Font size
WorksheetsCOMPTIA 02
Total questions: 132
Worksheet time: 1hrs 7mins
is a symmetric key block cipher that operates on 128-bit blocks and supports key sizes of 128, 192, and 256 bits.
Serpent
AWS
IDEA
RC4
ChaCha20
is a symmetric key block cipher that operates on 128-bit blocks and supports key sizes of 128, 192, and 256 bits. It is a joint development by NTT and Mitsubishi Electric Corporation.
Serpent
Camellia
IDEA
RC4
ChaCha20
is a symmetric key block cipher that operates on 64-bit blocks and supports key sizes of 128 bits.
Serpent
Camellia
IDEA
RC4
ChaCha20
is a stream cipher known for its simplicity and speed. It operates on variable-length keys and generates a keystream that is XORed with the plaintext to produce the ciphertext.
Serpent
Camellia
IDEA
RC4
ChaCha20
Is a stream cipher that is widely used in applications such as TLS. It operates on 512-bit blocks and supports key sizes of 128, 256 bits.
Serpent
Camellia
IDEA
RC4
ChaCha20
is one of the most widely used asymmetric encryption algorithms. It relies on the difficulty of factoring large prime numbers. The algorithm generates a public-private key pair, where the public key is used for encryption, and the private key is used for decryption. is often employed in secure email communication, SSL/TLS protocols, digital signatures, and key exchange.
RSA
Diffie-Hellman (DH)
Elliptic Curve Cryptography (ECC):
Digital Signature Algorithm (DSA):
is a key exchange algorithm that allows two parties to establish a shared secret key over an insecure communication channel. It enables secure communication even if an eavesdropper intercepts the exchange. is used in various protocols such as SSL/TLS, IPsec, and secure email.
RSA
Diffie-Hellman (DH)
Elliptic Curve Cryptography (ECC):
Digital Signature Algorithm (DSA):
is a family of asymmetric algorithms based on the mathematics of elliptic curves over finite fields.provides the same level of security as RSA but with smaller key sizes, making it computationally efficient. It is commonly used in resource-constrained environments such as mobile devices and Internet of Things (IoT) devices, is utilized in SSL/TLS, digital signatures, and secure key exchange.
RSA
Diffie-Hellman (DH)
Elliptic Curve Cryptography (ECC):
Digital Signature Algorithm (DSA):
is a widely used algorithm for creating and verifying digital signatures. It provides authentication, integrity, and non-repudiation of digital documents.uses the mathematics of modular exponentiation and discrete logarithms. It is commonly used in digital certificates, secure email, and secure file transfers.
RSA
Diffie-Hellman (DH)
Elliptic Curve Cryptography (ECC):
Digital Signature Algorithm (DSA):
ensures that you are communicating with the correct website or service
RSA
DNSSEC
Elliptic Curve Cryptography (ECC):
Digital Signature Algorithm (DSA):
was the original security protocol used for wireless networks. However, it is now considered weak and easily compromised. Its use is strongly discouraged.
WEP
WPA
WPA2
WPA3
EAP
A is an improvement over WEP and provides stronger security. It uses TKIP (Temporal Key Integrity Protocol) for encryption and includes authentication mechanisms like WPA-PSK (Pre-Shared Key) and WPA-Enterprise, using an authentication server
WEP
WPA
WPA2
WPA3
EAP
s the current standard for wireless network security. It uses the AES (Advanced Encryption Standard) algorithm for encryption and offers stronger security than WPA. It supports both WPA2-PSK and WPA2-Enterprise authentication modes
WEP
WPA
WPA2
WPA3
EAP
is the latest iteration of Wi-Fi security protocols. It enhances security by introducing new features like SAE (Simultaneous Authentication of Equals) and stronger encryption methods
WEP
WPA
WPA2
WPA3
EAP
is an authentication framework used in wireless networks. It allows for different authentication methods to be used, such as EAP-TLS (Transport Layer Security), EAP-TTLS (Tunneled TLS),
WEP
WPA
WPA2
WPA3
EAP
(Flexible Authentication via Secure Tunneling
PEAP
WPA
WPA2
WPA3
EAP
rules or protocols for secure connections over a network
IPsec
AH
ESP
Transport mode
Transport mode
authenticates the origin of packets
IPsec
AH
ESP
Transport mode
Transport mode
provides confidentiality, integrity, and authentication
IPsec
AH
ESP
Transport mode
only encrypts payload
IPsec
AH
ESP
Transport mode
- entire packet encryption
Tunnel mode
AH
ESP
Transport mode
one-way incoming mail protocol that downloads emails onto a local device
Tunnel mode
POP3
ESP
Transport mode
a security feature on network switches that mitigates the risk of rogue DHCP serves and unauthorized network access
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
- security solutions designed to detect and respond to threats and malicious activities on endpoints
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
acts as the middle man between an organization’s on prem infrastructure and cloud, to ensure that both are secure
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
provides organizations with visibility, control, and protection for web traffic.
