Click Study Flashcards above to open the flashcard hub — hundreds of CISSP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the eight official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CISSP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
CISSP Flashcard Study Modes
Flip mode turns cards at your own pace, Match times you pairing terms with their definitions, Type shows a definition and asks you to produce the term yourself — SOAR, for example — and Quiz builds multiple-choice items from the same 355 cards. Use Flip on unfamiliar domains first, then let Type and Quiz confirm that recall holds without the prompt in front of you.

Why Flashcards Work for the CISSP
Security & Risk Management is the largest block at 81 cards and 16% of the exam, so start there. The cards drill governance and legal vocabulary alongside risk math, mixing regulations such as SOX, GDPR, and GLBA with availability metrics like MTBF and MTTR, plus threat-rating terms including DREAD and foundations like Asset and Risk.
Security Architecture & Engineering carries 48 cards at 13%, heavy on cryptography: AES, RSA, and ECC for algorithms, then Hashing, Salt, and HMAC for integrity work, with SHA-256 and TEMPEST covering implementation detail. Communication & Network Security matches that 13% across 40 cards on segmentation and secure transport, from DMZ, VLAN, and NAC on the design side to TLS, SSH, and IPsec on the protocol side, with WEP as the cautionary card.
Identity & Access Management, also 13%, brings 40 cards on authentication protocols and administrative control: AAA, SAML, and Kerberos, then Kerberos KDC and OAuth 2.0, with personnel controls such as Need to know and Job rotation. Security Operations adds 40 more at the same weight for detection and recovery — SIEM, SOAR, and CSIRT, plus site cards including Hot site and Warm site.
Security Assessment & Testing holds 31 cards at 12%, covering vulnerability scoring and audit evidence: CVE and CVSS, techniques such as Fuzzing and Code review, and reporting cards including SOC 1 report and SOC 2 report. Asset Security has 35 cards at 10% for classification and sanitization, from PII and PHI through Clearing, Purging, and Degaussing. Software Development Security closes with 40 cards, also 10%, on pipeline and maturity vocabulary: CI/CD, DevOps, and DevSecOps, maturity models like BSIMM and OWASP SAMM, and cards such as Injection and Shift left.
The CISSP is dense with terminology — risk formulas, security models, cryptography, access control, and operations frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
CISSP Flashcards by Domain
The cards are organized by the eight official ISC2 domains. The weights are fairly even, so cover them all — but start with the largest, Security & Risk Management:[1]
| Domain | Exam weight |
|---|---|
| Security & Risk Management | 16% |
| Security Architecture & Engineering | 13% |
| Communication & Network Security | 13% |
| Identity & Access Management | 13% |
| Security Operations | 13% |
| Security Assessment & Testing | 12% |
| Asset Security | 10% |
| Software Development Security | 10% |
How to Get the Most Out of These Flashcards
- Start with risk. Security & Risk Management is 81 cards and 16% of the exam, the biggest return on early effort, so get SOX, GDPR, and DREAD solid before touching cryptography.
- Type-drill the look-alikes. Terms that blur under pressure, such as MTBF and MTTR or Clearing against Purging, reward typing the exact word instead of recognizing it in a list.
- Match the acronyms. Short cryptography and network fronts like AES, HMAC, and IPsec pair quickly, so Match builds the recall speed that the exam’s longer scenario wording assumes you already have.
- Move to the practice test. Once Quiz scores hold steady across all eight domains, switch to the practice test for scenario phrasing, then return to Flip on the cards you missed.
- Keep a rotating cadence. With 355 cards, work one domain per session and re-Flip the previous session’s set first, so Asset Security and Security Assessment & Testing never go stale.
CISSP Flashcards FAQ
Hundreds of free CISSP flashcards, organized across all eight ISC2 domains — Security & Risk Management, Asset Security, Security Architecture & Engineering, Communication & Network Security, Identity & Access Management, Security Assessment & Testing, Security Operations, and Software Development Security. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the CISSP's heavy terminology across risk, cryptography, IAM, and operations.
All eight ISC2 domains: Security & Risk Management (CIA, risk, BCP/DR, ethics), Asset Security, Security Architecture & Engineering (security models, cryptography), Communication & Network Security, Identity & Access Management, Security Assessment & Testing, Security Operations (incident response, DR), and Software Development Security.
Cover all eight domains — the CISSP's weights are relatively even — but start with Security & Risk Management (16%), the largest. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 exam outline effective April 15, 2024, covering all eight scored domains in their official proportions.
CISSP flashcard bank
All 355 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Security & Risk Management (81)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Preventing unauthorized disclosure of data; protected by encryption and access controls.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered except by authorized parties; protected by hashing and digital signatures.
- Availability
Show answerHide answer
Ensuring authorized users have timely, reliable access to systems and data.
- DAD triad
Show answerHide answer
Disclosure, Alteration, Destruction — the opposite of CIA; names the threats to each goal.
- Authenticity
Show answerHide answer
Assurance that data, a transaction, or a message is genuine and from its claimed source.
- Non-repudiation
Show answerHide answer
Assurance that a party cannot deny an action; achieved via digital signatures and logging.
- Defense in depth
Show answerHide answer
Layering multiple, overlapping controls so that if one fails, others still protect the asset.
- Security governance
Show answerHide answer
The framework of policies, roles, and oversight by which senior management directs and controls security.
- Due diligence
Show answerHide answer
Doing the research and developing the plans and policies needed to protect the organization.
