The usage of deceptive emails and websites to maliciously gather personal information
Any type of software that is designed to intentionally harm or damage a computer or network.
A type of attack that uses psychological manipulation to trick people into giving up information, clicking links, or taking unsafe actions without using technical hacking.
A tactic in social engineering where an attacker asks questions to extract useful information from a target
A tactic in social engineering where an attacker uses threats or fear of negative consequences to pressure someone into acting
A tactic in social engineering where an attacker creates time pressure to prevent the target from thinking carefully before responding
Stealing login credentials like passwords or multi-factor authentication codes.
The process of identifying a user and granting them access. Authentication is proving that someone is who they say they are.
A network security device that monitors and filters incoming and outgoing network traffic.
A type of authentication that is similar to a password but longer and is usually a sentence or a series of words
(2FA) A type of multifactor authentication that typically combines something the user knows (like a password) with something the user has (like a mobile phone)
(MFA) An extra layer of authentication that requires two or more factors for authentication. Typically, these factors fall into three categories: something you know (password), something you have (such as a phone), or something you are (such as your fingerprint).
A form of authentication that uses an individual’s physical or behavioral characteristics to verify their identity
Tools that store and manage passwords for various accounts, generating strong passwords and auto-filling login credentials.
The Internet of Things (IoT) is the network of physical devices, vehicles, home appliances, and other items embedded with electronics, software, sensors, actuators, and connectivity which enables these things to connect and exchange data.
The protection of information from people who are not authorized to view it.
Aims at ensuring that information is protected from unauthorized or unintentional alteration.
The assurance that systems and data are accessible by authorized users when and where needed.
Updates that address and fix security vulnerabilities within a program or product.
Ensures that one cannot deny having sent or received a message.
A flaw or weakness in a system or device.
The potential for loss when an attack happens.
A potential for a cybercriminal to exploit a vulnerability.
The process of enforcing policies and user privileges. Once a user is authenticated, they may only be authorized to access specific areas or may only have rights to perform specific tasks.
The process of measuring what is happening within the system. This is the final process of the AAA framework and ensures that there is a log of all actions within the network or system.
Measures that protect information by ensuring their confidentiality, integrity, and availability.
a weakness which can be exploited by a malicious actor / attacker to perform unauthorized actions within a computer system.
A person, group, or automated system that attempts to attack, exploit, or break into computers.
An undocumented security flaw unknown to the software developer, giving defenders "zero days" to prepare.
The name of a Wi-Fi network that appears in the list of available networks.
A wireless attack where an attacker creates a fake Wi-Fi network that copies a legitimate SSID to trick users into connecting.
A denial-of-service (DoS) attack that floods the airwaves with electromagnetic interference to prevent devices from connecting.
The act of gathering information about a target before launching an attack.
Driving through an area to scan wifi networks and collect data on things like signal strength and security.
AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. These tools analyze settings across your systems and flag potential weaknesses before attackers can exploit them.
AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. By scanning code for common security flaws, these tools help developers catch issues early in the development process.
AI-powered tools can suggest rules for automated detection systems. These rules help identify suspicious activity on networks and systems, enabling faster response to potential threats.
Designed and used to assess computers, networks or applications for known weaknesses.
Publicly available information from social media, websites, and databases that can be collected and analyzed.
Malicious code that mutates and changes its own appearance every time it spreads, making it difficult for traditional antivirus to detect.
A technique where adversaries craft specific inputs to manipulate an AI into bypassing its safety filters or revealing restricted information.
AI-generated video or audio content designed to convincingly impersonate a real person.
A manipulation attack where adversaries flood training data sources with false information to corrupt an AI's knowledge base.
An attack where hackers optimize fake websites to appear in an AI's live search results, causing it to report false information as fact.
Tricking the AI into revealing secrets it should keep quiet. Adversaries use clever prompts to bypass safety filters and extract sensitive data.
Corrupting the AI's knowledge at the source. Adversaries feed false information into training data or search results.
The practice of protecting computers, networks, devices, and data from unauthorized access, attacks, and damage.
A word, phrase, or fact known only by two people, used to verify identity in high-stakes situations.
The process of cleaning inputs to remove or neutralize hidden malicious commands before an AI processes them.
The practice of protecting personal and sensitive information by not entering it into AI tools.
A security practice where professionals deliberately try to break systems to find vulnerabilities before real attackers do.
Information that can be used to identify a specific individual, such as names, addresses, phone numbers, or Social Security numbers.
