All certifications / Security+ / Cheat sheet
Security+ SY0-701 cheat sheet
Domain 1: General security concepts (12%)
Exam tips
- Category asks 'how is it implemented', type asks 'what does it do'. If an answer choice mixes the two lists, such as 'preventive' offered for a category question, eliminate it.
- When a question says the normal control 'cannot' be applied, look for compensating. When a control only discourages but would not physically stop a determined attacker, it is deterrent, not preventive.
- Hashing gives integrity, encryption gives confidentiality, and digital signatures give integrity plus non-repudiation. Symmetric encryption can never give non-repudiation because both parties share the key.
- Decision is control plane (policy engine and policy administrator); enforcement is data plane (PEP). If an answer puts the PEP in the control plane, it is wrong.
- Honeypot is a fake system, honeynet is a fake network of systems, honeytoken is fake data. All are primarily detective: any interaction is suspicious because nothing legitimate should touch them.
- If a question says a failed change could not be reversed quickly, the missing piece is the backout plan. If it says a dependency broke unexpectedly, the missing piece is impact analysis.
- Symmetric for speed and bulk data, asymmetric for key exchange and signatures, and hybrid in practice. To send a secret, use the recipient's public key; to sign, use your own private key.
- Salt defeats rainbow tables and hides duplicate passwords; key stretching slows brute force. Hashing is for integrity and is never 'decrypted'.
- Match the level to the threat: stolen device means full disk; single file sharing means file-level; insider or compromised DB account reading sensitive fields means record or column-level.
- Tokenization has no key or math link to the original, so stolen tokens are worthless; masking hides data on display or in copies; steganography hides that data exists at all.
- Encrypt with the recipient's public key; sign with your own private key. Escrow encryption keys for recovery, but never signing keys, because that would undermine non-repudiation.
- Wildcard means one level of subdomains under a single domain; SAN means a list of specific names, possibly across different domains.
- CRL is a whole list downloaded periodically; OCSP is a per-certificate real-time query; stapling moves the OCSP query to the server, which delivers the CA-signed answer in the handshake.
- Sign with the sender's private key; verify with the sender's public key. A signature gives integrity, authentication and non-repudiation, but not confidentiality.
- TPM equals one device (boot integrity, disk encryption); HSM equals enterprise-scale key vault and crypto processor; KMS equals lifecycle management; secure enclave equals isolated processor area for secrets and data in use.
- Match the control to the layer: Layer 2 attacks need switch features, Layer 3 and 4 attacks need routers and firewalls, and Layer 7 attacks like SQL injection or HTTP floods need a WAF or application-aware controls.
- SFTP runs over SSH on port 22; FTPS is FTP plus TLS. Both are secure, but they are different protocols, and the exam loves to swap them.
- Know the secure-versus-insecure pairs by port: 22 vs 23, 443 vs 80, 636 vs 389, 993 vs 143, 995 vs 110. If a question asks which port to allow for secure directory access, the answer is 636, not 389.
- ARP poisoning is Layer 2 and local-network only. If users reach a fake site even with correct ARP entries, suspect DNS poisoning. If clients receive the wrong gateway, suspect a rogue DHCP server.
Key terms
- Technical control
- A control enforced by hardware, software or firmware, such as a firewall, encryption or MFA.
- Managerial control
- A control that directs or governs security, such as a policy, risk assessment or vendor assessment; also called administrative.
- Operational control
- A control carried out by people in daily work, such as guards, backup procedures or delivering training.
- Physical control
- A control that protects tangible spaces and objects, such as fences, locks, bollards and cameras.
- Control category
- How a control is implemented and by whom; separate from control type, which describes what it does.
- Defense in depth
- Layering several different controls so that the failure of one does not expose the asset.
- Preventive control
- Stops an incident before it happens, such as a firewall rule, lock or MFA.
- Deterrent control
- Discourages an attacker from trying, such as a warning sign, visible camera or login banner.
- Detective control
- Identifies or records an incident, such as an IDS, SIEM alert, audit or log review.
- Corrective control
- Limits damage and restores normal operation after an incident, such as restoring backups or reimaging.
- Compensating control
- An alternative control used when the primary control cannot be implemented, addressing the same risk.
- Directive control
- Instructs people on required behavior, such as a policy, procedure or acceptable use agreement.
- Confidentiality
- Ensuring only authorized parties can access information.
- Integrity
- Ensuring information is accurate and unchanged except by authorized processes.
- Availability
- Ensuring systems and data are accessible to authorized users when needed.
- Authentication
- Proving a claimed identity, for example with a password, token, certificate or biometric.
- Authorization
- Determining what an authenticated subject is allowed to do.
- Accounting
- Recording user activity so it can be reviewed, audited or billed.
- Non-repudiation
- Assurance that someone cannot deny an action, typically provided by digital signatures.
- Zero trust
- A security model that removes implicit trust based on network location and verifies every access request.
- Control plane
- The part of a zero trust architecture that manages policy and makes access decisions.
- Data plane
- The part of a zero trust architecture where traffic flows and access decisions are enforced.
- Policy engine
- The control plane component that evaluates a request against policy and decides to grant, deny or revoke.
- Policy administrator
- The control plane component that carries out the engine's decision by establishing or ending sessions.
- Policy enforcement point (PEP)
- The data plane component between subject and resource that allows, monitors or terminates connections.
- Adaptive identity
- Adjusting authentication requirements based on risk signals such as location, device and behavior.
- Implicit trust zone
- The area behind a PEP where traffic is trusted after passing the check; kept as small as possible.
- Bollard
- A short, sturdy post that blocks vehicles from reaching entrances or buildings.
- Access control vestibule
- A small room with two interlocking doors that allows one person through at a time; also called a mantrap.
- Tailgating
- Following an authorized person through a secured entrance without their knowledge; piggybacking is with their consent.
- Honeypot
- A decoy system with no legitimate use, designed to attract attackers and detect their activity.
- Honeynet
- A network of honeypots that simulates a real environment to observe attacker behavior.
- Honeytoken
- Fake data, such as a bogus account, record or credential, that triggers an alert when used or accessed.
- DNS sinkhole
- A DNS server configuration that returns a controlled address for known-malicious domains to disrupt and detect malware.
- Change management
- The formal process for requesting, approving, testing, implementing and documenting changes.
- Change advisory board (CAB)
- The group that reviews and approves or rejects significant changes.
- Impact analysis
- An assessment of what a change could affect, how badly and how likely, before it is approved.
- Backout plan
- Documented steps to return a system to its previous state if a change fails.
- Maintenance window
- A pre-agreed time when changes are allowed because business impact is lowest.
- Stakeholder
- Anyone affected by a change who should be consulted or informed.
- Version control
- Tracking changes to code or configuration over time so they can be reviewed and reverted.
- Symmetric encryption
- Encryption that uses the same secret key to encrypt and decrypt; fast and suited to bulk data.
