All certifications / SecurityX / Cheat sheet
SecurityX CAS-005 cheat sheet
Domain 1: Governance, risk and compliance (20%)
Exam tips
- If a question asks where a specific technical value (algorithm, key length, password length) belongs, the answer is usually a standard, not a policy. Policies state intent; standards state measurable requirements.
- In a RACI, only one party is Accountable for a task. When a question asks who owns the decision about data classification or access, the answer is the data owner, not the administrator who configures the system.
- Expect questions where the root cause is an unapproved or undocumented change. The fix is usually process: route changes through change management with testing and back-out plans, and detect drift against the baseline.
- Buying insurance is transference, not mitigation; it does not change the likelihood of the event. And only a person with appropriate authority can accept risk above appetite, not the analyst who assessed it.
- Type II beats Type I because it covers operating effectiveness over time. When a question asks how to find which products contain a vulnerable component quickly, think SBOM.
- Do not mix up RTO (time to restore) and RPO (data loss tolerance). Tabletop exercises are discussion only; parallel and full interruption tests touch real systems, and a full interruption test is the most disruptive.
- Match the regulation to the data: card data means PCI DSS, US health data means HIPAA, EU personal data means GDPR, public company financial reporting means SOX. Location requirements point to data sovereignty or localization.
- If the question needs certification by an accredited auditor, choose ISO/IEC 27001. If it needs a detailed control catalog for federal systems, choose NIST SP 800-53. If it needs a high-level way to describe and communicate program maturity, choose NIST CSF.
- When litigation is anticipated, the first action is to preserve data with a legal hold, not to delete, copy it around by email or alter it. When a breach involves EU personal data, remember the 72-hour authority notification window.
- STRIDE is a per-element category checklist used at design time; ATT&CK describes observed real-world adversary behavior; PASTA is risk-centric with seven stages. Match the method to the wording of the question.
- Instructions hidden in data the model reads is indirect prompt injection; corrupting training data is poisoning. For employees leaking data into public AI tools, the first answer is governance (acceptable use policy with approved tools) backed by technical controls such as DLP.
Key terms
- Policy
- A high-level, mandatory statement of management intent approved by senior leadership.
- Standard
- A mandatory, specific and measurable requirement that supports a policy, such as a required algorithm or setting.
- Procedure
- Step-by-step instructions for performing a task consistently.
- Guideline
- Recommended but optional advice that helps people meet a policy.
- Policy exception
- A documented, time-limited approval to deviate from a requirement, usually with compensating controls.
- RACI matrix
- A chart assigning Responsible, Accountable, Consulted and Informed roles for each activity.
- Data owner
- The business leader accountable for a data set's classification and access decisions.
- Data custodian
- The person or team that implements and operates the controls protecting data.
- KPI
- Key performance indicator: a measure of how well a process is performing.
- KRI
- Key risk indicator: a measure that signals increasing exposure to a risk.
- CMDB
- Configuration management database: a record of configuration items and their relationships.
- Configuration item (CI)
- Any component managed under configuration control, such as a server, application or network device.
- Change advisory board (CAB)
- The group that reviews and approves normal changes based on risk and impact.
- Back-out plan
- The documented steps to reverse a change if it fails.
- Data inventory
- A record of data sets, their classification, location, owner, retention and flows.
- Annualized loss expectancy (ALE)
- Expected yearly loss from a risk: single loss expectancy multiplied by annualized rate of occurrence.
- Risk appetite
- The amount and type of risk an organization is willing to accept in pursuit of its objectives.
- Residual risk
- The risk that remains after controls have been applied.
- Risk transference
- Shifting part of a risk's financial impact to another party, such as an insurer.
- Risk register
- A documented list of risks with owners, scores, treatments and status.
- SOC 2 Type II
- An independent auditor's report on whether a service organization's controls operated effectively over a period of time.
- SBOM
- Software bill of materials: an inventory of components and versions in a software product.
- Right to audit
- A contract clause allowing the customer to audit, or obtain audit evidence of, the vendor's controls.
- Subprocessor
- A third party that a vendor uses to process the customer's data.
- Vendor tiering
- Classifying vendors by the risk they pose so assessment effort matches the risk.
- Business impact analysis (BIA)
- An analysis of critical processes, their dependencies and the impact of their loss over time.
- RTO
- Recovery time objective: the target time to restore a system or process after a disruption.
- RPO
- Recovery point objective: the maximum acceptable amount of data loss, measured in time.