The point at which an attacker first enters a system or network
Techniques that allow an attacker to remain inside a system over time
The process of moving from one device or account to another inside a network
Publicly available information collected from websites, social media, job postings, and other open sources
Gathering information without directly interacting with the target's systems
Collecting information by directly probing systems, networks, or devices
A numbered communication channel that allows specific types of network traffic into and out of a device
The total number of possible entry points an attacker could exploit
Ransomware is a type cyber attack that threatens to publish the victim's data or block access to it unless a ransom is paid.
A type of malware that attaches itself onto a host program, such as a document. It can cause serious damage to files or an entire device.
Once downloaded onto a user’s computer, the software secretly gathers information about a person or organization and sends it to the attacker.
Software designed to disrupt, damage, or gain unauthorized access to a computer system
Malware that self-propagates across networks without requiring user action
Malware that hides deep inside the operating system to avoid detection
Malware that gives an attacker remote control of a compromised device
A system that allows an attacker to remotely communicate with and issue commands to compromised devices
The process of maintaining long-term access to a compromised system so an attacker can return without re-exploiting a vulnerability
The technique of spreading through a network from an initial point of compromise to reach other systems
The process of gaining access to accounts or permissions beyond what was initially obtained
When a company hires a white hat hacker to assess the security of a system by finding and exploiting vulnerabilities.
An automatic record of events on a computer or server such as logins, file access, and account changes.
The unauthorized transfer of data out of a network or system
The deliberate modification or deletion of system logs to conceal attacker activity
Breaking large data transfers into smaller chunks to avoid detection during exfiltration
Social Engineering is the use of deception to manipulate individuals into divulging confidential or personal information that may be used for fraudulent purposes.
Pretending to be someone else to gather sensitive information. Involves researching the victim's background and gaining their trust.
A specific group of hackers who are motivated by their ideological views.
Have political motivations with the intent to harm, typically resulting in violence.
Impersonating someone with power over a target, or pretending to relay instructions from that person, to compel compliance
Creating social pressure by making a target believe that everyone else is already complying with a request.
Creating a sense of limited availability to prompt a target to act quickly before an opportunity disappears.
Pretending to be or know someone close to a target in order to establish trust.
A low-skilled adversary who uses hacking tools created by others without understanding how they work.
A current or former employee, contractor, or business partner who uses their legitimate access to systems to cause harm.
A sophisticated criminal group that operates across national borders and conducts cyberattacks primarily for financial gain.
A security measure that uses tangible objects or personnel to restrict access to physical spaces and hardware (e.g., locks, security cameras, fences)
A security measure implemented through software, hardware, or network configurations to protect digital systems (e.g., firewalls, encryption, anti-malware)
A security measure consisting of policies, rules, and procedures that govern expected security behaviors (e.g., password policies, access reviews, incident response plans)
A control designed to stop a security incident before it occurs
A control designed to identify a security incident while it is occurring or shortly after
A control designed to restore systems or limit damage after a security incident has occurred
A security strategy that uses multiple layers of controls so that if one layer fails, other layers can still protect the asset. The six layers are human, physical, network, device, application, and data.
A technical security control that monitors network traffic and automatically blocks or restricts activity as malicious; classified as both detective and corrective.
Using social engineering to convince an authorized person to grant access to a restricted area
Following closely behind an authorized person through a secured entrance without their knowledge
Watching a user access sensitive information, sometimes with a camera, to use it later
Searching a target's physical trash for useful information
Copying an authorized user's access card to gain the access that card grants
A device placed between a keyboard and a computer that records keystrokes and is not detectable by antivirus software
Cutting or disrupting power by damaging fuses, breakers, wiring, substations, or transformers to make devices and services unavailable
A compromise type in which systems or the services they provide become unavailable
A weakness in the physical environment, such as an unlocked door or an exposed network port, that an adversary could exploit.
How important a system, space, or piece of data is to the organization, used to help determine risk level.
An initial point of access that an adversary uses to move toward higher-value systems.
The CIA Triad is a widely-accepted security measure that should be guaranteed in every secure system. It stands for Confidentiality, Integrity, and Availability.
Risk response that removes the risk by avoiding the behavior completely.
Risk response that shares the responsibility of the risk with someone else.
Risk response that accepts the risk as is.
Risk response that takes steps to avoid the risk or minimize the impact or likelihood.
The probability of observing the evidence assuming the prior belief is true.
Anything valuable that an organization needs to protect, including financial resources, intellectual property, data, digital infrastructure, physical property, and reputation
The potential damage caused if a threat successfully exploits a vulnerability, measured in financial, operational, reputational, or safety terms
The risk that remains after a management strategy and security controls have been applied. No system is completely secure, so some level of risk always remains.
A safeguard or countermeasure designed to protect an asset, reduce a threat, or close a vulnerability.
