Shared Flashcard Set

Details

CompTIA Sec+ 2.3
Technologies and Tools: Troubleshoot common security issues
15
Computer Science
Professional
11/12/2018

Additional Computer Science Flashcards

 


 

Cards

Term
Configuration Compliance Scanner
Definition
-Checks hosts against various config templates
-Identifies systems not in compliance
-Allows for quick remediation
Term
Access Violations
Definition
-Outside of Baselines
-Occasional wrong clicks weeded out
-Identify Brute-force attacks
-Probes as attackers try and see what they can access
-SKilled and persistent access over time
-Map the network
Term
Certificate Issues
Definition
-Results in giving access to people that shouldn't have it
-Quickly recall and replace
-Rotate keys keep track of how resources are secured
-Infrastructure needed to quickly invalidate when compromised
Term
Certificate Hierarchy
Definition
-Root CA offline
-Subordinate CA's
-Issuing CA's
Term
Misconfigured Devices
Definition
-Firewalls can allow traffic that should be blocked and reduces overall security
-Content Filters can allow malicious code to be displayed and downloaded
-Access Points: Can be used to capture credentials, traffic, confidential info
Term
Downgrade attack
Definition
Attacker negotiates a weaker security protocol
Term
Personnel Issues
Definition
Policy Violations
-Methods in place to deal with violations
-Automated process to alert on violations
Insider Threats
-Audit logs, monitoring, access controls with triggers
-Job Rotation, Mandatory Vacations
Term
Social Engineering
Definition
-Personnel give away too much information
Term
Social Media
Definition
-Posting sensitive or proprietary information on LInkedIn and Facebook
Term
Unauthorized Software
Definition
Software Policies in Place
-Pirated software often contains malware
-Security implications are not vetted or fully understood
-Licensing and Copyright violations
-Unknown Intent
Term
Devices That Require Baselines and Monitoring
Definition
-Firewalls
-Switches
-Servers
-Applications
-SAN/NAS
-NIDS/NIPS
Term
License Compliance Violation
Definition
-Needs of Business
-Consume now True Up later
-Established Methods of Delivery
-Potential for application service to stop
Term
Cost of License Compliance VIolation
Definition
-Financial Penalties - fees
-True up costs
-Impact to availability or integrity
-Security product stop working
Term
Asset Management
Definition
-Compliance Licensing
-Patching/Updates
-Hard to monitor what you don't know
Term
Authentication Issues
Definition
-SSO
-Min level access
Supporting users have an ad free experience!