Font size
WorksheetsSEC+ SY0-501 Terms for Study (choose all answers)
Total questions: 92
Worksheet time: 46mins
bcrypt
hashing
password storage
bit locker
encryption
Windows Based
Active Directory
LDAP (queries) - TCP 389
Kerboros (Authentication) - TCP/UDP 88
Windows Management
802.1x
Authentication
EAP Extension
LAN or Wi-Fi
Requires Authentication Server (RADIUS, Diameter, TACACS+)
AES
Advanced Encryption Standard
Rijndael
Strongest / go-to
Symmetric / Block Style
AUP
Acceptable Use Policy
Authorization
Digital Certificate
Authentication
Person or System
Public key that has been digitally signed
CHAP
Challenge-Handshake Authentication Protocol
PPP 3-way
Shared Secret
Content Switch
Load Balancing
Uses NAT
Example: Multiple Servers Appear to be Only 1 Server after Content Switch with 1 virtual IP Address
CRC
Cyclic Redundancy Check
Integrity check on Hash
vulnerable
XSRF
Cross Site Request Forgery
Attacks Trust
Web Applications
XSS
Cross Site Scripting
Attacks Trust
Web Applications
DAC
Discretionary Access Control
Authorization
DHE
Diffie-Helman Ephemeral
Encryption
Key Exchange
Asymmetric
DLP
Data Loss Prevention
Availability
Security Tech
DNS Poisoning
Attacks Integrity
DNS Cache - Layer 3
DOM
Document Object Model
Web Applications
DPI
Deep Packet Inspection
Firewall
Security Tech
DSA
Digital Signature Algorithym
Encryption
Asymmetric
Dual-Homed Server
DMZ
Bastion Host
2+ NICs
EAP
Extensible Authentication Protocol
Supports Authentication
PPP Extension
PEAP = Protected EAP thru TLS Tunnel
EFS
Encrypting File System
Encryption
NTFS - Selectable Data
FDE
Full Drive Encryption
Encrypts All Data
Federated Identity Management
Authentication
Sharing
FQDN
Fully Qualified Domain Name
Web Applications
Fuzzing
Vulnerability Assessment
Can be either Malicious or NON-Malicious
GPG
GNU Privacy Guard
Encryption
OpenPGP
Security Tech
Hashing
Integrity
Highest Bits = Most Secure
Strongest to Weakest: SHA-2, SHA-3, RIPEMD, SHA-1, MD5, MD4
Salt for added Strength
HMAC
Keyed-Hash Message Authentication Code
Symmetric encryption
Verifies integrity and authenticity, but not perfect.
Hosts File
Operating System
Maps Hostnames to IP Addresses
ICMP
Internet Control Message Protocol
Networking
Example: Echo Request / Ping ...can use for DoS attack
ICS & SCADA
Industrical Control System
Supervisory Control and Data Acquisition
Industrial Networking Systems
IV
Initialization Vector
Encryption
Kerberos
SSO Authentication
TCP / UDP 88
Key Distribution Center (KDC) distributes Tickets
Authentication Server (AS) gives TGT
Ticket-Granting Service (TGS) validates TGT
L2TP
Layer 2 Tunneling Protocol
Networking / VPN
Not encrypted by itself
LDAP
Lightweight Directory Access Protocol
Authentication
Examples: Active Directory, Kerberos
Port 389
LDAPS
Secure Lightweight Directory Access Protocol
SSL or TLS
Port 636
Large attack surface
LEAP
Lightweight Extensible Authentication Protocol
CISCO product
802.11 or 802.1X
Replaced by EAP-FAST (EAP Flexible Authentication by Secure Tunneling)
MAC - not address...
Mandatory Access Control
Authorization
Think Military - Secret gives you access to secret files
Top Secret gives access to top secret files
MD5
Hashing
128 bit
obsolete for todays use
MDM
Mobile Device Management
Security Tech for mobile devices
NAC
Network Access Control
Security control for new clients
Examples: Guest network for WAP, Captive portal webpage or Accepting an AUP (Acceptable Use Policy)
May include a posture assessment, to verify BYOD meets security baseline
May require an agent to run on client machine [persistent (runs at startup and keeps running) or dissolvable (during login only)]
Agentless is another option.