- Due care
Show answerHide answer
Acting on due diligence — implementing and maintaining reasonable controls (the prudent person rule).
- Prudent person rule
Show answerHide answer
Acting with the care a reasonable, prudent person would in similar circumstances; reduces negligence liability.
- Policy
Show answerHide answer
A high-level management statement of intent and goals; mandatory and broad.
- Standard
Show answerHide answer
A mandatory, specific requirement that supports a policy (e.g., 'use AES-256').
- Procedure
Show answerHide answer
Detailed, mandatory step-by-step instructions for a task.
- Baseline
Show answerHide answer
A minimum required level of security that systems must meet.
- Guideline
Show answerHide answer
A recommended, discretionary (optional) best practice.
- Risk
Show answerHide answer
The likelihood that a threat exploits a vulnerability, and the resulting impact on an asset.
- Threat
Show answerHide answer
Any potential event or actor that could harm an asset by exploiting a vulnerability.
- Threat agent / actor
Show answerHide answer
The entity (person, group, or process) that carries out a threat.
- Vulnerability
Show answerHide answer
A weakness in a system, process, or control that a threat can exploit.
- Exposure
Show answerHide answer
An instance of being susceptible to loss from a threat exploiting a vulnerability.
- Asset
Show answerHide answer
Anything of value to the organization — data, systems, people, facilities, or reputation.
- Asset value (AV)
Show answerHide answer
The monetary worth assigned to an asset, used in quantitative risk analysis.
- Exposure factor (EF)
Show answerHide answer
The percentage of an asset's value lost if a specific risk event occurs.
- Single Loss Expectancy (SLE)
Show answerHide answer
Expected loss from one occurrence: SLE = Asset Value × Exposure Factor.
- Annualized Rate of Occurrence (ARO)
Show answerHide answer
The expected number of times a risk event occurs in one year.
- Annualized Loss Expectancy (ALE)
Show answerHide answer
Expected yearly cost of a risk: ALE = SLE × ARO.
- SLE formula
Show answerHide answer
SLE = AV × EF (Asset Value times Exposure Factor).
- ALE formula
Show answerHide answer
ALE = SLE × ARO (Single Loss Expectancy times Annualized Rate of Occurrence).
- Qualitative risk analysis
Show answerHide answer
Subjective ranking of risk (high/medium/low) using scenarios and judgment — fast, not dollar-based.
- Quantitative risk analysis
Show answerHide answer
Objective, dollar-based risk analysis using AV, EF, SLE, ARO, and ALE.
- Residual risk
Show answerHide answer
The risk that remains after controls are applied; senior management formally accepts it.
- Total risk
Show answerHide answer
The risk before any controls are applied (threats × vulnerabilities × asset value).
- Risk mitigation
Show answerHide answer
Reducing risk to an acceptable level by implementing controls.
- Risk transference
Show answerHide answer
Shifting the financial impact of a risk to a third party, such as insurance.
- Risk avoidance
Show answerHide answer
Eliminating a risk by ceasing the activity that creates it.
- Risk acceptance
Show answerHide answer
A documented, management-approved decision to tolerate a risk.
- Risk deterrence
Show answerHide answer
Discouraging a threat actor from acting (e.g., warnings, visible controls).
- Control cost rule
Show answerHide answer
A countermeasure should never cost more than the asset (or the ALE reduction) it provides.
- Safeguard / countermeasure
Show answerHide answer
A control that reduces the likelihood or impact of a risk.
- Administrative controls
Show answerHide answer
Policies, procedures, training, and personnel practices (management controls).
- Technical / logical controls
Show answerHide answer
Hardware and software controls such as firewalls, encryption, and access control.
- Physical controls
Show answerHide answer
Controls that protect facilities and equipment (locks, fences, guards, cameras).
- Preventive control
Show answerHide answer
A control that stops an incident before it happens (e.g., a lock, MFA).
- Detective control
Show answerHide answer
A control that identifies an incident in progress or after it (e.g., logs, IDS, cameras).
- Corrective control
Show answerHide answer
A control that restores systems after an incident (e.g., backups, patches).
- Deterrent control
Show answerHide answer
A control that discourages a threat (e.g., warning signs, visible cameras).
- Compensating control
Show answerHide answer
An alternative control used when the primary one isn't feasible.
- Threat modeling
Show answerHide answer
Systematically identifying and prioritizing threats to a system during design.
- STRIDE
Show answerHide answer
Threat model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
- DREAD
Show answerHide answer
A risk-rating model: Damage, Reproducibility, Exploitability, Affected users, Discoverability.
- Security control frameworks
Show answerHide answer
Structured sets of controls — e.g., NIST SP 800-53, ISO/IEC 27001/27002, COBIT.
- ISO/IEC 27001
Show answerHide answer
International standard for an Information Security Management System (ISMS).
- ISO/IEC 27002
Show answerHide answer
Code of practice giving guidance on information security controls.
- NIST Cybersecurity Framework
Show answerHide answer
A framework of five functions: Identify, Protect, Detect, Respond, Recover.
- ISC2 Code of Ethics — Canon 1
Show answerHide answer
Protect society, the common good, necessary public trust, and the infrastructure.
- ISC2 Code of Ethics — Canon 2
Show answerHide answer
Act honorably, honestly, justly, responsibly, and legally.
- ISC2 Code of Ethics — Canon 3
Show answerHide answer
Provide diligent and competent service to principals.
