CASP Terms Questions with 100% Correct Answers
802.1x Correct Answer An IEEE standard used to provide a port-based authentication mechanism over a LAN or wireless LAN. After Action Report Correct Answer A post-incident report that include lessons learned to improve security for the future. Accountability Correct Answer In security terms, the process of determining who to hold responsible for a particular activity or event. ACL Correct Answer A list that specifies which objects in a system have which permissions. Active Directory Correct Answer MS LDAP compatible directory service. Advanced Encryption Standard Correct Answer Most common type of block cipher, available in 128, 192, and 256-bit key sizes and used in symmetric encryption. Agile method Correct Answer Software development method in which development occurs in short, iterative time periods with a focus on adapting to change. Annual Loss Expectancy Correct Answer The total cost of a risk to an organization on annual basis. Application blacklist Correct Answer A list of specific undesirable programs prevented from running on a host or computer network. Application sandboxing Correct Answer The technique of isolating an application running on a system. Application security framework Correct Answer Framework that can be embedded in standard application development processes to facilitate a security approach. Application streaming Correct Answer Technique in which a server offers efficient on-demand streaming of application to thin clients. Application whitelist Correct Answer A list of approved programs that may run on a host or computer network. Annual Rate of Occurrence Correct Answer How many times per year a particular loss is expected to occur. Asset management Correct Answer The process of taking inventory of an enterprise's technology assets and tracking their usage. Attestation Correct Answer Technique of verifying that only the individuals who need certain access privileges have those privileges. Authentication Correct Answer The process of validating a particular individual or entity's unique credentials. Authorization Correct Answer The process of determining what rights and privileges a particular entity has. Baiting Correct Answer A form of social engineering in which an attacker leave infected physical media in an area where victim finds it and then inserts it into a computer. Bare metal Correct Answer A computer without an OS installed. Building Automation system Correct Answer A system that centralizes the monitoring and control networked building resources like lighting, heating, ventilation, power, and physical security. Business Continuity Planning Correct Answer The process of defining how normal day-to-day business will be maintained in the event of a business disruption or crisis. Bcrypt Correct Answer A key-derivation function based on the Blowfish cipher algorithm. Business Impact Analysis Correct Answer Document that identifies present organizational risks and determines the impact to ongoing, business-critical operations if such risks actualize. BIOS Correct Answer A standard motherboard firmware interface and boot loader that the vast majority of computers have used for decades. Black box test Correct Answer A penetration test in which the tester is given no information about the system being tested. Block cipher Correct Answer A type of symmetric encryption that encrypts data one block at a time, often in 64-bit blocks. It is usually more secure, but is also slower, than stream cipher. Bluejacking Correct Answer A method used by attackers to send out unwanted Bluetooth signals from smartphones, mobile phones, tablets, and laptops to other Bluetooth-enabled devices. Bluesnarfing Correct Answer A method in which attackers gain unauthorized access to information on a wireless devices using Bluetooth connection.
Document information
- Uploaded on
- April 19, 2024
- Number of pages
- 29
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers