SecurityX - (CAS-005) Exam
Common Libraries Shared software components or dependencies that multiple containers on the
same host system rely on.
Software Development Life Cycle (SDLC) Planning & Requirement Analysis:
Identify business needs, objectives, and feasibility.
Gather and define software requirements.
Determine project scope, risks, and resource allocation.
Stakeholders and developers collaborate to ensure alignment.
System Design:
Translate requirements into system and software architecture.
Design the UI/UX, database, APIs, and software components.
Create high-level and low-level design documents.
Define technologies, frameworks, and security measures.
Implementation (Coding & Development):
Convert design documents into actual code.
Developers write, review, and optimize code following best practices.
Use version control systems (e.g., Git, GitHub) for collaboration.
Conduct unit testing during development to catch early bugs.
Testing & Quality Assurance (QA):
Perform different types of testing:Unit Testing (checks individual
components)Integration Testing (checks interactions between
components)System Testing (verifies complete software functionality)User
Acceptance Testing (UAT) (ensures the software meets user requirements)
Identify, report, and fix bugs before release.
Deployment:
Deploy the software to production or staging environments.
Use CI/CD pipelines for automated deployment.
Monitor for errors and performance issues post-deployment.
Rollback strategy is prepared in case of failure.
Maintenance & Support:
Monitor system performance and security.
Release patches, bug fixes, and updates.
Improve features based on user feedback.
Address new security threats and compliance requirements.
Open SDN Open-source variant of SDN that relies on open-source technology.
Hybrid SDN A networking model that combines traditional networking with Software-
Defined Networking (SDN) principles. It allows organizations to gradually
transition from a traditional network to a software-defined approach while
maintaining compatibility with legacy systems.
SDN Overlay A networking approach where a logical (virtual) network is created on top of
an existing physical network using encapsulation protocols. This allows for
greater flexibility, network segmentation, and automation without requiring
changes to the underlying physical infrastructure.
Rapid Elasticity A type of services can allow you to get more storage and more resources
added to the cloud as fast as possible.
Resource Pooling The concept that allows a virtual environment to allocate memory and
processing capacity for a VMs use.
, SecurityX - (CAS-005) Exam
Event Correlation This service analyzes data from multiple sources to identify meaningful patterns
and relationships between security events, helping prioritize threats.
Smishing Attack An SMS-based phishing, where an attacker sends fraudulent messages to trick
users into clicking malicious links or sharing sensitive information.
Deauthentication Attack A type of Denial-of-Service (DoS) attack targeting Wi-Fi networks. It exploits
the 802.11 Wi-Fi deauthentication frame, forcing devices to disconnect from a
wireless network. Attackers use this technique to disrupt network access or to
execute further attacks, such as Wi-Fi eavesdropping (Evil Twin attack) or
credential theft.
CVSS Scores None 0.0
Low 0.1 -3.9
Medium 4.0 - 6.9
High 7.0 - 8.9
Critical 9.0 - 10
Attestation Services Services that are used to ensure the integrity of the computer's startup and
runtime operations. Hardware-based ******** is designed to protect against
threats and malicious code that could be loaded before the operating system
is loaded.
Secure Boot A UEFI feature that prevents a system from booting up with drivers or an OS
that are not digitally signed and trusted by the motherboard or computer
manufacturer.
HOTP HMAC-based One-Time Password. An open standard used for creating one-
time passwords. It combines a secret key and a counter, and then uses HMAC
to create a hash of the result. This password does not expire.
TOTP Time-based One-Time Password. Similar to HOTP, but it uses a timestamp
instead of a counter. One-time passwords created with TOTP expire after 30
seconds.
Risk Tolerance Refers to the specific amount or level of risk that an organization is willing to
accept or bear.
, SecurityX - (CAS-005) Exam
Risk Appetite The overall amount of risk an organization is willing to pursue or retain in order
to achieve its objectives. It is broader in nature and less specific than risk
tolerance.
JIT Access Features Enables users to temporarily elevate their privileges for specific, approved
tasks, reducing the risk of misuse or persistent vulnerabilities associated with
permanent administrative rights. (JIT = Just-In-Time)
SASE (Secure Access Service Edge) Framework A cloud-based network security framework that integrates networking and
security into a unified service. It combines SD-WAN (Software-Defined Wide
Area Networking) with security functions, such as Zero Trust Network Access
(ZTNA), Firewall-as-a-Service (FWaaS), Secure Web Gateway (SWG), Cloud
Access Security Broker (CASB), and Data Loss Prevention (DLP).
Facial recognition scan A type of scan will measure the size or distance of a person's external features
with a digital video camera.
Secure Encalve A protected, isolated execution environment within a processor that provides
enhanced security for sensitive operations such as cryptographic key
management, biometric authentication, and secure data processing. It ensures
that even if the main operating system is compromised, the data and operations
inside the enclave remain protected.
CPU Security Extensions Hardware-based security features built into modern processors to enhance
data protection, memory isolation, and secure execution environments. These
extensions help mitigate various security threats, such as malware, privilege
escalation, and memory-based attacks.
Software Composition Analysis (SCA) Tools Security and compliance solutions that help identify and manage open-source
and third-party software components within an application. They scan
dependencies, detect vulnerabilities, and ensure license compliance.
Low Impact Confidentiality Risk "The unauthorized disclosure of information could be expected to have a
limited adverse effect."
Moderate Impact Confidentiality Risk "A serious adverse effect expected."
High Impact Confidentiality Risk "A severe or catastrophic adverse effect expected."
Cryptographic Erase (CE) A wiping technique that encrypts the data on a media device and destroys the
encryption key. Performing a cryptographic erasure (CE) would sanitize and
purge the drives' data without harming the drives themselves.
