2FA
Two-Factor Authentication — multifactor authentication that uses exactly two different factors.
Security Fundamentals · Domain 4
AAA
Authentication, Authorization, and Accounting — the framework for verifying who you are, deciding what you may do, and recording what you did.
Security Fundamentals · Domain 4
access control vestibule
A small entry space with two interlocking doors that can’t be open at once, used to stop tailgating — also called a mantrap.
Security Fundamentals · Domain 4
account lockout
A security setting that temporarily disables an account after too many failed login attempts, limiting password guessing.
Network Attacks · Domain 4
accounting
Recording what a user did and when, such as logins and commands — the “what did you do?” part of AAA, used for auditing.
Security Fundamentals · Domain 4
ACL
Access Control List — an ordered list of permit and deny rules that a router, switch, or firewall uses to filter traffic; the first matching rule wins.
Defense Techniques & Solutions · Domain 4
air gap
A physical separation with no network connection at all between a system and other networks — the strongest form of isolation.
Defense Techniques & Solutions · Domain 4
amplification
A technique where a small request triggers a much larger response, so the attacker multiplies the volume of a flood — often combined with reflection using DNS or NTP servers.
Network Attacks · Domain 4
anomaly-based
A detection method that learns what normal behavior looks like and flags deviations from it — able to catch new attacks, but prone to more false positives.
Defense Techniques & Solutions · Domain 4
ARP poisoning
An attack that sends forged ARP replies so devices map the wrong MAC address to an IP address (often the gateway’s), redirecting local traffic through the attacker — also called ARP spoofing.
Network Attacks · Domain 4
asset disposal
The safe retirement of old equipment, including wiping or destroying the data, configurations, and keys it holds.
Security Fundamentals · Domain 4
asset tag
A label attached to a piece of equipment that identifies it so it can be tracked in an inventory.
Security Fundamentals · Domain 4
asymmetric encryption
Encryption that uses a linked pair of keys, a public key and a private key — slower, but it solves the problem of sharing keys (RSA is a common example).
Security Fundamentals · Domain 4
attack surface
The total number of ways an attacker could get into or attack a system — every open port, service, and account.
Defense Techniques & Solutions · Domain 4
authentication
Verifying who someone or something is — the “who are you?” part of AAA, such as a username and password.
Security Fundamentals · Domain 4
authentication factor
A category of proof of identity: something you know, something you have, something you are, and sometimes somewhere you are or something you do.
Security Fundamentals · Domain 4
authenticator
In 802.1X, the switch or access point that controls the port and relays the client’s credentials to the authentication server.
Defense Techniques & Solutions · Domain 4
authorization
Deciding what an authenticated user is allowed to access or do — the “what may you do?” part of AAA.
Security Fundamentals · Domain 4
availability
Making sure systems and data are accessible to authorized users whenever they’re needed — protected by redundancy, backups, and DDoS protection.
Security Fundamentals · Domain 4
backhauling
Sending branch or remote users’ traffic back to a central data center for inspection before it goes on to the internet or cloud, which adds delay.
Zero Trust & SASE · Domain 4
badge reader
A device at a door that reads an employee’s ID card or badge to decide whether to let them in, and logs who entered.
Security Fundamentals · Domain 4
biometrics
Authentication based on a physical characteristic of the person, such as a fingerprint, face, or iris.
Security Fundamentals · Domain 4
botnet
A large group of compromised devices (bots or zombies) that an attacker controls remotely, often used to launch DDoS attacks.
Network Attacks · Domain 4
BPDU
Bridge Protocol Data Unit — the messages switches exchange in Spanning Tree Protocol to elect a root bridge and prevent loops.
Network Attacks · Domain 4
BPDU guard
A switch feature that shuts down an access port if it receives BPDUs, blocking rogue switches from joining the Spanning Tree.
Network Attacks · Domain 4
brute force
A password attack that automatically tries every possible combination of characters until one works.
Network Attacks · Domain 4
CAM table
Content Addressable Memory table — the switch’s MAC address table, which maps MAC addresses to ports and has a limited size.
Network Attacks · Domain 4
captive portal
A web page that guests must sign in to or accept terms on before they’re allowed to use a network.
