Sign in to save your progress, vote, and build your own decks.Sign in
CISSP
91 cards·by grantsd
Single Loss Expectancy
SLE = AV * EF (%)
Annual Loss Expectancy
ALE = SLE * ARO
Cardinality
Number of rows
Degree (Database)
Number of columns
NIST 800-42
Security Testing
4 Stages of Pen Testing
Planning, Discovery, Attack, Reporting
Something that can happen to a system
Threat
Weakness or hole in security
Vulnerability
RAID 0
Striped
RAID 1
Mirrored
RAID 5
Striped, parity
What class abuse? Unauthorized access by circumventing access controls/masquerading
Class A
What class abuse? Unauthorized use of network resources for non-business purpose.
Class B
What class abuse? Eavesdropping, tapping, interception of files.
Class C
What class abuse? DOS and service disruptions.
Class D
What class abuse? Network intrusion, spoofing, etc
Class E
What class abuse? Probing
Class F
SMURF attack protocol?
ICMP
Fraggle attack protocol?
UDP
LAND attack protocol / flag?
TCP / SYN
What layer has FTP, Telnet, TFTP, SMTP, HTTP, SNMP?
Application
What layer has JPEG, TIFF, MID?
Presentation
What layer has NSF, SQL, RADIUS, RPC?
Session
What layer has TCP, UDP, SSL, SSH-2, NetBios?
Transport
What layer has IP, IPSEC, ICMP, BGP, OSPF, RIP, BOOTP, DHCP?
Network
What layer has L2F, PPTP, L2TP, PPP, SLIP, ARP, RARP,SNAP, CHAP, LCP, Frame Relay, Ethernet,
FDDI, etc?
Data Link
Telnet port?
23
FTP ports?
20/21
TFTP port?
69
SMTP port?
25
SSH port/protocol?
22/TCP
DNS port/protocol?
53/TCP/UDP
DHCP port/protocol?
67/68/UDP
HTTP port/protocol?
80/TCP
POP port/protocol?
110/TCP
Standard LDAP port/protocol?
389/TCP/UDP
Encrypted LDAP port/protocol?
636/TCP/UDP
Packet filtering firewall generation?
First
Application Level Firewall / Proxy Server generation?
Second
Stateful Inspection firewall generation?
Third
Dynamic Packet Filtering firewall generation?
Fourth
Kernel Proxy Firewall generation?
Fifth
T1 Speed (Mbps)
1.5
T3 Speed (Mbps
44.7
Network numbers value begin at 1 and end at 127?
Class A
Network numbers value begin at 128 and end at 191?
Class B
Network numbers value begin at 192 and end at 223?
Class C
Max 100Base-TX length in meters?
100
CIDR for unsubnetted network?
/24
DES key length? (bits)
56
DES encryption rounds?
16
How many DES modes?
4
Based on Rjindael Block Cipher?
AES
AES key lengths?
128/192/256
AES - symmetric or assymetric?
symmetric
DES - symmetric or assymetric?
symmetric
RSA - symmetric or asymmetric?
asymmetric
Diffie Hellman - symmetric or asymmetric?
asymmetric
El-Gamal - symmetric or asymmetric?
asymmetric
X.509 Standard common abbreviation?
PKI
What is encrypted in IPSEC Transport mode?
Data
What is encrypted in IPSEC Tunnel mode?
Data/Header
MAC Mode: All users can access all data, clearance for all info, need to know for all data
Dedicated
MAC Mode: All users can access some data, clearance for all info, need to know for SOME data?
System High
MAC Mode: All users can access some data, clearance for all info, need approval, need to
knowfor SOME data, use of labels?
Compartmented
MAC Mode: All users access some data (based on need to know, approval, clearance), Clearance
for accessed data, need to know SOME?
Multilevel
EAL: Inadequate assurance
0
EAL: Functionally tested
1
EAL: Structurally tested
2
EAL: Methodically tested and checked
3
EAL: Methodically designed, tested and reviewed
4
EAL: Semi-formally designed and tested
5
EAL: Semi-formally verified design and tested
6
EAL: Formally verified design and tested
7
EAL: Product to be tested (acronym)
TOE
EAL: Security properties of TOE
Security target
Access control: Uses graph to specify rights subjects can transfer to /take from other
subjects, uses STATE and STATE TRANSITION
TAKE-GRANT
Access control: No read up, no write down, confidentiality model
Bell-Lapadua
Access control: No read down, no write up, integrity model
BIBA
Access control: Integrity model, enforces segregation, requires auditing, limits access
to objects through program
CLARK-WILSON
Access control: Chinese Wall model, used for lawyers offices for instance
Brewer and Nash
Baseline of normal activity, used to ignore normal user errors
Clipping level
Two types of covert channels?
Storage/Timing
Initiating, Repeatable, Defined, Managed, Controlled are phases of what?
CMM
Conception, Initiation, Development, Implementation, Testing, Maintenance are phases of
what?
Security Lifecycle
Communication to object to perform an action
Message
Code that defines an action an object performs in response to a message
method
results exhibited by an object in response to a message
behavior
collection of methods that defines the behavior of objects
class
Forwarding request to another object
delegation
test
test2