- ISC2 Code of Ethics — Canon 4
Show answerHide answer
Advance and protect the profession.
- Code of Ethics canon order
Show answerHide answer
Canons are applied in order; when they conflict, the earlier (society) outranks the later (profession).
- GDPR
Show answerHide answer
EU General Data Protection Regulation — protects personal data of EU residents; heavy fines for noncompliance.
- HIPAA
Show answerHide answer
U.S. law protecting the privacy and security of health information (PHI).
- GLBA
Show answerHide answer
Gramm-Leach-Bliley Act — requires financial institutions to protect customers' personal financial data.
- SOX
Show answerHide answer
Sarbanes-Oxley Act — requires accurate financial reporting and internal controls for public companies.
- PCI DSS
Show answerHide answer
Payment Card Industry Data Security Standard — protects cardholder data (industry standard, not law).
- Intellectual property — patent
Show answerHide answer
Grants exclusive rights to an invention for a limited time (about 20 years).
- Intellectual property — trademark
Show answerHide answer
Protects words, symbols, or logos identifying goods/services.
- Intellectual property — copyright
Show answerHide answer
Protects original works of authorship (software, writing, art).
- Trade secret
Show answerHide answer
Confidential business information that gives a competitive edge, protected as long as it's kept secret.
- Business continuity plan (BCP)
Show answerHide answer
A plan to keep critical business functions operating during and after a disruption.
- Disaster recovery (DR)
Show answerHide answer
Processes and procedures to restore IT systems and operations after a disaster.
- Business Impact Analysis (BIA)
Show answerHide answer
Identifies critical functions and sets recovery objectives (MTD, RTO, RPO) — the heart of continuity planning.
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The longest a function can be unavailable before unacceptable harm; drives the RTO.
- Recovery Time Objective (RTO)
Show answerHide answer
The target time to restore a function after a disruption; must be less than the MTD.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable amount of data loss, measured backward in time; drives backup frequency.
- Work Recovery Time (WRT)
Show answerHide answer
Time to verify systems and data after recovery before resuming normal operations.
- MTBF
Show answerHide answer
Mean Time Between Failures — the average time a repairable component runs before failing.
- MTTR
Show answerHide answer
Mean Time To Repair — the average time to restore a failed component.
- Critical business functions
Show answerHide answer
The functions an organization must perform to survive; identified by the BIA.
- Senior management role in BCP
Show answerHide answer
Senior management must champion, fund, and ultimately own the BCP.
Asset Security (35)
- Data classification
Show answerHide answer
Labeling data by sensitivity so the right level of protection is applied.
- Government classification levels
Show answerHide answer
Top Secret, Secret, Confidential, Unclassified (high to low sensitivity).
- Commercial classification levels
Show answerHide answer
Common scheme: Confidential, Private, Sensitive, Public.
- Data owner
Show answerHide answer
The senior business manager accountable for data; assigns classification and protection requirements.
- Data custodian
Show answerHide answer
Implements and maintains the controls protecting data day to day — usually IT.
- Data controller
Show answerHide answer
Under privacy law, the entity that decides why and how personal data is processed.
- Data processor
Show answerHide answer
A party that processes personal data on behalf of, and on the instructions of, the controller.
- System owner
Show answerHide answer
The person responsible for a system's operation and security throughout its lifecycle.
- Data steward
Show answerHide answer
Responsible for data quality, definitions, and appropriate use within a business area.
- Data user
Show answerHide answer
An end user who accesses data to perform their job, following handling rules.
- Data states
Show answerHide answer
At rest (stored), in transit (moving), and in use (being processed in memory).
- Data at rest
Show answerHide answer
Stored data — protect with full-disk and database encryption.
- Data in transit
Show answerHide answer
Moving data — protect with TLS, IPsec, or VPNs.
- Data in use
Show answerHide answer
Data being processed in memory — hardest to protect (e.g., secure enclaves).
- Data lifecycle
Show answerHide answer
Create, store, use, share, archive, and destroy — each stage needs appropriate protection.
- Data remanence
Show answerHide answer
Residual data left on media after deletion or formatting that may be recoverable.
- Clearing
Show answerHide answer
Overwriting media so data can't be recovered by normal means; suitable for internal reuse.
- Purging
Show answerHide answer
Stronger sanitization (degaussing or multiple overwrites) to allow external release of media.
- Destruction
Show answerHide answer
Physically destroying media (shred, pulverize, incinerate) for the most sensitive data.
- Degaussing
Show answerHide answer
Using a strong magnetic field to erase data from magnetic media; does not work on SSDs.
- NIST SP 800-88
Show answerHide answer
Guidelines for media sanitization defining Clear, Purge, and Destroy levels.
- Data Loss Prevention (DLP)
Show answerHide answer
Technology that detects and blocks unauthorized exfiltration of sensitive data.
- Scoping
Show answerHide answer
Selecting only the security controls from a baseline that apply to a given system.
- Tailoring
Show answerHide answer
Adjusting a baseline of controls to fit an organization's specific needs.
- Data retention policy
Show answerHide answer
Defines how long data must be kept and when it must be securely destroyed.
- PII
Show answerHide answer
Personally Identifiable Information — data that can identify a specific individual.
- PHI
Show answerHide answer
Protected Health Information — individually identifiable health data under HIPAA.
- Data anonymization
Show answerHide answer
Removing identifiers so data can no longer be linked to an individual.
