Test your basic knowledge |

Comptia Security +: Vocab

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Good for distance - longer than 100M






2. Virtual LANs. Separating broadcast domains on a single network. A way of partitioning communications channels.






3. In cryptography - encryption is the process of obscuring information to make it unreadable without special knowledge.






4. In computing - the Challenge-Handshake Authentication Protocol authenticates a user to an Internet access provider. CHAP provides protection against playback attack by the peer through the use of an incrementally changing identifier and of a variable






5. The output of a hash function is a digest.






6. Business Impact Analysis. A BIA is a functional analysis in which a team collects data through interviews and documentary sources. It documents business functions - activities - and transactions.






7. Accepting all packets






8. This deals with differences between plaintext password storage and transmission - versus encrypted password storage and transmission.






9. In computer terminology - a honeypot is a trap set to detect - deflect or in some manner counteract attempts at unauthorized use of information systems. Generally it consists of a computer - data or a network site that appears to be part of a network






10. Software designed to infiltrate or damage a computer system - without the owner's consent.






11. 'If you cant see it - its secure'. Bad policy to live by.






12. Jumping into dumpsters to retrieve information about someone/something/a company






13. The most popular computer language used to create - modify - retrieve and manipulate data from relational database management systems. The language has evolved beyond its original purpose to support object-relational database management systems. It i






14. ('rotate by 13 places' - sometimes hyphenated ROT-13) Is a simple Caesar cipher used for obscuring text by replacing each letter with the letter thirteen places down the alphabet






15. In cryptography - a substitution cipher is a method of encryption by which units of plaintext are substituted with ciphertext according to a regular system; the 'units' may be single letters (the most common) - pairs of letters - triplets of letters






16. Same as a block cipher except that it is applied to a data stream one bit at a time






17. Among the most common types of viruses and the least damaging - these are hidden within applications that must be executed in order to execute the virus.






18. The user






19. Grabs an image of the finger which is then stored in a database and then works in a one-to-many database






20. Internet Architecture Board. This board is responsible for protecting the Internet.






21. Continuation of Operations Plan






22. An attempt to trick the system into believing that something false is real






23. Network devices that operate at layer 2. Every port on a switch is a separate collision domain






24. The EU spec. If databases exist - users are allowed to check data into them - allowed to change them if wrong - etc.






25. Disclosure - Alteration - Destruction. These things break the CIA triad






26. Methodical process of finding and reducing the number of bugs - or defects - in a computer program or a piece of electronic hardware thus making it behave as expected






27. If an employee is suspected of wrongdoing - sending them away from work for a while so that their actions can be audited.






28. An audit trail is a chronological sequence of audit records - each of which contains evidence directly pertaining to and resulting from the execution of a business process or system function. Audit records typically result from activities such as tra






29. Network Address Translation






30. Also civil law






31. A simple authentication protocol used to authenticate a user to a remote access server or Internet service provider (ISP). Almost all NOS remote servers support PAP. PAP transmits unencrypted ASCII passwords over the network and is therefore consider






32. The process of certifying a system that has been built to ensure that it meets the security standards that you have said you will use.






33. Involving the measurement of quantity or amount.






34. Ethernet - Cat5 - Twisted to allow for longer runs.






35. When a DNS server goes out to resolve a name - and gets the wrong response back - it caches the wrong address for the default DNS time period - thus poisoning the cache for that period of time






36. Deals with the same things as due diligence except that they deal with accepting responsibility instead of liability.






37. Trusted Computing Base. Comprised of the hardware - software - and firmware of the system.






38. In cryptanalysis and computer security - this attack is a technique for defeating a cipher or authentication mechanism by trying to determine its decryption key or passphrase by searching a large number of possibilities. In contrast with a brute forc






39. An instance of a scripting language






40. Also known as Rijndael - is a block cipher adopted as an encryption standard by the US government. It is expected to be used worldwide and analyzed extensively - as was the case with its predecessor - the Data Encryption Standard (DES). AES was adopt






41. Someone whose hacking is primarily targeted at the phone systems






42. A legal term used to describe an out-of-court statement offered to establish the truth of the facts asserted in that statement. Hearsay is generally not admissible in common law courts because it is of dubious value - but there are many exceptions to






43. The process of developing a planned approach to change in an organization. Typically the objective is to maximize the collective benefits for all people involved in the change and minimize the risk of failure of implementing the change.






44. Non-repudiation is the concept of ensuring that a contract - especially one agreed to via the Internet - cannot later be denied by one of the parties involved.






45. Random Number Base






46. Scanning the airwaves for radio transmissions






47. Attack which does not result in an unauthorized state change - such as an attack that only monitors and/or records data.






48. An attacker spoofs the source IP in a packet header - to make a ping request appear to have originated from the future victim's network - then the responding network responds in full force to these requests and brings down the victim's network.






49. The practice of following someone with a security code or keycard through a security door - generally in workplaces.






50. In a distributed attack - the attacking computer hosts are often zombie computers with broadband connections to the Internet that have been compromised by viruses or Trojan horse programs that allow the perpetrator to remotely control the machine and