All certifications / CISSP / Cheat sheet
CISSP 2024 outline cheat sheet
Domain 1: Security & risk management (16%)
Exam tips
- When answers pit canons against each other, pick the one that serves the higher canon: society first, then honesty and legality, then principals, then the profession. Prefer internal escalation before dramatic external action.
- If a question asks which control provides non-repudiation, look for a digital signature. Symmetric encryption, HMACs and hashes alone cannot provide it, because more than one party holds the secret or anyone can compute the hash.
- Ultimate responsibility for security always sits with senior management. Due diligence is knowing and verifying (research, assess, monitor); due care is doing (implement and maintain reasonable controls).
- Match the IP type to the asset: code is copyrighted, a logo is trademarked, an invention is patented, and a confidential recipe or algorithm is a trade secret. Remember PCI DSS is a contractual standard, not a law.
- Criminal cases need the most rigorous evidence handling and the highest standard of proof. If a scenario might become criminal, preserve evidence and involve legal counsel and senior management before anyone calls the police.
- Guidelines are the only optional document in the hierarchy. Policies are high-level and technology-neutral; standards and baselines are specific and mandatory; procedures are step by step.
- RPO is about data (how much you can lose); RTO is about time to restore. RTO must be less than MTD, and RTO plus work recovery time should fit inside MTD. People's safety always comes first.
- For involuntary terminations, disable access before or at the same time the employee is told. Mandatory vacations and job rotation detect fraud; separation of duties prevents it but cannot stop collusion.
- Memorize SLE = AV x EF and ALE = SLE x ARO. A safeguard is justified when ALE before minus ALE after exceeds its annual cost. Ignoring risk is never a valid response, and business owners accept risk.
- Match each STRIDE letter to the property it violates: spoofing-authentication, tampering-integrity, repudiation-non-repudiation, information disclosure-confidentiality, denial of service-availability, elevation of privilege-authorization. PASTA is the risk-centric, business-aligned one.
- Awareness changes behavior for everyone, training teaches job skills, education builds deep understanding. For effectiveness, prefer behavior-based metrics such as report rates and fewer human-error incidents over attendance numbers.
Key terms
- ISC2 Code of Ethics
- The preamble and four canons that every ISC2-certified member agrees to follow as a condition of certification.
- Canon
- One of the four ranked principles of the code; when two conflict, the higher-ranked canon takes priority.
- Principal
- The party you serve professionally, such as an employer, client or customer.
- Conflict of interest
- A situation where personal gain or divided loyalty could influence, or appear to influence, professional judgment.
- Code of conduct
- An organization's own written statement of expected behavior, values and consequences for violations.
- Ethics hotline
- A confidential or anonymous channel for staff to report suspected misconduct without fear of retaliation.
- Tone at the top
- The ethical climate set by senior leadership through its own behavior and enforcement.
- Confidentiality
- Assurance that information is disclosed only to authorized people, processes and devices.
- Integrity
- Assurance that data and systems are protected from unauthorized or accidental change, and that changes can be detected.
- Availability
- Assurance that authorized users have timely and reliable access to information and systems.
- Authenticity
- The property of being verifiably genuine, coming from the claimed source and unaltered.
- Non-repudiation
- Assurance that a party cannot credibly deny having performed an action, usually provided by digital signatures and logging.
- DAD triad
- Disclosure, alteration and destruction: the attacker-focused opposites of confidentiality, integrity and availability.
- Parkerian hexad
- A model that extends the CIA triad with possession or control, authenticity and utility.
- Security governance
- The leadership structures, responsibilities and processes that direct and oversee an organization's security program.
- Strategic plan
- A long-term plan, often three to five years, that aligns security with the organization's mission and goals.
- Tactical plan
- A mid-term plan, around one year, that turns strategy into specific projects and initiatives.
- Due care
- Acting as a reasonable, prudent person would by implementing and maintaining appropriate controls.
- Due diligence
- The research, assessment and ongoing verification needed to know what controls are appropriate and whether they work.
- Chief information security officer (CISO)
- The executive who leads the security program and advises senior management on risk.
- Security steering committee
- A group of business and technical leaders that sets security priorities and resolves conflicts.
- Criminal law
- Law addressing offenses against society, prosecuted by the government and punishable by fines or imprisonment.
- Civil law
- Law governing disputes between private parties, typically resolved through monetary damages or court orders.
- GDPR
- The European Union's General Data Protection Regulation, which governs processing of personal data about people in the EU.
- Copyright
- Protection for original works of expression, such as software code, that arises automatically when the work is created.
- Patent
- Time-limited protection for a novel, useful and non-obvious invention, granted in exchange for public disclosure.
- Trade secret
- Valuable confidential business information protected for as long as the owner takes reasonable steps to keep it secret.
- Transborder data flow
- The transfer of data, especially personal data, across national borders, often restricted by privacy and localization laws.
- Administrative investigation
- An internal inquiry into policy violations or operational issues, leading to discipline or process changes.
- Criminal investigation
- An inquiry by law enforcement into alleged crimes, requiring proof beyond a reasonable doubt.
- Civil investigation
- Fact-finding to support a lawsuit between parties, judged on the preponderance of the evidence.
- Regulatory investigation
- An inquiry by a government agency or authorized body into possible violations of regulations.
- Chain of custody
- Documentation of who collected, handled and stored evidence, when and how, from collection to court.
- Legal hold
- An instruction to preserve all information relevant to anticipated or current litigation, suspending normal deletion.
- eDiscovery
- The process of identifying, preserving, collecting, reviewing and producing electronically stored information for legal matters.
- Policy
- A high-level, mandatory statement of management intent approved by senior leadership.
- Standard
- A mandatory, specific requirement, such as a technology or configuration, that makes a policy measurable.
- Baseline
- A mandatory minimum security configuration for a type of system that may be exceeded but not undercut.
- Procedure
- Detailed, mandatory step-by-step instructions for performing a specific task.
- Guideline
- An optional recommendation or best practice that allows discretion.
- Policy exception
- A formally requested, risk-assessed, approved and time-limited deviation from a policy or standard.
- Business continuity planning (BCP)
- The process of keeping critical business functions operating during and after a disruption.
- Business impact analysis (BIA)
- An analysis that identifies critical processes, their dependencies and the impact of their loss over time.
- Maximum tolerable downtime (MTD)
- The longest a process can be unavailable before the damage becomes unacceptable.
- Recovery time objective (RTO)
- The target time to restore a process or system after a disruption, which must be less than the MTD.
- Recovery point objective (RPO)
- The maximum acceptable amount of data loss, measured as time since the last good copy.
- Work recovery time (WRT)
- The time needed after systems are restored to verify data and resume normal operations.
- Hot site
- A fully equipped alternate site with current data that can take over almost immediately.
- Background screening
- Verification of a candidate's identity, history and suitability, proportional to the sensitivity of the role.
- Non-disclosure agreement (NDA)
- A contract obliging a person to keep specified information confidential, often beyond employment.
- Separation of duties
- Splitting a critical task among multiple people so no one person can complete it alone.
- Job rotation
- Moving staff between roles periodically to deter fraud and spread knowledge.
- Mandatory vacation
- Requiring employees to take time off so others perform their duties and irregularities surface.
- Privilege creep
- The gradual accumulation of access rights beyond what a user's current role requires.
- Service-level agreement (SLA)
- A contract defining measurable service commitments, such as availability and response times.
- Risk
- The likelihood that a threat exploits a vulnerability, combined with the impact on an asset.
- Single loss expectancy (SLE)
- The expected monetary loss from one occurrence of a risk, calculated as asset value times exposure factor.
- Annualized rate of occurrence (ARO)
- The estimated number of times a risk event occurs in a year.
- Annualized loss expectancy (ALE)
- The expected yearly loss from a risk, calculated as SLE times ARO.
- Residual risk
- The risk that remains after safeguards have been applied.
- Risk transfer
- Shifting the financial impact of a risk to another party, such as through insurance or contracts.
- Delphi technique
- A qualitative method that gathers anonymous expert opinions over several rounds to reach consensus.
- Threat modeling
- A structured process for identifying, prioritizing and addressing threats to a system, ideally during design.