- Pseudonymization
Show answerHide answer
Replacing identifying fields with pseudonyms so re-identification needs separate, protected data.
- Tokenization
Show answerHide answer
Replacing sensitive data with a non-sensitive token, with the real value stored securely elsewhere.
- Data masking
Show answerHide answer
Hiding parts of data (e.g., showing only the last 4 digits) to limit exposure.
- Labeling vs. marking
Show answerHide answer
Labeling = machine-readable classification; marking = human-readable classification on documents.
- Information lifecycle protection
Show answerHide answer
Applying classification, handling, and disposal rules to data from creation to destruction.
- Asset inventory
Show answerHide answer
A maintained record of all assets and their owners — the basis for protecting them.
- Data sovereignty
Show answerHide answer
Data is subject to the laws of the country in which it is physically stored.
Security Architecture & Engineering (48)
- Security model
Show answerHide answer
A formal statement of rules that a system enforces to meet a security policy.
- Bell-LaPadula model
Show answerHide answer
Confidentiality model: no read up (Simple Security) and no write down (*-Property).
- Bell-LaPadula simple security property
Show answerHide answer
No read up — a subject can't read data above its clearance.
- Bell-LaPadula star property
Show answerHide answer
No write down — a subject can't write data to a lower level.
- Biba model
Show answerHide answer
Integrity model: no read down (Simple Integrity) and no write up (*-Integrity).
- Biba simple integrity axiom
Show answerHide answer
No read down — a subject can't read data of lower integrity.
- Biba star integrity axiom
Show answerHide answer
No write up — a subject can't write to a higher integrity level.
- Clark-Wilson model
Show answerHide answer
Integrity model using well-formed transactions and separation of duties (the access triple).
- Brewer-Nash (Chinese Wall)
Show answerHide answer
Confidentiality model that changes access dynamically to prevent conflicts of interest.
- Take-Grant model
Show answerHide answer
A model describing how rights can be passed (taken or granted) between subjects.
- Reference monitor
Show answerHide answer
The abstract concept that mediates ALL access between subjects and objects.
- Security kernel
Show answerHide answer
The hardware/software that implements the reference monitor concept.
- Trusted Computing Base (TCB)
Show answerHide answer
All hardware, software, and firmware that enforces a system's security policy.
- Security perimeter
Show answerHide answer
The boundary separating the TCB from the rest of the system.
- Common Criteria
Show answerHide answer
An international standard for evaluating product security, rated by EAL (1-7).
- Evaluation Assurance Level (EAL)
Show answerHide answer
A Common Criteria rating from EAL1 (lowest) to EAL7 (highest) assurance.
- Protection rings
Show answerHide answer
Hierarchical privilege levels (Ring 0 = kernel, outer rings = user) isolating processes.
- Trusted Platform Module (TPM)
Show answerHide answer
A hardware chip that securely stores keys and supports measured boot and disk encryption.
- Cryptography
Show answerHide answer
The science of protecting information using encryption, hashing, and related techniques.
- Plaintext / ciphertext
Show answerHide answer
Plaintext is readable data; ciphertext is the encrypted, unreadable form.
- Symmetric encryption
Show answerHide answer
One shared secret key for encrypting and decrypting; fast but key distribution is hard.
- Asymmetric encryption
Show answerHide answer
A public/private key pair; slower but solves key exchange and enables signatures.
- AES
Show answerHide answer
Advanced Encryption Standard — the dominant symmetric block cipher (128/192/256-bit keys).
- DES / 3DES
Show answerHide answer
Older symmetric ciphers; DES (56-bit) is broken, 3DES is deprecated.
- RSA
Show answerHide answer
A widely used asymmetric algorithm based on the difficulty of factoring large numbers.
- ECC
Show answerHide answer
Elliptic Curve Cryptography — asymmetric crypto giving strong security with smaller keys.
- Diffie-Hellman
Show answerHide answer
A key-exchange algorithm that lets two parties derive a shared secret over an insecure channel.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256).
- SHA-256
Show answerHide answer
A secure hashing algorithm producing a 256-bit digest; used for integrity and signatures.
- MD5 / SHA-1
Show answerHide answer
Older hash functions now considered insecure (collision attacks) — avoid for security.
- Digital signature
Show answerHide answer
A hash of a message encrypted with the sender's PRIVATE key — gives integrity, authenticity, non-repudiation.
- Encrypt for confidentiality
Show answerHide answer
Encrypt with the RECIPIENT's public key; only their private key can decrypt.
- Sign for authenticity
Show answerHide answer
Sign with YOUR private key; anyone can verify with your public key.
- Public Key Infrastructure (PKI)
Show answerHide answer
The framework of certificate authorities, certificates, and policies that manages public keys.
- Certificate Authority (CA)
Show answerHide answer
A trusted entity that issues and signs digital certificates binding a key to an identity.
- Digital certificate (X.509)
Show answerHide answer
A signed document binding a public key to an identity, issued by a CA.
- Hybrid cryptography
Show answerHide answer
Using asymmetric encryption to exchange a fast symmetric session key (e.g., TLS).
- Salt
Show answerHide answer
Random data added to a password before hashing to defeat precomputed (rainbow) attacks.
- HMAC
Show answerHide answer
A keyed hash providing integrity and authenticity of a message.
- Key escrow
Show answerHide answer
Storing a copy of cryptographic keys with a trusted third party for recovery.
- Perfect forward secrecy
Show answerHide answer
Session keys that, if compromised, don't expose past or future sessions.