- MTD
- Maximum tolerable downtime: the longest a process can be down before the harm is unacceptable.
- Tabletop exercise
- A discussion-based walkthrough of a scenario to test roles, decisions and communication.
- GDPR
- EU regulation protecting personal data, with rights for individuals and duties such as breach notification.
- PHI
- Protected health information regulated by HIPAA in the US.
- PCI DSS
- Payment Card Industry Data Security Standard for organizations handling cardholder data.
- Data sovereignty
- The principle that data is subject to the laws of the country where it is stored.
- Data localization
- A legal requirement to keep certain data within a country's borders.
- NIST CSF
- A voluntary outcome framework with six functions: Govern, Identify, Protect, Detect, Respond, Recover.
- NIST SP 800-53
- A catalog of security and privacy controls organized into families, used heavily by US federal systems.
- ISMS
- Information security management system: the policies, processes and controls used to manage security risk, as defined by ISO/IEC 27001.
- Statement of applicability
- An ISO/IEC 27001 document listing which controls apply, whether they are implemented and why.
- CSA CCM
- The Cloud Security Alliance's control framework for cloud computing.
- Data subject
- The individual whom personal data is about.
- Right to erasure
- A GDPR right allowing individuals to request deletion of their personal data in certain circumstances.
- Legal hold
- An instruction to preserve relevant data and suspend normal deletion because of litigation or investigation.
- E-discovery
- Identifying, preserving, collecting and producing electronic information for legal proceedings.
- Spoliation
- Destruction or alteration of evidence that should have been preserved.
- Trust boundary
- A point in a system where data or control passes between areas with different levels of trust.
- STRIDE
- Threat categories: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
- PASTA
- A seven-stage, risk-centric threat modeling process linking threats to business impact.
- Attack tree
- A diagram breaking an attacker's goal into alternative and required sub-steps.
- Attack surface
- The sum of all points where an attacker could try to enter or extract data from a system.
- Prompt injection
- Input crafted so a language model follows attacker instructions instead of its intended ones.
- Indirect prompt injection
- Prompt injection delivered through content the model processes, such as a document or web page.
- Data poisoning
- Corrupting training data so a model learns incorrect, biased or hidden behaviors.
- Model inversion
- Using a model's outputs to infer information about its training data.
- AI acceptable use policy
- Rules on which AI tools may be used, for what purposes and with what data.
Domain 2: Security architecture (27%)
Exam tips
- Redundancy inside one zone or region does not survive a regional outage; look for geographic dispersion. Vertical scaling adds capacity but not redundancy.
- Perimeter firewalls handle north-south traffic; microsegmentation handles east-west. MAC filtering alone is weak because MAC addresses are easy to spoof.
- Know the roles: the policy engine decides, the policy administrator executes the decision, and the policy enforcement point allows or blocks traffic in front of the resource. Zero trust never grants access just because a request comes from the internal network.
- SAST needs code and no running app; DAST needs a running app and no code. Vulnerable open-source libraries are found by SCA. A backdoor inserted in the build is addressed by pipeline integrity controls, not by more testing after release.
- The right answer to a false positive is precise tuning, not disabling the control or switching to detection-only mode. If events appear out of order in the SIEM, check time synchronization first.
- Tokenization is reversible through the vault and keeps values consistent for correlation; masking typically hides or permanently alters values. Base64 and unsalted fast hashes are not protection for card numbers.
- OAuth 2.0 is for authorization (access tokens for APIs); OIDC adds authentication (ID tokens); SAML uses XML assertions. Standing admin rights are the problem that just-in-time PAM solves.
- In IaaS, the customer patches the guest OS. Public buckets and open ports across accounts point to CSPM; controlling SaaS usage and shadow IT points to CASB; converged networking plus security as a cloud service points to SASE.
- Every image layer can be extracted, so a secret anywhere in an image is exposed; encoding does not hide it. For limiting blast radius in Kubernetes, think network policies, least-privilege service accounts and no privileged pods.
- Inconsistent controls across environments point to centralization: one identity provider, central key management, central logging and policy as code. Sharing one static key across environments is never the right answer.
- When the requirement is access to specific apps without putting users on the network, choose ZTNA over VPN. When data must never reach an unmanaged device, VDI is the strongest fit.
Key terms
- High availability
- Design that keeps a service running with minimal downtime, typically through redundancy and automatic failover.
- Active-active
- A configuration where all redundant nodes serve traffic at the same time.