- Trust boundary
- A point in a system where data or execution passes between components with different levels of trust.
- STRIDE
- A threat categorization model: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
- PASTA
- The Process for Attack Simulation and Threat Analysis, a seven-stage, risk-centric threat modeling method.
- Supply chain risk management (SCRM)
- Identifying and reducing risks introduced by suppliers, components, services and their own suppliers.
- Software bill of materials (SBOM)
- An inventory of the components and dependencies that make up a piece of software.
- Fourth-party risk
- Risk arising from the suppliers and subcontractors of your own direct suppliers.
- Security awareness
- Activities that keep security top of mind and influence everyday behavior across the whole workforce.
- Security training
- Instruction that teaches specific skills people need to perform their jobs securely.
- Security education
- In-depth learning that builds understanding of principles so people can handle new situations.
- Phishing simulation
- A controlled, fake phishing campaign used to teach and measure how staff respond to suspicious messages.
- Security champion
- A staff member within a team who promotes good security practice and acts as a link to the security function.
- Report rate
- The proportion of staff who report a suspicious message, a key behavior metric for awareness programs.
Domain 2: Asset security (10%)
Exam tips
- The data owner classifies data; custodians protect it. Systems and media take on the highest classification of any data they hold. Keep schemes simple enough that people apply them consistently.
- Backups and copies carry the same classification as the original data. Unlabeled media should be handled at the highest classification until its contents are verified. Labeling is on the media; marking is in the content.
- Asset inventory is foundational: the exam often expects it as the first step before vulnerability management, classification or risk assessment can succeed. Every asset needs a named owner.
- Classification should happen at the create phase. Data in use is typically the hardest state to protect because it is decrypted for processing. Destruction must reach every copy, and legal holds override it.
- Controller decides why and how; processor acts on the controller's behalf. Owner is accountable and classifies; custodian implements; steward manages quality. If a role 'determines purposes', it is a controller.
- The least risky data is data you never collected. When a scenario asks how to reduce privacy risk, limiting collection or deleting unneeded data often beats adding more controls.
- A legal hold always overrides the normal retention schedule. For unsupported (EOS) systems that cannot be replaced yet, the expected answer is isolation plus compensating controls and documented risk acceptance.
- Degaussing does not work on SSDs or flash. For SSDs, the best answers are manufacturer sanitize or secure erase, cryptographic erase or physical destruction. Deleting and formatting are never adequate sanitization.
- Match the control to the state: encryption plus key management for rest, TLS, IPsec or SSH for transit, and access control, masking and trusted execution environments for use. Tokenization is not encryption; no key mathematically reverses a token.
- Scoping removes controls that do not apply; tailoring adjusts the ones that do. DRM protects content after it leaves your environment, DLP stops it leaving inappropriately, and a CASB governs cloud service use.
Key terms
- Asset inventory
- A maintained record of the information and assets an organization holds, with owners and locations.
- Classification
- Assigning information a sensitivity or criticality level that determines its required protections.
- Data owner
- The senior business person accountable for a data set, including deciding its classification.
- Declassification
- Formally lowering or removing a classification when information no longer needs its original protection.
- Categorization
- Rating a system by the potential impact of losing confidentiality, integrity or availability.
- Personally identifiable information (PII)
- Information that can identify an individual directly or when combined with other data.
- Labeling
- Attaching a classification indicator to media or systems, such as a physical label on a drive or tape.
- Marking
- Displaying the classification within the information itself, such as headers, footers or banners.
- Metadata label
- A classification stored electronically with a file or record so systems can enforce handling rules.
- Handling requirements
- Rules that specify how information of each classification is stored, transmitted, used and destroyed.
- Mandatory access control (MAC)
- An access control model where the system enforces access based on labels and clearances, not owner discretion.
- Clean desk policy
- A rule requiring sensitive materials to be secured and desks cleared when unattended.
- Configuration management database (CMDB)
- A repository of assets and their configurations, relationships and owners.
- Shadow IT
- Technology used or deployed without the knowledge or approval of the IT or security function.
- Secure provisioning
- Deploying resources in an approved, hardened and recorded state from the start.
- Infrastructure as code (IaC)
- Defining infrastructure in version-controlled templates so builds are repeatable and reviewable.
- Configuration drift
- Gradual divergence of a system's actual configuration from its approved baseline.
- Data life cycle
- The phases data passes through: create, store, use, share, archive and destroy.
- Data minimization
- Collecting and keeping only the data needed for a specific, legitimate purpose.
- Archive
- Long-term storage of data no longer in active use, kept to meet retention requirements.
- Masking
- Hiding part of a sensitive value, such as showing only the last four digits, so users see only what they need.
- Legal hold
- A requirement to preserve relevant data for litigation or investigation, overriding normal destruction.
- Cryptographic erasure
- Destroying data by securely deleting the encryption keys that protect it, leaving only unreadable ciphertext.
- Data custodian
- The person or team, often IT, that implements and operates the protections the owner specifies.
- Data steward
- The role responsible for data quality, definitions, metadata and proper business use.
- Data controller
- The entity that determines the purposes and means of processing personal data.
- Data processor
- An entity that processes personal data on behalf of, and on the instructions of, a controller.
- Data subject
- The identifiable individual to whom personal data relates.
- Data protection officer (DPO)
- An independent role that advises on and monitors compliance with data protection law.
- Collection limitation
- The principle of collecting only the personal data needed for a specific, legitimate purpose by fair and lawful means.
- Purpose limitation
- Using personal data only for the purposes for which it was collected, unless a new lawful basis exists.
- Data sovereignty
- The concept that data is subject to the laws of the country where it is located.
- Data localization
- Legal requirements that certain data be stored or processed within a specific country or region.
- Data quality
- The principle that personal data should be accurate, complete and kept up to date.
- Pseudonymization
- Replacing direct identifiers with substitutes so data cannot be attributed to a person without additional, separately held information.
- Retention policy
- A policy defining how long each category of data is kept and how it is disposed of.
- Retention schedule
- A list of record types with their retention periods, owners and disposition methods.
- Spoliation
- The destruction or alteration of evidence that should have been preserved, which can bring legal penalties.
- End-of-life (EOL)
- The point at which a vendor stops selling or developing a product.
- End-of-support (EOS)
- The point after which a vendor no longer provides patches, updates or technical support.
- Compensating control
- An alternative control that reduces risk when the primary control is not feasible.
- Data remanence
- Residual data that remains on media after attempts to erase or remove it.
- Clearing
- Logical sanitization of user-addressable storage that protects against simple, non-invasive recovery.
- Purging
- Sanitization that makes recovery infeasible even with advanced laboratory techniques.
- Destruction
- Physically rendering media unusable and data unrecoverable, such as by shredding or incineration.
- Degaussing
- Erasing magnetic media with a strong magnetic field; ineffective on SSDs, flash and optical media.
- Cryptographic erase
- Sanitizing encrypted media by securely destroying every copy of its encryption keys.
- Wear leveling
- An SSD technique that spreads writes across cells, which can leave old data in areas overwriting cannot reach.
- Data at rest
- Data stored on media such as disks, databases, backups or cloud storage.
- Data in transit
- Data moving across a network between systems or locations.
- Data in use
- Data being actively processed in memory or viewed by a user.
- Transport Layer Security (TLS)
- A protocol that encrypts and authenticates application traffic such as web and API connections.
- Tokenization
- Replacing a sensitive value with a random token that maps to the original only through a secure vault.
- Confidential computing
- Processing data inside hardware-protected enclaves so it stays protected even from the host operating system.
- Data loss prevention (DLP)
- Tools that discover, monitor and control the movement of sensitive data.
- Standards selection
- Choosing which frameworks, baselines and standards apply based on obligations, contracts and business goals.
- Scoping
- Determining which controls in a baseline apply to a given system or environment.
- Tailoring
- Adjusting applicable controls, parameters and compensating measures to fit the organization's needs.
- Digital rights management (DRM)
- Technology that enforces usage restrictions on content wherever it goes, using encryption and licensing.
- Cloud access security broker (CASB)
- A policy enforcement point between users and cloud services that provides visibility, data protection and threat detection.