- Block vs. stream cipher
Show answerHide answer
Block ciphers encrypt fixed-size blocks (AES); stream ciphers encrypt bit/byte by byte (RC4).
- Kerckhoffs's principle
Show answerHide answer
A cryptosystem should be secure even if everything but the key is public.
- Physical security — CPTED
Show answerHide answer
Crime Prevention Through Environmental Design — using layout to deter crime.
- Mantrap / access control vestibule
Show answerHide answer
A two-door entry that allows only one person at a time, preventing tailgating.
- Fire suppression — water vs. gas
Show answerHide answer
Water (sprinklers) for general areas; clean-agent gas for equipment rooms to avoid damage.
- Faraday cage
Show answerHide answer
An enclosure that blocks electromagnetic signals (and emanations like TEMPEST).
- TEMPEST
Show answerHide answer
Standards to prevent data leakage via electromagnetic emanations from equipment.
Communication & Network Security (40)
- OSI model
Show answerHide answer
A seven-layer model: Physical, Data Link, Network, Transport, Session, Presentation, Application.
- OSI Layer 1 — Physical
Show answerHide answer
Cables, signals, and hubs; transmits raw bits.
- OSI Layer 2 — Data Link
Show answerHide answer
MAC addresses and switches; frames on the local network.
- OSI Layer 3 — Network
Show answerHide answer
IP addressing and routing; routers and IPsec operate here.
- OSI Layer 4 — Transport
Show answerHide answer
End-to-end delivery; TCP and UDP, port numbers.
- OSI Layer 5 — Session
Show answerHide answer
Establishes, manages, and tears down sessions.
- OSI Layer 6 — Presentation
Show answerHide answer
Data translation, encoding, and encryption formatting.
- OSI Layer 7 — Application
Show answerHide answer
User-facing protocols: HTTP, DNS, SMTP.
- TCP/IP model
Show answerHide answer
A four-layer model: Link, Internet, Transport, Application — maps onto OSI.
- TCP vs. UDP
Show answerHide answer
TCP is connection-oriented and reliable (handshake); UDP is connectionless and fast.
- TCP three-way handshake
Show answerHide answer
SYN, SYN-ACK, ACK — establishes a reliable TCP connection.
- Switch (Layer 2)
Show answerHide answer
Forwards frames using MAC addresses within a local network.
- Router (Layer 3)
Show answerHide answer
Forwards packets between networks using IP addresses.
- Firewall
Show answerHide answer
A device or software that filters traffic between networks based on rules.
- Stateful firewall
Show answerHide answer
Tracks the state of connections and allows return traffic for established sessions.
- Packet-filtering firewall
Show answerHide answer
Filters traffic by IP, port, and protocol without tracking connection state.
- Next-generation firewall (NGFW)
Show answerHide answer
Adds application awareness, IPS, and deep packet inspection to a firewall.
- Proxy server
Show answerHide answer
An intermediary that forwards requests on behalf of clients, hiding internal hosts.
- DMZ
Show answerHide answer
A screened subnet between the internet and the internal network for public-facing servers.
- VLAN
Show answerHide answer
A logical network segment that isolates traffic at Layer 2 for security and performance.
- Network segmentation
Show answerHide answer
Dividing a network into zones to limit lateral movement and contain breaches.
- VPN
Show answerHide answer
An encrypted tunnel that protects traffic over an untrusted network.
- IPsec
Show answerHide answer
A Layer 3 protocol suite that secures IP traffic; used for VPNs (AH and ESP).
- IPsec AH vs. ESP
Show answerHide answer
AH provides integrity/authentication; ESP provides confidentiality (encryption) plus integrity.
- TLS
Show answerHide answer
Transport Layer Security — encrypts application traffic (HTTPS); successor to SSL.
- SSH
Show answerHide answer
Secure Shell — encrypted remote administration; replaces Telnet.
- Insecure legacy protocols
Show answerHide answer
Telnet, FTP, HTTP, SNMPv1/2, and WEP transmit data in the clear — avoid them.
- WPA2 / WPA3
Show answerHide answer
Wi-Fi security protocols; WPA3 is the current standard with stronger encryption.
- WEP
Show answerHide answer
An obsolete, broken Wi-Fi security protocol — never use it.
- IDS vs. IPS
Show answerHide answer
An IDS detects and alerts on attacks; an IPS detects and actively blocks them.
- NAC
Show answerHide answer
Network Access Control — enforces policy (e.g., patch state) before allowing a device on the network.
- DDoS attack
Show answerHide answer
Distributed Denial of Service — overwhelming a target with traffic from many sources.
- Man-in-the-middle (MITM)
Show answerHide answer
An attacker intercepts and possibly alters communication between two parties.
- ARP spoofing
Show answerHide answer
Forging ARP replies to associate the attacker's MAC with another host's IP.
- DNS poisoning
Show answerHide answer
Corrupting DNS records to redirect users to malicious sites.
- Software-Defined Networking (SDN)
Show answerHide answer
Decoupling network control from forwarding, managed centrally by software.
- Network access — 802.1X
Show answerHide answer
A port-based network access control standard requiring authentication before access.
- Converged protocols
Show answerHide answer
Carrying multiple traffic types over one network (e.g., VoIP, FCoE) — security implications.
- Zero Trust
Show answerHide answer
A model that trusts no one by default; verifies every request regardless of network location.