Defense Techniques & Solutions · Domain 4
CASB
Cloud Access Security Broker — a control point between users and cloud services that gives visibility into cloud app use and enforces security policy, such as access control and data loss prevention.
Zero Trust & SASE · Domain 4
castle-and-moat
Another name for the perimeter security model: a strong wall and moat at the edge, and free movement for anyone who gets inside.
Zero Trust & SASE · Domain 4
certificate authority
A trusted organization that issues digital certificates and vouches that a public key belongs to its stated owner.
Security Fundamentals · Domain 4
CIA
Confidentiality, Integrity, and Availability — the three core goals of information security, and the model used to judge what a security control protects.
Security Fundamentals · Domain 4
ciphertext
Data that has been encrypted and is unreadable without the correct key.
Security Fundamentals · Domain 4
command and control
Command and Control (C2) — the server or channel an attacker uses to send instructions to the devices in a botnet.
Network Attacks · Domain 4
conditional access
A policy that grants, limits, blocks, or adds proof requirements for access based on conditions such as the user’s identity, device health, location, and risk level.
Zero Trust & SASE · Domain 4
confidentiality
Keeping data private so that only authorized people can see it — protected by controls like encryption and access controls.
Security Fundamentals · Domain 4
content filtering
Blocking or allowing web content by category, URL, domain, or file type, to enforce acceptable use and reduce exposure to malicious sites.
Defense Techniques & Solutions · Domain 4
continuous verification
Re-checking identity, device health, and context throughout a session, not only at login, so access can be limited or revoked if conditions change.
Zero Trust & SASE · Domain 4
control plane
The part of a system that makes decisions and sets up how traffic is handled, without carrying user data — in zero trust, the policy engine and policy administrator.
Zero Trust & SASE · Domain 4
credential stuffing
An attack that takes username and password pairs leaked in one breach and tries them on other sites, exploiting password reuse.
Network Attacks · Domain 4
cross-site scripting
An attack that injects malicious script into a web page so it runs in other users’ browsers — often shortened to XSS.
Defense Techniques & Solutions · Domain 4
data plane
The part of a system that carries the actual user traffic — in zero trust, the path from the user through the policy enforcement point to the resource.
Zero Trust & SASE · Domain 4
DDoS
Distributed Denial of Service — a denial-of-service attack launched from many sources at once, usually a botnet, which makes it harder to block.
Network Attacks · Domain 4
deauthentication attack
An attack that sends forged management frames to disconnect wireless clients from an access point, used for denial of service or to push users toward an evil twin.
Network Attacks · Domain 4
deep packet inspection
Examining the contents of packets, not just their headers, so a device can identify applications and detect threats.
Defense Techniques & Solutions · Domain 4
default credentials
The manufacturer’s preset username and password on a new device, which are widely known and must be changed.
Defense Techniques & Solutions · Domain 4
defense in depth
Protecting assets with multiple layers of different security controls, so that if one fails, others still protect them.
Security Fundamentals · Domain 4
DHCP snooping
A switch feature that only allows DHCP server replies from trusted ports, blocking rogue DHCP servers.
Network Attacks · Domain 4
dictionary attack
A password attack that tries words and common passwords from a wordlist instead of every possible combination.
Network Attacks · Domain 4
digital certificate
An electronic document that ties a public key to an identity, such as a website, and is signed by a certificate authority.
Security Fundamentals · Domain 4
digital signature
A hash of a message signed with a sender’s private key, which anyone can verify with the public key to prove who sent it and that it wasn’t altered.
Security Fundamentals · Domain 4
DLP
Data Loss Prevention — controls that detect and block sensitive data, such as customer records or card numbers, from leaving the organization.
Zero Trust & SASE · Domain 4
DMZ
Demilitarized Zone — a buffer network holding public-facing servers between the internet and the internal network; now often called a screened subnet.
Defense Techniques & Solutions · Domain 4
DNS poisoning
An attack that plants false records in a DNS server’s cache, or forges a response, so a real domain name resolves to the attacker’s IP address — also called DNS spoofing.
