Unit 1
Unit 2
Unit 3
Unit 4
Unit 5
100

Using multiple layers so that one failure is not enough

defense in depth

100

90 days

How long a private report of a bug should take.

100

Identify assets, Define treats and vulnerabilities, Calculate likelihoods and impacts, Select risk response options and controls

4 steps of risk analysis

100

Enables a host to discover another host's MAC address

ARP (Address Resolution Protocol)

100

The rules for filtering traffic

needs an implicit deny

Firewall ACL's

200

The CIA triad stands for

Confidentiality

integrity

availability

200

publishing bug vs report privately

Full disclosure vs coordinated

200

Subjective vs. objective

Qualitative - high/low

vs

quantitative - ALE

200

SYN

SYN ACK

ACK

three-way handshake

200

Stateless/static, stateful, web application, next generation, host based, network edge vs. internal segmentation, standalone vs. shared device, hardware vs. software

Types of firewalls

300

confidentiality

only the right people can see the information

300

serving both peaceful/defensive and military/offensive purposes

Dual use

300

ALE = SLE * ARO

SLE = AV*EF

formula for ALE

300

The levels of the OSI model

physical, data link, network, transport, session, presentation, application

300

IDS vs IPS

solution that observes copies and alerts on anomalous activity

vs.

solution situated "in line" with network traffic and can block anomalous activity

400

A structured way to identify what can go wrong in a system and deciding what to do before attackers cause harm

threat modeling

400

Competence, Integrity, non-maleficence

Major duties of code of ethics

400

physical, procedural/administrative, technical, legal

vs.

Directive, preventative, detective, corrective, forensic

security controls by nature vs. by time

400

Protocol for automatically assigning network configuration parameters vs. Protocol for translating IP addresses to FQDNs

DHCP vs. DNS

400

WEP - insecure

WPA2/802.11i

WPA3 - secure/preferred

Types of wireless security protocols

500

stride stands for

Spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege

500

What is allowed at RIT in regard to AI?

brainstorming concepts, or debugging hints after getting permission

500

asks Who is accountable for cybersecurity in this organization?

govern function from NIST CSF 2.0

500

proxy between clients and internet to manage outbound vs. proxy sitting between internet and backend servers to manage inbound traffic

forward vs. reverse proxy

500

can't secure the physical medium

no static network perimeter, external business requirements, cloud-based applications

possible threats

M
e
n
u