Using a personal access badge to enter a restricted area; employees should not let others in through tailgating or piggybacking
The loss of a laptop or phone that can expose files, saved passwords, and network access; countered with cable locks, secure storage, and fast reporting for remote lock or wipe
Locking a device before leaving it unattended so no one can use an open session
Clearing or securing sensitive documents and storage devices before leaving a workstation unattended
A physical overlay that narrows a monitor's viewing angle to prevent shoulder surfing
A surge protector guards against voltage spikes
An uninterruptible power supply adds battery backup so work can be saved during an outage
Checks to see which ports on a network are open.
The process of identifying, assessing and prioritizing potential risks for an organization or company.
The practice of gathering, collecting, and logging some or all packets that pass through a computer network.
The probability that a specific threat will exploit a vulnerability, determined by target value, ease of exploitation, and adversary motivation and capability
A vulnerability assessment technique that actively attempts to exploit weaknesses in a system, simulating a real attack to confirm whether a vulnerability can be successfully used by an adversary
A vulnerability assessment technique that identifies potential weaknesses without attempting to exploit them, using observation and scanning methods that do not disrupt normal system operation
A tool or technique used to guess passwords, typically through methods such as brute force (trying all possible combinations), dictionary attacks, or rainbow table lookups
Stopping the activity that creates the risk; not possible when the activity is critical to the organization's mission
Shifting the burden of a risk to another entity, such as an insurance company, a government, or consumers
Implementing security controls to reduce the likelihood or impact of a risk
Acknowledging the risk that remains and deciding to live with it, since absolute security is unattainable
The risk that remains after avoidance, transference, and mitigation have been applied; the level of risk an organization is willing to accept
How much residual risk an organization is willing to accept
A control that costs less to install and maintain than the expected loss from an attack
The expected financial loss from a single occurrence of a threat
The expected number of times a threat occurs in a year
The expected yearly loss, calculated as SLE multiplied by ARO
A source of potential harm, including both human adversaries and natural disasters such as floods, fires, storms, and earthquakes
A weakness or flaw that could allow an asset to be compromised
The harm that results when a vulnerability is exploited
Fencing, gates, and bollards that deter adversaries from physically reaching a building
Barriers on doors, server cabinets, and computers that prevent devices from being accessed or stolen
A badge-based control that denies unauthorized badges and logs which badge accessed each entry and when
Entry controls that let only one authenticated person through at a time, preventing tailgating and piggybacking
Disabling ports through software or physical blockers so external drives cannot load malware
A fuel-powered source that supplies electricity to a building or critical systems during extended outages
Preventive controls stop an attack before it happens, detective controls identify that an incident occurred, and corrective controls restore systems afterward
A control that identifies that an attack or incident has occurred, such as a camera, motion sensor, or security guard
A device that captures a visual record of activity; most effective when its feed is both recorded and actively monitored
Entrances and exits, which are high-priority locations for cameras because everyone must pass through them
Software paired with cameras that can automatically alert security when an unrecognized or unauthorized individual enters a controlled area
When a system incorrectly matches one person to someone else; in facial recognition this can wrongly identify an innocent person as a suspect
When a system is more accurate for some groups than others because its training data did not represent all groups equally
A control that detects movement in a defined area and automatically alerts security, without requiring someone to watch a feed
An alert triggered by harmless activity; frequent false alarms cause teams to ignore alerts, so sensors belong where traffic is unexpected
Combining a motion sensor with a camera so defenders can visually verify what triggered an alert
A record of who accessed a door and how long it stayed open; an unusually long open time can reveal piggybacking after the fact
A person who monitors an area and responds to suspicious activity, bringing judgment that sensors and cameras cannot
A guard in one fixed position, most effective at choke points where all traffic must pass, such as entrances and gates
A guard who moves on a changing route, well suited to perimeters and large open areas where unpredictability closes coverage gaps
Employees who know their space and notice anomalies, such as an unfamiliar face or a propped-open door, before any sensor flags them
The employee's role is to report suspicious activity through the proper channel, not to confront a potential intruder
The process of sending data between two computers on the internet. The data is sent through routers that determine the route.
Packets are the units of data that are sent over the network.
An access point that allows for network management and security configuration.
Occurs when someone secretly intercepts communications between two parties by impersonating one or both parties.
When data is passed from one network segment to another.
The number of hops it takes for data to get to its final destination.
The unique address that is assigned to each device connected to the internet. It is part of the Internet Protocol.
An attack in which an attacker sends frames with thousands of spoofed MAC addresses to a network switch, overflowing the switch's MAC address table and forcing it to broadcast all traffic to every connected port.