Network Attacks · Domain 4
DNSSEC
DNS Security Extensions — a set of protections that digitally sign DNS records so resolvers can verify they’re authentic and unaltered.
Network Attacks · Domain 4
DoS
Denial of Service — an attack that overwhelms a system or network so legitimate users can no longer use it; it targets availability.
Network Attacks · Domain 4
DTP
Dynamic Trunking Protocol — a Cisco protocol that automatically negotiates trunk links between switches; attackers abuse it for switch spoofing.
Network Attacks · Domain 4
dumpster diving
Searching through trash for discarded documents, drives, or notes that contain sensitive information.
Network Attacks · Domain 4
dynamic ARP inspection
A switch feature that checks ARP messages against trusted address bindings and drops forged ones, defending against ARP poisoning.
Network Attacks · Domain 4
encryption
Scrambling readable data into unreadable ciphertext using an algorithm and a key, so only someone with the right key can read it.
Security Fundamentals · Domain 4
encryption key
A secret value used by an encryption algorithm to scramble and unscramble data.
Security Fundamentals · Domain 4
evil twin
A malicious wireless access point that copies the name (SSID) of a legitimate network so users connect to it, letting the attacker capture their traffic and credentials.
Network Attacks · Domain 4
exploit
A specific tool, piece of code, or technique that takes advantage of a vulnerability.
Security Fundamentals · Domain 4
false negative
A real attack that a security tool fails to detect or alert on.
Defense Techniques & Solutions · Domain 4
false positive
An alert that flags harmless, legitimate activity as an attack.
Defense Techniques & Solutions · Domain 4
firewall
A device or service that allows or blocks network traffic based on a defined set of rules.
Defense Techniques & Solutions · Domain 4
forward proxy
A proxy that sits in front of clients and handles their outbound requests to the internet — used for filtering, logging, and caching.
Defense Techniques & Solutions · Domain 4
FWaaS
Firewall as a Service — a firewall delivered from the cloud instead of a hardware appliance at each site, filtering traffic for offices and remote users.
Zero Trust & SASE · Domain 4
guest network
An isolated network for visitors that usually offers internet access only, with no access to internal resources.
Defense Techniques & Solutions · Domain 4
hardening
Securing a device by reducing its attack surface — disabling unused ports and services, changing default credentials, and applying patches.
Defense Techniques & Solutions · Domain 4
hashing
Running data through a one-way function to produce a fixed-length fingerprint (a hash) — it can’t be reversed, and it’s used to check integrity.
Security Fundamentals · Domain 4
honeynet
A network of honeypots that imitates a real network to lure and study attackers.
Defense Techniques & Solutions · Domain 4
honeypot
A decoy system built to look like a valuable target so attackers go after it, giving defenders an early warning and a way to study their techniques.
Defense Techniques & Solutions · Domain 4
identity provider
IdP — a service that stores user identities, authenticates them, and vouches for them to applications.
Zero Trust & SASE · Domain 4
IDS
Intrusion Detection System — monitors traffic for suspicious activity and generates alerts, without directly blocking it.
Defense Techniques & Solutions · Domain 4
implicit deny
The invisible final rule in an ACL or firewall policy that blocks any traffic no earlier rule allowed.
Defense Techniques & Solutions · Domain 4
implicit trust
Trust granted automatically because of where a user or device is — such as inside the office network — instead of because it was verified.
Zero Trust & SASE · Domain 4
inline
Placed directly in the path of network traffic, so all traffic passes through the device — unlike a device that only sees a copy.
Defense Techniques & Solutions · Domain 4
integrity
Keeping data accurate and unaltered, so any unauthorized change is prevented or detected — protected by controls like hashing and digital signatures.
Security Fundamentals · Domain 4
IP spoofing
Forging the source IP address in packets to hide the sender’s identity or impersonate another host — the basis of reflection attacks.
Network Attacks · Domain 4
IPS
Intrusion Prevention System — sits inline with live traffic and can actively block suspicious traffic in real time.
Defense Techniques & Solutions · Domain 4
lateral movement
An attacker’s movement from one compromised system to others inside a network, looking for more valuable targets.