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
- network protocol that focuses on AAA, and managing user access to network resources
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
provides organizations with visibility, control, and protection for web traffic.
DHCP snooping
EDR (Endpoint Detection and Response)
SWG (Secure Web Gateway)
CASB (Cloud Access Security Broker)
RADIUS (Remote Authentication Dial-In User Service)
one-way incoming mail protocol that downloads emails onto a local device
Tunnel mode
POP3
ESP
Transport mode
facilitates the collection of information about devices on a network
SNMP
SMTP
TCP
MAC
facilitates the collection of information about devices on a network
SNMP
SMTP
TCP
MAC
a TCP/IP protocol used in sending and receiving mail
SNMP
SMTP
TCP
MAC
is responsible for delivery, while IP is responsible for the correct address to which the data is sent
SNMP
SMTP
TCP
MAC
- high level of access control security that requires all access to be predefined based on system classification, configuration, and authentication
SNMP
SMTP
TCP
MAC
- vulnerability assessment tool that assesses vulnerabilities in computer networks, systems, and apps
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
networking tool that manages network connections
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
- vulnerability assessment tool that assesses vulnerabilities in computer networks, systems, and apps
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
- a suite of network security tools for assessing the security of Wi-Fi networks, capturing network packets, and conducting various attacks on Wi=Fi encryption protocols
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
are cryptographic hash functions, which means they take any length input and produce a fixed-size output called a hash value or digest
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
wireless security protocol designed to secure Wi-Fi networks, more secure than WEP
Nessus
Netcat
Aircrack-ng
MD5 and SHA-1
WPA
a command line tool that allows you to trace the route a network packet takes from your computer to a destination IP address or hostname
tracert
GLBA
SOX
DHCP scope
federal law that requires financial institutions to share how they share and protect customer’s private information
tracert
GLBA
SOX
DHCP scope
- U.S. federal law that sets requirements for all US public company boards
tracert
GLBA
SOX
DHCP scope
- the range of IP addresses that are able to be assigned to devices within a network
tracert
GLBA
SOX
DHCP scope
technology that provides hardware-based encryption to protect data that is stored on the drive
Opal - SED
MTBF
MTTR
MTTF
RTO
- measure to estimate the average time between the failures of a system
Opal - SED
MTBF
MTTR
MTTF
RTO
the amount of time it’ll take to repair a system
Opal - SED
MTBF
MTTR
MTTF
RTO
the amount of time until a system is expected to fail
Opal - SED
MTBF
MTTR
MTTF
RTO
the maximum amount of time that is tolerable to have the systems down
Opal - SED
MTBF
MTTR
MTTF
RTO
- an authentication framework that controls access to a network, ensures that only authorized devices are granted access to the network resources
802.1X -
DAC (Discretionary Access Control) -
access to a resource is outlined by the owner
802.1X -
DAC (Discretionary Access Control) -
MDM strategy where organizations provide devices, while allowing limited personal use
COPE (Corporate Owned Personally-Enabled)
VDI (Virtual Desktop Infrastructure)
DNS Sinkhole
Dump
POST (Power-On Self Test) -
- technology that allows OS and apps to be hosted and delivered to end-user devices over a network
COPE (Corporate Owned Personally-Enabled)
VDI (Virtual Desktop Infrastructure)
DNS Sinkhole
Dump
POST (Power-On Self Test) -
manipulating DNS responses to redirect traffic from malicious domains to a non-existent or controlled destination
COPE (Corporate Owned Personally-Enabled)
VDI (Virtual Desktop Infrastructure)
DNS Sinkhole
Dump
POST (Power-On Self Test) -
the process of capturing the contents inside of a computer’s RAM at a specific moment
COPE (Corporate Owned Personally-Enabled)
VDI (Virtual Desktop Infrastructure)
DNS Sinkhole
Dump
POST (Power-On Self Test) -
- tests performed by a computer system to verify hardware components are functioning properly during start up
COPE (Corporate Owned Personally-Enabled)
VDI (Virtual Desktop Infrastructure)
DNS Sinkhole
Dump
POST (Power-On Self Test) -
- a network authentication protocol that provides secure authentication for client-server applications over an untrusted network, helps prevent eavesdropping, replay attacks, and unauthorized access
Kerberos
HSM
Screened subnet or DMZ
VPN concentrator or VPN gateway -
IMAP
tamper-resistant hardware device designed for secure key management, used to safeguard sensitive information like cryptography keys, certificates, and other critical data
Kerberos
HSM
Screened subnet or DMZ
VPN concentrator or VPN gateway -
IMAP
- a network architecture design that separates the internal network from the internet (like a network air gap)
Kerberos
HSM
Screened subnet or DMZ
VPN concentrator or VPN gateway -
IMAP
- networking device that enables secure remote access to a private network over the internet
Kerberos
HSM
Screened subnet or DMZ
VPN concentrator or VPN gateway -
IMAP
- email retrieval protocol that allows clients to manage emails stored on the mail server
Kerberos
HSM
Screened subnet or DMZ
VPN concentrator or VPN gateway -
IMAP
a standard for securing email messages with encryption and digital signatures