An attack in which an attacker sends unsolicited ARP (Address Resolution Protocol) replies to devices on a network, causing them to update their ARP tables with incorrect MAC address mappings and redirecting traffic through the attacker's device.
An attack in which an attacker injects false records into a DNS resolver, causing domain name lookups to return malicious IP addresses and redirecting users to fake websites.
A denial-of-service attack in which an attacker sends ICMP echo requests to a network's broadcast address, causing all devices on the network to reply and flooding the network with amplified traffic.
The part of a packet that contains the source and destination IP address along with other routing information.
A number assigned to a network device's hardware that can be changed through MAC spoofing.
the process of converting information or data, usually to prevent unauthorized access
a network of devices that all exist within a single building or group of adjacent buildings
The name that identifies a wireless network, broadcast by an access point so that nearby devices can discover and connect to it.
A signal a wireless access point broadcasts to announce its presence, which can leak the network's name and settings beyond the building.
An unauthorized wireless access point plugged into a network port, giving an attacker wireless access to the internal network.
Gaining network access by plugging a device directly into an open wired port.
A protocol that encrypts data between a browser and a website, protecting it even on an open network.
A standard that encrypts wireless traffic between a device and the router.
An automated tool that probes a network for known weaknesses and produces a report of findings, severities, and recommended fixes.
The combination of likelihood and impact, often expressed as Risk = Likelihood Ă— Impact.
A specific action that prevents or reduces the damage from a vulnerability.
Enables wired connections between more than one computer or device.
A list of specific routing destinations; essentially a map for the router.
The protocol devices use to match IP addresses with MAC addresses on a local network.
The router that acts as a network's exit point for traffic headed outside the local network.
A table on a switch that maps each device's MAC address to the port it is connected to.
A unit of data sent across a local network.
When a switch whose table is full begins sending frames out of every port instead of only the correct one.
Used to translate domain names into IP addresses.
Distributed Denial of Service attack. Spam a web server with so many requests so close together that it crashes. Sometimes spitting out valuable information as it crashes.
A computer that stores web pages and makes them available to users on the internet.
A server that stores domain names and their associated IP addresses and answers lookups.
The process of a DNS server finding the IP address that matches a domain name.
A verified ID that a website presents to prove it owns a domain; a mismatch can reveal a poisoned redirect.
A protocol devices use to send short diagnostic messages, such as a ping.
An ICMP message that checks whether another device is reachable and prompts an echo reply.
A special address that delivers a message to every device on a network at once.
A group of two or more computer systems linked together.
A virtual LAN that allows for the setup of separate networks by configuring a network device.
The architectural strategy of dividing a network into smaller, isolated sections to limit the spread of attacks and apply different security policies to different areas.
A firewall that evaluates each packet in isolation using only its header, with no memory of prior traffic
A firewall that tracks active connections in a state table and uses connection context to make decisions
A firewall that inspects packet contents and identifies applications, going beyond headers and connection state
Examining the actual contents of a packet, not just its header, to detect hidden threats
Identifying which application is generating traffic, not just which port it uses
An ordered set of rules that tells a firewall whether to permit or deny each packet
The person who writes ACL rules based on an organization's security policy
A built-in deny-all at the end of every ACL that blocks any packet not matched by a rule
A way to write an IP range using a slash and a number (like 10.0.1.0/24) to show how many leading parts of the address are locked in place
When a broader rule placed higher in the list hides a more specific rule below it, so the lower rule is never reached
A separate section of a network grouped by its users, data, or purpose
A firewall placed where the internal network meets the public internet
The firewall applies the first rule whose criteria match and stops checking
A rule that never fires because an earlier rule always matches the same traffic first
A file that records events that occur in an operating system (or other software) and/or messages between different users of a communication software.
A method of recording individual network packets as they travel across a network, capturing details such as source and destination IP addresses, protocols, ports, and payload content for analysis.
A technique used to physically locate a wireless device by measuring signal strength readings from three or more scanners at known positions and finding the single point where all measurements intersect.
Any piece of evidence found during a security investigation that suggests a system may have been attacked or compromised.
Evidence of an attack found in the device's own state: its running processes, installed software, configuration settings, or system logs.
Evidence of an attack found in files stored on a device, such as a file with a suspicious name, an unexpected hash match to known malware, or a file in an unusual location.
Evidence of an attack based on anomalous patterns of activity, such as a login at an unusual time, from an unexpected location, or following abnormal sequences of events.
Creates a private network connection over a public network
A security measure consisting of policies, rules, and procedures that govern expected security behaviors (e.g., password policies, access reviews, incident response plans) * Preventative control
A documented minimum standard that applies to every device, every time, regardless of who sets it up.
