Full Test Flashcards
(142 cards)
What is RipeMD
- RACE integrity Primitive Evaluation Message Digest
- open source hashing algo
160-320 bit
What is BPDU Guard
- Bridge Protocol Data Unit
- Enhancement to Spanning Tree Protocol
- CISCO calls it “port fast”
What is EAP TTLS
- Extensible Auth Protocol Tunnelled TLS
- Used with other protocols
- Auth Server needs a certificate
- WPA2 enterprise
What is VMI?
- Virtual Mobile Infrastructure
- Mobile Apps actually run from remote server
What is CASB?
- Cloud Access Security Broker “Caz-Bee”
- OnPrem or Cloud software that provides visibility, security, compliance, and threat prevention
What is conditional access?
- Manage access through SaaS
- Condtions like Geography, IP, used device, browser, OS
What is PAM?
- Privilege Access Managment
- Admins “check out” admin privileges for a set length of time
What is NIST SP800-61?
-Computer Security Incident Handling Guide
What is ISO 27001?
- International Standard for Information Security Management Systems
What is ISO 27002?
- Code of practice for implementing security controls.
- if ISO 27001 is the “what and why” then 27002 is the “how”
What is ISO 27701?
- Intl standard for Privacy Information Managment Systems
- Extends 27001 to deal with GDPR
What is ISO 31000?
- Intl Std for Risk Management
- Generic guidelines
What is CSA?
- Cloud Security Alliance
- Organization dedicated to defining best practices for secure cloud computing
- Cloud Control Matrix is the framework
What does the Data Steward do?
- Oversight or governance role
- Responsibility for accuracy, privacy, & security
- Applies sensitivity labels
- Ensures legal and compliance standards are met
What is a Data Controller?
- How and why data is used within organization
What is a Data Custodian?
- Responsible for the safe custody, transport, and storage of data.
- IT function more than business function.
What is a Data Protection Officer?
- Responsible for Overall Data Privacy Policy.
- GDPR compliance
- All PII/PHI data is handled correctly
What is SASL?
- Simple Authentication and Security Layer
- Used with various auth schemes. Eg.
Kerebos
What is SNMPv3?
- Simple Network Managment Protocol v 3
- Provides CIA for Network Managment
- UDP 161
What is STP?
- Spanning Tree Protocol
- Prevents Layer 2 loops
- Leaves single active path between nodes
- 802.1D/802.1Q-2014
What is RFC?
- Request For Comments
- Standard Setting bodies on Internet like Internet Engineering Task Force (IETF)
- Shape Internet internal workings since 1969.
What is TTP?
- Tactics, Techniques, & Procedures
- Codified playbook for individual attackers
What is IRM?
- Information Rights Management
- E-DRM
- “remote-control” of documents
What is RTO?
- Recovery Time Objective
- Time after EVENT before normal operations resume
- “Acceptable levels” of ops