Domain 3: Security architecture & engineering (13%)
Exam tips
- Fail secure for data and systems, but fail safe (open) for doors on life-safety paths: human safety wins every time on the CISSP exam. Zero trust means no implicit trust from network location.
- Confidentiality: Bell-LaPadula (no read up, no write down). Integrity: Biba (no read down, no write up) and Clark-Wilson (transactions, separation of duties). Conflict of interest: Brewer-Nash. 'Simple' means read; 'star' means write.
- A higher EAL means the product was evaluated more rigorously, not that it is guaranteed secure. Customers write protection profiles; vendors write security targets. Certification is technical; authorization is management accepting risk.
- TPM equals one device, boot integrity and sealed disk keys; HSM equals centralized, high-volume key storage and crypto operations for many applications. The reference monitor must be tamperproof, always invoked and small enough to verify.
- For ICS/OT the exam favors segmentation and availability-safe controls over patching or active scanning. For cloud, customer misconfiguration is the most common failure under shared responsibility. Containers share the host kernel.
- To send someone a confidential message, encrypt with their public key. To sign, use your own private key. Symmetric needs n(n-1)/2 keys; asymmetric needs 2n. Only digital signatures give non-repudiation.
- Match the defense to the attack: salting stops rainbow tables, slow hashing and lockout slow brute force, constant-time and tamper-resistant hardware stop side channels, certificate validation stops on-path attacks, and tested offline backups are the key ransomware control.
- Human safety always outranks protecting assets. Server rooms go in the building's interior, not the basement, top floor or along exterior walls.
- Pre-action is the preferred sprinkler for data centers. Sag and brownout are low voltage (momentary vs prolonged); spike and surge are high voltage (momentary vs prolonged). Never use water on energized electrical fires.
- Security belongs in the first phase, requirements, not at deployment. Verification is 'built it right' against the specification; validation is 'built the right thing' for the stakeholders.
Key terms
- Least privilege
- Granting only the minimum access needed to perform a function, for only as long as needed.
- Defense in depth
- Using multiple, diverse, independent layers of controls so the failure of one does not expose the asset.
- Secure defaults
- Shipping and deploying systems in their most secure reasonable configuration.
- Fail securely
- Designing components so that failures leave the system in a secure state, such as denying access.
- Zero trust
- An architecture that grants no implicit trust based on network location and verifies every request.
- Privacy by design
- Embedding privacy into systems from the outset, with privacy as the default setting.
- Secure access service edge (SASE)
- A cloud-delivered model combining SD-WAN with security services such as ZTNA, CASB and secure web gateway.
- Bell-LaPadula
- A confidentiality model enforcing no read up (simple security) and no write down (star property).
- Biba
- An integrity model enforcing no read down (simple integrity) and no write up (star integrity).
- Clark-Wilson
- A commercial integrity model using well-formed transactions, access triples and separation of duties.
- Brewer-Nash
- The Chinese Wall model, which dynamically blocks access that would create a conflict of interest.
- Transformation procedure (TP)
- In Clark-Wilson, a certified program that is the only way to modify constrained data items.
- Noninterference model
- A model requiring that high-level actions cannot affect what lower-level subjects observe, limiting covert channels.
- Lattice-based access control
- Ordering security levels so each subject and object has a place, forming the basis of mandatory access control.
- Common Criteria
- An international framework (ISO/IEC 15408) for independently evaluating the security of IT products.
- Target of evaluation (TOE)
- The specific product or system being evaluated under Common Criteria.
- Protection profile (PP)
- An implementation-independent set of security requirements for a category of products, usually written by customers or governments.
- Security target (ST)
- A vendor's document describing the security properties and evaluated configuration of its product.
- Evaluation assurance level (EAL)
- A rating from EAL1 to EAL7 describing how rigorously a product was evaluated.
- Authorization (accreditation)
- Management's formal decision to accept residual risk and allow a system to operate.
- Compensating control
- An alternative control used when a primary control is not feasible, providing similar risk reduction.
- Trusted Platform Module (TPM)
- A secure cryptoprocessor bound to one device that stores keys and records boot measurements.
- Hardware security module (HSM)
- A tamper-resistant device that securely generates, stores and uses keys for many applications.
- Root of trust
- A trusted hardware or firmware component on which the security of the rest of the system depends.
- Address space layout randomization (ASLR)
- Randomizing memory locations of code and data to make memory corruption attacks harder to exploit.
- Data execution prevention (DEP)
- Marking memory regions as non-executable so data injected there cannot run as code.
- Trusted computing base (TCB)
- The combination of hardware, firmware and software components that enforce a system's security policy.
- Reference monitor
- An abstract component that mediates all access; it must be tamperproof, always invoked and verifiable.
- Aggregation
- Combining individually low-sensitivity data items to reveal more sensitive information.
- Inference
- Deducing sensitive information from data a user is authorized to access.
- Polyinstantiation
- Maintaining multiple versions of a record at different classification levels to prevent inference.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer, varying by service model.
- ICS/OT
- Industrial control systems and operational technology that monitor and control physical processes.
- VM escape
- A compromise in which code in a virtual machine breaks isolation to reach the hypervisor or other guests.
- Serverless
- A cloud model where the provider runs functions on demand and the customer manages code, permissions and data.
- Symmetric encryption
- Encryption using one shared secret key for both encryption and decryption.
- Asymmetric encryption
- Encryption using a mathematically related public and private key pair.
- Hash function
- A one-way function that produces a fixed-length digest from input of any size.
- Digital signature
- A hash of a message encrypted with the signer's private key, providing integrity, authenticity and non-repudiation.
- Public key infrastructure (PKI)
- The roles, policies and systems that issue, manage and revoke digital certificates.
- Online Certificate Status Protocol (OCSP)
- A protocol for checking the revocation status of an individual certificate in real time.
- Split knowledge and dual control
- Controls ensuring no single person knows or can use a whole critical key alone.
- Brute force attack
- Trying every possible key or password until the correct one is found, defeated by large key spaces, slow hashing and lockout.
- Rainbow table
- A precomputed set of hash chains used to reverse unsalted password hashes quickly, made useless by unique salts.
- Birthday attack
- An attack that exploits the relative ease of finding any two inputs with the same hash value.
- Side-channel attack
- An attack that extracts secrets from physical behavior such as timing, power use or emissions rather than from the algorithm.
- On-path attack
- An attacker positioned between two parties to intercept or modify their traffic, also called man-in-the-middle.
- Pass the hash
- Authenticating with a stolen password hash instead of the password, possible with protocols such as NTLM.
- Double extortion
- A ransomware tactic that both encrypts data and threatens to publish stolen copies of it.
- CPTED
- Crime Prevention Through Environmental Design, using layout, lighting and landscaping to discourage crime.
- Natural surveillance
- The CPTED strategy of arranging spaces so activity is easily visible to others.
- Territorial reinforcement
- The CPTED strategy of using physical cues to show a space is owned and cared for.
- Access control vestibule
- A small space between two doors that admits one person at a time, also called a mantrap.
- Tailgating
- Following an authorized person through a controlled entrance without their knowledge.
- Piggybacking
- Entering a controlled area with an authorized person's consent but without your own authorization.
- Deter, detect, delay, respond
- The layered physical security sequence in which each barrier buys time for a response.
- Brownout
- A prolonged period of low voltage on the power supply.
- Sag
- A momentary drop in voltage.
- Surge
- A prolonged period of high voltage, compared with a spike, which is momentary.
- Uninterruptible power supply (UPS)
- Battery-backed equipment that keeps systems running through short outages and allows clean shutdown or transfer.
- Pre-action sprinkler
- A system that fills pipes only after detection and releases water only when a head also opens, reducing accidental discharge.
- Clean agent
- A gaseous fire suppressant that extinguishes fire without leaving residue or damaging electronics.
- Positive pressurization
- Keeping air pressure higher inside a room so air flows out, not in, when doors open.
- Stakeholder requirements
- The needs of everyone with an interest in a system, including security and privacy needs, captured before design.
- Requirements analysis
- Refining stakeholder needs into specific, testable system requirements.
- Verification
- Confirming the system was built correctly according to its specified requirements.
- Validation
- Confirming the system meets stakeholders' actual needs in its intended environment.
