Módulo 06 - Resiliency and Site Security Flashcards
(102 cards)
Define:
Environmental Design (Physical Security)
Security approach that uses the built environment to enhance security
List:
Environmental Design options
- Barricades and Entry/Exit point
- Fencing
- Lights
- Bollards (Coisa de ferro ou cimento controlado remotamente que impede a passagem de veículos)
List:
Lock types
- Physical
- Electronic
- Biometric
Define:
PACS - Physical Access Control System
Designed to control who can access specific locations within a building, essential to protect access badges (NFC cards)
List:
The use of AI and camera systems
- Motion Recognition
- Object Detection
- Drones/UAV
List:
Type of alarms
- Circuit
- Motion Detection
- Noise Detection
- Proximity
- Duress
List:
Types of sensors
- Infrared
- Pressure
- Microwave
- Ultrasonic
Acronym:
RFID
Radio Frequency ID
List:
Common Physical Attacks
- Brute Force
- Environmental
- RFID Cloning
What’s the fundamental concept in network monitoring?
Know which computer are the big receivers and senders of information in the network.
List
Network Monitoring Tools
ping
tracert/traceroute
pathping
netstat
route
arp
nslookup/dig
ipconfig/ifconfig
hping
netcat
IP scanners
nmap
Define:
Passive reconnaissance
Gathering information on the target with no direct interaction
List:
Passive reconnaissance methods
- Packet sniffing
- Eavesdropping
- OSINT - Open Source Intelligence
- Network Traffic analysis
Acronym:
OSINT
Open Source Intelligence
Define:
OSINT - Open Source Intelligence
Collecting data from public sources
Define:
Active reconnaissance
Gathering information on a target by probing and interacting
List:
Active reconnaissance techniques
- Port scanning
- Service enumeration
- OS fingerprinting
- DNS enumeration
- Web Application Crawling
List:
Type of reconnaissance
- Passive
- Active
List:
Target information to extract
- Security posture (Physical and network)
- Narrow the focus for attack
- Potential vulnerabilities
- Create a network map
List:
Reconnaissance tools
- OSINT framework
- theHarvester
- Shodan
- DNSenum
- curl and wget
- Scanless
- Nessus
Acronym:
IPS
Intrusion Prevention System
Acronym:
IDS
Intrusion Detective System
Define:
Intrusion Prevention System
Detects attacks and suspicious activity and automates responses to the malicious actitivity
Define:
Intrusion Detection System
Detect attacks and suspicious activity