mitigate phase
Contain Damage
IR Recovery phase
Restore system back to original state
IR Remediation phase
Root Cause Analysis, patch.
IR Response phase
Gather the IR team
Software test coverage that verifies every if statement in code has been executed under all ‘if’ and ‘else’ conditions?
Branch coverage
Split-response attack
Cache Poisoning
DCE and IDL??
DCOM, RPC, CORBA….
WiFi uses _______ for collision detection
CSMA/CA