- Authorization to operate
- A formal management decision to accept residual risk and allow a system into production.
- Operations and maintenance
- The typically longest lifecycle phase, covering patching, monitoring, change control and reassessment.
- Retirement
- The planned end of a system's life, including data archiving, media sanitization and removal of access.
Domain 4: Communication & network security (13%)
Exam tips
- Switches and ARP are layer 2, routers and IP are layer 3, TCP/UDP ports are layer 4, WAFs and proxies are layer 7. A layer 3 packet filter cannot see an injection attack inside HTTP.
- AH gives integrity but no confidentiality; ESP gives both. Tunnel mode is gateway-to-gateway, transport mode is host-to-host. SNMPv1 and v2c send community strings in cleartext; only SNMPv3 is secure.
- The standard answer for converged traffic is isolation (dedicated VLANs or networks) plus authentication and encryption. FCoE runs at layer 2 and cannot be routed; FCIP and iSCSI run over IP.
- Micro-segmentation and SDP both support zero trust by limiting lateral movement and hiding resources. In SDN, the controller is the crown jewel: protect it and its APIs.
- For the strongest enterprise Wi-Fi, choose WPA3-Enterprise (or WPA2-Enterprise) with 802.1X and EAP-TLS. SSID hiding and MAC filtering are not real security controls.
- Perimeter firewalls mainly handle north-south traffic. When a question asks how to stop lateral movement, choose east-west controls such as micro-segmentation and internal monitoring.
- IDS detects and alerts; IPS is inline and blocks. Signature-based detection misses zero-days; anomaly-based catches novel behavior with more false positives. Fiber is the most secure transmission medium against tapping and interference.
- For remote access, the best answers include MFA, encryption and least privilege. TACACS+ encrypts the whole payload; RADIUS encrypts only the password. Third-party connections need both contractual (ISA, contract) and technical (segmentation, monitoring) controls.
- DNSSEC provides integrity and authenticity for DNS records, not confidentiality. SYN cookies mitigate SYN floods; ingress and egress filtering reduce IP spoofing; HSTS defends against SSL stripping.
- Flow data shows who talked to whom and how much, packet capture shows content, SNMP shows device health, syslog shows events. SNMPv3 is the secure choice, and time synchronization is a prerequisite for log correlation.
Key terms
- OSI model
- A seven-layer reference model describing network communication from physical transmission to application services.
- Encapsulation
- Each layer adding its own header to data as it moves down the stack, removed in reverse at the receiver.
- Three-way handshake
- The SYN, SYN-ACK, ACK exchange TCP uses to establish a connection.
- Frame
- The layer 2 unit of data, addressed with MAC addresses.
- Packet
- The layer 3 unit of data, addressed with IP addresses.
- Stateful inspection
- Firewall filtering that tracks connection state, a primarily layer 4 capability.
- Web application firewall (WAF)
- A layer 7 control that inspects HTTP traffic for attacks such as injection.
- NAT
- Network address translation, mapping private internal addresses to public ones; it hides addressing but is not a firewall.
- SLAAC
- Stateless address autoconfiguration, the IPv6 method by which hosts assign their own addresses from router advertisements.
- Forward secrecy
- A property of key exchange ensuring that compromise of a long-term key does not expose past session keys.
- Authentication Header (AH)
- The IPsec protocol that provides integrity and origin authentication without encryption.
- Encapsulating Security Payload (ESP)
- The IPsec protocol that provides confidentiality as well as integrity and authentication.
- Security association (SA)
- A one-way IPsec agreement on keys and algorithms, negotiated by IKE.
- SNMPv3
- The version of SNMP that adds authentication, integrity and encryption.
- Converged protocol
- A protocol that carries specialized traffic such as storage or voice over standard IP or Ethernet networks.
- iSCSI
- A protocol that transports SCSI storage commands over TCP/IP networks.
- FCoE
- Fibre Channel over Ethernet, which carries Fibre Channel frames directly in Ethernet at layer 2 and is not IP-routable.
- LUN masking
- Storage-side access control that limits which hosts can see which logical storage units.
- Zoning
- Fabric-level control of which storage devices and hosts can communicate.
- RDMA
- Remote direct memory access, letting one system access another's memory without involving its processor.
- SRTP
- Secure Real-time Transport Protocol, which encrypts and authenticates voice and video media streams.
- Micro-segmentation
- Applying security policy to individual workloads so each can talk only to explicitly permitted peers.
- Control plane
- The part of networking that decides where traffic should go.
- Data plane
- The part of networking that forwards traffic according to control plane decisions.
- SDN controller
- The centralized component that programs network devices in a software-defined network.
- VXLAN
- An overlay that carries layer 2 frames inside UDP across layer 3 networks with a 24-bit segment ID.
- Virtual private cloud (VPC)
- A logically isolated customer network within a public cloud.
- Software-defined perimeter (SDP)
- An architecture that keeps applications hidden until a user and device authenticate and are authorized.
- WPA3
- The current Wi-Fi security generation, using SAE for personal networks and requiring protected management frames.
- SAE
- Simultaneous Authentication of Equals, a handshake that resists offline dictionary attacks and provides forward secrecy.
- 802.1X
- Port-based network access control that authenticates users or devices, typically with RADIUS and EAP.
- EAP-TLS
- An EAP method using certificates on both client and server, the strongest common enterprise Wi-Fi option.
- Evil twin
- A malicious access point that impersonates a legitimate network to capture traffic or credentials.
- Rogue access point
- An unauthorized access point connected to an organization's network.
- Bluesnarfing
- Unauthorized access to data on a Bluetooth device.
- Content distribution network (CDN)
- A distributed set of edge servers that cache and serve content close to users.
- Edge server
- A CDN server near users that serves cached content and often applies security controls.
- Origin server
- The authoritative server that holds the original content a CDN caches.
- North-south traffic
- Traffic flowing between a data center or cloud environment and the outside world.
- East-west traffic
- Traffic flowing laterally between systems inside a data center or cloud environment.
- Cache poisoning
- Causing a cache to store and serve malicious or incorrect content.
- Mutual TLS
- TLS in which both client and server present certificates, often used to authenticate service-to-service traffic.
- Stateful inspection firewall
- A firewall that tracks connection state and permits return traffic only for established sessions.
- Next-generation firewall (NGFW)
- A firewall combining stateful inspection with application awareness, user identity and intrusion prevention.
- IDS vs IPS
- An IDS detects and alerts on suspicious activity, while an IPS sits inline and can block it.
- Anomaly-based detection
- Detection that flags deviations from a learned baseline, able to catch new attacks but prone to false positives.
- Network access control (NAC)
- Controls that authenticate devices and check their posture before and during network access.
- Reverse proxy
- An intermediary in front of servers that receives client requests and forwards them, often adding load balancing and TLS termination.
- Endpoint detection and response (EDR)
- Endpoint software that records activity and supports detection, investigation and response.
- Toll fraud
- Unauthorized use of an organization's phone system to place calls at its expense.
- Split tunneling
- A VPN configuration that sends only corporate traffic through the tunnel and other traffic directly to the internet.
- Zero trust network access (ZTNA)
- Remote access that grants authenticated users access to specific applications rather than the whole network.
- TACACS+
- A AAA protocol that runs over TCP, encrypts the full payload and separates authentication, authorization and accounting.
- Interconnection security agreement (ISA)
- A document that specifies the technical and security requirements for connecting two organizations' systems.
- DMARC
- An email policy mechanism that builds on SPF and DKIM to tell receivers how to handle unauthenticated mail from a domain.
- DDoS
- Distributed denial of service, an availability attack launched from many sources at once.
- SYN flood
- A protocol attack that sends many TCP connection requests without completing the handshake, exhausting state tables.
- Amplification attack
- Sending small spoofed requests to services that reply with much larger responses to the victim.
- Ingress and egress filtering
- Dropping inbound packets with internal source addresses and outbound packets with non-internal sources to reduce spoofing.
- DNSSEC
- Extensions that sign DNS records so resolvers can verify authenticity and integrity, without encrypting them.
- HSTS
- HTTP Strict Transport Security, a header that tells browsers to connect to a site only over HTTPS.
