StudyToCert

All certifications / SecurityX / Cheat sheet

SecurityX CAS-005 cheat sheet

Every exam tip and key term from the free SecurityX lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Governance, risk and compliance (20%)

Exam tips

Key terms

Policy
A high-level, mandatory statement of management intent approved by senior leadership.
Standard
A mandatory, specific and measurable requirement that supports a policy, such as a required algorithm or setting.
Procedure
Step-by-step instructions for performing a task consistently.
Guideline
Recommended but optional advice that helps people meet a policy.
Policy exception
A documented, time-limited approval to deviate from a requirement, usually with compensating controls.
RACI matrix
A chart assigning Responsible, Accountable, Consulted and Informed roles for each activity.
Data owner
The business leader accountable for a data set's classification and access decisions.
Data custodian
The person or team that implements and operates the controls protecting data.
KPI
Key performance indicator: a measure of how well a process is performing.
KRI
Key risk indicator: a measure that signals increasing exposure to a risk.
CMDB
Configuration management database: a record of configuration items and their relationships.
Configuration item (CI)
Any component managed under configuration control, such as a server, application or network device.
Change advisory board (CAB)
The group that reviews and approves normal changes based on risk and impact.
Back-out plan
The documented steps to reverse a change if it fails.
Data inventory
A record of data sets, their classification, location, owner, retention and flows.
Annualized loss expectancy (ALE)
Expected yearly loss from a risk: single loss expectancy multiplied by annualized rate of occurrence.
Risk appetite
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
Residual risk
The risk that remains after controls have been applied.
Risk transference
Shifting part of a risk's financial impact to another party, such as an insurer.
Risk register
A documented list of risks with owners, scores, treatments and status.
SOC 2 Type II
An independent auditor's report on whether a service organization's controls operated effectively over a period of time.
SBOM
Software bill of materials: an inventory of components and versions in a software product.
Right to audit
A contract clause allowing the customer to audit, or obtain audit evidence of, the vendor's controls.
Subprocessor
A third party that a vendor uses to process the customer's data.
Vendor tiering
Classifying vendors by the risk they pose so assessment effort matches the risk.
Business impact analysis (BIA)
An analysis of critical processes, their dependencies and the impact of their loss over time.
RTO
Recovery time objective: the target time to restore a system or process after a disruption.
RPO
Recovery point objective: the maximum acceptable amount of data loss, measured in time.
MTD
Maximum tolerable downtime: the longest a process can be down before the harm is unacceptable.
Tabletop exercise
A discussion-based walkthrough of a scenario to test roles, decisions and communication.
GDPR
EU regulation protecting personal data, with rights for individuals and duties such as breach notification.
PHI
Protected health information regulated by HIPAA in the US.
PCI DSS
Payment Card Industry Data Security Standard for organizations handling cardholder data.
Data sovereignty
The principle that data is subject to the laws of the country where it is stored.
Data localization
A legal requirement to keep certain data within a country's borders.
NIST CSF
A voluntary outcome framework with six functions: Govern, Identify, Protect, Detect, Respond, Recover.
NIST SP 800-53
A catalog of security and privacy controls organized into families, used heavily by US federal systems.
ISMS
Information security management system: the policies, processes and controls used to manage security risk, as defined by ISO/IEC 27001.
Statement of applicability
An ISO/IEC 27001 document listing which controls apply, whether they are implemented and why.
CSA CCM
The Cloud Security Alliance's control framework for cloud computing.
Data subject
The individual whom personal data is about.
Right to erasure
A GDPR right allowing individuals to request deletion of their personal data in certain circumstances.
Legal hold
An instruction to preserve relevant data and suspend normal deletion because of litigation or investigation.
E-discovery
Identifying, preserving, collecting and producing electronic information for legal proceedings.
Spoliation
Destruction or alteration of evidence that should have been preserved.
Trust boundary
A point in a system where data or control passes between areas with different levels of trust.
STRIDE
Threat categories: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
PASTA
A seven-stage, risk-centric threat modeling process linking threats to business impact.
Attack tree
A diagram breaking an attacker's goal into alternative and required sub-steps.
Attack surface
The sum of all points where an attacker could try to enter or extract data from a system.
Prompt injection
Input crafted so a language model follows attacker instructions instead of its intended ones.
Indirect prompt injection
Prompt injection delivered through content the model processes, such as a document or web page.
Data poisoning
Corrupting training data so a model learns incorrect, biased or hidden behaviors.
Model inversion
Using a model's outputs to infer information about its training data.
AI acceptable use policy
Rules on which AI tools may be used, for what purposes and with what data.