- Microsegmentation
Show answerHide answer
Fine-grained segmentation down to individual workloads, a key Zero Trust technique.
Identity & Access Management (40)
- Identification
Show answerHide answer
A subject claiming an identity (e.g., a username) — the first step of access control.
- Authentication
Show answerHide answer
Proving a claimed identity with a credential (knowledge, possession, or inherence).
- Authorization
Show answerHide answer
Determining what an authenticated identity is permitted to access and do.
- Accountability
Show answerHide answer
Tying actions back to a specific identity through logging and auditing.
- AAA
Show answerHide answer
Authentication, Authorization, and Accounting — the pillars of access control.
- Type 1 factor — something you know
Show answerHide answer
Knowledge factor: password, PIN, or passphrase.
- Type 2 factor — something you have
Show answerHide answer
Possession factor: smart card, hardware token, or phone.
- Type 3 factor — something you are
Show answerHide answer
Inherence (biometric) factor: fingerprint, iris, or face.
- Multi-factor authentication (MFA)
Show answerHide answer
Using two or more factors from DIFFERENT categories — know, have, are.
- Why two passwords isn't MFA
Show answerHide answer
Two of the same factor type (password + security question) is still single-factor.
- Biometric — FAR
Show answerHide answer
False Acceptance Rate — wrongly accepting an unauthorized person (a security failure).
- Biometric — FRR
Show answerHide answer
False Rejection Rate — wrongly rejecting an authorized person (a usability failure).
- Biometric — CER
Show answerHide answer
Crossover Error Rate — where FAR equals FRR; lower CER means a better biometric system.
- Least privilege
Show answerHide answer
Granting users and processes only the minimum access needed — and nothing more.
- Need to know
Show answerHide answer
Limiting access to the specific information required to perform a task.
- Separation of duties
Show answerHide answer
Splitting a sensitive task so no single person controls it end to end.
- Job rotation
Show answerHide answer
Periodically moving staff between roles to detect fraud and reduce dependence.
- Mandatory vacation
Show answerHide answer
Requiring time off so fraud that depends on continuous presence is exposed.
- Discretionary access control (DAC)
Show answerHide answer
The data owner decides who gets access (file permissions, ACLs).
- Mandatory access control (MAC)
Show answerHide answer
The system enforces access from labels and clearances; rigid and high-security.
- Role-based access control (RBAC)
Show answerHide answer
Access granted by job role rather than the individual; scales in enterprises.
- Attribute-based access control (ABAC)
Show answerHide answer
Access decided by attributes and policy (user, resource, time, location) — most granular.
- Rule-based access control
Show answerHide answer
Global rules applied to everyone (e.g., a firewall ruleset, time-of-day limits).
- Access Control List (ACL)
Show answerHide answer
A list specifying which subjects may access an object and with what rights.
- Capability table
Show answerHide answer
A list of the objects a specific subject is allowed to access (subject-centric).
- Single sign-on (SSO)
Show answerHide answer
One authentication grants access to multiple systems.
- Kerberos
Show answerHide answer
A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).
- Kerberos KDC
Show answerHide answer
Key Distribution Center — issues tickets; comprises the Authentication Server and TGS.
- Kerberos TGT
Show answerHide answer
Ticket-Granting Ticket — proves a user authenticated, used to request service tickets.
- SAML
Show answerHide answer
Security Assertion Markup Language — XML standard for web SSO and federation.
- OAuth 2.0
Show answerHide answer
An authorization framework that lets apps access resources without sharing passwords.
- OpenID Connect (OIDC)
Show answerHide answer
An authentication layer on top of OAuth 2.0 for federated login.
- Federation
Show answerHide answer
Linking identity across organizations so one set of credentials works across trusted domains.
- Identity provider (IdP)
Show answerHide answer
The system that authenticates users and asserts identity to service providers.
- Provisioning / deprovisioning
Show answerHide answer
Creating and removing user access; timely deprovisioning prevents orphan accounts.
- Privileged Access Management (PAM)
Show answerHide answer
Controlling, monitoring, and securing accounts with elevated rights.
- Identity proofing
Show answerHide answer
Verifying that a person is who they claim before issuing credentials.
- Session management
Show answerHide answer
Securely creating, maintaining, and terminating sessions (timeouts, tokens).
- Just-in-time (JIT) access
Show answerHide answer
Granting elevated access only when needed and for a limited time.
- Account lockout
Show answerHide answer
Disabling an account after repeated failed logins to slow brute-force attacks.
Security Assessment & Testing (31)
- Security assessment
Show answerHide answer
A broad review of a system's controls and risk posture against requirements.
- Security audit
Show answerHide answer
An independent, systematic evaluation of controls against a standard or policy.
- Vulnerability scan
Show answerHide answer
An automated check that identifies known weaknesses without exploiting them.
- Penetration test
Show answerHide answer
An authorized, simulated attack that actively exploits weaknesses to show real impact.
- Scan vs. pen test
Show answerHide answer
A scan finds the holes; a pen test proves what an attacker could do with them.
- Black-box test
Show answerHide answer
The tester has no prior knowledge of the target (simulates an outside attacker).
- White-box test
Show answerHide answer
The tester has full knowledge of the target (architecture, source, credentials).
- Gray-box test
Show answerHide answer
The tester has partial knowledge of the target.
- Rules of engagement
Show answerHide answer
The written scope, limits, and authorization for a penetration test.
- Static application security testing (SAST)
Show answerHide answer
Analyzing source code for flaws without running it.