NAT
Network Address Translation
Replaces Header IP Addresses so data can go from two different networks (internal to internal, or internal to external) or vice versa
Can allow two different network types to communicate (IPv4 and IPv6 as an example)
Done by NAT Router - Level 3
Could be one-to-one (not shared public IP...not necessarily static) or one-to-many (Shared public IP)
SNAT
Source Network Address Translation
Generally for internal networks only
Not "Static" NAT, could still be dynamic addresses
DNAT
Destination Network Address Translation
Generally for traffic from external systems
Not "Dynamic" NAT...address could still be static
PAT
Port Address Translation
same as NAT, just adds Ports
Non-Repudiation
Authentication
Digital Signatures
SLA
Service-Level Agreement - Business Stuff
Supplemented by Operational-Level Agreement (OLA) to further define relationships
PBKDF2
Password-based key derivation function 2
hashing
password storage
PEAP
Protected Extensible Authentication Protocol (EAP)
PPP (Point-to-Point Protocol) Authentication
TLS
PGP
Pretty Good Privacy
Trust Model
You trust me and I trust him so you can trust him too.
PPP
Point-to-Point Protocol
Used for WAN or VPN IP traffic
Authentication with: PAP, CHAP, MS-CHAP, or EAP
VPN Technogies
PPTP (Point-to-Point Tunneling Protocol)
GRE (Generic Routing Encapsulation) - just tunneling
L2TP / IPsec (RADIUS or TACACS+ and IPsec)
SSL/TLS (Open VPN or Microsoft's SSTP)
SSH
Protocol Anayzer
Packet Sniffer with more functionalilty
Malicious or Non-Malicious
Monitoring or Vulnerability Scanning
IPsec
Often for VPNs
Provides confidentiality, integrity, and authentication
IKE (Internet Key Exchange) - Secures Connection
AH (Authentication Header) - Provides Integrity
ESP (Encapsulating Security Payload) - Encrypts (Confidentiality)
Proxy Server
Content Caching / Load Balancing
Intermediary between a client and a server (Forward Proxy) or vice versa (Reverse Proxy)
Content Filtering
Anonymity
Load Balancing
Controls Bandwidth & Utilization
Helps with Redundancy & Availability
Content Switch - Uses NAT to split server requests
PSK
Pre-Shared Key
Wireless
Authentication
RADIUS
Remote Authentication Dial-In User Service
UDP Based
Client Request >
Network Access Server (NAS) >
Radius / Authentication Server for Authentication / Authorization.
802.1X with EAP, common with Wi-Fi
TACACS+
Terminal Access Controller Access Control System
TCP Based
CISCO Proprietary
Supports non-IP protocols
Diameter
RADIUS successor
twice as good as radius (pun)
Used in 4G Carrier Networks
Authentication
RAS
Remote Access Service
Windows Server
Authentication Protocol
Routing Added to make it RRAS (Routing and Remote Access Service)
RAT
Remote Access Trojan
Backdoor for Persistence
Port Open and "Listening"
Full Control of Computer
RBAC
Role or Rule Based Access Control
Authorization
RC4 or RC6
Rivest Cipher / Ron's Code
RC4 = Block, RC6 = Stream
Symmetric Encryption
Symmetric Encryption Standards (Block Style)
AES - Rijndael ---Strongest and standard
Twofish - better blowfish
Blowfish - first strong cipher in public domain
Serpent - placed second to AES
RCs and CAST
Asymmetric Algorithms (Public Key Cyrptography)
1 key shared with public, 1 key kept private.
