Windows Security Flashcards
Windows local sign in
Uses LSA (Local Security Authority)
Aka interactive login
SAM database
Security Accounts Manager database
Stores credentials for local login
Network sign in
Uses Kerberos
TGT system
Remote sign in
Uses VPN or web portal
SSL/TLS
Windows hello
Facial recognition
Fingerprint
Pin (stored on tpm and encrypted)
SSO authentication
One sign on authenticates multiple services or apps
(used in a domain or cloud)
Local account
Only exists on one computer
Stored in SAM (security account manager)
Inside of HKEY_LOCAL_MACHINE registry
Microsoft account
Created online
Can be used to sign in to multiple devices
Domain account
Works like a local account but stored inside of Active Directory
4 basic user groups in windows
User
Admin
Guest (disabled)
Power
UAC
User account control
Windows feature to protect against malicious programs
Admins run programs with user permissions so programs don’t get root privileges
(EFS) encrypting file system
NTFS feature (data at rest)
Single file or folder encryption
BitLocker and BitLocker to go
Full disk encryption
Removable encryption
NTFS file permissions
(Security and share tabs)
Can be set for local and network file and folder
Can assign users or groups
Implicit and explicit permissions
Viruses and malware are caught using signature patterns called..
Definitions