- DNS tunneling
- Hiding data or command traffic inside DNS queries and responses.
- Observability
- Collecting telemetry rich enough to answer unanticipated questions about system behavior.
- Flow data
- Summaries such as NetFlow or IPFIX that record endpoints, ports, timing and volume of conversations without full content.
- Syslog
- A standard for sending event messages from devices to a central collector.
- Baseline
- A measured picture of normal behavior against which deviations are detected.
- NTP
- Network Time Protocol, used to synchronize clocks so events can be correlated.
- Capacity management
- Trending and forecasting resource use so services stay available.
- Out-of-band management
- Administering devices over a separate network isolated from production traffic.
Domain 5: Identity & access management (13%)
Exam tips
- Classify each control by both type (administrative, technical, physical) and function (preventive, detective, corrective and so on). A monitored camera is detective; an unmonitored or dummy camera is only a deterrent.
- Two items from the same category are not MFA. The order is identification, then authentication, then authorization, and accountability depends on unique identities plus auditing.
- To make access easier to manage and audit as people change jobs, assign permissions to groups or roles, not individuals. For sessions: random IDs, regenerate at login, encrypt in transit, and time out.
- SAML is XML-based and common for enterprise SSO; OAuth 2.0 is authorization (delegated access), not authentication; OIDC is authentication built on OAuth 2.0 using JSON tokens.
- The main risk of SSO is a single point of compromise and of failure. The main mitigation is strong MFA at the SSO point plus availability and monitoring of the identity service.
- To reduce the risk of compromised administrator accounts, remove standing privilege (JIT), separate admin and daily-use accounts, and add vaulting, rotation and session monitoring.
- Ask who decides. Owner decides: DAC. System labels decide: MAC. Job function decides: role-based RBAC. Global rules decide: rule-based. Many attributes decide: ABAC. Live risk score decides: risk-based.
- Privilege creep is the risk most associated with transfers, and periodic access reviews are the control that detects it. For hostile terminations, disable access at the same moment the person is notified.
- RADIUS uses UDP, encrypts only the password and combines authentication with authorization; TACACS+ uses TCP, encrypts the full body and separates all three A's. Kerberos needs time synchronization and has the KDC as a single point of failure.
- Type I is false rejection (FRR); Type II is false acceptance (FAR). The best biometric has the lowest CER. When security matters most, tune to minimize FAR even though FRR rises.
Key terms
- Subject
- An active entity, such as a user, process or device, that requests access to an object.
- Object
- A passive resource, such as a file, system or room, that a subject accesses.
- Least privilege
- Granting only the minimum access needed to perform an assigned task.
- Need to know
- Restricting access to information required for a specific duty, regardless of clearance level.
- Compensating control
- An alternative control used when the primary control is not feasible, providing comparable protection.
- Detective control
- A control that identifies that an event has occurred, such as log review or a monitored camera.
- Default deny
- A policy that blocks all access not explicitly permitted.
- Identification
- Claiming an identity, for example by entering a username or presenting a badge.
- Authentication
- Proving a claimed identity with one or more factors.
- Authorization
- Determining what an authenticated subject is permitted to do.
- Accountability
- Tracing actions to a unique individual through identification and auditing.
- Multifactor authentication (MFA)
- Authentication using factors from two or more different categories.
- FIDO2
- A passwordless standard combining WebAuthn and CTAP that uses per-site key pairs and is phishing-resistant.
- Passkey
- A FIDO credential that can be synchronized across a user's devices and replaces a password.
- Identity proofing
- Verifying that a person is who they claim to be before issuing credentials.
- Registration
- Creating an identity record and account in a system.
- Role
- A collection of permissions representing a job function, assigned to users who perform it.
- Role explosion
- An unmanageable proliferation of narrowly defined roles.
- AAA
- Authentication, authorization and accounting, often centralized with RADIUS or TACACS+.
- Session fixation
- An attack in which a victim is made to use a session ID the attacker already knows, prevented by regenerating IDs at login.
- Absolute session timeout
- A maximum session lifetime after which reauthentication is required regardless of activity.
- Identity provider (IdP)
- The system that authenticates users and issues signed identity assertions or tokens.
- Service provider (SP)
- The application that relies on the IdP's assertion to grant access, called a relying party in OIDC.
- SAML assertion
- A signed XML statement from an IdP about a user's identity and attributes.
- OAuth 2.0
- An authorization framework for granting applications delegated, scoped access without sharing passwords.
- Access token
- A credential issued under OAuth that a client presents to an API to exercise granted scopes.
- OpenID Connect (OIDC)
- An authentication layer built on OAuth 2.0 that issues a signed ID token.
- ID token
- A signed JWT in OIDC that tells the relying party who the user is and who issued the token.
- Credential
- Anything a subject uses to prove identity, such as a password, key, token or certificate.
- Password vault
- A system that stores credentials encrypted and controls and logs their use.
- Secrets manager
- A service that supplies machine credentials to applications at runtime and rotates them.
- Hardware security module (HSM)
- Tamper-resistant hardware that generates, stores and uses cryptographic keys.
- Single sign-on (SSO)
- Authenticating once to gain access to multiple systems through tickets or tokens.
- Password synchronization
- Keeping the same password on multiple systems, which the user still enters separately on each.
- Step-up authentication
- Requiring additional authentication before a higher-risk action or application.
- Privileged access management (PAM)
- Processes and tools that discover, vault, limit and monitor privileged accounts.
- Standing privilege
- Elevated rights that remain assigned at all times whether or not they are in use.
- Just-in-time (JIT) access
- Granting elevated rights only when needed, for a limited time, and removing them automatically.
- Just-enough administration
- Limiting elevation to the specific commands or resources a task requires.
- Session brokering
- Connecting users to privileged systems through a proxy so they never see the underlying credential.
- Privileged access workstation
- A hardened device used only for administrative tasks.
- Break-glass account
- A tightly controlled emergency account used when normal access mechanisms fail.
- Discretionary access control (DAC)
- A model in which object owners decide who may access their objects, typically via ACLs.
- Mandatory access control (MAC)
- A model in which the system enforces access based on labels and clearances that users cannot change.
- Role-based access control
- A non-discretionary model that grants permissions through roles representing job functions.
- Rule-based access control
- A model that applies global rules, such as time or address conditions, to all subjects.
- Attribute-based access control (ABAC)
- A model that evaluates policies combining subject, object, action and environment attributes.
- Risk-based access control
- Adaptive authorization that adjusts decisions based on a real-time risk score.
- Security label
- A classification and compartment marking used by MAC to make access decisions.
- Joiner, mover, leaver (JML)
- The lifecycle stages of hiring, transfer and departure that drive access changes.
- Provisioning
- Creating accounts and granting approved access to a new or changed identity.
- Deprovisioning
- Disabling or removing access when it is no longer needed.
- Privilege creep
- Gradual accumulation of excess access as people change roles without old rights being removed.
- Access review (recertification)
- A periodic check by managers or owners that each person's access is still appropriate.
- Orphaned account
- An account with no current owner, such as one belonging to a departed employee.
- Authoritative source
- The system of record, often HR, that triggers identity lifecycle changes.
- Key distribution center (KDC)
- The trusted Kerberos authority that contains the authentication service and ticket-granting service.
- Ticket-granting ticket (TGT)
- A Kerberos ticket issued at login and used to obtain service tickets without re-entering credentials.
- Service ticket
- A Kerberos ticket that authenticates a user to a specific service.
- Golden ticket
- A forged TGT created with a stolen KDC signing key, granting broad access.
- RADIUS
- A UDP-based AAA protocol for network access that encrypts only the password field.
- TACACS+
- A TCP-based AAA protocol that encrypts the full payload and separates authentication, authorization and accounting.
- Time skew
- Clock difference between systems, which can cause Kerberos authentication to fail.
- Password spraying
- Trying a few common passwords across many accounts to avoid lockout thresholds.
- Credential stuffing
- Replaying username and password pairs leaked from other breaches against new sites.
- False rejection rate (FRR)
- The Type I error rate at which legitimate users are wrongly denied.
- False acceptance rate (FAR)
- The Type II error rate at which impostors are wrongly accepted.