S/MIME -
Data Custodian -
ALE
SLE
ARO
a team or individual responsible for the storage, management, and protection of data
S/MIME -
Data Custodian -
ALE
SLE
ARO
the expected financial impact of a specific risk over one year
S/MIME -
Data Custodian -
ALE
SLE
ARO
the expected loss of revenue from a specific risk
S/MIME -
Data Custodian -
ALE
SLE
ARO
the frequency of the specific event occurring within a one-year period
S/MIME -
Data Custodian -
ALE
SLE
ARO
- a process that involves measuring and recording the integrity of various boot components during startup like firmware, bootloader, OS kernel by the TPM
Measured
Trusted
Secure
verifies the measured components’ integrity against a known set of trusted values
Measured
Trusted
Secure
security feature that prevents the execution of malicious software during the boot process
Measured
Trusted
Secure
data protection and privacy for individuals in the EU
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
- a standard for protecting credit cards
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
data protection and privacy for individuals in the EU
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
- security controls and best practices frameworks for secure cloud computing environments
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
- U.S. federal law framework that protects gov. info, ops, and assets
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
requires financial institutions to explain how they share and protect their customer’s private information
GDPR (General Data Protection Regulation)
PCI DSS (Payment Card Industry Data Security Standard)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
US federal law that sets requirements for US public company boards, management, and public accounting firms
GDPR (General Data Protection Regulation)
SOX (Sarbanes-Oxley)
CSA CCM (Cloud Security Alliance Cloud Controls Matrix) -
FISMA (Federal Information Security Management Act)
GLBA (Gramm-Leach-Bliley Act)
This standard specifies the requirements for an information security management system (ISMS). It provides a framework for implementing and managing security controls to protect information assets.
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
: This standard provides a code of practice for information security controls. It offers guidance on selecting, implementing, and managing security controls to address specific risks identified in an organization. PII
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
This standard focuses on information security risk management. It provides guidelines for identifying, assessing, and treating information security risks in a systematic and consistent manner.
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
This standard offers specific guidelines for information security controls in cloud computing environments. It addresses security considerations related to the use of cloud services and provides guidance for both cloud service providers and cloud customers
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
This standard focuses on information security risk management. It provides guidelines for identifying, assessing, and treating information security risks in a systematic and consistent manner.
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
This standard focuses on privacy protection in public cloud computing environments. It provides guidelines for the implementation of controls to protect personal data in cloud-based services.
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
This standard addresses business continuity management for information and communication technology (ICT) systems. It provides guidelines for planning, establishing, implementing, operating, monitoring, reviewing, and maintaining ICT continuity.This standard addresses business continuity management for information and communication technology (ICT) systems. It provides guidelines for planning, establishing, implementing, operating, monitoring, reviewing, and maintaining ICT continuity.
ISO/IEC 27031
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 27017
ISO/IEC 27018:
- command used to display the last part of a file or stream
It stars with letter T
(a)
an open source software library all about cryptography
Starts with O
(a)
tool that performs port scanning or reconnaissance
scanless
grep
Nmap
curl
a command that is used for searching and filtering text files or streams based on patterns or regular expressions
scanless
grep
Nmap
curl
open source network scanning tool, identifies open ports, and gathers information about hosts and services that are running in a network
scanless
grep
Nmap
curl
command line tool that is used for making HTTP requests and interacting with web servers, can be used to download files, send data to web servers, and test APIs
scanless
grep
Nmap
curl
command used to display the first few lines of a file or beginning of a stream
head
tracert
netstat
netcat
dig
command that is used to trace the route a packet takes from the source device to the destination device
head
tracert
netstat
netcat
dig
command used to view active network connections, listening ports, routing tables, network interface stats
head
tracert
netstat
netcat
dig
- command that is used to establish and interact with network connections, can be used for data transmission, port scanning, file transfer, and testing
head
tracert
netstat
netcat
dig
command used for querying DNS servers to get information about domain names, IP addresses, and more.