- Geographic dispersion
- Placing redundant components in separate physical locations to survive local or regional disasters.
- Graceful degradation
- Keeping core functions working by reducing or disabling non-essential features under stress.
- Fail closed
- A failure mode where a control blocks access when it fails, favoring security over availability.
- Screened subnet
- A network zone between external and internal firewalls for public-facing services, also called a DMZ.
- Microsegmentation
- Fine-grained policy that controls traffic between individual workloads, even within one subnet.
- East-west traffic
- Traffic moving laterally between systems inside a network or data center.
- 802.1X
- An IEEE standard for port-based network access control using an authenticator and an authentication server.
- SDN
- Software-defined networking: separating the control plane into a central controller that programs network devices.
- Policy engine
- The zero trust component that decides whether to grant access based on policy and signals.
- Policy enforcement point
- The component in the data path that enables, monitors and ends connections according to the decision.
- Implicit trust zone
- An area where entities are trusted by location; zero trust aims to shrink these to the smallest possible.
- Continuous verification
- Re-evaluating trust throughout a session as context changes, rather than only at login.
- Just-in-time access
- Granting privileges only when needed and for a limited time.
- SAST
- Static application security testing: analyzing source code or binaries without executing them.
- DAST
- Dynamic application security testing: testing a running application from the outside.
- SCA
- Software composition analysis: identifying third-party components and their known vulnerabilities and licenses.
- Build provenance
- Verifiable metadata describing how, where and from what sources an artifact was built.
- Shift left
- Moving security activities earlier in the development life cycle.
- Implicit deny
- The default rule at the end of a firewall rule base that blocks anything not explicitly allowed.
- WAF
- Web application firewall: a control that inspects and filters HTTP requests to web applications.
- False positive
- An alert or block triggered by legitimate activity.
- False negative
- Malicious activity that a control fails to detect or block.
- Log normalization
- Converting logs from different sources into a common format and field names for analysis.
- Data classification
- Assigning a sensitivity level to data based on the impact of its compromise.
- DLP
- Data loss prevention: tools and policies that detect and stop unauthorized movement of sensitive data.
- Tokenization
- Replacing sensitive data with a random token, with the mapping held in a secured vault.
- Dynamic data masking
- Hiding data values at query or display time based on the viewer's permissions.
- Crypto-shredding
- Rendering encrypted data unrecoverable by securely destroying its encryption keys.
- Identity provider (IdP)
- The system that authenticates users and issues assertions or tokens to applications.
- SAML 2.0
- An XML-based standard for exchanging authentication assertions between an IdP and service providers.
- OpenID Connect
- An authentication layer on top of OAuth 2.0 that issues ID tokens.
- PKCE
- Proof Key for Code Exchange: an OAuth 2.0 extension that protects the authorization code flow for public clients.
- Privileged access management
- Controls that secure, limit, monitor and audit privileged accounts.
- Shared responsibility model
- The division of security duties between a cloud provider and its customer, varying by service model.
- CSPM
- Cloud security posture management: continuous detection of risky cloud configurations.
- CWPP
- Cloud workload protection platform: security for VMs, containers and serverless workloads.
- CASB
- Cloud access security broker: visibility and policy enforcement for cloud and SaaS use.
- SASE
- Secure access service edge: SD-WAN combined with cloud-delivered security services.
- Base image
- The starting image on which a container image is built, such as a minimal OS layer.
- Admission control
- A Kubernetes mechanism that checks or blocks workloads, such as unsigned images or privileged pods, before they run.
- Network policy
- A Kubernetes rule that limits which pods can communicate with each other.
- Secrets manager
- A service that stores, controls access to and rotates secrets, delivering them at run time.
- API gateway
- A front door for APIs that enforces authentication, rate limiting and other policies.
- Hybrid cloud
- An environment combining on-premises infrastructure with one or more public clouds.
- Multicloud
- Using services from more than one public cloud provider.
- BYOK
- Bring your own key: generating keys under your control and importing them into a cloud key service.
- HYOK
- Hold your own key: keeping keys in your own systems so the provider never holds them.
- Policy as code
- Defining security and compliance rules in machine-readable code that is versioned and automatically enforced.
- Split tunneling
- Sending only corporate traffic through a VPN tunnel while other traffic goes directly to the internet.
- ZTNA
- Zero trust network access: per-application access brokered after identity and device checks, without network-level access.
- VDI
- Virtual desktop infrastructure: hosting desktops centrally and delivering them remotely.