- Asymmetric encryption
- Encryption that uses a public/private key pair; slower but solves key distribution and enables signatures.
- AES
- Advanced Encryption Standard, the current standard symmetric block cipher with 128-, 192- or 256-bit keys.
- ECC
- Elliptic curve cryptography, an asymmetric approach offering strong security with smaller keys.
- Diffie-Hellman
- A key agreement method that lets two parties derive a shared secret over an untrusted network.
- Session key
- A temporary symmetric key used to encrypt one communication session.
- Perfect forward secrecy
- Use of ephemeral keys so that compromise of a long-term key does not expose past sessions.
- Hash
- A fixed-length, one-way output of a hash function used to verify integrity.
- Collision
- Two different inputs that produce the same hash, which breaks a hash function's security.
- Salt
- A random, per-user value added to a password before hashing to make each hash unique.
- Rainbow table
- A precomputed table of hashes and matching passwords used to reverse unsalted hashes quickly.
- Key stretching
- Repeating or strengthening a hash so each guess is slow, using algorithms like PBKDF2, bcrypt or Argon2.
- HMAC
- A hash-based message authentication code that combines a hash with a secret key for integrity and authenticity.
- Pepper
- A secret value added to passwords before hashing that is stored separately from the password database.
- Full disk encryption (FDE)
- Encrypting an entire drive, including the OS, so data is unreadable without the key when the device is off.
- Self-encrypting drive (SED)
- A drive that performs full disk encryption in its own hardware.
- Volume encryption
- Encrypting a specific partition or logical volume rather than the whole disk.
- File-level encryption
- Encrypting individual files or folders, often tied to specific users.
- Transparent data encryption (TDE)
- Database encryption of data and log files at rest, decrypted automatically for authorized queries.
- Record-level encryption
- Encrypting individual records or fields, such as card numbers, within a database.
- Obfuscation
- Making data difficult to understand or recognize, with or without encryption.
- Steganography
- Hiding data inside another file or medium so its existence is concealed.
- Tokenization
- Replacing a sensitive value with a random token that can only be mapped back through a secure vault.
- Token vault
- The protected system that stores the mapping between tokens and original sensitive values.
- Data masking
- Hiding part or all of a data value, such as showing only the last four digits of a card.
- Static masking
- Permanently replacing sensitive values in a copy of data, often for testing.
- Dynamic masking
- Hiding data at display time based on the viewer's role while stored data stays unchanged.
- Public key
- The shareable half of a key pair, used to encrypt data for the owner or verify the owner's signatures.
- Private key
- The secret half of a key pair, used to decrypt data sent to the owner or create digital signatures.
- Key pair
- A mathematically linked public and private key used in asymmetric cryptography.
- Key escrow
- Storing a copy of a key with a trusted party or system so it can be recovered when needed.
- Key rotation
- Replacing keys periodically or after suspected compromise to limit exposure.
- Dual control
- Requiring two or more authorized people to perform a sensitive action, such as recovering an escrowed key.
- Public key infrastructure (PKI)
- The CAs, certificates, policies and processes used to manage and trust public keys.
- Certificate authority (CA)
- A trusted entity that validates identities and signs digital certificates.
- Certificate signing request (CSR)
- A request containing a public key and identity details, sent to a CA to obtain a certificate.
- Root of trust
- The trusted anchor, usually a root CA certificate preinstalled in the trust store, from which trust chains are built.
- Intermediate CA
- A CA signed by the root that issues end-entity certificates, keeping the root offline.
- Self-signed certificate
- A certificate signed with its own private key rather than by a trusted CA.
- Wildcard certificate
- A certificate for all first-level subdomains of a domain, such as *.example.com.
- Subject Alternative Name (SAN)
- A certificate field listing multiple specific host names or domains the certificate is valid for.
- Revocation
- Invalidating a certificate before its expiration date, for example after key compromise.
- Certificate revocation list (CRL)
- A CA-signed list of revoked certificate serial numbers published periodically.
- CRL distribution point
- A field in a certificate that tells clients where to download the CRL.
- OCSP
- Online Certificate Status Protocol, which returns the real-time status of a single certificate.
- OCSP responder
- The CA server that answers OCSP requests with signed good, revoked or unknown responses.
- OCSP stapling
- The server attaches a recent CA-signed OCSP response to its certificate during the TLS handshake.
- Soft fail
- A client behavior that accepts a certificate when revocation status cannot be checked.
- Digital signature
- A value created with a private key over a message's hash, proving integrity, origin and non-repudiation.
- Message digest
- The fixed-length hash of a message that is actually signed.
- Signing
- Using the signer's private key to create a signature over a digest.
- Verification
- Using the signer's public key to check a signature against a freshly computed hash.
- Code signing
- Digitally signing software so users can verify its publisher and that it was not modified.
- ECDSA
- Elliptic Curve Digital Signature Algorithm, a common signature algorithm using elliptic curve keys.
- Trusted Platform Module (TPM)
- A chip on a device's motherboard that securely stores keys and boot measurements for that device.
- Measured boot
- Recording hashes of boot components so their integrity can be checked or attested.
- Hardware security module (HSM)
- A tamper-resistant appliance or service that generates, stores and uses keys for many systems.
- Secure enclave
- An isolated, protected processor environment that keeps secrets and code separate from the main OS.
- Key management system (KMS)
- Software and processes that manage keys through their lifecycle, including rotation and auditing.
- Remote attestation
- A device proving its boot and configuration state to a remote server, typically using its TPM.
- Non-exportable key
- A key that can be used inside secure hardware but never extracted from it.
- OSI model
- A seven-layer conceptual model describing how network communication is divided into functions.
- Encapsulation
- Wrapping data from a higher layer with each lower layer's header as it moves down the stack.
- Layer 2 (Data Link)
- The layer that moves frames between devices on the same local network using MAC addresses.
- Layer 3 (Network)
- The layer that routes packets between networks using IP addresses.
- Layer 4 (Transport)
- The layer that provides end-to-end delivery using TCP or UDP and port numbers.
- Layer 7 (Application)
- The layer where user-facing protocols such as HTTP, DNS and SMTP operate.
- SYN flood
- A Layer 4 denial-of-service attack that exhausts a server with half-open TCP connections.
- Telnet
- A cleartext remote terminal protocol on TCP 23, replaced by SSH.
- SSH
- Secure Shell, an encrypted remote access and tunneling protocol on TCP 22.
- SFTP
- SSH File Transfer Protocol, which transfers files over an encrypted SSH connection.
- FTPS
- FTP secured with TLS, a different protocol from SFTP.
- LDAPS
- LDAP over TLS, typically on TCP 636, protecting directory queries and binds.
- SNMPv3
- The version of SNMP that adds authentication, integrity and encryption with per-user credentials.
- HSTS
- HTTP Strict Transport Security, which tells browsers to use only HTTPS for a site.
- Port
- A number that identifies a specific service or application on a host.