Domain 2: Security architecture (27%)

Exam tips

Key terms

High availability
Design that keeps a service running with minimal downtime, typically through redundancy and automatic failover.
Active-active
A configuration where all redundant nodes serve traffic at the same time.
Geographic dispersion
Placing redundant components in separate physical locations to survive local or regional disasters.
Graceful degradation
Keeping core functions working by reducing or disabling non-essential features under stress.
Fail closed
A failure mode where a control blocks access when it fails, favoring security over availability.
Screened subnet
A network zone between external and internal firewalls for public-facing services, also called a DMZ.
Microsegmentation
Fine-grained policy that controls traffic between individual workloads, even within one subnet.
East-west traffic
Traffic moving laterally between systems inside a network or data center.
802.1X
An IEEE standard for port-based network access control using an authenticator and an authentication server.
SDN
Software-defined networking: separating the control plane into a central controller that programs network devices.
Policy engine
The zero trust component that decides whether to grant access based on policy and signals.
Policy enforcement point
The component in the data path that enables, monitors and ends connections according to the decision.
Implicit trust zone
An area where entities are trusted by location; zero trust aims to shrink these to the smallest possible.
Continuous verification
Re-evaluating trust throughout a session as context changes, rather than only at login.
Just-in-time access
Granting privileges only when needed and for a limited time.
SAST
Static application security testing: analyzing source code or binaries without executing them.
DAST
Dynamic application security testing: testing a running application from the outside.
SCA
Software composition analysis: identifying third-party components and their known vulnerabilities and licenses.
Build provenance
Verifiable metadata describing how, where and from what sources an artifact was built.
Shift left
Moving security activities earlier in the development life cycle.
Implicit deny
The default rule at the end of a firewall rule base that blocks anything not explicitly allowed.
WAF
Web application firewall: a control that inspects and filters HTTP requests to web applications.
False positive
An alert or block triggered by legitimate activity.
False negative
Malicious activity that a control fails to detect or block.
Log normalization
Converting logs from different sources into a common format and field names for analysis.
Data classification
Assigning a sensitivity level to data based on the impact of its compromise.
DLP
Data loss prevention: tools and policies that detect and stop unauthorized movement of sensitive data.
Tokenization
Replacing sensitive data with a random token, with the mapping held in a secured vault.
Dynamic data masking
Hiding data values at query or display time based on the viewer's permissions.
Crypto-shredding
Rendering encrypted data unrecoverable by securely destroying its encryption keys.
Identity provider (IdP)
The system that authenticates users and issues assertions or tokens to applications.
SAML 2.0
An XML-based standard for exchanging authentication assertions between an IdP and service providers.
OpenID Connect
An authentication layer on top of OAuth 2.0 that issues ID tokens.
PKCE
Proof Key for Code Exchange: an OAuth 2.0 extension that protects the authorization code flow for public clients.
Privileged access management
Controls that secure, limit, monitor and audit privileged accounts.
Shared responsibility model
The division of security duties between a cloud provider and its customer, varying by service model.
CSPM
Cloud security posture management: continuous detection of risky cloud configurations.
CWPP
Cloud workload protection platform: security for VMs, containers and serverless workloads.
CASB
Cloud access security broker: visibility and policy enforcement for cloud and SaaS use.
SASE
Secure access service edge: SD-WAN combined with cloud-delivered security services.
Base image
The starting image on which a container image is built, such as a minimal OS layer.
Admission control
A Kubernetes mechanism that checks or blocks workloads, such as unsigned images or privileged pods, before they run.
Network policy
A Kubernetes rule that limits which pods can communicate with each other.
Secrets manager
A service that stores, controls access to and rotates secrets, delivering them at run time.
API gateway
A front door for APIs that enforces authentication, rate limiting and other policies.
Hybrid cloud
An environment combining on-premises infrastructure with one or more public clouds.
Multicloud
Using services from more than one public cloud provider.
BYOK
Bring your own key: generating keys under your control and importing them into a cloud key service.
HYOK
Hold your own key: keeping keys in your own systems so the provider never holds them.
Policy as code
Defining security and compliance rules in machine-readable code that is versioned and automatically enforced.
Split tunneling
Sending only corporate traffic through a VPN tunnel while other traffic goes directly to the internet.
ZTNA
Zero trust network access: per-application access brokered after identity and device checks, without network-level access.
VDI
Virtual desktop infrastructure: hosting desktops centrally and delivering them remotely.
Bastion host
A hardened, monitored server used as the controlled entry point for administrative access.
Secure email gateway
A service that filters email for threats and enforces policies such as DLP and encryption.