- Bastion host
- A hardened, monitored server used as the controlled entry point for administrative access.
- Secure email gateway
- A service that filters email for threats and enforces policies such as DLP and encryption.
Domain 3: Security engineering (31%)
Exam tips
- When one federated app fails and the rest work, suspect that app's trust configuration, especially an outdated IdP signing certificate. When time-based things fail on one server only, check NTP.
- For fixed-function devices, application allow listing is usually the strongest answer. EDR's advantage over traditional antivirus is behavioral detection and response, not better signatures.
- Secure Boot blocks untrusted code; measured boot records what ran so it can be attested. A TPM is per device; an HSM serves many applications at high volume.
- In OT questions, prefer answers that preserve availability and safety: segmentation, passive monitoring and controlled remote access. Answers that run aggressive scans or install new agents on controllers are usually wrong.
- Manual changes that differ from Terraform or the baseline are configuration drift; the fix is detection and reapplying the declared state. For automation safety, look for testing, dry runs, peer review and least privilege.
- Harvest now, decrypt later points to post-quantum planning; stolen server key and past sessions points to forward secrecy; computing on encrypted data points to homomorphic encryption; data key wrapped by a master key points to envelope encryption.
- Signatures are created with the sender's private key and verified with the public key; encryption for confidentiality uses the recipient's public key. Proving the publisher of software points to code signing.
- The offline root plus online intermediates design limits damage from a CA compromise. OCSP stapling improves revocation checking performance and privacy. Pinning breaks TLS inspection proxies.
- Only DMARC tells receivers to reject spoofed mail and provides reports; SPF and DKIM alone do not set a policy. DNSSEC gives authenticity of DNS answers; DoH and DoT give privacy.
- For BYOD, look for containerization and selective wipe rather than full device wipe. Rooted or jailbroken devices are detected through attestation and blocked through conditional access.
- An exposed secret must be revoked and rotated; removing it from the code does not undo the exposure. Separation of duties means key administrators should not be able to use keys to read data.
- SNMPv3 with authPriv is the secure answer for monitoring; changing the community string or port does not add encryption. Centralized AAA with TACACS+ gives per-command authorization and accounting for administrators.
Key terms
- Clock skew
- A difference between system clocks that can cause time-sensitive tokens, tickets and codes to be rejected.
- Signing certificate
- The certificate an IdP uses to sign assertions; service providers must trust the current one.
- Extended key usage
- A certificate field that limits what the certificate may be used for, such as client or server authentication.
- CRL distribution point
- The location in a certificate where verifiers download the certificate revocation list.
- MFA fatigue
- An attack that floods a user with push prompts hoping they approve one.
- Secure baseline
- The approved minimum security configuration for a type of system.
- Application allow list
- A control that permits only approved applications to run.
- EDR
- Endpoint detection and response: tools that record endpoint activity, detect threats and support response actions.
- Configuration drift
- Divergence of a system's actual configuration from its approved baseline.
- Host-based firewall
- A firewall running on an individual system that controls its own network connections.
- TPM
- Trusted Platform Module: a device-bound chip that stores keys and boot measurements.
- HSM
- Hardware security module: a tamper-resistant device or service for high-volume key management and cryptographic operations.
- Secure Boot
- A UEFI feature that allows only signed, trusted boot components to run.
- Measured boot
- Recording hashes of boot components into the TPM so the boot state can be verified later.
- Remote attestation
- Sending signed measurements of a device's state to a verifier that decides whether to trust it.
- SCADA
- Supervisory control and data acquisition: systems that monitor and control distributed industrial assets.
- PLC
- Programmable logic controller: an industrial computer that controls a physical process.
- Zones and conduits
- An ISA/IEC 62443 approach grouping assets into security zones and controlling the paths between them.
- Data diode
- A unidirectional gateway that physically allows data to flow in only one direction.
- Compensating control
- An alternative control that reduces risk when the primary control cannot be applied.
- SOAR
- Security orchestration, automation and response: platforms that run playbooks across security tools.
- Playbook
- A defined, often automated sequence of steps for handling a specific type of event.
- Infrastructure as code
- Defining and provisioning infrastructure through machine-readable files instead of manual steps.
- Policy as code
- Security and compliance rules written as code and enforced automatically, for example in a pipeline.
- Immutable infrastructure
- An approach where systems are replaced with new builds instead of being modified in place.
- Post-quantum cryptography
- Algorithms designed to resist attacks from quantum computers, such as ML-KEM and ML-DSA.
