Security+ Glossar
Kurze, klare Definitionen der wichtigsten CompTIA Security+ (SY0-701) Begriffe, geordnet nach Prüfungsdomänen. Es kommen laufend neue hinzu.
Grundkonzepte
Gap-Analyse (gap analysis)
Zero Trust (Zero Trust)
Steuerungsebene und Datenebene (control plane and data plane)
Adaptive Identität (adaptive identity)
Zugangsschleuse (access control vestibule)
Präventive und detektive Kontrollen (preventive and detective controls)
Honeypot (honeypot)
Change Management (change management)
Kryptografie
Symmetrische Verschlüsselung (symmetric encryption)
Asymmetrische Verschlüsselung (asymmetric encryption)
Hashing (hashing)
Salt (salt)
Hash-based Message Authentication Code (HMAC)
Digitale Signatur (digital signature)
Diffie-Hellman-Schlüsselaustausch (Diffie-Hellman key exchange)
Digitales Zertifikat (digital certificate)
Trusted Platform Module (TPM)
Hardware Security Module (HSM)
Secure Enclave
Key Escrow (Schlüsselhinterlegung)
Online Certificate Status Protocol (OCSP)
Certificate Pinning
Downgrade-Angriff (downgrade attack)
Bedrohungsakteure und Vektoren
Insider-Bedrohung (insider threat)
Advanced Persistent Threat (APT)
Merkmale von Bedrohungsakteuren (threat actor attributes)
Motivation von Bedrohungsakteuren (threat actor motivation)
Double-Extortion-Ransomware (double extortion ransomware)
Social Engineering (social engineering)
Phishing (phishing)
Watering-Hole-Angriff (watering hole attack)
Watering Hole
Typosquatting (Registrieren ähnlicher Domains)
Business Email Compromise (BEC)
Smishing (SMS-Phishing)
Pretexting (erfundenes Szenario)
Malware und schädliche Aktivitäten
Virus und Wurm (virus and worm)
Trojanisches Pferd und Remote Access Trojan (RAT)
Rootkit (rootkit)
Ransomware (ransomware)
Logische Bombe (logic bomb)
Denial-of-Service und Distributed Denial-of-Service (DoS/DDoS)
On-Path-/MITM-Angriff und Evil Twin (on-path / MITM attack and evil twin)
Indicator of Compromise (IoC)
Pass-the-Hash
Golden Ticket
Command and Control (C2)
Beaconing (periodisches Melden)
Verteidigungstechniken
Architektur und Infrastruktur
Modell der geteilten Verantwortung (shared responsibility model)
Hohe Verfügbarkeit und Beständigkeit (high availability and durability, HA)
Risikoübertragung (risk transference)
Vertikale und horizontale Skalierung (vertical and horizontal scaling)
Infrastructure as Code (IaC)
Serverlose Architektur (serverless architecture)
Containerisierung und Virtualisierung (containerization and virtualization)
Software-Defined Networking (SDN)
Mikrosegmentierung (microsegmentation)
Unternehmensinfrastruktur
Demilitarisierte Zone / abgeschirmtes Subnetz (DMZ)
Jump-Server / Bastion-Host
Angriffserkennungssystem / Angriffsverhinderungssystem (IDS/IPS)
Firewall
Next-Generation-Firewall (NGFW)
Web Application Firewall (WAF)
802.1X portbasierte Netzwerkzugangskontrolle
Virtuelles privates Netzwerk / IPsec (VPN)
Secure Access Service Edge (SASE)
EAP-TLS (EAP - Transport Layer Security)
WPA3-SAE (Simultaneous Authentication of Equals)
Sicherheitsziele und Kontrollen
Enterprise-Sicherheitsfunktionen
Sender Policy Framework (SPF)
DomainKeys Identified Mail (DKIM)
Domain-based Message Authentication, Reporting and Conformance (DMARC)
Endpoint Detection and Response / Extended Detection and Response (EDR/XDR)
User and Entity Behavior Analytics (UEBA)
Network Access Control (NAC)
File Integrity Monitoring (FIM)
DNS Security Extensions (DNSSEC)
Cloud Access Security Broker (CASB)
Datenschutz
Härtung und Asset-Sicherheit
Risikomanagement
Schwachstellenmanagement
Schwachstellen-Scanning (vulnerability scanning)
Penetrationstest (penetration testing)
Common Vulnerabilities and Exposures (CVE)
Common Vulnerability Scoring System (CVSS)
Zero-Day-Schwachstelle (zero-day vulnerability)
False Positive / False Negative
Authentifizierter / nicht authentifizierter Scan (authenticated / unauthenticated scan)
Kompensierende Maßnahme (compensating control)
Race Condition / TOCTOU
Open-Source Intelligence (OSINT)
Monitoring und Alarmierung
Sicherheitsüberwachung (security monitoring)
Agentenbasierte vs. agentenlose Überwachung (agent-based vs. agentless monitoring)
Log-Aggregation (log aggregation)
Log-Archivierung (log archiving)
Security Information and Event Management (SIEM)
NetFlow
Simple Network Management Protocol (SNMP)
Security Content Automation Protocol (SCAP)
Alarmmüdigkeit (alert fatigue)
Alarm-Tuning (alert tuning)
NetFlow (Netzwerkfluss-Analyse)
Automatisierung und Incident Response
Automatisierung (automation)
Orchestrierung (orchestration)
Incident Response (IR)
Eindämmung und Beseitigung (containment and eradication)
Tabletop-Übung (tabletop exercise)
Threat Hunting
Root Cause Analysis (RCA)
Beweiskette (chain of custody)
Reihenfolge der Flüchtigkeit (order of volatility)
Security Orchestration, Automation, and Response (SOAR)
MITRE ATT&CK Framework
Identitäts- und Zugriffsverwaltung (IAM)
Sicherheits-Governance
Compliance und Drittanbieter-Risiken
Compliance
Due Diligence und Due Care
Attestierung (attestation)
Betroffene Person (data subject)
Recht auf Vergessenwerden (right to be forgotten, RTBF)
Datenminimierung (data minimization)
Drittanbieter-/Lieferantenrisiko (third-party / vendor risk)
Prüfungsrechtsklausel (right-to-audit clause)
Software Bill of Materials (SBOM)
Resilienz und Wiederherstellung
Single Point of Failure (SPOF)
Hochverfügbarkeit (high availability, HA)
Lastverteilung (load balancing)
Clustering
Notfallwiederherstellung (disaster recovery, DR)
Ausweichstandorte: hot, warm, cold (recovery sites)
Geografische Verteilung (geographic dispersion)
Fortführung des Betriebs (continuity of operations, COOP)
Audits, Bewertungen und Awareness
Sicherheitsaudit (security audit)
Internes vs. externes Audit (internal vs. external audit)
White-, Gray-, Black-Box-Pentest-Typen (white, gray, black box pentest)
Aufklärung (reconnaissance)
Red, Blue, Purple Team
Sicherheitsbewusstsein (security awareness)
Phishing-Simulation und -Meldung (phishing simulation and reporting)
Purple Team
CertOwl im App Store laden
Gratis-Download · A+ und Network+ komplett kostenlos
+ tägliche Lektionen, Karteikarten und komplette Prüfungssimulationen