QuickCruitLearning

Reference

Look it up in seconds

The acronyms, ports, and terminology you'll be expected to know — all searchable in one place.

  • AAAAuthentication, Authorization, and Accounting
  • ACLAccess Control List
  • AESAdvanced Encryption StandardSymmetric block cipher (128/192/256-bit keys)
  • AES-256Advanced Encryption Standard 256-bitAES using a 256-bit key
  • AHAuthentication HeaderIPSec component providing integrity/authentication
  • AIArtificial Intelligence
  • AISAutomated Indicator SharingCISA program for sharing cyber threat indicators
  • ALEAnnualized Loss ExpectancyALE = SLE x ARO
  • APAccess Point
  • APIApplication Programming Interface
  • APTAdvanced Persistent Threat
  • AROAnnualized Rate of Occurrence
  • ARPAddress Resolution ProtocolMaps IP addresses to MAC addresses
  • ASLRAddress Space Layout Randomization
  • AUPAcceptable Use Policy
  • BASHBourne Again ShellCommon Unix/Linux command shell and scripting language
  • BCPBusiness Continuity Planning
  • BGPBorder Gateway ProtocolInternet routing protocol between autonomous systems
  • BIABusiness Impact Analysis
  • BIOSBasic Input/Output SystemLegacy firmware; largely superseded by UEFI
  • BPABusiness Partners Agreement
  • BPDUBridge Protocol Data UnitSTP messages; BPDU Guard protects switch ports
  • BYODBring Your Own Device
  • CACertificate Authority
  • CAPTCHACompletely Automated Public Turing Test to Tell Computers and Humans Apart
  • CARCorrective Action Report
  • CASBCloud Access Security Broker
  • CBCCipher Block ChainingBlock cipher mode of operation
  • CCMPCounter Mode Cipher Block Chaining Message Authentication Code ProtocolEncryption protocol used by WPA2
  • CCTVClosed-Circuit TelevisionPhysical security surveillance
  • CERTComputer Emergency Response Team
  • CFBCipher FeedbackBlock cipher mode of operation
  • CHAPChallenge Handshake Authentication Protocol
  • CIAConfidentiality, Integrity, and AvailabilityThe core security triad
  • CIOChief Information Officer
  • CIRTComputer Incident Response Team
  • CMSContent Management System
  • COOPContinuity of Operations Planning
  • COPECorporate-Owned, Personally EnabledMobile deployment model
  • CRCCyclic Redundancy CheckError-detection checksum (not cryptographically secure)
  • CRLCertificate Revocation List
  • CSOChief Security Officer
  • CSPCloud Service Provider
  • CSRCertificate Signing Request
  • CSRFCross-Site Request Forgery
  • CSUChannel Service UnitOften paired with DSU (CSU/DSU) for WAN connections
  • CTMCounter ModeBlock cipher mode of operation (CTR)
  • CTOChief Technology Officer
  • CVECommon Vulnerabilities and Exposures
  • CVSSCommon Vulnerability Scoring System
  • DACDiscretionary Access Control
  • DBADatabase Administrator
  • DDoSDistributed Denial of Service
  • DEPData Execution Prevention
  • DESData Encryption StandardSymmetric block cipher; insecure 56-bit key. CompTIA's appendix prints 'Digital Encryption Standard', but DES = Data Encryption Standard.