- Dynamic application security testing (DAST)
Show answerHide answer
Testing a running application from the outside for vulnerabilities.
- Code review
Show answerHide answer
Examining source code (manually or with tools) to find security and quality flaws.
- Fuzzing
Show answerHide answer
Feeding malformed or random input to find crashes and security flaws.
- Misuse case testing
Show answerHide answer
Testing how a system behaves under intentional misuse or attack scenarios.
- Test coverage analysis
Show answerHide answer
Measuring how much of the code or requirements the tests exercise.
- Synthetic transactions
Show answerHide answer
Scripted, simulated user interactions used to test and monitor systems.
- Log review
Show answerHide answer
Examining logs to detect anomalies, policy violations, and incidents.
- SOC 1 report
Show answerHide answer
An attestation on controls relevant to financial reporting.
- SOC 2 report
Show answerHide answer
An attestation on controls for security, availability, processing integrity, confidentiality, privacy.
- SOC 3 report
Show answerHide answer
A general-use, public summary version of a SOC 2 report.
- SOC Type I vs. Type II
Show answerHide answer
Type I = controls at a point in time; Type II = controls' operating effectiveness over a period.
- KPI vs. KRI
Show answerHide answer
KPI measures performance toward a goal; KRI measures risk exposure (an early warning).
- Vulnerability management lifecycle
Show answerHide answer
Discover, prioritize, remediate, and verify vulnerabilities continuously.
- CVSS
Show answerHide answer
Common Vulnerability Scoring System — a 0-10 severity score for vulnerabilities.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a standardized identifier for a known vulnerability.
- Internal vs. external testing
Show answerHide answer
Internal simulates an insider/compromised host; external simulates an internet attacker.
- Account management review
Show answerHide answer
Periodically reviewing accounts and entitlements to enforce least privilege.
- Disaster recovery testing
Show answerHide answer
Checklist, tabletop, simulation, parallel, and full-interruption tests of recovery plans.
- Tabletop exercise
Show answerHide answer
A discussion-based walkthrough of a plan with no system disruption.
- Parallel test
Show answerHide answer
Bringing recovery systems online alongside production to verify they work, without cutover.
- Full-interruption test
Show answerHide answer
Shutting down production to fully exercise recovery — most realistic, most risky.
Security Operations (40)
- Security operations
Show answerHide answer
The day-to-day work of running, monitoring, and defending security controls.
- Incident
Show answerHide answer
An event that actually or potentially harms the confidentiality, integrity, or availability of assets.
- Event vs. incident
Show answerHide answer
An event is any observable occurrence; an incident is an event that causes or threatens harm.
- Incident response — Detection
Show answerHide answer
Identify and confirm that an incident has occurred.
- Incident response — Response
Show answerHide answer
Contain the incident to limit damage.
- Incident response — Mitigation
Show answerHide answer
Reduce the impact and stop the spread.
- Incident response — Reporting
Show answerHide answer
Notify stakeholders and required authorities.
- Incident response — Recovery
Show answerHide answer
Restore systems to normal operation.
- Incident response — Remediation
Show answerHide answer
Fix the root cause so the incident can't recur.
- Incident response — Lessons Learned
Show answerHide answer
Review the response and improve the plan and controls.
- Containment
Show answerHide answer
Limiting the scope and damage of an incident before eradication and recovery.
- NIST SP 800-61
Show answerHide answer
Incident handling guide: Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident.
- CSIRT
Show answerHide answer
Computer Security Incident Response Team — the group that handles incidents.
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs for detection and analysis.
- SOAR
Show answerHide answer
Security Orchestration, Automation, and Response — automates incident handling workflows.
- Logging and monitoring
Show answerHide answer
Recording events and watching them to detect, investigate, and prove activity.
- Clipping level
Show answerHide answer
A threshold of activity that, when exceeded, triggers an alert (e.g., failed logins).
- Egress monitoring
Show answerHide answer
Watching outbound traffic to detect data exfiltration.
- Change management
Show answerHide answer
A controlled process for requesting, evaluating, approving, and documenting system changes.
- Configuration management
Show answerHide answer
Maintaining known-good, documented configurations and baselines for systems.
- Patch management
Show answerHide answer
Identifying, testing, and deploying software updates to fix vulnerabilities.
- Backup — full
Show answerHide answer
Backs up all selected data; fastest to restore, slowest to back up.
- Backup — incremental
Show answerHide answer
Backs up changes since the last backup of any type; fast backup, slow restore.
- Backup — differential
Show answerHide answer
Backs up changes since the last full backup; slower backup, faster restore.
- 3-2-1 backup rule
Show answerHide answer
Keep 3 copies, on 2 media types, with 1 copy offsite.
- RAID
Show answerHide answer
Redundant Array of Independent Disks — combines disks for redundancy and/or performance.
- RAID 1 / RAID 5
Show answerHide answer
RAID 1 mirrors disks; RAID 5 stripes with parity, tolerating one disk failure.
- Hot site
Show answerHide answer
A fully equipped alternate site with near-real-time failover; fastest, most expensive.
- Warm site
Show answerHide answer
An alternate site with hardware and connectivity; data restored on demand; moderate cost.
- Cold site
Show answerHide answer
An alternate site with power and space only; cheapest, slowest to bring online.
- Redundant site
Show answerHide answer
A fully mirrored, always-on duplicate of the primary site (highest cost).
