Test your basic knowledge |

Comptia Security +: Vocab

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A distinctive sign of some kind which is used by a business to uniquely identify itself and its products and services to consumers - and to distinguish the business and its products and / or services from those of other businesses.






2. A computer program that contains some of the subject-specific knowledge of one or more human experts. The most common form of expert systems is a program (like a wizard) made up of a set of rules that analyze information (usually supplied by the user






3. Provides a means to obtain passwords or encryption keys and thus bypass other security measures. This can be accomplished through hardware or software means.






4. The art of breaking code. Testing the strength of an algorithm.






5. Not a picture - but rather vectors of your finger geometry with an acceptable variance built in to provide for slight changes.






6. Chief Executive Officer






7. An attempt to trick the system into believing that something false is real






8. In cryptography - a substitution cipher is a method of encryption by which units of plaintext are substituted with ciphertext according to a regular system; the 'units' may be single letters (the most common) - pairs of letters - triplets of letters






9. Setting up the user to access the honeypot for reasons other than the intent to harm.






10. A type of circuit switched telephone network system - designed to allow digital transmission of voice and data over ordinary telephone copper wires - resulting in better quality and higher speeds than available with analog systems.






11. In computer security - this type of attack is a situation in which one person or program successfully masquerades as another by falsifying data and thereby gains an illegitimate advantage.






12. A type of virus that changes its telltale code segments so that it ' looks' different from one infected file to another - thus making detection more difficult.






13. Involving the measurement of quantity or amount.






14. Testing a company's network to test for vulnerabilities in their systems so that weaknesses can be fixed. This testing does not actually fix anything.






15. Someone who hacks using programs that they can download from the Internet. This person usually doesn't find new exploits - but simply exploits vulnerabilities that others have found.






16. In a separation of duties model - this is where code is checked in and out






17. A meme and a joke are the same thing. e.g. When someone says to delete a file that is really just fine and they call it a virus






18. Determines the monetary loss (impact) for each occurrence of a threatened event. SLE = Asset Value x Exposure Factor






19. Any authentication protocol that requires two independent ways to establish identity and privileges. This contrasts with traditional password authentication - which requires only one factor (knowledge of a password) in order to gain access to a syste






20. False Acceptance Rate - False Rejection Rate - Crossover Error Rate






21. The frequency with which a threat is expected to occur.






22. In a computer system (or cryptosystem or algorithm) these are methods of bypassing normal authentication or securing remote access to a computer - while attempting to remain hidden from casual inspection.






23. A number of computer software products and specifications from Sun Microsystems that together provide a system for developing and deploying cross-platform applications. Java is used in a wide variety of computing platforms spanning from embedded devi






24. Non-repudiation is the concept of ensuring that a contract - especially one agreed to via the Internet - cannot later be denied by one of the parties involved.






25. Method of authenticating to a system. Something that you supply and something you know.






26. Animals with teeth. Not as discriminate as guards






27. Repeats the signal. It amplifies the signal before sending it on.






28. Someone whose hacking is primarily targeted at the phone systems






29. A compact disc that contains data only accessible by a computer. All modern CD-ROM drives can also read audio CDs. It is possible to produce composite CDs containing both data and audio with the latter capable of being played on a CD player - whilst






30. A RFC standard. A mechanism for performing commands on a remote system






31. The threshold is a baseline for violation activities that may be normal for a user to commit before alarms are raised.






32. Something used to put out a fire. Can be in Classes A - B - C - D - or H






33. If an employee is suspected of wrongdoing - sending them away from work for a while so that their actions can be audited.






34. Reasonable doubt






35. A class of storage media used in computers and other electronic devices. Because it cannot (easily) be written to - its main uses lie in the distribution of firmware.






36. More discriminate than dogs






37. 0 = striping without parity 1 = mirroring 3 = striping with parity (parity on single drive) 5 = striping with parity (parity striped across all drives)






38. A sandbox. Emulates an operating environment.






39. Basic Input/Output System






40. The process of training end users / employees in the ways and processes of security. This helps to mitigate risk to the company (if the employees know what to do) and also helps the employees to know what is expected of them security-wise - so that t






41. A birthday attack is a type of cryptographic attack which exploits the mathematics behind the birthday paradox - making use of a space-time tradeoff.






42. Component Object Model.






43. In a distributed attack - the attacking computer hosts are often zombie computers with broadband connections to the Internet that have been compromised by viruses or Trojan horse programs that allow the perpetrator to remotely control the machine and






44. Chief Information Officer






45. Issued by the United States National Computer Security Center (NCSC - an arm of the NSA) as 'Trusted Computer System Evaluation Criteria' - a DOD standard 5200.23-STD in December 1985 superseding CSC-STD-001-83 - the TCSEC (frequently referred to as






46. A remote authentication protocol that is used to communicate with an authentication server commonly used in UNIX networks. TACACS allows a remote access server to communicate with an authentication server in order to determine if the user has access






47. An international standard defining security assurance and functionality profiles. Replaced the TCSEC - ITSEC - etc.






48. Refers to the formal acceptance by organization executive management that they accept the residual risk associated with using a formally certified information system.






49. When you have a certain amount of access and you change jobs and you keep that access from the previous position. Also known as enlargement of permission and privilege escalation.






50. A set of exclusive rights granted by governments to regulate the use of a particular expression of an idea or information. Artists ability to control their work