An older remote management service that sends data, including passwords, in plain text, so policies require disabling it.
A switch control that limits which devices, or how many devices, can connect to a port.
A VPN configuration that routes some traffic through the tunnel and some directly to the internet, which policies prohibit.
Routing all of a device's traffic through the VPN so it passes through the organization's security controls.
A framework that verifies each user or device through an approved authentication server before it joins a wireless network.
An encryption standard, used with a minimum key length, that protects wireless traffic.
Monitors network traffic and raises an alert when it detects an attack, but does not stop it
Detects attacks like a NIDS and can also act to stop them, such as blocking an IP or closing a port
Collects and correlates data from many sources to spot attack patterns a single tool would miss
A record of events that have occurred on a system or network
Probing a system across many ports to find open services, often a sign of reconnaissance
The set steps an analyst follows to resolve or escalate an alert
A percentage the AI assigns for how likely an event is malicious, instead of a yes or no answer
Matching traffic against a known list of attack signatures for a definitive match or no match
The confidence level at which an event triggers an alert for a human to investigate
When too many alerts, often false positives, lead analysts to stop taking alerts seriously
Intrusion detection systems (IDSs) are available in two different types: host-based intrusion system (HBIS) and network-based intrusion system (NBIS). An IDS tries to detect malicious activity such as denial-of-service attacks, port scans and attacks by monitoring the network traffic.
A symmetric, block cipher that groups data into 128-bit blocks and uses a 128-, 192- or 256-bit key along with an algorithm and 10, 12, or 14 rounds of encryption.
A WAP setting that controls how far the wireless signal travels, which can be reduced to keep the signal inside the intended space.
An early, now broken, wireless encryption protocol whose key can be cracked in seconds.
A convenience feature for connecting devices with a PIN that has a critical flaw, so policies require disabling it.
Compares traffic against a database of known attack patterns and alerts on a match
Learns a baseline of normal activity and alerts when traffic deviates from it
Combines the signature and anomaly methods for the broadest coverage, at a higher cost
A known pattern that identifies a specific attack
A record of a network's normal activity, used as the reference for anomaly detection
How much traffic the network carries, which affects whether a method can keep up without lag
How predictable the traffic patterns are, which affects whether a reliable baseline is possible
How critical or confidential the protected systems and data are
A benign entry that gets flagged as an attack.
A real attack that a detection method fails to catch.
Traffic volume, traffic consistency, network sensitivity, and likelihood of novel attacks
A downside accepted in exchange for a benefit, such as more false positives for better coverage
The output from any input that has been processed through a hashing algorithm / function.
The word hashing literally means to scramble. Hashing changes a message into an unreadable string of text for the purpose of verifying the message’s contents, but not hiding the message itself. It must be easy to compute the output (the digest) for any input, but hard to compute the input for any output. A hash function takes an input string of arbitrary length and produces a fixed- size, short output called a digest . It’s always the same length no matter how big the input is AND the output is always the same hash for any given input. Unlike symmetric and asymmetric algorithms, there are no “keys” in hashing functions.
A property of hash functions where a small change in the input produces a completely different digest.
A unique random string added to a password before hashing to ensure that identical passwords produce different stored hashes.
A precomputed list of common passwords paired with their corresponding hash values, used to quickly identify matching hashes in a stolen database.
A password attack that systematically tests every possible combination of characters until a match is found.
A password attack that hashes a curated wordlist of likely passwords and compares the results against stolen hashes.
A password attack where the adversary cracks hashes on their own machine with no further interaction with the target system; cannot be detected through auth logs.
A password attack where the adversary sends credentials directly to the target login system; leaves traces in authentication logs.
A pattern in auth logs suggesting an account's credentials have been obtained and used by an unauthorized party.
A computer whose job is to provide services, such as websites or files, to other devices on a network.
A general-purpose computer designed for one user at a time, such as a desktop or laptop.
A smaller, battery-powered, general-purpose device built for portability, such as a smartphone or tablet.
A computer built into a machine to perform one specific job, usually without direct user interaction.
An embedded computer that connects to a network, allowing it to be reached, monitored, or controlled remotely.
A facility that houses large numbers of computers, often used to run servers.
A description of who could attack a device and how, which shifts once a device is connected to a network.
