The applications on either end of the API are synchronized and protecting the integrity of the information that passes through the API. It also enables proper updating and versioning required in many environments.
Card 22
Question
application wrapping
Answer
Technique to protect mobile devices and the data they contain. Application wrappers (implemented as policies) enable administrators to set policies that allow employees with mobile devices to safely download an app, typically from an internal store.
Card 23
Question
Arachni
Answer
A Ruby framework for assessing the security of a web application.
Card 24
Question
asset criticality
Answer
A measure of how essential an asset is to the organization’s business.
Card 25
Question
asset tagging
Answer
Process of placing physical identification numbers of some sort on all assets.
Card 26
Question
asset value (AV)
Answer
Value of an asset. Multiplied by the exposure factor (EF) to calculate single loss expectancy (SLE).
Card 27
Question
asymmetric algorithms
Answer
Algorithms that use both a public key and a private or secret key. The public key is known by all parties, and the private key is known only by its owner.
Card 28
Question
atomic execution
Answer
A set of instructions either execute in order and in entirety or the changes they make are rolled back or prevented Atomic operations in concurrent programming are program operations that run independently of any other processes (threads). Making the operation atomic consists of using synchronization mechanisms in order to make sure that the operation is seen, from any other thread, as a single, atomic operation. This increases security by preventing one thread from viewing the state of the data when the first thread is still in the middle of the operation.
Card 29
Question
Attack Complexity (AC)
Answer
CVSS base metric that describes the difficulty of exploiting the vulnerability.
Card 30
Question
attack frameworks
Answer
Frameworks and methodologies that include security program development standards, enterprise and security architect development frameworks, security control development methods, corporate governance methods, and process management methods.
Card 31
Question
attack vector
Answer
A segment of the communication path that an attack uses to access a vulnerability.
Card 32
Question
Attack Vector (AV)
Answer
CVSS base metric that describes how the attacker would exploit the vulnerability.
Card 33
Question
attestation
Answer
Process in which the software and platform components have been identified, or “measured,” using cryptographic techniques.
Card 34
Question
attribute-based access control (ABAC)
Answer
Authentication system that grants or denies user requests based on arbitrary attributes of the user and arbitrary attributes of the object, and environment conditions that may be globally recognized.
Card 35
Question
Authentication Header (AH)
Answer
IPsec component that provides data integrity, data origin authentication, and protection from replay attacks.
Card 36
Question
authentication period
Answer
How long a user can remain logged in.
Card 37
Question
authentication server
Answer
In the 802.1X framework, the centralized device that performs authentication.
Card 38
Question
authenticator
Answer
In the 802.1X framework, the device through which the supplicant is attempting to access the network.
Card 39
Question
automated malware signature creation
Answer
A method of identifying malware in which the AV software monitors incoming unknown files for the presence of malware and analyzes the file based on both classifiers of file behavior and classifiers of file content.
Card 40
Question
Availability (A)
Answer
CVSS base metric that describes the disruption that might occur if the vulnerability is exploited.
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.