- Port 22
- SSH, SFTP and SCP for encrypted remote access and file transfer.
- Port 25
- SMTP, used to deliver email between mail servers.
- Port 53
- DNS, using UDP for most queries and TCP for zone transfers and large responses.
- Ports 389 and 636
- LDAP (cleartext or StartTLS) and LDAPS (LDAP over TLS) respectively.
- Port 3389
- Remote Desktop Protocol for graphical remote access to Windows systems.
- Port 443
- HTTPS, web traffic protected by TLS.
- ARP poisoning
- Sending forged ARP replies to associate the attacker's MAC address with another host's IP, enabling on-path attacks.
- DNS poisoning
- Inserting false records into a DNS resolver's cache so users are redirected to malicious addresses.
- Rogue DHCP server
- An unauthorized DHCP server that hands out incorrect settings such as a malicious gateway or DNS server.
- DHCP starvation
- Exhausting a DHCP server's address pool with requests from fake MAC addresses.
- DHCP snooping
- A switch feature that allows DHCP server responses only on trusted ports.
- Dynamic ARP inspection
- A switch feature that drops ARP messages that do not match trusted IP-to-MAC bindings.
- DNSSEC
- DNS Security Extensions, which digitally sign DNS records so resolvers can verify their authenticity and integrity.
Domain 2: Threats, vulnerabilities & mitigations (22%)
Exam tips
- Decide by motivation and resources, not by the target: espionage with long dwell time and zero-days is nation-state, money is organized crime, a cause is a hacktivist, and legitimate access is an insider.
- Look at what the attacker did after getting in: quiet theft over time suggests espionage, a ransom demand suggests financial gain, public embarrassment suggests ideology, and a grievance suggests revenge.
- Distinguish vector, vulnerability and actor: the vector is how they got in (email, USB, MSP), the vulnerability is the weakness they used, and the actor is who they are.
- BEC is about fraudulent payments and often uses no malware, so the best control is a process: out-of-band verification and dual approval for payment or bank changes.
- SSRF means the server is tricked into making the request; CSRF means the user's browser is tricked. For injection, the best answer is almost always parameterized queries, not just input validation.
- Stored XSS is saved on the server and hits every viewer; reflected XSS bounces off the server in one crafted request. CSRF abuses the site's trust in the user's browser, while XSS abuses the user's trust in the site.
- TOCTOU is about the gap between checking and using, so the fix is to make them one atomic step. Buffer overflows are about writing past a fixed size, so the fix is bounds checking, helped by DEP and ASLR.
- Map STRIDE letters to the security property they violate: spoofing breaks authentication, tampering breaks integrity, repudiation breaks non-repudiation, information disclosure breaks confidentiality, denial of service breaks availability, elevation of privilege breaks authorization.
- Virus needs a user to run an infected file; worm spreads by itself. Logic bomb waits for a condition; rootkit hides itself. Fileless malware lives in memory and abuses built-in tools.
- Account lockout defeats online brute force but not spraying or offline cracking. MFA is the best general answer, and 'one password, many accounts' always means spraying.
- Downgrade attacks exploit whatever weak option is still enabled, so the fix is to disable it. Birthday attacks halve a hash's effective strength against collisions, so the fix is a longer, modern hash.
- Missing or cleared logs are an indicator in their own right. When one indicator appears, look for others on the same account or host; correlation is what turns a clue into an incident.
- VLANs create separation, but firewalls or ACLs between them create security. If a question asks how to limit lateral movement or protect an unpatchable device, segmentation or isolation is usually the answer.
- ACLs are processed top-down with first match wins and an implicit deny at the end. If a specific deny is placed after a broad permit, the deny never takes effect.
- Allow listing is default-deny for software, so it stops unknown and zero-day executables that signature-based antivirus misses. Hash rules are precise but break on updates; publisher rules survive updates.
- If a question mentions a vulnerability that cannot be patched yet, look for compensating controls like segmentation or virtual patching, not 'accept the risk' unless the scenario says it is formally approved.
- Hardening means removing and restricting: fewer services, fewer ports, fewer accounts, less software, and no default passwords. A baseline plus drift detection keeps it that way.
Key terms
- Threat actor
- The individual or group responsible for a threat or attack.
- Nation-state actor
- A government-sponsored group with high resources and sophistication, often conducting espionage or sabotage.
- Advanced persistent threat (APT)
- A long-term, stealthy campaign by a skilled, well-resourced actor that maintains access to a target.
- Organized crime
- Financially motivated criminal groups running operations such as ransomware and fraud.
- Hacktivist
- An actor who attacks to promote a political or social cause, often through defacement, DDoS or leaks.
- Unskilled attacker
- An attacker who relies on tools and exploits created by others; formerly called a script kiddie.
- Insider threat
- A risk from someone with legitimate access, whether malicious or accidental.
- Shadow IT
- Technology used within an organization without approval from IT or security.
- Espionage
- Covertly gathering secret or sensitive information for a government or competitor.
- Data exfiltration
- Unauthorized transfer of data out of an organization's environment.
- Financial gain
- Attacking for money, through ransomware, fraud, theft or selling data.
- Blackmail (extortion)
- Threatening to release data or continue harm unless the victim pays or complies.
- Double extortion
- Ransomware that both encrypts data and threatens to publish stolen copies.
- Service disruption
- Attacking to make systems or services unavailable.
- Cryptojacking
- Secretly using a victim's computing resources to mine cryptocurrency.
- Threat vector
- The path or method an attacker uses to reach a target; also called an attack vector.
- Attack surface
- The total set of points where an attacker could try to enter or extract data.
- Smishing
- Phishing delivered by SMS text message.
- Vishing
- Phishing conducted over voice calls.
- Baiting
- Leaving infected media or offering something tempting so a victim introduces malware themselves.
- Supply chain attack
- Compromising a target through a trusted supplier, vendor, software update or service provider.
- Unsupported system
- A system past end of life that no longer receives security updates.
- Default credentials
- Factory-set usernames and passwords that attackers know and try first.
- Phishing
- Fraudulent messages, usually email, that trick recipients into revealing information or running malware.
- Spear phishing
- Phishing targeted at a specific person or group using tailored details.
- Whaling
- Spear phishing aimed at senior executives.
- Pretexting
- Creating an invented but believable scenario to justify a request for information or access.
- Business email compromise (BEC)
- Using a compromised or spoofed business email account to trick staff into sending money or data.
- Watering hole attack
- Compromising a website the target group commonly visits in order to infect its visitors.
- Typosquatting
- Registering misspelled versions of real domains to catch typos or make phishing look legitimate.
- Out-of-band verification
- Confirming a request through a separate, trusted channel such as a known phone number.
- OWASP Top 10
- A regularly updated list of the most critical web application security risk categories.
- Broken access control
- Failures that let users act outside their intended permissions, such as viewing others' records.
- Insecure direct object reference
- Accessing an object by changing an identifier because the server does not check authorization.