Using credentials stolen from a breach, or documented default credentials, to log into an account or device
Trying one common password across many accounts so no single account reaches its lockout limit
The factory username and password a device ships with, identical across every unit and easily abused if never changed
A policy that disables an account after a set number of failed login attempts, which stops online guessing
The scrambled form in which a password is stored, so the plaintext is never kept directly
Testing every possible combination of characters, guaranteed to work eventually but slow for long passwords
Testing a curated wordlist of likely passwords, fast against predictable passwords but blind to truly random ones
Looking up stolen hashes in a precomputed table of hashes, very fast but defeated by salting
A second verification step beyond the password, so a stolen password alone is not enough to log in
Adding a unique random value to each password before hashing, which gives identical passwords different hashes and defeats rainbow tables
Malicious code that stays dormant until a specific trigger condition is met, then fires
Malware that runs entirely in memory using legitimate system tools, leaving no file to scan
A technical control that verifies a user's identity before granting access
A category of proof used to verify identity
Something you know, such as a password, PIN, or security question answer
Something you have, such as a phone, access card, or hardware token
Something you are, such as a fingerprint, face, eye, or voice
Somewhere you are, such as an IP address, GPS position, or Wi-Fi network
A system that requires only one factor, such as a password alone
A system that requires two or more factors from different categories
A special kind of firmware that runs programs strictly to start up your computer.
Software missing security updates, leaving known flaws open to attack
Login protection that is easy to defeat, such as short, common, or reused passwords
A setting that automatically runs a program from an external drive the moment it is connected
A network slot actively listening for connections, which becomes an entry point when it is exposed
A running firewall whose rules have gaps that let malicious traffic through
Software on a device that detects and blocks malicious code, serving as a last line of defense
A public database of known software vulnerabilities that defenders and adversaries both use
A program or technique built to take advantage of a specific vulnerability
The full set of points where an adversary could try to enter a device or network
The process of evaluating a vulnerability to decide how urgently it needs to be addressed and what happens if it is not
A grid that plots likelihood of exploitation against impact if compromised to help classify risk quickly
A vulnerability whose exploitation is both likely and severe, requiring immediate action
A real vulnerability with limited damage potential or a lower chance of exploitation, worth addressing soon
A vulnerability that would cause minor harm or is very unlikely to be exploited, worth tracking but rarely urgent
How important a device is to operations
How sensitive the data stored on or passing through a device is
How likely it is that an adversary would actually target a given vulnerability
The severity of what would happen if a vulnerability were exploited
A timestamped record of events that occur on a computer system, used for auditing, debugging, and security analysis.
A log that records every login attempt (successful or failed), capturing the username, source IP address, timestamp, and result.
A log that records which programs start and stop on a system, including who launched them and when.
A log that records when files are created, read, modified, downloaded, or deleted.
A log that records changes to system settings, such as firewall rules or account permissions.
The network address of the device that initiated a connection or login attempt.
The date and time recorded in a log entry that shows exactly when an event occurred.
A formal document users must agree to before accessing an organization's network or devices. It defines permitted and prohibited uses, consequences for violations, privacy expectations, and monitoring practices.
A policy setting the rules for how users create and manage passwords
A policy defining whether and how users may install software on their devices
A practice that lets personal devices access company networks or data under set rules
A technical control that lets only pre-approved applications run on a device
A scan that checks a file the moment it arrives, is opened, or is executed, the first line of defense for individual files
A full scan run on a set schedule that catches threats an on-access scan may have missed, including files that only match a signature added in a later update
The hash fingerprint of a known piece of malware, which anti-malware matches files against
The constantly updated collection of known malware signatures, which can only catch threats it already describes
An isolated holding area where a flagged file cannot run, containing the threat without deleting it so the decision can be reviewed
A harmless file mistakenly flagged as malware, which quarantine makes recoverable
A targeted fix for a specific vulnerability, often urgent
A regular release that bundles patches with minor improvements
A major new version of software, rarely an emergency
The time between a patch's release and its installation, when a known, documented flaw is most likely to be exploited
A service that centralizes alerts from many devices so analysts can spot patterns across the whole network
The sequence of stages in an attack, where device-level detection is a late layer that catches what earlier defenses missed
A valid account showing a sudden shift from its normal login pattern, such as a new location, device, or time
A firewall is a system that provides network security by filtering incoming and outgoing network traffic based on a set of firewall rules. The purpose of a firewall is to reduce or eliminate the occurrence of unwanted network communications while allowing all legitimate communication to flow freely.
Firewall software running on a single device that filters all traffic to and from that device
A firewall at the edge of a network that filters traffic crossing the network boundary, but not traffic between devices inside it
A rule that controls traffic arriving at the device from outside
A rule that controls traffic leaving the device, which matters because not every program on the device can be trusted
A rule that filters by the specific program sending traffic, or by service, rather than by port number
The principle that a firewall checks rules top to bottom and acts on the first rule that matches, so rule order determines the outcome
A firewall that remembers established connections, so return traffic for a connection the device started is allowed without a separate rule
An encryption method in which each letter of the message is shifted by a certain amount, called the key
The same key is used to encrypt and decrypt (e.g., Caesar, Vigenere)
Ordinary, readable information.