- Evidence — chain of custody
Show answerHide answer
Documentation of who handled evidence and when, preserving its integrity.
- Best evidence rule
Show answerHide answer
Original documents/evidence are preferred over copies in legal proceedings.
- Real / documentary / testimonial evidence
Show answerHide answer
Physical objects; written records; witness statements — types of evidence.
- Forensics — order of volatility
Show answerHide answer
Collect the most volatile data first (CPU/RAM) before disk and archives.
- eDiscovery
Show answerHide answer
The process of identifying and producing electronic data for legal proceedings.
- Service Level Agreement (SLA)
Show answerHide answer
A contract defining the expected level of service and remedies.
- Honeypot
Show answerHide answer
A decoy system designed to attract and study attackers.
- Whitelisting / allow-listing
Show answerHide answer
Permitting only approved applications or addresses; everything else is blocked.
- Sandboxing
Show answerHide answer
Running untrusted code in an isolated environment to contain harm.
Software Development Security (40)
- Software Development Lifecycle (SDLC)
Show answerHide answer
The phased process of building software: requirements, design, build, test, deploy, maintain.
- Secure SDLC
Show answerHide answer
Building security into every phase of development rather than testing for it at the end.
- Shift left
Show answerHide answer
Moving security activities earlier in development, where flaws are cheaper to fix.
- Waterfall model
Show answerHide answer
A sequential, phase-by-phase development model; rigid, suits stable requirements.
- Agile model
Show answerHide answer
Iterative development in short sprints; flexible and delivers frequently.
- DevOps
Show answerHide answer
Integrating development and operations for continuous, automated delivery.
- DevSecOps
Show answerHide answer
Embedding automated security testing throughout DevOps CI/CD pipelines.
- Spiral model
Show answerHide answer
An iterative model with heavy risk analysis in each cycle.
- CI/CD
Show answerHide answer
Continuous Integration / Continuous Delivery — automated build, test, and deployment pipelines.
- Threat modeling in design
Show answerHide answer
Identifying threats early (e.g., STRIDE) so the design mitigates them.
- Capability Maturity Model (CMM/CMMI)
Show answerHide answer
A model rating process maturity from initial to optimizing.
- BSIMM
Show answerHide answer
Building Security In Maturity Model — measures a software security program against peers.
- OWASP SAMM
Show answerHide answer
Software Assurance Maturity Model — a framework to assess and improve secure development.
- OWASP Top 10
Show answerHide answer
A community list of the most critical web application security risks.
- Broken access control
Show answerHide answer
The #1 OWASP risk — users acting outside their intended permissions.
- Injection
Show answerHide answer
Untrusted input is interpreted as a command or query (e.g., SQL injection).
- SQL injection
Show answerHide answer
Inserting malicious SQL via unvalidated input to read or alter a database.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting malicious scripts into web pages viewed by other users.
- Cross-site request forgery (CSRF)
Show answerHide answer
Tricking a logged-in user's browser into making unwanted requests.
- Input validation
Show answerHide answer
Checking and sanitizing all input — the primary defense against injection attacks.
- Parameterized queries
Show answerHide answer
Using prepared statements with bound parameters to prevent SQL injection.
- Output encoding
Show answerHide answer
Encoding data before rendering it to prevent XSS.
- Buffer overflow
Show answerHide answer
Writing past a buffer's bounds to corrupt memory or execute code; prevented by bounds checking.
- Race condition (TOCTOU)
Show answerHide answer
Time-of-check to time-of-use — a flaw exploiting the gap between checking and using a resource.
- Inference
Show answerHide answer
Deducing sensitive information from data you are allowed to see.
- Aggregation
Show answerHide answer
Combining individually harmless pieces of data into sensitive information.
- Polyinstantiation
Show answerHide answer
Storing different data at different classification levels to prevent inference.
- Database — ACID
Show answerHide answer
Atomicity, Consistency, Isolation, Durability — properties of reliable transactions.
- Database normalization
Show answerHide answer
Organizing data to reduce redundancy and improve integrity.
- Stored procedure
Show answerHide answer
Precompiled SQL stored in the database; can reduce injection risk and centralize logic.
- Code repository security
Show answerHide answer
Protecting source control with access control, signing, and secret scanning.
- Software supply chain risk
Show answerHide answer
Vulnerabilities introduced through third-party libraries and dependencies.
- Software Composition Analysis (SCA)
Show answerHide answer
Scanning dependencies for known vulnerabilities and license issues.
- Sandboxing untrusted code
Show answerHide answer
Isolating code (e.g., applets, plugins) so it can't harm the host.
- Secure coding standards
Show answerHide answer
Documented rules (e.g., OWASP, CERT) for writing safe code.
- Maintenance hooks / backdoors
Show answerHide answer
Hidden developer access that must be removed before release.
- Object-oriented security
Show answerHide answer
Encapsulation, inheritance, and polymorphism affect how data is protected in code.
- API security
Show answerHide answer
Protecting APIs with authentication, authorization, rate limiting, and input validation.
- Regression testing
Show answerHide answer
Re-running tests after changes to ensure new code didn't break existing functionality.
- Code signing
Show answerHide answer
Digitally signing software so users can verify its source and integrity.
References
- 1.ISC2. “CISSP Certification Exam Outline (effective April 15, 2024).” isc2.org. ↑
- 2.ISC2. “CISSP — Certified Information Systems Security Professional.” isc2.org. ↑
- 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