- Injection
- Sending untrusted input to an interpreter so it is executed as part of a command or query.
- Security misconfiguration
- Insecure defaults, unnecessary features, verbose errors or open storage that weaken an application.
- Software and data integrity failure
- Trusting code, updates or data without verifying their integrity, such as unsigned updates or insecure deserialization.
- Server-side request forgery (SSRF)
- Tricking a server into making requests to destinations the attacker chooses, often internal systems.
- SQL injection
- Inserting SQL syntax into input that an application places into a database query, changing the query's meaning.
- Parameterized query
- A query with fixed structure where user input is passed separately as data; also called a prepared statement.
- Reflected XSS
- Script supplied in a request that the server immediately includes in its response to that victim.
- Stored XSS
- Script saved by the application and served to every user who views the affected content.
- Output encoding
- Converting special characters so browsers display untrusted data as text rather than executing it.
- CSRF
- Cross-site request forgery, which makes a logged-in user's browser send an unwanted request to a trusted site.
- Anti-CSRF token
- A random value tied to the session that must accompany state-changing requests, which attackers cannot guess.
- Buffer overflow
- Writing more data to a buffer than it can hold, overwriting adjacent memory.
- Race condition
- A flaw where the result depends on the timing of events that an attacker can influence.
- TOCTOU
- Time-of-check to time-of-use, a race condition where a resource changes between being checked and being used.
- Memory injection
- Placing and running malicious code inside the memory of a legitimate running process.
- DLL injection
- Forcing a running process to load a malicious dynamic link library.
- ASLR
- Address space layout randomization, which randomizes memory locations to make exploitation harder.
- DEP
- Data execution prevention, which marks data regions of memory as non-executable.
- Threat modeling
- A structured process for identifying and prioritizing threats to a system and planning mitigations.
- Data flow diagram
- A diagram showing how data moves between users, processes and stores, used as the basis for a threat model.
- Trust boundary
- A point where data moves between areas with different levels of trust.
- STRIDE
- A threat categorization: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
- Attack tree
- A diagram breaking an attacker's goal into the alternative ways it could be achieved.
- MITRE ATT&CK
- A public knowledge base of real-world adversary tactics and techniques.
- Cyber Kill Chain
- A model of intrusion stages from reconnaissance to actions on objectives.
- Ransomware
- Malware that encrypts data or systems and demands payment for recovery, often also stealing data.
- Trojan
- Malware disguised as legitimate software that the user installs willingly.
- Worm
- Self-replicating malware that spreads across networks without user action.
- Rootkit
- Malware that hides deep in the OS or firmware to conceal itself and maintain privileged access.
- Logic bomb
- Malicious code that triggers when a specific condition, such as a date or event, occurs.
- Keylogger
- Software or hardware that records keystrokes to capture sensitive input.
- Fileless malware
- Malware that runs in memory and abuses legitimate tools, leaving little or nothing on disk.
- Spyware
- Malware that secretly monitors and collects information about a user.
- Brute force attack
- Trying many possible passwords against an account until one works.
- Dictionary attack
- A guessing attack using lists of common words and known passwords.
- Password spraying
- Trying a few common passwords against many accounts to avoid lockout.
- Credential stuffing
- Using username and password pairs stolen from one breach to log in to other services.
- Offline attack
- Cracking stolen password hashes on the attacker's own hardware, where no lockout applies.
- Account lockout
- Disabling an account temporarily after a set number of failed login attempts.
- Passwordless authentication
- Logging in without a shared password, for example with passkeys or FIDO2 security keys.
- Downgrade attack
- Forcing parties to negotiate a weaker protocol version or cipher than both support.
- SSL stripping
- Rewriting HTTPS connections or links to plain HTTP so traffic is not encrypted.
- Collision
- Two different inputs that produce the same hash value.
- Birthday attack
- Exploiting probability to find hash collisions in roughly the square root of the possible hash values.
- Collision resistance
- The property that it is infeasible to find two inputs with the same hash.
- HSTS
- HTTP Strict Transport Security, a header that tells browsers to use only HTTPS for a site.
- Indicator
- An observable clue that suggests malicious activity may be occurring.
- Impossible travel
- Logins from locations too far apart to reach in the time between them.
- Concurrent session usage
- The same account active in multiple places at once when that is not normal.
- Resource consumption
- Unusual CPU, memory, disk or network use that may signal malware or exfiltration.
- Missing logs
- Gaps or deletions in logging, often caused by attackers covering their tracks.
- Out-of-cycle logging
- Activity recorded at unusual times for the user or system.
- Indicator of compromise (IoC)
- A specific artifact, such as a hash, IP address or domain, linked to known malicious activity.
- Segmentation
- Dividing a network into zones and controlling traffic between them to limit an attacker's reach.
- VLAN
- A virtual LAN that logically separates traffic on shared switch hardware.
- Screened subnet
- A zone between the internet and the internal network for public-facing servers; formerly called a DMZ.
- Microsegmentation
- Fine-grained segmentation that applies policy to individual workloads or applications.
- Lateral movement
- An attacker moving from one compromised system to others within a network.
- Air gap
- Physical isolation of a system or network from all other networks.
- Isolation
- Separating a system so it cannot communicate, used for high-risk systems or during incident response.
- Least privilege
- Granting only the minimum access needed to perform a task, for only as long as needed.
- Access control list (ACL)
- An ordered list of rules on a resource specifying which subjects are allowed or denied which access.
- Implicit deny
- The default rule that blocks anything not explicitly permitted.
- Privilege creep
- The gradual accumulation of unnecessary access as users change roles.
- Access review
- A periodic check where owners confirm that each user's access is still required.
- Need to know
- Restricting access to information to those who require it for a specific task.
- Separation of duties
- Splitting a sensitive process among several people so no one can complete it alone.
- Application allow listing
- Permitting only approved software to run and blocking everything else by default.
- Deny listing
- Blocking specific known-bad software while allowing everything else.
- Hash rule
- An allow list rule that approves a file by its exact cryptographic hash.
- Publisher rule
- An allow list rule that approves software signed by a trusted vendor's certificate.
- Path rule
- An allow list rule that approves programs in a specific folder location.
- Audit mode
- Running an allow list policy that logs would-be blocks without enforcing them.
- Living off the land
- Attackers using legitimate built-in tools to avoid detection and bypass controls.
- Patch management
- The process of identifying, testing, deploying and verifying software updates.
- Virtual patching
- Blocking exploitation of a vulnerability with a network control, such as an IPS or WAF rule, until a real patch is applied.
- End of life
- The point after which a vendor stops providing updates for a product.
- Encryption at rest
- Encrypting stored data on disks, databases or backups.
- Encryption in transit
- Encrypting data as it moves across networks, for example with TLS or a VPN.
- SIEM
- Security information and event management, which collects, correlates and alerts on logs from many sources.
- Asset inventory
- An accurate list of hardware and software, needed to know what to patch and monitor.