Information which has been made unintelligible.
A cipher that changes one character or symbol into another.
A cipher that shifts the positions of plaintext character (or groups of characters) according to a regular system.
The total number of possible keys for a cipher, where a larger keyspace is harder to brute force
Encryption that divides data into fixed-size blocks and encrypts each one, well suited to stored data
Encryption that processes data one unit at a time as it arrives, well suited to real-time data in transit
A protection, such as encryption, chosen to address a specific risk
Recording events, such as encryption and decryption attempts, to verify a control is working and to spot problems
A cipher that groups bits into blocks of plaintext before applying the encryption.
The National Institute of Standards and Technology, which ran the open competition that chose AES
The size of the AES key, either 128, 192, or 256 bits, where a longer key means more possible keys
Trying every possible key until the right one is found, which becomes infeasible as key length grows
The balance between stronger encryption from a longer key and the extra processing it costs, which matters most on constrained devices
The tool that allows users to access and interact with the command line. Different operating systems have their own built-in terminals (e.g., Terminal on macOS, Command Prompt on Windows, and Bash on Linux).
Software that manages computer hardware and software resources and provides services for computer programs.
A browser tool that encrypts and decrypts files without installing anything
A downloadable application that encrypts a file into a .aes file using a password
A command-line tool that encrypts and decrypts files using AES commands in the terminal
An option that changes how a command runs, written with a dash, such as -e to encrypt, -d to decrypt, or -k to supply the password
Data that has been decrypted and is open on a screen or in memory, which file encryption no longer protects
One key encrypts, a different key decrypts.
The key that is shared openly and used to encrypt a message to its owner
The secret key, kept only by its owner, that decrypts messages encrypted with the matching public key
The matched public and private keys generated together, where each undoes what the other does
A string of bits that controls how data is scrambled and unscrambled during encryption
The total number of possible keys for a given key length, equal to 2 to the n for an n-bit binary key
The number of bits in a key, where each added bit doubles the keyspace
The rule that key length only indicates relative strength when both keys use the same algorithm, so a 256-bit AES key and a 256-bit RSA key are not equally secure
The first widely used asymmetric algorithm used for both signing and encryption.
An asymmetric algorithm that reaches RSA-level security with much smaller keys by using the math of elliptic curves
The OpenSSL option that names the key file a command uses, the public key to encrypt and the private key to decrypt
The OpenSSL flags that turn a file into ciphertext with the public key and back into the original with the private key
Files stored without encryption, so their contents can be read by anyone who gains access to the drive without needing a password
An account that holds more administrative access than its role requires, often because temporary privileges were never revoked
Permissions set too broadly, giving many accounts access to data they do not need
The process of scrambling data so it can only be read with the correct key
A person or group that attempts to gain unauthorized access to data or systems
The rules that determine which accounts can read, write, or modify specific files or systems
refers to an injection attack wherein an attacker can execute malicious SQL statements (also commonly referred to as a malicious payload) that control a web application's database server (also commonly referred to as a Relational Database Management System – RDBMS).
Cross-site scripting (XSS) is a security bug that can affect websites. If present in your website, this bug can allow an attacker to add their own malicious JavaScript code onto the HTML pages displayed to your users. Once executed by the victim's browser, this code could then perform actions such as completely changing the behavior or appearance of the website, stealing private data, or performing actions on behalf of the user.
XSS where the malicious script is saved on the server and runs automatically for every user who loads the affected page
XSS where the malicious script is delivered in a crafted link and runs when the victim clicks it
Checking user input against expected rules before the application processes it, so unexpected or malicious input is rejected
Removing or escaping dangerous characters in user input so it cannot be executed as code
A command sent to a database to read or change stored data
A value stored in a user's browser that keeps them logged in, and a common target of XSS attacks
A fixed-size region of memory set aside to hold a specific piece of data
The top directory a web application is allowed to serve files from, meant to keep the rest of the server off-limits
The ../ notation that moves up one directory level, used to climb out of an intended folder
An attack that submits more data than a fixed memory allocation can hold, so the excess spills into adjacent memory
An attack that uses path sequences like ../ to reach files outside the directory the application intended to serve
Rejecting input longer than a set maximum so it cannot overflow a buffer
Checking a requested file path so it cannot escape the web root
How reachable and easy to carry out an attack is, such as public-facing versus requiring internal credentials
The overall rating of high, moderate, or low that combines data sensitivity and exploit likelihood
This is when data is being accessed by a person or program.