- Crossover error rate (CER)
- The point where FAR equals FRR, used to compare biometric accuracy; lower is better.
- Liveness detection
- Techniques that confirm a biometric sample comes from a live person rather than a fake.
- Biometric template
- The stored mathematical representation of enrolled biometric features.
Domain 6: Security assessment & testing (12%)
Exam tips
- Know the independence ladder: internal teams are cheapest and most frequent, while external and third-party auditors are most independent and credible. When a question emphasizes objectivity for stakeholders or regulators, choose an external or third-party audit.
- The single most important precondition for a penetration test is written authorization from someone with authority over the systems. Match knowledge levels: zero knowledge is black box, partial is gray box, full is white box.
- Synthetic transactions are proactive and scripted; real user monitoring is passive. Clipping levels reduce noise by ignoring events below a threshold. BAS provides continuous validation of detection and prevention controls.
- Static means the code is not running, can happen early and points to the exact line; dynamic means the application is running and shows the attacker's view. Fuzzing is dynamic and targets input handling, and misuse cases test what an attacker would try.
- Compliant does not mean secure. A compliance check verifies adherence to a defined requirement or baseline; when a requirement cannot be met, expect documentation, compensating controls and formal risk acceptance.
- KPIs measure how well you are doing against a goal; KRIs warn that risk is increasing. For backups, the only real proof is a successful test restore, not a report that the job completed.
- Exceptions need approval from someone with authority to accept the risk, compensating controls, documentation and an expiry date. Remediation is not complete until a retest verifies it, and prioritization uses business context, not the CVSS score alone.
- For evaluating a vendor's security controls, choose SOC 2 Type II. SOC 1 is about financial reporting, SOC 3 is a public summary, Type I is design at a point in time and Type II is operating effectiveness over a period.
- In the cloud you usually cannot audit the provider directly; rely on third-party attestations for the provider's side and audit your own configuration for your side. Know how responsibility shifts across IaaS, PaaS and SaaS, and that accountability for data never moves.
Key terms
- Security test
- A procedure that verifies whether a specific control works as intended.
- Security assessment
- A broad review of a system or environment to identify risks and weaknesses.
- Audit
- A formal, independent evaluation against defined criteria that results in an opinion or attestation.
- Internal audit
- Assessment by the organization's own staff, ideally reporting independently to the audit committee.
- External audit
- An audit performed by an outside firm engaged by the organization.
- Third-party audit
- An audit performed by or on behalf of another party, such as a customer or regulator.
- SOC report
- A System and Organization Controls report in which an independent auditor attests to a service organization's controls.
- Vulnerability assessment
- Identifying and prioritizing known weaknesses, usually with automated scanning.
- Penetration test
- An authorized attempt to exploit weaknesses to demonstrate real impact.
- Credentialed scan
- A scan that logs in to systems to inspect software and configuration more accurately.
- False negative
- A real vulnerability that a test fails to detect.
- Rules of engagement (RoE)
- The written agreement defining a test's scope, methods, timing, contacts and data handling.
- Black-box test
- A zero-knowledge test in which testers start with little or no information about the target.
- White-box test
- A full-knowledge test in which testers receive documentation, code and credentials.
- Log review
- Examining event records to identify policy violations, errors and signs of attack.
- SIEM
- Security information and event management, a platform that centralizes and correlates logs and alerts.
- Clipping level
- A threshold of activity below which events are not flagged, used to reduce noise.
- Statistical sampling
- Selecting records randomly so that conclusions about the whole set can be drawn.
- Synthetic transaction
- A scripted, scheduled simulation of user activity used to verify function, performance and security behavior.
- Real user monitoring (RUM)
- Passive observation of the experience of actual users.
- Breach and attack simulation (BAS)
- Automated, continuous safe execution of attacker techniques to validate prevention and detection.
- Static application security testing (SAST)
- Analysis of source code, bytecode or binaries for vulnerabilities without running the program.
- Dynamic application security testing (DAST)
- Testing a running application from the outside by sending requests and analyzing responses.
- Fuzzing
- Supplying large volumes of malformed or random input to a running program to trigger crashes and errors that reveal flaws.
- Misuse case
- A scenario describing how an attacker or careless user could abuse a feature, used to design negative tests.
- Test coverage analysis
- Measurement of how much code, such as statements or branches, was exercised by tests.
- Interface testing
- Testing the connection points between components, such as APIs and user interfaces, for input handling, authorization and error handling.
- Fagan inspection
- A formal, structured code review process with defined roles and stages.
- Compliance
- Conformity with a defined set of requirements from laws, regulations, contracts, frameworks or internal policy.
- Configuration compliance scan
- An automated comparison of a system's settings against an approved baseline or benchmark.
- Security Content Automation Protocol (SCAP)
- A NIST suite of specifications that standardizes how security checks, configurations and results are expressed.
- Cloud security posture management (CSPM)
- Tools that continuously check cloud accounts and resources against security and compliance policy.
- Control matrix
- A mapping of each requirement to the control that satisfies it, its owner and the evidence that proves it.
- Compensating control
- An alternative control that reduces risk when a required control cannot be implemented as specified.
- Key performance indicator (KPI)
- A metric showing how well a process or control is performing against a defined goal.
- Key risk indicator (KRI)
- A forward-looking metric that warns when risk is rising toward or beyond the organization's appetite.
- Orphaned account
- An account whose owner has left or can no longer be identified, but which remains active.
- Management review
- Documented oversight by leadership of security metrics, risks, findings and decisions.
- Test restore
- Recovering data from backup to confirm it is complete, usable and restorable within the required time.
- Recovery time objective (RTO)
- The target time within which a system or function must be restored after disruption.
- False positive
- A finding that reports a vulnerability or problem that does not actually exist.
- Common Vulnerability Scoring System (CVSS)
- A standard for rating the technical severity of vulnerabilities on a numeric scale.
- Executive summary
- The part of a report that states overall risk, key findings and needed decisions in business language.
- Exception
- A formal, documented, time-limited approval to operate without meeting a requirement, usually with compensating controls.
- Remediation
- The action taken to fix a finding, verified by retesting.
- Risk register
- A record of identified risks, their owners, ratings, treatments and accepted exceptions.
- SOC 1
- An attestation report on a service organization's controls relevant to customers' internal control over financial reporting.
- SOC 2
- A detailed, restricted-use attestation report on controls for security, availability, processing integrity, confidentiality and privacy.
- SOC 3
- A general-use summary report on the same Trust Services Criteria as SOC 2, without detailed test results.
- Type I report
- An opinion on the design of controls at a specific point in time.
- Type II report
- An opinion on the design and operating effectiveness of controls over a period of time.
- Trust Services Criteria
- The AICPA criteria of security, availability, processing integrity, confidentiality and privacy used in SOC 2 and SOC 3.
- Complementary user entity controls (CUECs)
- Controls the customer must operate for the service provider's controls to be effective.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer, which shifts across IaaS, PaaS and SaaS.
- Third-party attestation
- An independent auditor's report or certification, such as SOC 2 or ISO/IEC 27001, that customers rely on instead of auditing a provider themselves.
- Right-to-audit clause
- A contract term defining the customer's right to audit or receive evidence of a provider's controls.
- Data residency
- The requirement or practice of storing and processing data in specific geographic locations or jurisdictions.
- Cloud Controls Matrix (CCM)
- A Cloud Security Alliance framework of cloud security controls used to assess and compare providers.
Domain 7: Security operations (13%)
Exam tips
- Always work from a verified copy, never the original, and keep an unbroken chain of custody. When asked what to collect first, choose the most volatile data, usually memory.
- SIEM detects by collecting and correlating; SOAR responds through automation and orchestration. Threat hunting is proactive and human-driven, starting from a hypothesis, while ordinary monitoring waits for alerts.
- A baseline is both the secure starting point and the yardstick for detecting drift. Unauthorized changes found by comparison should be investigated as potential incidents, not just quietly corrected.
- Separation of duties is a preventive control defeated by collusion; job rotation and mandatory vacations are mainly detective controls for fraud. Need to know limits information; least privilege limits permissions and rights.
- Match sanitization to where media go next: clearing for reuse inside the organization, purging before release outside, destruction when media are highly sensitive or cannot be reliably purged. Degaussing does not work on SSDs.