---Used in KEY EXCHANGE---
RSA - 2 Prime numbers
DSA - NIST Standard
ECC - Mathematical / Elliptical Curves
Diffie-Hellman (DH or DHE) - First openly published public-key
SFTP
SSH File Transfer Protocol
Resource Sharing
TCP Port 22, same as SSH
SIEM
Security Information Event Management
Logs / Security Tool
Alerts
SOAP
Simple Object Access Protocol
Cloud
Mobile
SPI
Stateful Packet Inspection
Used by Stateful Firewall
Tracks Conversations
Good, but not as effective as DPI (Deep Packet Inspection)
TKIP
Temporal Key Integrity Protocol
Encryption
Wireless
TLS
Transport Layer Security
Encryption / Confidentiality
Stronger than SSL
UTM
Unified Threat Management
Multiple tech items in one
Security Appliance
WAF
Web-Application Firewall
Protect against web server and application attacks such as buffer overflows, SQL injections, XSS
WEP
Wired Equivalent Privacy
Wireless Encryption
Useless and weak...replaced by WPA
WPA
Wireless Protected Access
WPA2 is strongest
Wireless Encryption
X.509 Standard
Certificates
PKI - Public Key Infrastructure
XML
eXtensible Markup Language
Networking / Application Language
Can be exploited with injection on web applications
CRL
Certificate Revocation List
Downloaded list of revoked certificates
Just the certificate S/N, not the whole Cert.
CSR
Certificate Signing Request
Given to CA to request a SSL certificate
Incident Response (IR) Process
- Preparation - Have tools and training in place before.
- Identification - Clearly detect when, nature, and severity.
- Containment - Quarantine (stop damage or observe in containment.
- Investigation - Identify the precise effects and root cause.
- Eradication - Eliminate the root cause of the incident and prevent immediate recurrence.
- Recovery - Restore services, return to baseline state
- Lessons Learned - Review and take actions for future
Goal is to assess damage done and minimize losses.
RAID
RAID 0 - Disk Striping (high speed, no backup)
RAID 1 - Mirroring (backup)
RAID 5 - Striping on at least 3 drives with parity
RAID 6 - Same as 5, but 4 drives with 2x parity
RAID 10 - Raid 1+0, Striping and mirroring
Pharming
Combination of Farming and Phishing
Application of DNS poisoning
Host Files and DN Servers are most vulnerable.
Phishing
Client-Side Attack
Conceal identity of fake URL or website.
Could come from link in email.
Goal is to obtain information such as usernames, passwords, and credit-card data.
Certificate Types
Limited Purpose - CA specifies what purposes a cert should and should not be used for
Email - Sending and receiving S/MIME emails
Code Signing - Signing an executable file to authenticate its source and guarantee its integrity
SAN (Subject Alternative Name) - Covers multiple domains
Wildcard - Multi-domain cert that can cover any number of subdomains within a single domain.
EV (Extended Validation) - Stricter identity validation - Stronger proof against phishing websites.
SRTP / RTP
Secure Real-Time Transfer Protocol
TCP / UDP 554
Encrypted Streaming Audio or Video Data
VOIP
Key / Certificate Pinning
Protects against fraudulent certificates
Copies / Hashes of a known server certificate or public key are stored locally and verified when connecting to that server.
Static Pinning - high traffic sites pinned by browser
Dynamic pinning - if supported, every server pins a key so that it can be verified next time the client reaches back out to that server.
Continuity Planning
BCP - Business Continuity Plan
Risk Analysis, Controls to mitigate, procedures for restoring service
BIA - Business Impact Analysis
Identifies critical business functions and how long they can be down
DRP - Disaster Recovery Plan
Technical procedures for restoring services and ops after major disruptions
COOP - Continuity of Ops Plan
Procedures for moving ops to temporary site during disaster recovery
Redundancy
Backup Power - UPS
RAID - for data loss
Load Balancing - not just for performance
Clustering - Servers are "aware" of each other and can work together.
Alternate Sites - Disaster Recovery
Hot Spare - Component powered on ready to go
Cold Spare - Something sitting on a shelf, could still be hot-swappable
Hot Site - Fully operational site, can be up in hours or less
Cold site - No hardware setup in advance...just power, HVAC, and network connectivity
Warm site - Mix of hot and cold
URL Hijacking
Typo-Squatting - misspelling of the legitimate site
URL Hijacking - Takes advantage of a similar name (comptia.com instead of comptia.org)
Clickjacking - Hidden clickable content overlay on normal things. Users click on them without knowing.