head
tracert
netstat
netcat
dig
combines the features of ping and tracert
pathping
hping
chmod
netcat
dig
used for security auditing and testing of firewalls and networks
pathping
hping
chmod
netcat
dig
sets permissions of files or directories
pathping
hping
chmod
netcat
dig
a network protocol used to prevent loops in Ethernet networks
STP frame (Spanning Tree Protocol)
MTU (Maximum Transmission Unit)
BPDU (Bridge Protocol Data Unit)
Jump server
NAT (Network Address Translation)
) - the maximum size of a data packet that can be transmitted over a network protocol without fragmentation
STP frame (Spanning Tree Protocol)
MTU (Maximum Transmission Unit)
BPDU (Bridge Protocol Data Unit)
Jump server
NAT (Network Address Translation)
- unit of communication in STP protocol
STP frame (Spanning Tree Protocol)
MTU (Maximum Transmission Unit)
BPDU (Bridge Protocol Data Unit)
Jump server
NAT (Network Address Translation)
- a dedicated system used as an access point for connecting and managing other systems in a network
STP frame (Spanning Tree Protocol)
MTU (Maximum Transmission Unit)
BPDU (Bridge Protocol Data Unit)
Jump server
NAT (Network Address Translation)
process for translating IP address between different network domains, Layer 3, used to overcome IPv4 limitations by allowing multiple devices with private IP address to share a single public IP address
STP frame (Spanning Tree Protocol)
MTU (Maximum Transmission Unit)
BPDU (Bridge Protocol Data Unit)
Jump server
NAT (Network Address Translation)
- technology that allows the creation of virtual boundaries around realworld geographic area
Geofencing
OTG (On-the-go)
IdP (Identity Provider)
KBA
- enables direct USB connection between devices
Geofencing
OTG (On-the-go)
IdP (Identity Provider)
KBA
manages the authentication and authorization process for users within a network
Geofencing
OTG (On-the-go)
IdP (Identity Provider)
KBA
(Knowledge-Based Authentication)
Geofencing
OTG (On-the-go)
IdP (Identity Provider)
KBA
Windows group policy settings that defines what a system looks like and how it behaves to a group of users
GPO (Group Policy Object) -
Syslog
Nessus
centralized log management system
GPO (Group Policy Object) -
Syslog
Nessus
- vulnerability scanning tool that helps identify vulnerabilities, and take appropriate actions to mitigate them
GPO (Group Policy Object) -
Syslog
Nessus
Port numbers FTP (File Transfer Protocol)
20 DATA 21 CONTROL
22
23
25
SSH (Secure Shell):
20 DATA 21 CONTROL
22
23
25
Telnet
20 DATA 21 CONTROL
22
23
25
SMTP (Simple Mail Transfer Protocol):
20 DATA 21 CONTROL
22
23
25
SMTP (Simple Mail Transfer Protocol):
20 DATA 21 CONTROL
22
23
25
DNS (Domain Name System)
53
: 67 (server), 68 (client)
80
443
DHCP
53
: 67 (server), 68 (client)
80
443
DNS (Domain Name System)
53
: 67 (server), 68 (client)
80
443
HTTP (Hypertext Transfer Protocol)
53
: 67 (server), 68 (client)
80
443
HTTPS (Hypertext Transfer Protocol Secure):
53
: 67 (server), 68 (client)
80
443
HTTP (Hypertext Transfer Protocol)
53
: 67 (server), 68 (client)
80
443
RDP (Remote Desktop Protocol)
3389
161 (SNMP agent), 162 (SNMP manager)
123
389
143
SNMP (Simple Network Management Protocol):
3389
161 (agent), 162 (manager)
123
389
143
NTP (Network Time Protocol):
3389
161 (agent), 162 (manager)
123
389
143
LDAP (Lightweight Directory Access Protocol):
3389
161 (agent), 162 (manager)
123
389
143
IMAP (Internet Message Access Protocol)
3389
161 (agent), 162 (manager)
123
389
143
POP3 (Post Office Protocol version 3)
110
445
548
(Remote Authentication Dial-In User Service): 1812 (authentication), 1813 (accounting)
SMB Server Message Block
110
445
548
(Remote Authentication Dial-In User Service): 1812 (authentication), 1813 (accounting)
AFP (Apple Filing Protocol):
110
445
548
(Remote Authentication Dial-In User Service): 1812 (authentication), 1813 (accounting)
RADIUS (Remote Authentication Dial-In User Service):
110
445
548
1812 (authentication), 1813 (accounting)
SIP (Session Initiation Protocol):
5060
990
69
FTPS (FTP Secure)
5060
990
69
TFTP (Trivial File Transfer Protocol):
5060
990
69
