Security+ section 1 Flashcards
(42 cards)
W.I a preventative control give examples
it physically blocks a person firewall (technical), on-boarding policy (managerial), guard shake (operational), doorlock (physical)
W.I a deterrent control give examples
discourages an intrusion attempt splash screen, demotion, reception desk, warning signs
W.I a detective control
identifies and logs intrusion attempts. System logs
W.I a corrective control
performs an action after detection of an intrusion. eg restore backups
W.I a compensating control
temporary non-comprehensive correction to an intrusion eg block instead of patrch
W.I directive control type
direct a subject to more secure procedure file storage policy
W.I non-repudiation
proof of integrity and proof of origin
W.I the CIA (AIC) triad
Availability, integrity (messages cannot be modified without detection), confidentiality (only authorized users see this data)
how do you get proof of integrity
use a hash
how do you get proof of origin
use a digital signature with a private key which is decrypted using a public key
W.I authentication
prove who you are
W.I authorization
what do you have access to
W.I accounting
resources used
how do you authenticate a system?
with a certificate
what is the data plane?
process the frames packets and network data.
what is the control plane?
manages the actions of the data plane, define policies and rules, determines how packets should be forwarded.
W.I adaptive identity
consider information other than Authentication information. eg location relationship to organization. Then if needed create stronger authentication
W.I threat scope reduction
decrease possible entry points
W.I security zone
the path of connection
W.I policy enforcement point
gatekeeper of resources
policy decision point
decider in policy enforcement point
W.I. change management
policies for making changes to a system
W.I. Public key infrastructure(PKI)
policies procedures, hardwar, software, people associated with certificates
W.I. out of band key exchange
exchange not over internet