- After confirming an incident, the first priority in most questions is containment to limit damage. Recovery restores operations; remediation fixes the root cause; lessons learned is the step most often skipped and the one that prevents recurrence.
- IDS detects, IPS prevents. Signature detection misses zero-day attacks; anomaly detection can catch them but with more false positives. Allow listing is stronger than deny listing because it blocks the unknown.
- Patches should be tested before production deployment and go through change management; emergency changes are still documented and reviewed afterward. Prioritize vulnerabilities by risk, meaning severity plus asset value, exposure and active exploitation, not by score alone.
- Incremental restores need the full plus every incremental; differential restores need the full plus only the last differential. Hot sites are fastest and costliest, cold sites slowest and cheapest. RAID and replication are availability controls, not backups.
- Know the test order from least to most disruptive: read-through (checklist), walkthrough (tabletop), simulation, parallel, full interruption. Parallel keeps production running; full interruption does not and needs senior management approval.
- When an answer choice protects human life, it is almost always correct. Fail-safe protects people and fail-secure protects assets. Duress systems let people comply with an attacker while silently raising the alarm.
Key terms
- Chain of custody
- The documented record of every person who handled evidence, when, and for what purpose, from collection to presentation.
- Order of volatility
- The practice of collecting the most short-lived data, such as memory, before more persistent data such as disk contents.
- Write blocker
- A hardware or software device that allows reading from storage media while preventing any writes to it.
- Forensic image
- A bit-for-bit copy of storage media, verified by hash, used for analysis instead of the original.
- Best evidence rule
- A legal principle that prefers original documents over copies as evidence.
- Enticement
- Offering an opportunity to someone already inclined to commit an offense, which is generally legal, unlike entrapment.
- Security information and event management (SIEM)
- A system that collects, normalizes, stores and correlates logs from many sources to detect security events.
- Security orchestration, automation and response (SOAR)
- A platform that runs automated playbooks across security tools to speed and standardize response.
- User and entity behavior analytics (UEBA)
- Analytics that baseline normal behavior of users and devices and flag anomalies.
- Continuous monitoring
- Ongoing observation of controls, configurations and threats to support risk-based decisions.
- Indicator of compromise (IOC)
- An observable artifact, such as a file hash or malicious domain, that suggests a system has been compromised.
- Threat hunting
- A proactive, hypothesis-driven search for attackers who have evaded existing detections.
- Alert fatigue
- Desensitization of analysts caused by excessive, often false, alerts, leading to missed real incidents.
- Configuration management (CM)
- The process of establishing and maintaining systems in a known, approved and secure state.
- Configuration item (CI)
- A component tracked under configuration management, such as a server, application or setting.
- Configuration management database (CMDB)
- A repository of configuration items, their attributes and their relationships.
- Baseline
- The approved minimum secure configuration for a type of system, also used as a reference to detect drift.
- Golden image
- A hardened, approved system image used to provision new systems consistently.
- Configuration drift
- Divergence of a system's actual configuration from its approved baseline.
- Immutable infrastructure
- An approach in which running systems are replaced from updated images rather than modified in place.
- Need to know
- Restricting access to specific information to people whose current duties require it.
- Least privilege
- Granting only the minimum rights and permissions, for the minimum time, needed to perform a function.
- Separation of duties
- Dividing a sensitive task among multiple people so no single person can complete it alone.
- Collusion
- Two or more people cooperating to bypass controls such as separation of duties.
- Job rotation
- Periodically moving staff between roles to cross-train and to help detect fraud.
- Privilege creep
- The gradual accumulation of access rights as a person changes roles without old rights being removed.
- Service level agreement (SLA)
- A formal agreement defining the level of service a provider commits to and the remedies if targets are missed.
- Data remanence
- Residual data that remains on media after deletion or formatting and may be recoverable.
- Clearing
- Sanitization using logical techniques such as overwriting, protecting against simple non-invasive recovery.
- Purging
- Sanitization using stronger methods, such as cryptographic erase or degaussing, that protect against laboratory recovery.
- Destruction
- Physically rendering media unusable through shredding, disintegration, pulverizing or incineration.
- Degaussing
- Erasing magnetic media with a strong magnetic field; it does not work on SSDs or optical media.
- 3-2-1 backup rule
- Keeping at least three copies of data on two types of media with one copy offsite.
- Immutable backup
- A backup copy that cannot be modified or deleted for a set period, protecting it from ransomware.
- Event
- Any observable occurrence in a system or network.
- Incident
- An event or series of events that actually or potentially harms confidentiality, integrity or availability, or violates policy.
- Triage
- Rapid assessment of an incident to determine its validity, severity and priority.
- Containment (mitigation)
- Actions that limit the spread and impact of an incident, such as isolating hosts or disabling accounts.
- Recovery
- Restoring affected systems and data to normal operation.
- Remediation
- Fixing the root cause so the incident cannot recur the same way.
- Lessons learned
- A post-incident review that identifies improvements to controls, plans and training.
- Stateful inspection firewall
- A firewall that tracks connection state and allows return traffic for established sessions.
- Intrusion detection system (IDS)
- A passive, detective control that monitors activity and alerts on suspected attacks.
- Intrusion prevention system (IPS)
- An inline, preventive control that can block traffic it identifies as malicious.
- Allow list
- A list of explicitly approved items, with everything else denied by default.
- Sandbox
- An isolated environment for safely running and observing suspicious code.
- Honeypot
- A decoy system with no legitimate use, so any interaction signals suspicious activity.
- Endpoint detection and response (EDR)
- Endpoint software that records activity, detects attacker techniques and supports response actions.
- Vulnerability management
- The continuous cycle of discovering, prioritizing, remediating and verifying weaknesses.
- Authenticated scan
- A vulnerability scan that logs in to systems to see installed software and settings, giving more accurate results.
- Patch management
- The process of acquiring, testing, approving, deploying and verifying software updates.
- Zero-day vulnerability
- A flaw that is exploited before a vendor fix is available.
- Change advisory board (CAB)
- The group that reviews and approves or rejects significant changes.
- Emergency change
- A change implemented quickly to address an urgent issue, documented and reviewed after the fact.
- Rollback plan
- Documented steps to return a system to its previous state if a change fails.
- Recovery time objective (RTO)
- The target time within which a function or system must be restored after disruption.
- Recovery point objective (RPO)
- The maximum acceptable amount of data loss, measured as time since the last good copy.
- Maximum tolerable downtime (MTD)
- The longest a function can be unavailable before the organization suffers unacceptable harm.
- Incremental backup
- A backup of data changed since the last backup of any type, which clears the archive bit.
- Differential backup
- A backup of data changed since the last full backup, which does not clear the archive bit.
- Hot site
- A fully equipped alternate site with current data that can take over within hours or less.
- Remote journaling
- Frequently transmitting transaction logs offsite so a database can be restored by replaying them.
- Disaster recovery plan (DRP)
- The documented procedures for restoring IT systems and data after a disruptive event.
- Read-through (checklist) test
- Individual review of the plan to confirm it is accurate, complete and current.
- Walkthrough (tabletop) test
- A group discussion of a disaster scenario, stepping through the plan to find gaps.
- Simulation test
- A more detailed scenario exercise that may practice procedures without moving production.
- Parallel test
- Bringing up systems at the recovery site and processing data while the primary site continues production.
- Full-interruption test
- Shutting down the primary site and moving operations entirely to the recovery site.
- Salvage team
- The team responsible for assessing and restoring the primary site after a disaster.
- Business continuity planning (BCP)
- Planning to keep critical business functions operating during and after a disruption.
- Crime prevention through environmental design (CPTED)
- Using building and landscape design, such as lighting and sight lines, to deter crime.
- Mantrap (access control vestibule)
- A small space with two interlocking doors that allows only one authorized person through at a time.
- Fail-safe
- A design in which a failure leaves a system in a state that protects people, such as doors unlocking on power loss.
- Fail-secure
- A design in which a failure leaves a system locked or closed to protect assets.
- Duress code
- A covert signal, such as a special PIN, that lets a person under threat alert security while appearing to comply.
- Occupant emergency plan
- A plan describing how building occupants evacuate or shelter during an emergency.
