Enterprise mode uses an 802.1x server (implemented as a RADIUS server).
Enterprise mode requires an 802.1x server.
PEAP and EAP-TTLS require a certificate on the 802.1x server. EAP-TLS also uses TLS, but it requires certificates on both the 802.1x server and each of the clients.
Card 2
Question
3DES
Answer
Triple Digital Encryption Standard.
A symmetric algorithm used to encrypt data and provide confidentiality.
A block cipher that encrypts data in 64-bit blocks.
Originally designed as a replacement for DES.
Still used in some applicaitons, such as when hardware doesnt support AES.
Card 3
Question
AAA
Answer
Authentication, Authroization and Accounting.
Used in remote access systems.
Examples: TACACS+ which uses multiple challengs and responses during a session.
Authenticaiton verifies a users identification.
Authorization determines if a user should have acces.
Accounting tracks a users access with logs.
Card 4
Question
ACE
Answer
Access Control Entry.
Identifies a user or group that is granted permission to a resource.
Are contained within a DACL in NTFS.
Card 5
Question
ACK
Answer
Acknowledgement.
A packet in a TCP handshake.
In a SYN flood attack, attackers send the SYN packet, but don't complete the handshake after recieving the SYN/ACK packet.
Card 6
Question
ACL
Answer
Access Control List.
Routers and packet-filtering firewalls perform basic filtering using an ACL to control traffic based on networks, subnets, IP addresses, ports and some protocols.
In NTFS a list of ACEs makes up the ACL for a resource.
Card 7
Question
AES
Answer
Advanced Encryption Standard.
A symmetric algorithm used to encrypt data and provide confidentiality.
AES is a block cipher and it encrypts data in 128-bit blocks.
It is quick, highly secure, and used in a wide assortment of cryptography schemes.
It includes key sizes of 128 bits, 192 bits, or 256 bits.
Card 8
Question
AES-256
Answer
Advanced Encryption Standard 256 bit.
AES sometimes includes the number of bits used in the encryption keys and AES-256 uses 256-but encryption keys.
Blowfish (448-bit encryption) is quicker that AES-256.
Card 9
Question
AH
Answer
Authentication Header.
AH provides authentication and integrity using HMAC.
AH is identified with protocol ID number 51.
IPSec includes both AH and ESP.
ESP provides confidentiality, integrity, and authentication using HMAC, and AES or 3DES.
Card 10
Question
ALE
Answer
Annual (or annualized) Loss Expentancy.
Identifies the expected annual loss and is used to measure risk with ARO and SLE in a quantitative risk assessment.
Calculation: SLE x ARO = ALE
Card 11
Question
AP
Answer
Access Point.
Short for Wirewall Access Point (WAP).
Provides access to a wired network to wireless clients.
Many APs support Isolation mode to segment wireless users from other wireless users.
Card 12
Question
API
Answer
Application Programming Interface.
A software module or component that identifies inputs and outputs for an application.
Card 13
Question
APT
Answer
Advanced Persistent Threat.
A group that has both the capability and intent to launch sophisticated and targeted attacks.
Card 14
Question
ARO
Answer
Annual (or annualized) rate of occurence.
Identifies how many times a loss is expected to occur in a year and is used to meaure risk with ALE and SLE in a quantitative risk assessment.
Calculation: SLE x ARO = ALE
Card 15
Question
ARP
Answer
Address Resolution Protocol.
Resolves IPv4 addresses to MAC addresses.
ARP poisoning attacks can redirect traffic through an attackers system by sending false MAC address updates.
NDP is used with IPv6 instead of ARP.
Card 16
Question
ASCII
Answer
American Standard Code for Information Interchange.
Code used to display characters.
Card 17
Question
ASP
Answer
Application Service Provider.
Provides an applicaiton as a service over a network.
Card 18
Question
AUP
Answer
Acceptable Usage Policy.
Defines proper system usage.
Will often descript the purpose of computer systems and networks, how users can access them, and the responsibilities of users when accessing the systems.
Card 19
Question
BAC
Answer
Business Availablility Center.
An application that shows availability and performance of applications used or provided by a business.
Card 20
Question
BCP
Answer
Business Continuity Plan.
A plan that helps an organization predict and plan for potential outages of critical services or functions.
Includes disaster recovery elements that provide steps used to return critical functions to operation after an outage.
A BIA is a part of a BCP and the BIA drives decisions to create redundancies such as failover clusters or alternative sites.
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.