- Hardening
- Reducing a system's attack surface by removing unneeded components and securing its configuration.
- Secure baseline
- A documented, approved secure configuration applied consistently to systems.
- CIS Benchmarks
- Consensus-based secure configuration guides published by the Center for Internet Security.
- Configuration drift
- Gradual deviation of a system's settings from its approved baseline.
- Host-based firewall
- Firewall software on an individual system that controls its inbound and outbound traffic.
Domain 3: Security architecture (18%)
Exam tips
- Provider secures the cloud; customer secures what is in the cloud. In every model, including SaaS, the customer owns its data, identities and access configuration.
- Containers share the host kernel, so they are less isolated than virtual machines. With IaC, one bad template is replicated everywhere, so scan templates before deployment.
- VM escape is fixed mainly by patching the hypervisor and minimizing virtual hardware. VM sprawl is a governance problem, fixed by inventory, ownership and lifecycle rules.
- For ICS and SCADA, availability and safety come first. When a device cannot be patched, segmentation and isolation are the go-to compensating controls.
- No model is automatically most secure. Look for the scenario's deciding requirement: control and sovereignty point to on premises, elasticity points to cloud, and a mix of legacy and new points to hybrid.
- A WAF protects web servers from web attacks; an NGFW protects networks with application awareness; a Layer 4 firewall only sees addresses, ports and connection state.
- IDS equals passive and alerts (copy via tap or SPAN); IPS equals inline and blocks. A false negative is the most dangerous error because nobody knows an attack happened.
- Fail-open favors availability; fail-closed favors confidentiality and integrity. For doors, life safety wins: exit routes fail safe (unlocked).
- In 802.1X, supplicant is the client, authenticator is the switch or AP, and authentication server is RADIUS. Port security uses MAC addresses, which can be spoofed, so it is weaker than 802.1X.
- IPsec: AH gives integrity only, ESP adds encryption; tunnel mode wraps the whole packet (site-to-site), transport mode protects only the payload (host-to-host).
- The data owner decides the classification; the custodian implements the controls. Classification exists so that controls are proportional to sensitivity.
- Encryption at rest does nothing for data in transit, and neither helps data in use. Identify the state in the question, then pick the control that fits it.
- Ask whether the original must come back. Yes, by key holders: encryption. Yes, through a vault only: tokenization. No, just verify: hashing. Just hide on screen: masking. Stop it leaving: DLP.
- RAID protects against disk failure only; it is never a backup. Load balancers and clusters protect against server failure; backups protect against deletion, corruption and ransomware.
- RPO equals how much data you can lose (points back in time); RTO equals how long you can be down. Differential restores need full plus latest differential; incremental restores need full plus every incremental.
Key terms
- IaaS
- Infrastructure as a Service, providing virtual machines, storage and networks; the customer manages the OS and above.
- PaaS
- Platform as a Service, providing a managed platform where the customer deploys code and manages data and access.
- SaaS
- Software as a Service, a complete application run by the provider; the customer manages data, users and settings.
- Shared responsibility model
- The division of security duties between cloud provider and customer, varying by service model.
- Multitenancy
- Multiple customers sharing the same underlying cloud infrastructure while logically separated.
- Hybrid cloud
- A combination of on-premises or private infrastructure with public cloud services.
- CASB
- Cloud access security broker, which provides visibility and policy enforcement for cloud and SaaS use.
- Infrastructure as code (IaC)
- Defining and deploying infrastructure through machine-readable templates rather than manual setup.
- Serverless
- Running event-triggered functions without managing servers; the provider handles the underlying platform.
- Microservices
- An architecture that splits an application into small, independent services communicating over APIs.
- Container
- A lightweight package of an application and its dependencies that shares the host operating system kernel.
- Container image
- The template from which containers are created, which should be scanned and trusted.
- Orchestration
- Automated deployment, scaling and management of containers, for example with Kubernetes.
- Immutable infrastructure
- Replacing components with new versions rather than modifying them in place.
- Hypervisor
- Software that creates and manages virtual machines and keeps them isolated from each other.
- Type 1 hypervisor
- A bare-metal hypervisor that runs directly on hardware.
- Type 2 hypervisor
- A hosted hypervisor that runs as an application on a normal operating system.
- VM escape
- An attack in which code breaks out of a virtual machine to reach the hypervisor, host or other VMs.
- VM sprawl
- Uncontrolled growth of virtual machines that are unmanaged, unpatched or forgotten.
- Resource reuse
- The risk that data remains in memory or storage reassigned from one VM or tenant to another.
- Snapshot
- A saved state of a VM at a point in time, which may contain sensitive data and old vulnerabilities.
- Industrial control system (ICS)
- Systems that monitor and control physical industrial processes.
- SCADA
- Supervisory control and data acquisition, an ICS type that manages geographically distributed processes.
- PLC
- Programmable logic controller, a rugged computer that controls machinery in industrial settings.
- IoT
- Internet of Things, network-connected everyday devices such as cameras, sensors and smart appliances.
- Embedded system
- A computer built into another device to perform a dedicated function.
- RTOS
- Real-time operating system, designed to respond to events within strict, predictable time limits.
- Data diode
- A device that allows network traffic to flow in only one direction.
- On-premises
- Infrastructure owned and operated by the organization in its own facilities.
- Vendor lock-in
- Dependence on one provider's services that makes switching costly or difficult.
- Data sovereignty
- The principle that data is subject to the laws of the country where it is stored.
- Scalability
- The ability to increase or decrease capacity to match demand.
- Capital expenditure (CapEx)
- Up-front spending on assets such as servers, typical of on-premises infrastructure.
- Operating expenditure (OpEx)
- Ongoing pay-as-you-go spending, typical of cloud services.
- Stateless packet filter
- A firewall that evaluates each packet independently against address, protocol and port rules.
- Stateful firewall
- A firewall that tracks connection state and allows return traffic for established connections.
- Layer 7 firewall
- A firewall that understands and filters based on application protocols and content.
- Next-generation firewall (NGFW)
- A firewall combining stateful inspection, application awareness, user identity and integrated IPS.
- Web application firewall (WAF)
- A firewall that inspects HTTP/HTTPS traffic to protect web applications from attacks like SQL injection.
- Unified threat management (UTM)
- An all-in-one appliance combining firewall, IPS, antivirus, filtering and VPN functions.
- TLS inspection
- Decrypting and re-encrypting TLS traffic so a security device can inspect its contents.
- IDS
- Intrusion detection system, which monitors and alerts on suspicious activity without blocking it.
- IPS
- Intrusion prevention system, which sits inline and can block malicious traffic automatically.
- Inline
- Deployed directly in the traffic path so traffic must pass through the device.
- Network tap
- A hardware device that copies all traffic on a network link to a monitoring tool.
- SPAN port
- A switch port configured to mirror traffic from other ports to a monitoring device.
- Signature-based detection
- Detecting attacks by matching known patterns.