- Crypto agility
- The ability to change cryptographic algorithms and keys without redesigning systems.
- Key stretching
- Deriving keys from passwords with slow, salted functions to resist guessing.
- Forward secrecy
- A property where compromise of long-term keys does not reveal past session keys.
- Envelope encryption
- Encrypting data with a data key, then encrypting that data key with a master key in a KMS or HSM.
- Data in use
- Data being processed in memory or by the CPU, as opposed to stored or transmitted.
- Field-level encryption
- Encrypting specific fields within a record so they stay protected in the database and backups.
- Digital signature
- A value created with a private key over a hash of data, verifiable with the matching public key.
- Non-repudiation
- Assurance that a party cannot credibly deny having performed an action, such as signing a document.
- HMAC
- Hash-based message authentication code: a keyed hash that proves integrity and origin to key holders.
- Intermediate CA
- A CA whose certificate is signed by the root and which issues end-entity certificates.
- CSR
- Certificate signing request: a message containing a public key and identity details sent to a CA for signing.
- OCSP stapling
- A server including a recent signed OCSP response in its TLS handshake.
- Certificate pinning
- Configuring a client to accept only specific certificates or public keys for a service.
- Mutual TLS
- TLS in which both client and server authenticate with certificates.
- SPF
- A DNS record listing servers authorized to send mail for a domain.
- DKIM
- A method of signing email with a domain key published in DNS.
- DMARC
- A policy that requires aligned SPF or DKIM results and tells receivers how to handle failures, with reporting.
- DNSSEC
- Extensions that add digital signatures to DNS data so resolvers can verify authenticity.
- S/MIME
- A standard for signing and encrypting individual email messages with certificates.
- MDM
- Mobile device management: enrolling devices and enforcing security policies on them.
- UEM
- Unified endpoint management: one platform managing mobile devices, laptops and desktops.
- Containerization
- Separating corporate apps and data from personal content on a device.
- Selective wipe
- Removing only corporate data and apps from a device, leaving personal content.
- Device attestation
- Hardware-backed proof that a device is genuine and not compromised, such as rooted or jailbroken.
- Secrets vault
- A system that stores, controls and audits access to secrets and delivers them at run time.
- Dynamic secret
- A credential generated on request with a short lifetime and revoked automatically.
- Key rotation
- Replacing cryptographic keys on a schedule or after compromise.
- Dual control
- Requiring two or more people to act together to perform a sensitive operation.
- Split knowledge
- Dividing a secret so no single person knows it completely.
- Management plane
- The functions and interfaces used to configure, monitor and administer a network device.
- SNMPv3 authPriv
- The SNMPv3 security level providing both authentication and encryption.
- TACACS+
- A protocol for centralized administrator authentication, authorization and accounting on network devices.
- RPKI
- Resource Public Key Infrastructure: cryptographic validation that a network is authorized to announce an IP prefix.
- Control plane policing
- Rate limiting traffic destined to a device's CPU to protect routing processes.
Domain 4: Security operations (22%)
Exam tips
- Fix noise with precise, documented exceptions and better context, never by disabling a rule or dropping log sources. When correlation breaks, check time synchronization and parsing before anything else.
- STIX is the format; TAXII is the transport. When asked which detections last longer, choose behavior (TTPs) over hashes and IPs.
- A hunt that starts from a report or ATT&CK technique is hypothesis- or intelligence-driven. Legitimate access does not rule out misuse; UEBA flags behavior that departs from a user's own baseline.
- A known exploited flaw on an exposed system beats a higher CVSS score on an isolated one. When a scanner flags an old version that the distribution has backported a fix for, verify and document it as a false positive.
- Match the fix to the root cause: parameterized queries for SQL injection, output encoding for XSS, atomic transactions for race conditions, data-only formats and allow lists for deserialization, memory-safe languages and fuzzing for memory corruption.
- Exact hashes miss rebuilt variants; YARA rules catch shared patterns. Always analyze samples in an isolated sandbox, not on a production workstation, and avoid uploading sensitive samples to public sites.
- Order matters: after detection and analysis comes containment, then eradication, then recovery, and lessons learned come last. Restoring before containment and root cause analysis risks reinfection.
- Memory before disk, disk before backups. Hashes prove integrity; chain of custody proves handling. Analysts examine copies, not the original evidence.
- You cannot protect assets you do not know about, so discovery comes first. Penetration test findings should be fixed at the root cause and retested.
