Test your basic knowledge |

Comptia Security +: Vocab

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An imaginary boundary between the components that make up the TCB and the components that are not covered by the TCB






2. A spoofing attack - a kind of attack in data communication - in which a third party tries to mislead the communication participants using forged information.






3. In a separation of duties model - this is where code is checked in and out






4. Communications that don't take the natural course of email (when you don't want eavesdropping to happen)






5. An audit trail is a chronological sequence of audit records - each of which contains evidence directly pertaining to and resulting from the execution of a business process or system function. Audit records typically result from activities such as tra






6. Business Impact Analysis. A BIA is a functional analysis in which a team collects data through interviews and documentary sources. It documents business functions - activities - and transactions.






7. Rotating employee's job duties so that things can be checked that they are doing to make sure nothing fraudulent is occurring.






8. Residual physical representation of data that has been in some way erased. After storage media is erased there may be some physical characteristics that allow data to be reconstructed.






9. Computer Incident Response Team






10. Also known as Rijndael - is a block cipher adopted as an encryption standard by the US government. It is expected to be used worldwide and analyzed extensively - as was the case with its predecessor - the Data Encryption Standard (DES). AES was adopt






11. A form of redundancy check (a very simple measure for protecting the integrity of data by detecting errors in data that is sent through space or time.






12. A name given to a system implemented by the FBI that is analogous to wiretapping except in this case - e-mail and other communications are being tapped instead of telephone conversations. Carnivore was essentially a customizable packet sniffer that c






13. A specialized form of software authentication that enables a user to authenticate once and gain access to the resources of multiple software systems.






14. A formula - practice - process - design - instrument - pattern - or compilation of information used by a business to obtain an advantage over competitors within the same industry or profession.






15. Issued by the United States National Computer Security Center (NCSC - an arm of the NSA) as 'Trusted Computer System Evaluation Criteria' - a DOD standard 5200.23-STD in December 1985 superseding CSC-STD-001-83 - the TCSEC (frequently referred to as






16. This factor represents a measure of the magnitude of loss or impact on the value of an asset.






17. In computer networking - this is the method for finding a host's hardware address when only its IP address is known. Due to the overwhelming prevalence of IPv4 and ethernet - ARP is primarily used to translate ethernet MAC addresses from IP addresses






18. When security is managed at many different points in an organization






19. Network devices that operate at layer 3. This device separates broadcast domains.






20. A mechanism by which connections to TCP services on a system are allowed or disallowed






21. The process of training end users / employees in the ways and processes of security. This helps to mitigate risk to the company (if the employees know what to do) and also helps the employees to know what is expected of them security-wise - so that t






22. They all deal with objects or identifiers that are used during authentication. They provide information that will allow the authentication to happen. There are many types.






23. A hash function (or hash algorithm) is a way of creating a small digital 'fingerprint' from any kind of data. The function chops and mixes the data to create the fingerprint - often called a hash value. The hash value is commonly represented as a sho






24. A site that is ready and available within minutes or hours to continue processing. This is a site that is fully configured and ready to go.






25. A distinctive sign of some kind which is used by a business to uniquely identify itself and its products and services to consumers - and to distinguish the business and its products and / or services from those of other businesses.






26. A hidden communications channel on a system that allows for the bypassing of the system security policy






27. Threat to physical security.






28. An attacker spoofs the source IP in a packet header - to make a ping request appear to have originated from the future victim's network - then the responding network responds in full force to these requests and brings down the victim's network.






29. Network device that operates at layer 1. Concentrator.






30. Countermeasure to put fake stuff into a database so if someone is reading it they will get the wrong info.






31. Must be in place for you to use a biometric system






32. The amount of users that the system can process in a given amount of time. A typical acceptable amount is 10/minute






33. (OLE) is a distributed object system and protocol developed by Microsoft. OLE allows an editor to 'farm out' part of a document to another editor and then reimport it. Its primary use is for managing compound documents - but it is also used for trans






34. This is the file on a UNIX system where usernames to password MD5 hash outputs are stored. The system uses this file to determine if the password entered for a given username is correct.






35. In risk assessment - the average monetary value of losses per year. SLE x ARO = ALE






36. Also civil law






37. When a DNS server goes out to resolve a name - and gets the wrong response back - it caches the wrong address for the default DNS time period - thus poisoning the cache for that period of time






38. Personal - Network - and Application






39. Internet Relay Chat.






40. The real cost of acquiring/maintaining/developing a system






41. Animals with teeth. Not as discriminate as guards






42. In cryptography - it is a block cipher






43. Software designed to infiltrate or damage a computer system - without the owner's consent.






44. When you know something from a source - and can infer other related information based off of what you know - when you may not necessarily have access to that data normally.






45. If an employee is suspected of wrongdoing - sending them away from work for a while so that their actions can be audited.






46. Emanations from one wire coupling with another wire






47. When you have a certain amount of access and you change jobs and you keep that access from the previous position. Also known as enlargement of permission and privilege escalation.






48. In cryptography - it is one of the simplest and most widely-known encryption techniques. It is a type of substitution cipher in which each letter in the plaintext is replaced by a letter some fixed number of positions further down the alphabet.






49. An attack that is similar to smurf but instead of using ICMP (ping) it uses UDP as its weapon of choice. It broadcasts a spoofed UDP packet to the amplifying network.






50. Entails planning and system actions to ensure that a project is following good quality management practices