Shared Flashcard Set

Details

IT296 - Chapter 04
IT296 - Chapter 04 (Security+)
62
Computer Science
Undergraduate 2
04/23/2016

Additional Computer Science Flashcards

 


 

Cards

Term
access list
Definition
A paper or electronic record of individuals who have permission to enter a
secure area, the time that they entered, and the time they left the area.
Term
activity phase controls
Definition
security controls, classified as deterrent, preventive,
detective, compensation, or corrective.
Term
administrative control
Definition
Process for developing and ensuring that policies and procedures
are carried out, specifying actions that users may do, must do, or cannot do.
Term
alarm
Definition
An audible sound to warn a guard of an intruder.
Term
antispyware
Definition
Software that helps prevent computers from becoming infected by different
types of spyware.
Term
antivirus (AV)
Definition
Software that can examine a computer for any infections as well as monitor
computer activity and scan new documents that might contain a virus.
Term
barricade
Definition
A structure designed to block the passage of traffic.
Term
Bayesian filtering
Definition
Spam filtering software that analyzes every word in an email and
determines how frequently a word occurs in order to determine if it is spam.
Term
Big Data
Definition
A collection of data sets so large and complex that it becomes difficult to process
using on-hand database management tools or traditional data processing applications.
Term
blacklist
Definition
Permitting everything unless it appears on the list; a list of nonapproved senders.
Term
cable lock
Definition
A device that can be inserted into the security slot of a portable device and
rotated so that the cable lock is secured to the device to prevent it from being stolen.
Term
client-side validation
Definition
Having the client web browser perform all validations and error
recovery procedures.
Term
closed circuit television (CCTV)
Definition
Video cameras and receivers used for surveillance in areas
that require security monitoring.
Term
compensating control
Definition
Control that provides an alternative to normal controls that for
some reason cannot be used.
Term
corrective control
Definition
that is intended to mitigate or lessen the damage caused by an
incident.
Term
cross-site request forgery (XSRF)
Definition
An attack that uses the user’s web browser settings to
impersonate the user.
Term
data at-rest
Definition
Data that is stored on electronic media.
Term
data in-transit
Definition
Data that is in transit across a network, such as an email sent across the
Internet.
Term
data in-use
Definition
A state of data in which actions upon it are being performed by “endpoint devices”
such as printers.
Term
data loss prevention (DLP)
Definition
A system that can identify critical data, monitor how it is being
accessed, and protect it from unauthorized users.
Term
deadbolt lock
Definition
A door lock that extends a solid metal bar into the door frame for extra security.
Term
detective control
Definition
A control that is designed to identify any threat that has reached the
system.
Term
deterrent control
Definition
A control that attempts to discourage security violations before they occur.
Term
embedded system
Definition
A computer system with a dedicated function within a larger electrical
or mechanical system.
Term
errors
Definition
Faults in a program that occur while the application is running. Also called
exceptions.
Term
exceptions
Definition
See errors. - Faults in a program that occur while the application is running. Also called
exceptions.
Term
fencing
Definition
Securing a restricted area by erecting a barrier.
Term
firewall
Definition
Hardware or software that is designed to prevent malicious packets from entering
or leaving computers. Also called packet filter.
Term
fuzz testing (fuzzing)
Definition
software testing technique that deliberately provides invalid,
unexpected, or random data as inputs to a computer program.
Term
guard
Definition
A human who is an active security element.
Term
host-based application firewall
Definition
A firewall that runs as a program on a local system.
Term
hotfix
Definition
Software that addresses a specific customer situation and often may not be
distributed outside that customer’s organization.
Term
input validation
Definition
Verifying a user’s input to an application.
Term
lighting
Definition
Lights that illuminate an area so that it can be viewed after dark.
Term
locking cabinet
Definition
A ruggedized steel box with a lock.
Term
mainframe
Definition
A very large computing system that has significant processing capabilities.
Term
mantrap
Definition
A device that monitors and controls two interlocking doors to a small room
(a vestibule), designed to separate secure and nonsecure areas.
Term
motion detection
Definition
Determining an object’s change in position in relation to its
surroundings.
Term
NoSQL
Definition
A nonrelational database that is better tuned for accessing large data sets.
Term
NoSQL databases vs. SQL databases
Definition
An argument regarding which database technology is
superior. Also called SQL vs. NoSQL.
Term
OS hardening
Definition
Tightening security during the design and coding of the OS.
Term
packet filter
Definition
Hardware or software that is designed to prevent malicious packets from
entering or leaving computers. Also called firewall.
Term
patch
Definition
A general software security update intended to cover vulnerabilities that have been
discovered.
Term
popup blocker
Definition
Either a program or a feature incorporated within a browser that stops
popup advertisements from appearing.
Term
preventive controls
Definition
A control that attempts to prevent the threat from coming in and
reaching contact with the vulnerability.
Term
protected distribution system (PDS)
Definition
A system of cable conduits that is used to protect
classified information being transmitted between two secure areas.
Term
proximity reader
Definition
A device that detects an emitted signal in order to identify the owner.
Term
safe
Definition
A ruggedized steel box with a lock.
Term
SCADA (supervisory control and data acquisition)
Definition
Large-scale, industrial-control systems.
Term
security control
Definition
Any device or process that is used to reduce risk.
Term
security policy
Definition
A document or series of documents that clearly defines the defense
mechanisms an organization will employ to keep information secure.
Term
server-side validation
Definition
Having the server perform all validations and error recovery
procedures.
Term
service pack
Definition
Software that is a cumulative package of all security updates plus additional
features.
Term
sign
Definition
A written placard that explains a warning, such as notice that an area is restricted.
Term
smartphone
Definition
A cell phone with an operating system that allows it to run third-party
applications (apps).
Term
SQL vs. NoSQL
Definition
An argument regarding which database technology is better. Also called
NoSQL databases vs. SQL databases.
Term
static environment
Definition
Devices in which additional hardware cannot easily be added or attached.
Term
technical controls
Definition
Security controls that are carried out or managed by devices.
Term
trusted OS
Definition
An operating system that has been designed through OS hardening.
Term
video surveillance
Definition
Monitoring activity that is captured by a video camera.
Term
whitelist
Definition
Permitting nothing unless it appears on the list.
Term
wrapper function
Definition
A substitute for a regular function that is used in testing.
Supporting users have an ad free experience!