  • DHCPDynamic Host Configuration Protocol
  • DKIMDomainKeys Identified Mail
  • DLLDynamic Link LibraryWindows shared library; target of DLL injection
  • DLPData Loss Prevention
  • DMARCDomain-based Message Authentication, Reporting, and Conformance
  • DNATDestination Network Address Translation
  • DNSDomain Name System
  • DNSSECDomain Name System Security Extensions
  • DoSDenial of Service
  • DPOData Protection OfficerRole required under GDPR (CompTIA lists it as Data Privacy Officer)
  • DRPDisaster Recovery Plan
  • EAPExtensible Authentication Protocol
  • ECBElectronic CodebookBlock cipher mode; insecure for repeating data
  • ECCElliptic Curve Cryptography
  • ECDHEElliptic Curve Diffie-Hellman EphemeralKey exchange providing perfect forward secrecy
  • ECDSAElliptic Curve Digital Signature Algorithm
  • EDREndpoint Detection and Response
  • EFSEncrypting File SystemWindows file-level encryption
  • ERPEnterprise Resource Planning
  • ESPEncapsulating Security PayloadIPSec component providing confidentiality
  • FACLFile System Access Control List
  • FDEFull Disk Encryption
  • FIMFile Integrity Monitoring
  • FPGAField Programmable Gate ArrayReconfigurable hardware chip
  • FRRFalse Rejection RateBiometric Type I error
  • FTPFile Transfer Protocol
  • FTPSFile Transfer Protocol SecureFTP over SSL/TLS
  • GCMGalois/Counter ModeAuthenticated block cipher mode
  • GDPRGeneral Data Protection Regulation
  • GPGGNU Privacy GuardOpen-source OpenPGP implementation (CompTIA lists this as GPG, not GnuPG)
  • GPOGroup Policy Object
  • GPSGlobal Positioning System
  • GPUGraphics Processing UnitOften used for password cracking/hashing
  • GREGeneric Routing EncapsulationTunneling protocol
  • HAHigh Availability
  • HIDSHost-based Intrusion Detection System
  • HIPSHost-based Intrusion Prevention System
  • HMACHash-based Message Authentication Code
  • HOTPHMAC-based One-Time PasswordCounter-based OTP
  • HSMHardware Security Module
  • HTTPHypertext Transfer Protocol
  • HTTPSHypertext Transfer Protocol Secure
  • HVACHeating, Ventilation, and Air ConditioningEnvironmental control; a physical/OT security concern
  • IaaSInfrastructure as a Service
  • IaCInfrastructure as Code
  • IAMIdentity and Access Management
  • ICSIndustrial Control System
  • IDFIntermediate Distribution FrameWiring closet connecting to the MDF
  • IdPIdentity ProviderIssues assertions in federated SSO (SAML/OAuth)
  • IDSIntrusion Detection System
  • IKEInternet Key ExchangeNegotiates IPSec security associations
  • IMInstant Messaging
  • IMAPInternet Message Access Protocol
  • IoCIndicators of CompromiseArtifacts suggesting a breach
  • IoTInternet of Things
  • IPSIntrusion Prevention System
  • IPSecInternet Protocol Security
  • IRIncident Response
  • IRPIncident Response Plan
  • ISOInternational Organization for Standardization
  • ISPInternet Service Provider
  • ISSOInformation Systems Security Officer
  • IVInitialization Vector
  • KDCKey Distribution CenterKerberos component that issues tickets
  • L2TPLayer 2 Tunneling Protocol
  • LDAPLightweight Directory Access Protocol
  • LDAPSLightweight Directory Access Protocol over SSL
  • MaaSMonitoring as a Service
  • MACMandatory Access ControlAccess control model based on classifications/labels
  • MACMedia Access ControlHardware address of a network interface
  • MACMessage Authentication CodeCryptographic integrity/authenticity check
  • MDFMain Distribution FramePrimary wiring/cabling distribution point (NOT a multifunction device - that is MFD/MFP)
  • MDMMobile Device Management
  • MFAMultifactor Authentication
  • MFDMultifunction DeviceCombined printer/scanner/fax/copier
  • MFPMultifunction Printer
  • MLMachine Learning
  • MMSMultimedia Messaging Service
  • MOAMemorandum of Agreement
  • MOUMemorandum of Understanding
  • MPLSMultiprotocol Label SwitchingWAN technology using labels to forward traffic
  • MSAMaster Service Agreement
  • MSCHAPMicrosoft Challenge Handshake Authentication Protocol
  • MSPManaged Service Provider
  • MSSPManaged Security Service Provider
  • MTBFMean Time Between Failures
  • MTTFMean Time to FailureExpected lifetime of a non-repairable asset
  • MTTRMean Time to Repair
  • MTUMaximum Transmission UnitLargest packet size on a network link
  • NACNetwork Access Control
  • NATNetwork Address Translation
  • NDANon-Disclosure Agreement
  • NFCNear Field CommunicationShort-range wireless used for contactless payments
  • NGFWNext-Generation Firewall
  • NIDSNetwork-based Intrusion Detection System
  • NIPSNetwork-based Intrusion Prevention System
  • NISTNational Institute of Standards and Technology
  • NTPNetwork Time Protocol
  • OAuthOpen Authorization
  • OCSPOnline Certificate Status Protocol
  • OIDObject IdentifierUnique identifier used in certificates and SNMP MIBs
  • OSOperating System
  • OSINTOpen-Source Intelligence
  • OSPFOpen Shortest Path FirstLink-state interior routing protocol
  • OTOperational TechnologyHardware/software controlling physical processes (ICS/SCADA)
  • OTAOver-the-AirWireless updates/provisioning, e.g., for mobile devices
  • OWASPOpen Worldwide Application Security Project
  • P12PKCS #12Binary format (.p12/.pfx) bundling a private key with its certificate
  • PaaSPlatform as a Service
  • PACProxy Auto-ConfigurationAlso Protected Access Credential in EAP-FAST
  • PAMPrivileged Access Management
  • PAPPassword Authentication Protocol
  • PATPort Address TranslationNAT overload mapping many hosts to one IP via ports
  • PBKDF2Password-Based Key Derivation Function 2
  • PCAPPacket CaptureCaptured network traffic file format
  • PCI DSSPayment Card Industry Data Security Standard
  • PDUPower Distribution UnitAlso Protocol Data Unit in networking
  • PEAPProtected Extensible Authentication ProtocolEAP wrapped in a TLS tunnel
  • PEDPersonal Electronic Device
  • PEMPrivacy Enhanced MailBase64 ASCII certificate/key format (.pem)
  • PFSPerfect Forward SecrecySession keys not compromised if long-term key is exposed
  • PGPPretty Good PrivacyEmail/file encryption using a web of trust
  • PHIProtected Health InformationRegulated under HIPAA (CompTIA lists it as Personal Health Information)
  • PIIPersonally Identifiable Information
  • PKIPublic Key Infrastructure
  • POPPost Office Protocol
  • POTSPlain Old Telephone ServiceTraditional analog phone lines
  • PPPPoint-to-Point ProtocolLayer 2 protocol for direct connections
  • PPTPPoint-to-Point Tunneling Protocol
  • PUPPotentially Unwanted Program
  • RARecovery AgentCan decrypt/recover encrypted data or keys (also Registration Authority in PKI)
  • RADIUSRemote Authentication Dial-In User ServiceAuth ports UDP 1812/1813
  • RAIDRedundant Array of Independent DisksDisk redundancy/performance (levels 0, 1, 5, 6, 10)
  • RASRemote Access Server
  • RATRemote Access TrojanMalware giving an attacker remote control
  • RBACRole-Based Access Control
  • RDPRemote Desktop ProtocolTCP 3389
  • RFIDRadio Frequency IdentificationUsed in badges, asset tags; susceptible to cloning/skimming
  • RPORecovery Point ObjectiveMaximum acceptable data loss (time)
  • RSARivest, Shamir, AdlemanWidely used asymmetric encryption/signature algorithm
  • RTBHRemotely Triggered Black HoleDDoS mitigation that drops traffic to a target
  • RTORecovery Time ObjectiveTarget time to restore after an outage
  • RTOSReal-Time Operating SystemUsed in embedded/ICS systems
  • RTPReal-time Transport ProtocolCarries voice/video; secured by SRTP
  • S/MIMESecure/Multipurpose Internet Mail Extensions
  • SaaSSoftware as a Service
  • SAESimultaneous Authentication of EqualsWPA3 handshake replacing the WPA2 PSK 4-way handshake
  • SAMLSecurity Assertion Markup Language
  • SANSubject Alternative NameCertificate field listing additional names/domains (also Storage Area Network)
  • SASESecure Access Service Edge
  • SCADASupervisory Control and Data Acquisition
  • SCAPSecurity Content Automation Protocol
  • SCEPSimple Certificate Enrollment ProtocolAutomated certificate issuance, common for devices/MDM
  • SD-WANSoftware-Defined Wide Area Network
  • SDKSoftware Development Kit
  • SDLCSoftware Development Life Cycle
  • SDLMSoftware Development Lifecycle Methodology
  • SDNSoftware-Defined NetworkingSeparates control plane from data plane
  • SEDSelf-Encrypting DriveHardware-based full-disk encryption
  • SEHStructured Exception HandlerWindows error handling; target of SEH overwrite exploits
  • SELinuxSecurity-Enhanced Linux
  • SFTPSSH File Transfer ProtocolFile transfer over SSH (TCP 22)
  • SHASecure Hash Algorithm
  • SHTTPSecure Hypertext Transfer ProtocolLegacy/obsolete; distinct from HTTPS
  • SIEMSecurity Information and Event Management
  • SIMSubscriber Identity ModuleTarget of SIM-swapping/cloning attacks
  • SLAService-Level Agreement
  • SLESingle Loss ExpectancySLE = asset value x exposure factor
  • SMSShort Message ServiceText messaging; weak as an MFA channel
  • SMTPSimple Mail Transfer Protocol
  • SMTPSSimple Mail Transfer Protocol SecureSMTP over TLS
  • SNMPSimple Network Management Protocol
  • SOAPSimple Object Access ProtocolXML-based web services messaging protocol
  • SOARSecurity Orchestration, Automation, and Response
  • SOCSecurity Operations Center
  • SOWStatement of Work
  • SPFSender Policy Framework
  • SPIMSpam over Instant MessagingCompTIA lists this as Spam over Internet Messaging
  • SQLStructured Query Language
  • SQLiSQL InjectionInjection attack against database queries
  • SRTPSecure Real-time Transport ProtocolEncrypted RTP for VoIP/video
  • SSDSolid State Drive
  • SSHSecure ShellTCP 22
  • SSLSecure Sockets LayerDeprecated; superseded by TLS
  • SSOSingle Sign-On
  • STIXStructured Threat Information eXpressionStandard format for cyber threat intelligence; pairs with TAXII (CompTIA lists it as eXchange)
  • SWGSecure Web Gateway
  • TACACS+Terminal Access Controller Access Control System PlusAuth port TCP 49
  • TAXIITrusted Automated eXchange of Indicator InformationTransport protocol for sharing STIX threat intel
  • TCPTransmission Control Protocol
  • TGTTicket-Granting TicketIssued by the Kerberos KDC
  • TKIPTemporal Key Integrity ProtocolLegacy WPA encryption; deprecated in favor of CCMP/AES
  • TLSTransport Layer Security
  • TOCTime-of-CheckTOC/TOU describes a race-condition vulnerability
  • TOTPTime-based One-Time Password
  • TOUTime-of-UseThe use half of a TOC/TOU race condition
  • TPMTrusted Platform Module
  • TSIGTransaction SignatureAuthenticates DNS updates/zone transfers
  • TTPTactics, Techniques, and ProceduresBehavioral description of threat actors (e.g., MITRE ATT&CK)
  • UATUser Acceptance Testing
  • UAVUnmanned Aerial VehicleDrone
  • UDPUser Datagram Protocol
  • UEBAUser and Entity Behavior Analytics
  • UEFIUnified Extensible Firmware Interface
  • UEMUnified Endpoint ManagementManages mobile and traditional endpoints centrally
  • UPSUninterruptible Power Supply
  • URIUniform Resource Identifier
  • URLUniform Resource Locator
  • USBUniversal Serial Bus
  • USB OTGUSB On-the-GoLets a mobile device act as a USB host
  • UTMUnified Threat Management
  • UTPUnshielded Twisted PairCommon copper network cabling
  • VBAVisual Basic for ApplicationsOffice macro language; common malware delivery vector
  • VDEVirtual Desktop Environment
  • VDIVirtual Desktop InfrastructureHosts user desktops on centralized servers
  • VLANVirtual Local Area Network
  • VLSMVariable Length Subnet Mask
  • VMVirtual Machine
  • VoIPVoice over Internet Protocol
  • VPCVirtual Private CloudIsolated cloud network segment
  • VPNVirtual Private Network
  • VTCVideo Teleconferencing
  • WAFWeb Application Firewall
  • WAPWireless Access Point
  • WEPWired Equivalent PrivacyObsolete, insecure Wi-Fi encryption
  • WIDSWireless Intrusion Detection System
  • WIPSWireless Intrusion Prevention System
  • WOWork Order
  • WPAWi-Fi Protected Access
  • WPSWi-Fi Protected Setup
  • WTLSWireless Transport Layer SecurityTLS variant for the WAP wireless stack
  • XDRExtended Detection and Response
  • XMLExtensible Markup Language
  • XORExclusive ORBitwise operation fundamental to many ciphers
  • XSRFCross-Site Request ForgeryAlternate abbreviation for CSRF
  • XSSCross-Site Scripting