- Sigma is for log events across SIEMs; YARA is for files; Snort and Suricata are for network packets. Deception alerts are high-fidelity because legitimate users never touch decoys.
Key terms
- Log aggregation
- Collecting logs from many sources into a central platform for analysis.
- Normalization
- Mapping fields from different log formats to a common schema.
- Correlation rule
- A detection that combines multiple events across sources or time to identify suspicious patterns.
- Enrichment
- Adding context such as asset value, identity details or threat intelligence to events.
- Alert fatigue
- Desensitization of analysts caused by high volumes of low-value alerts.
- IoC
- Indicator of compromise: an artifact such as a hash, IP or domain associated with malicious activity.
- TTP
- Tactics, techniques and procedures: the patterns of behavior an adversary uses.
- STIX
- Structured Threat Information Expression: a standard format for describing threat intelligence.
- TAXII
- A protocol for exchanging STIX intelligence over HTTPS.
- Traffic Light Protocol
- A labeling system that sets how widely shared information may be distributed.
- Threat hunting
- Proactive, analyst-driven searching for threats that evaded existing detections.
- Hypothesis
- A testable statement about possible attacker activity that guides a hunt.
- UEBA
- User and entity behavior analytics: detecting deviations from baselines of normal behavior.
- Stacking
- Counting how often values occur across many systems to find rare outliers.
- Living off the land
- Attackers using legitimate built-in tools to avoid detection.
- Credentialed scan
- A vulnerability scan that logs in to systems for accurate software and configuration data.
- CVSS
- Common Vulnerability Scoring System: a 0 to 10 severity rating for vulnerabilities.
- EPSS
- Exploit Prediction Scoring System: an estimate of the probability a vulnerability will be exploited.
- KEV catalog
- CISA's list of vulnerabilities known to be exploited in the wild.
- Virtual patching
- Blocking exploitation of a vulnerability with a control such as a WAF or IPS rule until a real fix is applied.
- Parameterized query
- A database query where user input is passed as data parameters, never as part of the SQL code.
- Insecure deserialization
- Reconstructing objects from untrusted data in a way that can trigger unintended behavior.
- TOCTOU
- Time-of-check to time-of-use: a race condition between checking a condition and acting on it.
- Use-after-free
- A memory flaw where a program uses memory after it has been released.
- SSRF
- Server-side request forgery: tricking a server into making requests to unintended destinations, such as internal services.
- Static analysis
- Examining a sample without executing it, for example hashes, strings and headers.
- Dynamic analysis
- Running a sample in a controlled environment to observe its behavior.
- Sandbox
- An isolated environment for safely executing and observing suspicious code.
- YARA
- A rule language for identifying and classifying files by patterns and conditions.
- Fuzzy hashing
- Hashing that produces similar values for similar files, helping group variants.
- Playbook
- A documented procedure for handling a specific type of incident.
- Containment
- Actions that limit the spread and impact of an incident.
- Eradication
- Removing the cause of an incident, including malware, persistence and the exploited weakness.
- Recovery
- Restoring systems to normal operation and verifying they are clean.
- Lessons learned
- A post-incident review that identifies improvements to prevent or better handle future incidents.
- Order of volatility
- The sequence for collecting evidence from most to least short-lived.
- Chain of custody
- Documentation of who handled evidence, when and why, from collection onward.
- Write blocker
- A device or software that prevents changes to storage media during acquisition.
- Forensic image
- A bit-for-bit copy of storage media used for analysis.
- Timeline analysis
- Arranging events from many sources in time order to reconstruct an incident.
- Attack surface management
- Continuous discovery, inventory and reduction of assets exposed to attackers.
- Certificate transparency
- Public logs of issued TLS certificates, useful for discovering an organization's hostnames.
- Rules of engagement
- The agreed scope, methods, timing and limits for a penetration test.
- Purple teaming
- Collaboration between attackers (red) and defenders (blue) to improve detection and response.
- Shadow IT
- Systems and services used without the knowledge or approval of IT and security.
- Detection engineering
- Designing, building, testing and maintaining detections as managed code.
- Sigma
- A vendor-neutral YAML format for log-based detection rules that can be converted into SIEM queries.
- Coverage mapping
- Showing which ATT&CK techniques existing detections and data sources can observe.
- Honeytoken
- A fake credential, file or record that should never be used, so any use signals compromise.
- Adversary emulation
- Safely reproducing known adversary behaviors to test defenses.
Study SecurityX for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SecurityX study planLessons, quizzes, exam simulations and hands-on labs.