Domain 8: Software development security (10%)
Exam tips
- The exam favors building security in from the earliest phase, requirements and design, because that is where flaws are cheapest to fix. DevSecOps means automation and shared responsibility, not a separate security gate at the end.
- Memorize the CMM levels in order: initial, repeatable, defined, managed, optimizing. Level 5 is continuous improvement. SAMM is prescriptive and specific to software security; BSIMM describes what organizations actually do.
- If a question asks how to ensure security is considered throughout development, look for including security personnel in cross-functional teams from the start rather than adding a review at the end. Development infrastructure is part of the attack surface.
- Treat the build pipeline and repositories as production-grade assets. Common exam answers: SCA for third-party library risk, branch protection and code review for repository integrity, and a secrets manager instead of hard-coded credentials.
- Match tool to situation: no running app yet and need exact code lines, SAST; running app, attacker's view, source unavailable, DAST; open-source dependency risk, SCA; instrumented running app with low false positives, IAST.
- Logs must capture enough to reconstruct events (who, what, when, where, outcome) but never secrets like passwords or session tokens. Risk analysis prioritizes by likelihood and impact, and residual risk needs formal acceptance by an owner.
- The organization remains accountable for its data regardless of model. In IaaS the customer manages the most; in SaaS the least, but always data, identities and configuration. For COTS, escrow protects against vendor failure.
- Server-side input validation with allow lists and context-aware output encoding are the cornerstone answers for injection and XSS questions. For APIs, remember object-level authorization: verify the caller may access each specific record, not just that they are logged in.
- The strength of software-defined security is centralized, automated, consistent policy; its main risk is that the controller or management plane becomes a single high-value target, and mistakes propagate at machine speed.
- Distinguish XSS from CSRF: XSS runs attacker script in the victim's browser (the user trusts the site); CSRF sends forged requests using the victim's session (the site trusts the browser). Parameterized queries are the best single answer for SQL injection.
Key terms
- Software development lifecycle (SDLC)
- The structured process for planning, building, testing, deploying, operating and retiring software.
- Waterfall
- A sequential development model in which each phase is completed before the next begins.
- Spiral model
- An iterative model that repeats planning, risk analysis, engineering and evaluation in each loop.
- Agile
- An iterative approach that delivers working software in short sprints and adapts to change.
- DevSecOps
- Integrating security practices and automation into DevOps as a shared responsibility.
- Shift left
- Moving security activities earlier in the development lifecycle.
- Definition of done
- The agreed criteria, which can include security checks, that work must meet to be considered complete.
- Capability Maturity Model (CMM)
- A five-level model describing process maturity from initial to optimizing.
- Capability Maturity Model Integration (CMMI)
- The successor to CMM that integrates process improvement across disciplines.
- Software Assurance Maturity Model (SAMM)
- An open OWASP framework for assessing and improving software security practices across five business functions.
- Building Security In Maturity Model (BSIMM)
- A descriptive model reporting the software security activities organizations actually perform.
- Optimizing level
- The highest CMM level, focused on continuous process improvement.
- Regression testing
- Testing after a change to confirm that previously working functions still work.
- Integrated product team (IPT)
- A cross-functional team that includes all disciplines needed to deliver a product, including security.
- Security champion
- A team member with extra security training who acts as the team's first point of contact for security.
- Software supply chain
- All the components, tools, services and people involved in producing and delivering software.
- Software bill of materials (SBOM)
- An inventory of the components and dependencies that make up a piece of software.
- Threat modeling
- A structured analysis of how a system could be attacked and which controls are needed.
- Development ecosystem
- The people, tools, infrastructure and suppliers used to build and deliver software.
- Memory-safe language
- A language that prevents or manages memory errors such as buffer overflows by design.
- Software composition analysis (SCA)
- Tooling that identifies third-party components and their known vulnerabilities and licenses.
- Dependency confusion
- An attack in which a public package with the same name as an internal one is fetched by the build instead.
- Branch protection
- Repository rules that require reviews or checks before changes are merged into important branches.
- Secrets manager
- A service that stores and issues credentials and keys securely instead of embedding them in code.
- Continuous integration and continuous delivery (CI/CD)
- Automated pipelines that build, test and deploy code changes.
- Artifact signing
- Digitally signing build outputs so their origin and integrity can be verified before deployment.
- Static application security testing (SAST)
- White-box analysis of source code, bytecode or binaries without running the program.
- Dynamic application security testing (DAST)
- Black-box testing of a running application by sending requests and analyzing responses.
- Interactive application security testing (IAST)
- Instrumentation inside a running application that observes execution during testing to confirm vulnerabilities.
- Runtime application self-protection (RASP)
- Instrumentation in a production application that detects and blocks attacks from within.
- Transitive dependency
- A component your application depends on indirectly, through another dependency.
- Source and sink
- In data-flow analysis, the point where untrusted input enters and the sensitive operation it may reach.
- Process audit
- A review of whether required development and security practices were actually followed, often by sampling.
- Security log
- A record of security-relevant events capturing who, what, when, where and outcome.
- Log injection
- Inserting crafted input into logs to forge entries or mislead analysis, prevented by encoding logged input.
- STRIDE
- A threat classification: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
- Residual risk
- The risk that remains after controls are applied, which must be formally accepted by an owner.
- Vulnerability density
- The number of vulnerabilities relative to the size of the codebase or application, used to compare and trend quality.
- Commercial off-the-shelf (COTS)
- Software bought from a vendor for general use, typically without access to source code.
- Source code escrow
- An arrangement in which a third party holds a vendor's source code for release to the customer under agreed conditions, such as vendor failure.
- Shared responsibility model
- The division of security duties between a cloud provider and customer, varying across IaaS, PaaS and SaaS.
- Infrastructure as a service (IaaS)
- A cloud model providing virtual compute, storage and networks, with the customer managing operating systems and above.
- Platform as a service (PaaS)
- A cloud model providing a managed platform and runtime on which the customer deploys its code.
- Software as a service (SaaS)
- A cloud model providing a complete application, with the customer managing data, users and configuration.
- Due diligence
- The investigation and assessment performed before and during a relationship to understand and manage its risks.
- Common Weakness Enumeration (CWE)
- A catalog of software and hardware weakness types, including a list of the most dangerous.
- Input validation
- Checking that input matches expected type, length, format and range, ideally against an allow list on the server.
- Output encoding
- Converting data so it is treated as data, not code, in the context where it is displayed or used.
- Parameterized query
- A database query in which user input is passed separately from the SQL text, preventing injection.
- Broken object-level authorization (BOLA)
- An API flaw in which the server returns objects without checking that the caller may access them.
- Maintenance hook
- An undocumented entry point left in code that bypasses normal security controls.
- Fail securely
- Designing errors to deny access by default and reveal minimal information.
- Software-defined networking (SDN)
- An architecture that separates the network control plane from the data plane so traffic is managed centrally through software.
- Control plane
- The layer that makes decisions about policy and traffic flow.
- Data plane
- The layer that forwards traffic according to the control plane's instructions.
- Micro-segmentation
- Fine-grained security policy between individual workloads to limit lateral movement.
- Policy as code
- Security and compliance rules written in machine-readable form so they can be versioned and tested automatically.
- Software-defined perimeter (SDP)
- An approach that hides services until users and devices are authenticated and authorized, creating per-session access.
- Injection
- A flaw where untrusted input is interpreted as part of a command or query.
- Cross-site scripting (XSS)
- A flaw that lets attacker-supplied script run in a victim's browser in the context of a trusted site.
- Cross-site request forgery (CSRF)
- An attack that makes an authenticated user's browser send an unwanted request to a trusting site.
- Buffer overflow
- Writing more data into a memory buffer than it can hold, overwriting adjacent memory.
- Time-of-check to time-of-use (TOCTOU)
- A race condition where a condition changes between being checked and being used.
- Insecure deserialization
- Rebuilding objects from untrusted serialized data in a way that allows manipulation or code execution.
- Content Security Policy (CSP)
- A browser security header that restricts where scripts and other content may load from, limiting XSS impact.
Study CISSP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISSP study planLessons, quizzes, exam simulations and hands-on labs.