- Anomaly-based detection
- Detecting attacks by spotting deviations from a learned baseline of normal behavior.
- False negative
- A real attack that the system fails to detect.
- Fail-open
- A failure mode where a device allows traffic or access when it fails, favoring availability.
- Fail-closed
- A failure mode where a device blocks traffic or access when it fails, favoring security.
- Fail-safe (physical)
- A lock that unlocks on power loss so people can exit safely.
- Fail-secure (physical)
- A lock that stays locked on power loss to protect assets.
- Bypass module
- Hardware that passes traffic around an inline device if it fails, a fail-open design.
- High availability pair
- Two redundant devices where one takes over if the other fails.
- 802.1X
- An IEEE standard for port-based network access control using EAP and usually RADIUS.
- Supplicant
- The device or software requesting network access in 802.1X.
- Authenticator
- The switch or access point that enforces 802.1X by controlling the port.
- Authentication server
- The server, usually RADIUS, that checks credentials and approves or denies access.
- EAP-TLS
- An EAP method using certificates on both client and server for mutual authentication.
- Network access control (NAC)
- Checking identity and device posture before granting network access and enforcing policy.
- Port security
- A switch feature that restricts which and how many MAC addresses can use a port.
- Dissolvable agent
- A temporary NAC agent that checks a device's posture and then removes itself.
- Site-to-site VPN
- An encrypted tunnel connecting two networks, typically between gateways.
- Split tunnel
- A VPN setup where only corporate traffic uses the tunnel and other traffic goes directly to the internet.
- IPsec tunnel mode
- IPsec mode that encrypts the entire original packet and adds a new header, used between gateways.
- ESP
- Encapsulating Security Payload, the IPsec protocol that provides encryption plus integrity and authentication.
- SD-WAN
- Software-defined WAN, which manages and routes traffic across multiple links using policy.
- SASE
- Secure access service edge, which combines SD-WAN style networking with cloud-delivered security services.
- Jump server
- A hardened host that administrators connect through to reach sensitive systems.
- Reverse proxy
- A server that receives inbound requests on behalf of back-end servers.
- Data classification
- Labeling data by sensitivity and value so appropriate controls can be applied.
- PII
- Personally identifiable information that can identify an individual.
- PHI
- Protected health information, health data linked to an individual.
- Regulated data
- Data governed by laws or industry standards, such as card data or health records.
- Trade secret
- Confidential business information that provides a competitive advantage.
- Data owner
- The senior person accountable for data who decides its classification and access.
- Data custodian
- The role, often IT, that implements and maintains the controls the owner requires.
- Data at rest
- Data stored on disks, databases, backups or other media.
- Data in transit
- Data moving across a network; also called data in motion.
- Data in use
- Data being actively processed in memory or displayed.
- Transport encryption
- Protecting data in transit with protocols such as TLS, IPsec or SSH.
- Confidential computing
- Using hardware trusted execution environments to protect data while it is processed.
- Memory scraping
- Malware that reads sensitive data from a system's memory while it is in use.
- Encryption
- Reversible transformation of data using a key so only authorized holders can read it.
- Hashing
- One-way transformation producing a fixed-length value, used for integrity checks and password storage.
- Data masking
- Hiding part or all of a sensitive value from view.
- Tokenization
- Replacing sensitive data with a random token mapped back only through a secure vault.
- Data loss prevention (DLP)
- Tools and policies that detect and stop sensitive data from leaving authorized locations.
- Endpoint DLP
- DLP running on devices to control actions such as USB copying, printing and uploads.
- Geographic restriction
- Limiting where data may be stored or accessed from, for example by country.
- High availability
- Designing systems to keep running with minimal downtime through redundancy and failover.
- Single point of failure
- A component whose failure stops the whole system.
- Active-passive cluster
- A cluster where a standby node takes over if the active node fails.
- Active-active cluster
- A cluster where all nodes handle workload simultaneously.
- Load balancer
- A device or service that distributes requests across multiple servers and checks their health.
- RAID 5
- Disk striping with distributed parity across three or more disks, surviving one disk failure.
- RAID 6
- Disk striping with double parity, surviving two simultaneous disk failures.
- UPS
- Uninterruptible power supply, providing short-term battery power during outages.
- RPO
- Recovery point objective, the maximum acceptable data loss measured in time.
- RTO
- Recovery time objective, the maximum acceptable time to restore a service.
- MTBF
- Mean time between failures, the average time a component operates before failing.
- Incremental backup
- A backup of data changed since the last backup of any type.
- Differential backup
- A backup of data changed since the last full backup.
- Hot site
- A fully equipped, up-to-date recovery site ready to take over quickly.
- Cold site
- A recovery site with space and power but little or no equipment.
- Immutable backup
- A backup that cannot be modified or deleted for a defined retention period.
Domain 4: Security operations (28%)
Exam tips
- BYOD means the user owns it, so use containerization and selective wipe. COPE means the company owns it but allows personal use. CYOD means the user chooses from an approved list.
- SAE is WPA3's answer to offline cracking of pre-shared keys. For individual accountability, choose enterprise mode with 802.1X, RADIUS and ideally EAP-TLS.
- Sanitize when the media will be reused; destroy when it will not or the data is highly sensitive; certify to prove it. Formatting or deleting is never sanitization.
- Credentialed scans are more accurate and produce fewer false positives. CVE names the vulnerability; CVSS scores its severity; context decides priority.
- Passive recon never touches the target (OSINT, public records); active recon does (scans, banner grabs). No written authorization means it is not a pen test, it is an attack.
- SIEM correlates logs; NetFlow shows traffic metadata without content; SCAP standardizes automated compliance checks. Synchronized time is essential for all of them.
- SPF lists who may send, DKIM signs what was sent, DMARC decides what to do when they fail and reports back. None of them encrypt email or stop lookalike domains.
- EDR watches endpoints and responds; XDR correlates across many sources; DLP watches data leaving; UEBA watches users and entities for abnormal behavior.
- OAuth is authorization (what an app may access); OpenID Connect adds authentication (who the user is); SAML is XML-based SSO common in enterprises; LDAP queries directories.
- MFA means different categories: password plus PIN is still single-factor. Phishing-resistant MFA (FIDO2, passkeys) beats SMS and simple push, and JIT removes standing privileges attackers could steal.
- Contain before you eradicate: stop the spread first, then remove the cause. And preserve evidence during containment when possible, for example by isolating a host rather than powering it off.
- Tabletop equals discussion only, lowest cost and risk. Simulations and failover tests exercise real people and systems, giving more confidence at more cost and risk.
- Memory before disk (order of volatility); hash everything; work on copies; log every handoff (chain of custody); and when litigation is expected, suspend deletion (legal hold).
- Automation brings speed, consistency and scale, but watch for complexity, cost, single points of failure and technical debt. High-impact actions should keep a human approval step.
- Match the question to the source: 'what ran' is endpoint logs, 'what connected' is firewall and NetFlow, 'what was looked up' is DNS, 'what exactly was sent' is packet capture, 'who logged in' is OS security or identity logs.
