Test your basic knowledge |

Comptia Security +: Vocab

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. The person that controls access to the data






2. White hat l0pht






3. An agreement that you make with another company to be able to use their facilities in the event of a disaster. The least expensive - and not usually enforceable.






4. A form of binary to text encoding that originated as a Unix program for encoding binary data for transmission over the uucp mail system. The name 'uuencode' is derived from 'Unix-to-Unix encoding'. Since uucp converted characters between various comp






5. The frequency with which a threat is expected to occur.






6. A logic bomb is a piece of code intentionally inserted into a software system that will set off a malicious function when specified conditions are met.






7. RFC 1918 defined the following addresses as the private addressing ranges: 192.168.x.x - 10.x.x.x - 172.16.x.x - 172.31.x.x






8. ('rotate by 13 places' - sometimes hyphenated ROT-13) Is a simple Caesar cipher used for obscuring text by replacing each letter with the letter thirteen places down the alphabet






9. A team of individuals at the highest level of organizational management who have the day-to-day responsibilities of managing a corporation. And don't forget - they are always the ones ultimately responsible for due diligence / due care. They are also






10. This is an attack in which an attacker is able to read - insert and modify at will - messages between two parties without either party knowing that the link between them has been compromised. The attacker must be able to observe and intercept message






11. Data storage formats and equipment that allow the stored data to be accessed in any order






12. A sandbox. Emulates an operating environment.






13. They all deal with objects or identifiers that are used during authentication. They provide information that will allow the authentication to happen. There are many types.






14. An imaginary boundary between the components that make up the TCB and the components that are not covered by the TCB






15. An AAA (Authentication - Authorization - and Accounting) protocol for applications such as network access or IP mobility. It is intended to work in both local and roaming situations.






16. The physical part of a computer - as distinguished from the computer software that executes within the hardware.






17. A network that uses standard protocols (TCP/IP)






18. Base 64 is a positional numeral system using a base of 64. It is the largest power of two base that can be represented using only printable ASCII characters. This has led to its use as a transfer encoding for e-mail among other things.






19. The real cost of acquiring/maintaining/developing a system






20. Provides for less data leakage. Longer distance. Uses light instead of electrical impulse.






21. Enticing people to hit your honeypot to see how they try to access your system.






22. The Teardrop attack involved sending IP fragments with overlapping payloads to the target machine.






23. A type of hash function used to produce a checksum - which is a small - fixed number of bits - against a block of data. This is used to detect errors after transmission or storage.






24. A hash function (or hash algorithm) is a way of creating a small digital 'fingerprint' from any kind of data. The function chops and mixes the data to create the fingerprint - often called a hash value. The hash value is commonly represented as a sho






25. In the context of computer software - a Trojan horse is a malicious program that is disguised as or embedded within legitimate software.






26. Defines the objects and their attributes that exist in a database.






27. A network entity that provides a single entrance / exit point to the Internet.






28. Identifying risks and assessing the possible damage that can be caused in order to justify security safeguards






29. Diffie-Hellman (D-H) key exchange is a cryptographic protocol which allows two parties that have no prior knowledge of each other to jointly establish a shared secret key over an insecure communications channel. This key can then be used to encrypt s






30. In a computer system (or cryptosystem or algorithm) these are methods of bypassing normal authentication or securing remote access to a computer - while attempting to remain hidden from casual inspection.






31. Repeats the signal. It amplifies the signal before sending it on.






32. Someone who hacks using programs that they can download from the Internet. This person usually doesn't find new exploits - but simply exploits vulnerabilities that others have found.






33. A card that holds information that must be authenticated to before it can reveal the information that it is holding






34. Occupant Emergency Plan - Employees are the most important!






35. Network device that operates at layer 1. Concentrator.






36. Animals with teeth. Not as discriminate as guards






37. A system designed to stop piggybacking.






38. Non-repudiation is the concept of ensuring that a contract - especially one agreed to via the Internet - cannot later be denied by one of the parties involved.






39. Random Number Base






40. A computer program that contains some of the subject-specific knowledge of one or more human experts. The most common form of expert systems is a program (like a wizard) made up of a set of rules that analyze information (usually supplied by the user






41. Making individuals accountable for their actions on a system typically through the use of auditing






42. Public Key Infrastructure






43. The illegal practice of stealing money repeatedly in extremely small quantities - usually by taking advantage of rounding to the nearest cent (or other monetary unit) in financial transactions. Salami slicing is most often performed by employees of t






44. In computer networking - this is the method for finding a host's hardware address when only its IP address is known. Due to the overwhelming prevalence of IPv4 and ethernet - ARP is primarily used to translate ethernet MAC addresses from IP addresses






45. A distinctive sign of some kind which is used by a business to uniquely identify itself and its products and services to consumers - and to distinguish the business and its products and / or services from those of other businesses.






46. A form of redundancy check (a very simple measure for protecting the integrity of data by detecting errors in data that is sent through space or time.






47. Refers to the formal acceptance by organization executive management that they accept the residual risk associated with using a formally certified information system.






48. The threshold is a baseline for violation activities that may be normal for a user to commit before alarms are raised.






49. Systems that use a knowledge base - an inference engine - and general methods for searching problem solutions.






50. Someone whose hacking is primarily targeted at the phone systems