Domain 3: Security engineering (31%)

Exam tips

Key terms

Clock skew
A difference between system clocks that can cause time-sensitive tokens, tickets and codes to be rejected.
Signing certificate
The certificate an IdP uses to sign assertions; service providers must trust the current one.
Extended key usage
A certificate field that limits what the certificate may be used for, such as client or server authentication.
CRL distribution point
The location in a certificate where verifiers download the certificate revocation list.
MFA fatigue
An attack that floods a user with push prompts hoping they approve one.
Secure baseline
The approved minimum security configuration for a type of system.
Application allow list
A control that permits only approved applications to run.
EDR
Endpoint detection and response: tools that record endpoint activity, detect threats and support response actions.
Configuration drift
Divergence of a system's actual configuration from its approved baseline.
Host-based firewall
A firewall running on an individual system that controls its own network connections.
TPM
Trusted Platform Module: a device-bound chip that stores keys and boot measurements.
HSM
Hardware security module: a tamper-resistant device or service for high-volume key management and cryptographic operations.
Secure Boot
A UEFI feature that allows only signed, trusted boot components to run.
Measured boot
Recording hashes of boot components into the TPM so the boot state can be verified later.
Remote attestation
Sending signed measurements of a device's state to a verifier that decides whether to trust it.
SCADA
Supervisory control and data acquisition: systems that monitor and control distributed industrial assets.
PLC
Programmable logic controller: an industrial computer that controls a physical process.
Zones and conduits
An ISA/IEC 62443 approach grouping assets into security zones and controlling the paths between them.
Data diode
A unidirectional gateway that physically allows data to flow in only one direction.
Compensating control
An alternative control that reduces risk when the primary control cannot be applied.
SOAR
Security orchestration, automation and response: platforms that run playbooks across security tools.
Playbook
A defined, often automated sequence of steps for handling a specific type of event.
Infrastructure as code
Defining and provisioning infrastructure through machine-readable files instead of manual steps.
Policy as code
Security and compliance rules written as code and enforced automatically, for example in a pipeline.
Immutable infrastructure
An approach where systems are replaced with new builds instead of being modified in place.
Post-quantum cryptography
Algorithms designed to resist attacks from quantum computers, such as ML-KEM and ML-DSA.
Crypto agility
The ability to change cryptographic algorithms and keys without redesigning systems.
Key stretching
Deriving keys from passwords with slow, salted functions to resist guessing.
Forward secrecy
A property where compromise of long-term keys does not reveal past session keys.
Envelope encryption
Encrypting data with a data key, then encrypting that data key with a master key in a KMS or HSM.
Data in use
Data being processed in memory or by the CPU, as opposed to stored or transmitted.
Field-level encryption
Encrypting specific fields within a record so they stay protected in the database and backups.
Digital signature
A value created with a private key over a hash of data, verifiable with the matching public key.
Non-repudiation
Assurance that a party cannot credibly deny having performed an action, such as signing a document.
HMAC
Hash-based message authentication code: a keyed hash that proves integrity and origin to key holders.
Intermediate CA
A CA whose certificate is signed by the root and which issues end-entity certificates.
CSR
Certificate signing request: a message containing a public key and identity details sent to a CA for signing.
OCSP stapling
A server including a recent signed OCSP response in its TLS handshake.
Certificate pinning
Configuring a client to accept only specific certificates or public keys for a service.
Mutual TLS
TLS in which both client and server authenticate with certificates.
SPF
A DNS record listing servers authorized to send mail for a domain.
DKIM
A method of signing email with a domain key published in DNS.
DMARC
A policy that requires aligned SPF or DKIM results and tells receivers how to handle failures, with reporting.
DNSSEC
Extensions that add digital signatures to DNS data so resolvers can verify authenticity.
S/MIME
A standard for signing and encrypting individual email messages with certificates.
MDM
Mobile device management: enrolling devices and enforcing security policies on them.
UEM
Unified endpoint management: one platform managing mobile devices, laptops and desktops.
Containerization
Separating corporate apps and data from personal content on a device.
Selective wipe
Removing only corporate data and apps from a device, leaving personal content.
Device attestation
Hardware-backed proof that a device is genuine and not compromised, such as rooted or jailbroken.
Secrets vault
A system that stores, controls and audits access to secrets and delivers them at run time.
Dynamic secret
A credential generated on request with a short lifetime and revoked automatically.
Key rotation
Replacing cryptographic keys on a schedule or after compromise.
Dual control
Requiring two or more people to act together to perform a sensitive operation.
Split knowledge
Dividing a secret so no single person knows it completely.
Management plane
The functions and interfaces used to configure, monitor and administer a network device.
SNMPv3 authPriv
The SNMPv3 security level providing both authentication and encryption.
TACACS+
A protocol for centralized administrator authentication, authorization and accounting on network devices.
RPKI
Resource Public Key Infrastructure: cryptographic validation that a network is authorized to announce an IP prefix.
Control plane policing
Rate limiting traffic destined to a device's CPU to protect routing processes.