Key terms
- Secure baseline
- An approved secure configuration that systems of a given type must meet, established, deployed and maintained.
- MDM
- Mobile device management, software that enforces policies and can lock or wipe mobile devices.
- BYOD
- Bring your own device, where employees use personal devices for work.
- COPE
- Corporate-owned, personally enabled: company devices that allow personal use.
- CYOD
- Choose your own device: employees select from a list of approved company-managed devices.
- Containerization
- Separating work apps and data from personal content on a device.
- Jailbreaking/rooting
- Removing OS restrictions on iOS (jailbreaking) or Android (rooting), bypassing built-in security.
- WPA3
- The current Wi-Fi security standard, using SAE for personal mode and stronger enterprise options.
- SAE
- Simultaneous Authentication of Equals, the WPA3 handshake that resists offline password cracking.
- Pre-shared key (PSK)
- A shared passphrase used in WPA2-Personal, vulnerable to offline cracking after handshake capture.
- RADIUS
- A centralized authentication, authorization and accounting protocol used for enterprise Wi-Fi and network access.
- EAP
- Extensible Authentication Protocol, a framework for authentication methods used with 802.1X.
- EAP-TLS
- An EAP method with certificate-based mutual authentication.
- Evil twin
- A malicious access point impersonating a legitimate network name to intercept users.
- Captive portal
- A web page that users must interact with before gaining network access.
- Asset management
- Tracking hardware, software and data through their lifecycle with owners and inventory records.
- Enumeration
- Discovering and listing assets, for example through network scans or agents.
- Sanitization
- Removing data from media so it cannot be recovered, allowing reuse.
- Cryptographic erase
- Sanitizing an encrypted drive by securely destroying its encryption key.
- Degaussing
- Erasing magnetic media with a strong magnetic field.
- Destruction
- Physically destroying media by shredding, pulverizing or incineration.
- Certificate of destruction
- Documented proof from a disposal provider that specific assets were destroyed or sanitized.
- Vulnerability scan
- An automated check of systems for known weaknesses such as missing patches or misconfigurations.
- Credentialed scan
- A scan that logs in to systems for deeper, more accurate results.
- Non-credentialed scan
- A scan without login access, showing what an outsider can see.
- False positive
- A reported vulnerability that does not actually exist.
- False negative
- A real vulnerability that a scan fails to report.
- CVE
- Common Vulnerabilities and Exposures, unique public identifiers for known vulnerabilities.
- CVSS
- Common Vulnerability Scoring System, a 0.0 to 10.0 severity rating for vulnerabilities.
- Penetration test
- An authorized simulated attack that exploits weaknesses to show real-world impact.
- Rules of engagement
- The written agreement defining scope, methods, timing and limits of a test.
- Known environment
- A test where testers receive full information about the target; formerly white box.
- Unknown environment
- A test where testers start with little or no information; formerly black box.
- Passive reconnaissance
- Gathering information without directly interacting with target systems, such as OSINT.
- Active reconnaissance
- Gathering information by directly probing target systems, such as port scanning.
- Pivoting
- Using a compromised system as a stepping stone to reach other systems.
- OSINT
- Open-source intelligence gathered from publicly available sources.
- SIEM
- Security information and event management, which aggregates, normalizes, correlates and alerts on log data.
- Correlation
- Linking related events from different sources to identify patterns such as an attack.
- Log aggregation
- Collecting logs from many systems into a central location.
- Alert fatigue
- Analysts becoming desensitized to alerts because of excessive false positives.
- SCAP
- Security Content Automation Protocol, NIST standards for automated, consistent security checks.
- NetFlow
- A protocol that records metadata about network flows, such as addresses, ports and byte counts.
- Syslog
- A standard protocol for sending log messages to a central collector.
- SPF
- Sender Policy Framework, a DNS record listing servers authorized to send email for a domain.
- DKIM
- DomainKeys Identified Mail, which signs email with a private key and publishes the public key in DNS.
- DMARC
- A DNS policy that checks SPF/DKIM alignment with the From domain, sets handling and requests reports.
- Alignment
- The DMARC requirement that the visible From domain matches the domain authenticated by SPF or DKIM.
- DMARC policy
- The action receivers take on failing mail: none, quarantine or reject.
- Secure email gateway
- A system that filters inbound and outbound email for spam, malware and phishing.
- S/MIME
- A standard for signing and encrypting individual email messages with certificates.
- EDR
- Endpoint detection and response, agents that record endpoint activity and enable detection, investigation and response.
- XDR
- Extended detection and response, correlating telemetry across endpoints, network, email, identity and cloud.
- DLP
- Data loss prevention, tools that identify sensitive data and control where it can go.
- UEBA
- User and entity behavior analytics, which baselines normal behavior and flags deviations.
- Telemetry
- Detailed activity data collected from systems for analysis.
- Host isolation
- Cutting an endpoint off from the network, except the security console, to contain a threat.
- Behavioral baseline
- A model of normal activity against which anomalies are measured.
- Provisioning
- Creating accounts and granting access when a user joins or changes role.
- Deprovisioning
- Removing or disabling access when it is no longer needed.
- Single sign-on (SSO)
- Authenticating once to access multiple applications.
- Identity provider (IdP)
- The system that authenticates users and issues assertions or tokens to applications.
- SAML
- An XML-based standard for sending signed authentication assertions from an IdP to a service provider.
- OAuth 2.0
- An authorization framework that grants applications limited access to resources using tokens.
- OpenID Connect
- An authentication layer on OAuth 2.0 that provides an ID token identifying the user.
- LDAP
- A protocol for querying and modifying directory services such as Active Directory.
- Multifactor authentication (MFA)
- Authentication requiring two or more factors from different categories.
- Something you have
- A possession factor such as a phone app, hardware key or smart card.
- Something you are
- A biometric factor such as fingerprint, face or iris.
- MFA fatigue
- An attack that floods a user with push prompts until they approve one.
- FIDO2/passkeys
- Phishing-resistant authentication using public key cryptography bound to the real site.
- Privileged access management (PAM)
- Tools and processes that vault, control, monitor and audit privileged accounts.
- Just-in-time access
- Granting elevated privileges only when needed and removing them automatically after a set time.
- Crossover error rate (CER)
- The point where a biometric system's false acceptance and false rejection rates are equal.
- Incident response plan
- A documented approach defining roles, procedures and communications for handling incidents.
- Playbook
- Step-by-step procedures for responding to a specific type of incident.
- Detection
- Identifying that a potential security incident may be occurring.
- Containment
- Limiting the scope and spread of an incident, such as isolating systems or disabling accounts.
- Eradication
- Removing the cause of an incident, such as malware, attacker accounts and exploited vulnerabilities.
- Recovery
- Restoring systems and operations to normal and monitoring for recurrence.