This is when data is actively moving from one location to another.
This is when data is stored in a specific place that isn’t actively moving to other devices or networks.
Information that can be used to identify, contact, or locate a single person
Health records and medical information, regulated under HIPAA
Cardholder data such as account numbers and CVV codes, regulated by the PCI-DSS standard
A document that specifies the required protections for an organization's systems and data
The specific method used to encrypt data, such as AES-256 or RSA-2048
The system an organization uses to decide which subjects can perform which operations on which objects
A model that attaches permissions to roles and assigns each subject to a role
A model that checks a set of rules to decide whether a specific request is allowed, usually layered on top of another model
A model in which the owner of an object decides who can access it
A model in which an external administrator assigns levels and the system enforces access, with no owner override
A mandatory access control model that uses classification levels and two properties to control reading and writing
The Bell-LaPadula rule that a subject may not read an object above their level, summarized as no read up
The idea that entities should have only the access they need to do their job, and no more
The command that sets read, write, and execute permissions for the owner, group, and others, using either the numeric or the symbolic method.
The three entity categories Linux checks when deciding who can access a file
The three permission types that control whether an entity can view, change, or run a file
The field in ls -l output, such as -rwxr-xr--, that shows the file type and the permissions for each entity category
Setting permissions with three digits, where read is 4, write is 2, and execute is 1, added together per entity, such as 640
Setting permissions with letters and operators, such as u+x to add execute for the owner or o-r to remove read for others
Health-related information tied to a specific patient, such as diagnoses, lab results, treatment records, and prescription history.
Data tied to credit and debit card transactions, such as the card number, CVV code, cardholder name, and expiration date.
The federal law that sets the rules for how federal agencies collect and handle PII.
The federal law that governs PII collected from children under 13, which any service targeting kids must follow.
The federal law that governs PHI and applies to hospitals, insurers, and any business that handles patient data on their behalf.
An industry standard, not a law, that every business handling card payments must follow; card companies like Visa and Mastercard can fine violators or revoke their ability to accept cards.
A written policy that names approved algorithms, key lengths, and key generation and storage requirements.
A recognizable pattern in a log entry that points to a specific kind of attack.
An attack where an adversary types SQL database commands into a field meant to hold plain data.
An attack where an adversary places active code, such as a script tag, into a field that should hold only text.
An attack where an adversary sends more data than a field was built to hold, with the intent to spill past the field's limit and overwrite nearby memory.
An attack where an adversary uses repeated ../ sequences to reach files outside the folder the application is meant to stay in.
A method that alerts while an attack is happening, giving a chance to stop it, unlike after-the-fact methods that only reveal it later
Recording who accessed what, when, and from where, so activity that breaks a user's normal pattern can be spotted
Activity that deviates from normal patterns, which may or may not be malicious
A fake file that looks valuable but holds no real data, so any access to it is a warning sign
A function that produces a digest for a file, so a changed digest reveals the file was altered
A method that only reveals an attack once it is already over, useful for investigation but not prevention
A real-time tool that watches for sensitive data leaving a system and can block it
How much a detective control costs to run, which limits how many and which controls an organization can use
How damaging a breach of the data would be, which raises the monitoring it deserves
The category a piece of data falls into, such as PHI, PCI, or PII, which can carry legal monitoring requirements
A check that flags a file whose hash has changed, best for data that should not change
Software that scans logs as events happen and alerts on suspicious activity
A function that produces a fixed digest from a file, where any change to the file changes the digest
The property that the same input always produces the same hash output, so an unchanged file always hashes the same
Comparing a file's current hash to a recorded one to detect whether it was altered
The recorded hash value a later hash is compared against, only useful if an attacker cannot also change it
A hash protected by a digital signature, so tampering with the file or the hash is detected
Obtaining a baseline from somewhere an attacker does not control, so the comparison value can be believed
Building security into a product from the start rather than patching it in after release
Shipping a product and only addressing security after problems appear, treating security as a feature rather than a goal
Openly publishing vulnerabilities and owning them rather than fixing them quietly
Shipping a product with its most secure settings already enabled, so customers are protected without taking extra steps
A preset password shipped on a device, which becomes a major weakness when it is shared across units and rarely changed
A large attack that hijacked internet-connected devices still using their default passwords, showing the danger of insecure defaults
A punctuation mark such as a single quote or semicolon that SQL reads as part of a command rather than as text
Checking and cleaning user input before an application uses it, so it cannot be read as a command