Domain 4: Security operations (22%)

Exam tips

Key terms

Log aggregation
Collecting logs from many sources into a central platform for analysis.
Normalization
Mapping fields from different log formats to a common schema.
Correlation rule
A detection that combines multiple events across sources or time to identify suspicious patterns.
Enrichment
Adding context such as asset value, identity details or threat intelligence to events.
Alert fatigue
Desensitization of analysts caused by high volumes of low-value alerts.
IoC
Indicator of compromise: an artifact such as a hash, IP or domain associated with malicious activity.
TTP
Tactics, techniques and procedures: the patterns of behavior an adversary uses.
STIX
Structured Threat Information Expression: a standard format for describing threat intelligence.
TAXII
A protocol for exchanging STIX intelligence over HTTPS.
Traffic Light Protocol
A labeling system that sets how widely shared information may be distributed.
Threat hunting
Proactive, analyst-driven searching for threats that evaded existing detections.
Hypothesis
A testable statement about possible attacker activity that guides a hunt.
UEBA
User and entity behavior analytics: detecting deviations from baselines of normal behavior.
Stacking
Counting how often values occur across many systems to find rare outliers.
Living off the land
Attackers using legitimate built-in tools to avoid detection.
Credentialed scan
A vulnerability scan that logs in to systems for accurate software and configuration data.
CVSS
Common Vulnerability Scoring System: a 0 to 10 severity rating for vulnerabilities.
EPSS
Exploit Prediction Scoring System: an estimate of the probability a vulnerability will be exploited.
KEV catalog
CISA's list of vulnerabilities known to be exploited in the wild.
Virtual patching
Blocking exploitation of a vulnerability with a control such as a WAF or IPS rule until a real fix is applied.
Parameterized query
A database query where user input is passed as data parameters, never as part of the SQL code.
Insecure deserialization
Reconstructing objects from untrusted data in a way that can trigger unintended behavior.
TOCTOU
Time-of-check to time-of-use: a race condition between checking a condition and acting on it.
Use-after-free
A memory flaw where a program uses memory after it has been released.
SSRF
Server-side request forgery: tricking a server into making requests to unintended destinations, such as internal services.
Static analysis
Examining a sample without executing it, for example hashes, strings and headers.
Dynamic analysis
Running a sample in a controlled environment to observe its behavior.
Sandbox
An isolated environment for safely executing and observing suspicious code.
YARA
A rule language for identifying and classifying files by patterns and conditions.
Fuzzy hashing
Hashing that produces similar values for similar files, helping group variants.
Playbook
A documented procedure for handling a specific type of incident.
Containment
Actions that limit the spread and impact of an incident.
Eradication
Removing the cause of an incident, including malware, persistence and the exploited weakness.
Recovery
Restoring systems to normal operation and verifying they are clean.
Lessons learned
A post-incident review that identifies improvements to prevent or better handle future incidents.
Order of volatility
The sequence for collecting evidence from most to least short-lived.
Chain of custody
Documentation of who handled evidence, when and why, from collection onward.
Write blocker
A device or software that prevents changes to storage media during acquisition.
Forensic image
A bit-for-bit copy of storage media used for analysis.
Timeline analysis
Arranging events from many sources in time order to reconstruct an incident.
Attack surface management
Continuous discovery, inventory and reduction of assets exposed to attackers.
Certificate transparency
Public logs of issued TLS certificates, useful for discovering an organization's hostnames.
Rules of engagement
The agreed scope, methods, timing and limits for a penetration test.
Purple teaming
Collaboration between attackers (red) and defenders (blue) to improve detection and response.
Shadow IT
Systems and services used without the knowledge or approval of IT and security.
Detection engineering
Designing, building, testing and maintaining detections as managed code.
Sigma
A vendor-neutral YAML format for log-based detection rules that can be converted into SIEM queries.
Coverage mapping
Showing which ATT&CK techniques existing detections and data sources can observe.
Honeytoken
A fake credential, file or record that should never be used, so any use signals compromise.
Adversary emulation
Safely reproducing known adversary behaviors to test defenses.
Study SecurityX for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the SecurityX study plan