- Lessons learned
- The post-incident review that identifies improvements to prevent or better handle future incidents.
- Root cause analysis
- Identifying the underlying reason an incident was possible.
- Tabletop exercise
- A discussion-based walkthrough of a scenario to test a plan without touching systems.
- Inject
- A new development introduced during an exercise to test participants' responses.
- Walkthrough
- A step-by-step review of plan procedures to confirm they are complete and understood.
- Simulation
- An exercise that recreates realistic conditions, such as a phishing campaign or simulated attack.
- Parallel processing test
- Running recovery systems alongside production to confirm they work without interrupting operations.
- Failover test
- Actually switching operations to backup systems or sites to prove recovery works.
- After-action review
- The post-exercise discussion that records lessons and assigns improvements.
- Order of volatility
- Collecting evidence from the most short-lived sources first, such as memory before disk.
- Chain of custody
- Documented record of every person who handled evidence, when and why.
- Legal hold
- An instruction to preserve relevant data when litigation or investigation is expected, overriding normal deletion.
- Acquisition
- Collecting evidence, typically by creating forensic copies of media or memory.
- Write blocker
- A device or tool that prevents any changes to original evidence during acquisition.
- Forensic image
- A bit-by-bit copy of storage, including deleted files and unallocated space.
- E-discovery
- Identifying, collecting and producing electronic information for legal proceedings.
- Automation
- Using scripts and tools to perform tasks without manual effort.
- Orchestration
- Coordinating multiple tools and automated tasks into a workflow.
- SOAR
- Security orchestration, automation and response platforms that integrate tools and run response playbooks.
- Runbook
- A detailed step-by-step procedure for a specific operational or technical task.
- Guard rail
- An automated control that prevents insecure configurations or actions.
- Technical debt
- The future cost of maintaining quick or poorly designed solutions such as unmanaged scripts.
- Firewall log
- A record of allowed and denied network connections with addresses, ports and actions.
- Application log
- Events recorded by applications, such as requests, errors, logins and transactions.
- Endpoint log
- Activity recorded on a device, such as processes, file changes and registry edits.
- OS security log
- Operating system records of logins, privilege use and account or policy changes.
- Metadata
- Data about data, such as email headers or file timestamps.
- Packet capture
- A recording of full network packets, including content where not encrypted.
- DNS log
- Records of domain name lookups, useful for spotting malicious domains.
Domain 5: Program management & oversight (20%)
Exam tips
- Policy says what and why; standard says exactly what is required; procedure says how, step by step; guideline recommends. Only the guideline is optional.
- SLE = AV × EF; ALE = SLE × ARO. A control is worth it when the reduction in ALE is greater than the control's annual cost.
- Insurance transfers financial impact but never accountability. Acceptance must be documented and approved by someone with authority; otherwise the risk is simply being ignored.
- SLA is about measurable performance, MSA sets the general terms, SOW defines specific work, MOU is usually non-binding intent, NDA is confidentiality, and right to audit lets you verify the vendor's controls.
- The controller decides why and how personal data is used and is primarily accountable; the processor acts on the controller's instructions. External audits by independent parties carry more weight than internal ones.
- Reporting rate and speed often matter more than click rate, because one fast report lets the security team protect everyone. Simulations should educate, not shame.
Key terms
- Policy
- A high-level, mandatory statement of management's intent and direction.
- Standard
- A mandatory, specific requirement that supports a policy, such as a minimum key length.
- Procedure
- Detailed step-by-step instructions for performing a task consistently.
- Guideline
- Recommended, non-mandatory advice or best practice.
- Acceptable use policy (AUP)
- A policy defining permitted and prohibited use of organizational systems and data.
- Governance
- The structures, roles and processes by which an organization directs and oversees security.
- Policy exception
- A formally approved, documented deviation from a policy or standard, usually with compensating controls.
- Risk register
- A central record of risks with owners, ratings, controls, treatments and status.
- Risk appetite
- The amount and type of risk an organization is willing to pursue or accept overall.
- Risk tolerance
- The acceptable variation in risk around the appetite for specific risks or objectives.
- Single loss expectancy (SLE)
- The expected cost of one occurrence: asset value times exposure factor.
- Annualized rate of occurrence (ARO)
- The expected number of occurrences per year.
- Annualized loss expectancy (ALE)
- The expected yearly loss: SLE times ARO.
- Exposure factor (EF)
- The percentage of an asset's value lost in a single incident.
- Residual risk
- The risk that remains after controls are applied.
- Risk treatment
- The decision on how to respond to an identified risk.
- Mitigate
- Reduce a risk's likelihood or impact by applying controls.
- Transfer
- Shift the financial impact of a risk to another party, such as an insurer.
- Avoid
- Eliminate a risk by not performing the risky activity.
- Accept
- Formally acknowledge a risk and take no further action, usually because treatment costs more than the potential loss.
- Risk exception
- A formally approved, time-limited deviation from a policy or standard, often with compensating controls.
- Cyber insurance
- Insurance that covers financial losses from cyber incidents, a common form of risk transfer.
- Service level agreement (SLA)
- A contract defining measurable service levels, such as uptime and response times, and penalties for missing them.
- Memorandum of understanding (MOU)
- A usually non-binding document recording shared intent between parties.
- Master service agreement (MSA)
- A contract setting general terms for an ongoing relationship and future work.
- Statement of work (SOW)
- A document defining specific tasks, deliverables, timeline and cost for a project.
- Non-disclosure agreement (NDA)
- A legal agreement to keep shared information confidential.
- Right-to-audit clause
- A contract term allowing the customer or its auditor to assess the vendor's controls.
- Vendor due diligence
- Assessing a supplier's security, financial and legal standing before and during a relationship.
- Compliance
- Meeting the requirements of applicable laws, regulations, contracts and standards.
- Data controller
- The organization that decides why and how personal data is processed and is primarily accountable.
- Data processor
- An organization that processes personal data on the controller's behalf and instructions.
- Data subject
- The individual whom personal data describes.
- Right to be forgotten
- A data subject's right in some jurisdictions to have their personal data erased.
- Attestation
- A formal statement that controls meet specified criteria, such as a SOC 2 report.
- External audit
- An independent third-party examination of an organization's controls or compliance.
- Due care
- Acting responsibly to meet security and legal obligations.
- Security awareness training
- Education that helps people recognize threats, follow policy and report issues.
- Phishing simulation
- A harmless fake phishing campaign used to measure and improve staff responses.
- Reporting rate
- The percentage of recipients who report a phishing email, simulated or real.
- Role-based training
- Training tailored to the risks of specific roles, such as finance, developers or executives.
- Just-in-time training
- A short lesson delivered at the moment a user makes a mistake.
- Anomalous behavior recognition
- Training people to notice risky, unexpected or unintentional behavior that may indicate a threat.
- Click rate
- The percentage of recipients who click a link in a phishing simulation.
Study Security+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Security+ study planLessons, quizzes, exam simulations and hands-on labs.