CORRECT Answers
Common Configuration Enumeration (CCE) - CORRECT ANSWER - Configuration best
practice statements maintained by the NIST
Common Platform Enumeration (CPE) - CORRECT ANSWER - Methods for describing
and classifying operating systems applications and hardware devices.
common vulnerabilities and exposures (CVEs) - CORRECT ANSWER - Vulnerabilities
that have been identified and issued standard numbers.
Common Vulnerability Scoring System (CVSS) - CORRECT ANSWER - A system of
ranking vulnerabilities that are discovered based on predefined metrics
common weakness enumeration (CWE) - CORRECT ANSWER - Design flaws in the
development of software that can lead to vulnerabilities.
configuration management database (CMDB) - CORRECT ANSWER - A database that
keeps track of the state of assets, such as products, systems, software, facilities, and people, as
they exist at specific points in time.
container-based virtualization - CORRECT ANSWER - A type of server virtualization in
which the kernel allows for multiple isolated user-space instances. Also called operating system
virtualization.
content management system (CMS) - CORRECT ANSWER - A system that publishes,
edits, modifies, organizes, deletes, and maintains content from a central interface
continuous integration (CI) - CORRECT ANSWER - The practice of merging all
developer working copies into a shared mainline several times a day
, Counter Mode (CTR) - CORRECT ANSWER - A DES mode similar to OFB mode that
uses an incrementing initialization vector counter to ensure that each block is encrypted with a
unique keystream. Also, the ciphertext is not chaining into the encryption process. Because this
chaining does not occur, CTR performance is much better than with the other modes.
database activity monitor (DAM) - CORRECT ANSWER - A device that monitors
transactions and the activity of database services.
dd command - CORRECT ANSWER - A UNIX/Linux command that is used is to convert
and copy files
de facto standards - CORRECT ANSWER - Standards that are widely accepted but are not
formally adopted.
DMZ - CORRECT ANSWER - A perimeter network where resources are exposed to the
Internet while being logically separated from the internal network
de-perimeterization - CORRECT ANSWER - The process of changing a network
boundary to include devices normally considered to be outside the networks perimeter.
Device Fingerprinting - CORRECT ANSWER - Identifying information such as the
operating system of a device.
differential backup - CORRECT ANSWER - A type of partial backup that involves
copying all changes made since the last full backup. Thus, each new differential backup file
contains the cumulative effects of all activity since the last full backup.
digital rights management (DRM) - CORRECT ANSWER - An access control method
used by hardware manufacturers, publishers, copyright holders, and individuals to control the use
of digital content