Common Libraries Shared software components or dependencies that multiple containers on the
same host system rely on.
Software Development Life Cycle (SDLC) Planning & Requirement Analysis:
Identify business needs, objectives, and feasibility.
Gather and define software requirements.
Determine project scope, risks, and resource allocation.
Stakeholders and developers collaborate to ensure alignment.
System Design:
Translate requirements into system and software architecture.
Design the UI/UX, database, APIs, and software components.
Create high-level and low-level design documents.
Define technologies, frameworks, and security measures.
Implementation (Coding & Development):
Convert design documents into actual code.
Developers write, review, and optimize code following best practices.
Use version control systems (e.g., Git, GitHub) for collaboration.
Conduct unit testing during development to catch early bugs.
Testing & Quality Assurance (QA):
Perform different types of testing:Unit Testing (checks individual
components)Integration Testing (checks interactions between
components)System Testing (verifies complete software functionality)User
Acceptance Testing (UAT) (ensures the software meets user requirements)
Identify, report, and fix bugs before release.
Deployment:
Deploy the software to production or staging environments.
Use CI/CD pipelines for automated deployment.
Monitor for errors and performance issues post-deployment.
Rollback strategy is prepared in case of failure.
Maintenance & Support:
Monitor system performance and security.
Release patches, bug fixes, and updates.
Improve features based on user feedback.
Address new security threats and compliance requirements.
Open SDN Open-source variant of SDN that relies on open-source technology.
Hybrid SDN A networking model that combines traditional networking with Software-
Defined Networking (SDN) principles. It allows organizations to gradually
transition from a traditional network to a software-defined approach while
maintaining compatibility with legacy systems.
SDN Overlay A networking approach where a logical (virtual) network is created on top of
an existing physical network using encapsulation protocols. This allows for
greater flexibility, network segmentation, and automation without requiring
changes to the underlying physical infrastructure.
Rapid Elasticity A type of services can allow you to get more storage and more resources
added to the cloud as fast as possible.
Resource Pooling The concept that allows a virtual environment to allocate memory and
processing capacity for a VMs use.
, SecurityX - (CAS-005) Exam
Event Correlation This service analyzes data from multiple sources to identify meaningful patterns
and relationships between security events, helping prioritize threats.
Smishing Attack An SMS-based phishing, where an attacker sends fraudulent messages to trick
users into clicking malicious links or sharing sensitive information.
Deauthentication Attack A type of Denial-of-Service (DoS) attack targeting Wi-Fi networks. It exploits
the 802.11 Wi-Fi deauthentication frame, forcing devices to disconnect from a
wireless network. Attackers use this technique to disrupt network access or to
execute further attacks, such as Wi-Fi eavesdropping (Evil Twin attack) or
credential theft.
CVSS Scores None 0.0
Low 0.1 -3.9
Medium 4.0 - 6.9
High 7.0 - 8.9
Critical 9.0 - 10
Attestation Services Services that are used to ensure the integrity of the computer's startup and
runtime operations. Hardware-based ******** is designed to protect against
threats and malicious code that could be loaded before the operating system
is loaded.
Secure Boot A UEFI feature that prevents a system from booting up with drivers or an OS
that are not digitally signed and trusted by the motherboard or computer
manufacturer.
HOTP HMAC-based One-Time Password. An open standard used for creating one-
time passwords. It combines a secret key and a counter, and then uses HMAC
to create a hash of the result. This password does not expire.
TOTP Time-based One-Time Password. Similar to HOTP, but it uses a timestamp
instead of a counter. One-time passwords created with TOTP expire after 30
seconds.
Risk Tolerance Refers to the specific amount or level of risk that an organization is willing to
accept or bear.
, SecurityX - (CAS-005) Exam
Risk Appetite The overall amount of risk an organization is willing to pursue or retain in order
to achieve its objectives. It is broader in nature and less specific than risk
tolerance.
JIT Access Features Enables users to temporarily elevate their privileges for specific, approved
tasks, reducing the risk of misuse or persistent vulnerabilities associated with
permanent administrative rights. (JIT = Just-In-Time)
SASE (Secure Access Service Edge) Framework A cloud-based network security framework that integrates networking and
security into a unified service. It combines SD-WAN (Software-Defined Wide
Area Networking) with security functions, such as Zero Trust Network Access
(ZTNA), Firewall-as-a-Service (FWaaS), Secure Web Gateway (SWG), Cloud
Access Security Broker (CASB), and Data Loss Prevention (DLP).
Facial recognition scan A type of scan will measure the size or distance of a person's external features
with a digital video camera.
Secure Encalve A protected, isolated execution environment within a processor that provides
enhanced security for sensitive operations such as cryptographic key
management, biometric authentication, and secure data processing. It ensures
that even if the main operating system is compromised, the data and operations
inside the enclave remain protected.
CPU Security Extensions Hardware-based security features built into modern processors to enhance
data protection, memory isolation, and secure execution environments. These
extensions help mitigate various security threats, such as malware, privilege
escalation, and memory-based attacks.
Software Composition Analysis (SCA) Tools Security and compliance solutions that help identify and manage open-source
and third-party software components within an application. They scan
dependencies, detect vulnerabilities, and ensure license compliance.
Low Impact Confidentiality Risk "The unauthorized disclosure of information could be expected to have a
limited adverse effect."
Moderate Impact Confidentiality Risk "A serious adverse effect expected."
High Impact Confidentiality Risk "A severe or catastrophic adverse effect expected."
Cryptographic Erase (CE) A wiping technique that encrypts the data on a media device and destroys the
encryption key. Performing a cryptographic erasure (CE) would sanitize and
purge the drives' data without harming the drives themselves.