An XSS attack in which the hacker stores the user input on the target server, such as in a database, in a message forum, a visitor log, a comment field, and so forth, and then a victim is able to retrieve the stored data from the web application without that data being made safe to render in the browser. Also called a stored or Type I attack.
Card 322
Question
personal health information (PHI)
Answer
The medical records of individuals; also referred to as protected health information.
Card 323
Question
Personal Information Protection and Electronic Documents Act (PIPEDA)
Answer
Affects how private-sector organizations collect, use, and disclose personal information in the course of commercial business in Canada.
Card 324
Question
personally identifiable information (PII)
Answer
Any piece of data that can be used alone or with other information to identify a single person.
Card 325
Question
phishing
Answer
A social engineering attack in which attackers try to learn personal information, including credit card information and financial data.
Card 326
Question
physical control
Answer
A type of control that is implemented to protect an organization’s facilities and personnel.
Card 327
Question
ping sweep
Answer
A scan that uses ICMP to identify all live hosts by pinging all IP addresses in the known network.
Card 328
Question
piping
Answer
The process of sending the output of one function to another function as its input.
Card 329
Question
Platform as a Service (PaaS)
Answer
Cloud service model in which the vendor provides the hardware platform or data center and the software running on the platform, including the operating systems and infrastructure software.
Card 330
Question
Point-to-Point Tunneling Protocol (PPTP)
Answer
Microsoft protocol based on PPP that uses built-in Microsoft Point-to-Point encryption and can use a number of authentication methods, including CHAP, MS-CHAP, and EAP-TLS.
Card 331
Question
policy decision point (PDP)
Answer
An entity that retrieves all applicable polices in XACML and compares the request with the policies.
Card 332
Question
policy enforcement point (PEP)
Answer
An entity that protects the resource that the subject (a user or an application) is attempting to access in XACML.
Card 333
Question
port scan
Answer
A scan that attempts to connect to every port on each device and report which ports are open, or “listening.”
Card 334
Question
port security
Answer
Allows you to keep a port enabled for legitimate devices while preventing its use by illegitimate devices.
Card 335
Question
preventative control
Answer
A type of control that prevents an attack from occurring.
Card 336
Question
privacy
Answer
Relates to rights to control the sharing and use of one’s personal information.
Card 337
Question
private cloud
Answer
A cloud deployment model in which a private organization implements a cloud in its internal enterprise, and that cloud is used by the organization’s employees and partners.
Card 338
Question
Privilege Escalation
Answer
The process of exploiting a bug or weakness in an operating system to allow a user to receive privileges to which she is not entitled.
Card 339
Question
Privileges Required (Pr)
Answer
A CVSS base metric that describes the authentication an attacker would need to get through to exploit the vulnerability.
Card 340
Question
Process Explorer
Answer
A Sysinternals tool that enables you to look at the graph that appears in Task Manager and identify what caused spikes in the past, which is not possible with Task Manager alone.
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.