Zero Trust & SASE · Domain 4
least functionality
Configuring a device to provide only the functions it needs and nothing more, so there’s less to attack.
Defense Techniques & Solutions · Domain 4
least privilege
Giving every user, account, and system only the minimum access needed to do its job — and nothing more.
Security Fundamentals · Domain 4
MAC flooding
An attack that floods a switch with frames from fake source MAC addresses to overflow its CAM table, making it forward traffic out every port like a hub.
Network Attacks · Domain 4
MAC spoofing
Changing or cloning a device’s MAC address to impersonate another device or bypass MAC filtering.
Network Attacks · Domain 4
malware
Any software designed to harm a system, steal data, or gain unauthorized access.
Network Attacks · Domain 4
MD5
Message Digest 5 — an older hashing algorithm that is now considered weak and unsuitable for security purposes.
Security Fundamentals · Domain 4
MFA
Multifactor Authentication — requiring two or more different types of proof of identity, such as a password plus a fingerprint.
Security Fundamentals · Domain 4
microsegmentation
Dividing a network into very small, granular zones — down to a single workload or application — with policy controlling the traffic between them, to limit lateral movement.
Zero Trust & SASE · Domain 4
motion detection
A sensor system that raises an alert when it detects movement in an area that should be empty.
Security Fundamentals · Domain 4
MPLS
Multiprotocol Label Switching — a carrier-provided private WAN service that forwards traffic using labels; reliable, but usually more costly than broadband.
Zero Trust & SASE · Domain 4
NAC
Network Access Control — decides whether a device or user may join the network, and what it may reach, based on identity and health checks.
Defense Techniques & Solutions · Domain 4
native VLAN
The VLAN whose traffic crosses a trunk without an 802.1Q tag — the weakness that double-tagging attacks exploit.
Network Attacks · Domain 4
network segmentation
Dividing a network into smaller zones and controlling the traffic allowed between them, which limits how far an attack can spread.
Defense Techniques & Solutions · Domain 4
network tap
A hardware device placed on a link that copies the traffic passing through it to a monitoring device, without sitting in the traffic’s path.
Defense Techniques & Solutions · Domain 4
NGFW
Next-Generation Firewall — adds deep, application-aware inspection beyond basic IP address and port filtering.
Defense Techniques & Solutions · Domain 4
on-path attack
An attack where the attacker secretly positions themselves between two parties to intercept, read, or alter their communication — formerly called a man-in-the-middle (MITM) attack.
Network Attacks · Domain 4
on-path browser attack
A variant where malware inside the victim’s own web browser changes what the user sees or alters transactions as they’re sent — also called man-in-the-browser.
Network Attacks · Domain 4
password spraying
An attack that tries one or a few very common passwords against many different accounts, staying under account lockout limits.
Network Attacks · Domain 4
patch
A software or firmware update that fixes a known vulnerability or bug.
Defense Techniques & Solutions · Domain 4
perimeter security
A security model that defends the edge of the network, mainly with firewalls, and trusts users and devices once they are inside — also called the castle-and-moat model.
Zero Trust & SASE · Domain 4
phishing
A fraudulent message, usually an email with a link or attachment, sent to many people to trick them into revealing information or installing malware.
Network Attacks · Domain 4
piggybacking
Gaining entry to a secured area because an authorized person knowingly lets you in, such as by holding the door — unlike tailgating, where they don’t know.
Network Attacks · Domain 4
PKI
Public Key Infrastructure — the system of certificate authorities, policies, and processes that issues, manages, and verifies digital certificates.
Security Fundamentals · Domain 4
point of presence
PoP — a cloud provider’s regional location where user traffic is processed and secured close to the user.
Zero Trust & SASE · Domain 4
policy administrator
The zero trust component that carries out the policy engine’s decision by setting up or tearing down the connection, and telling the enforcement point what to allow.
Zero Trust & SASE · Domain 4
policy enforcement point
PEP — the zero trust component that sits in the path of the traffic and allows, monitors, and ends the connection between a user or device and a resource.
Zero Trust & SASE · Domain 4
policy engine
The zero trust component that decides whether to grant, deny, or revoke access, by weighing each request against policy and signals such as identity, device health, and risk.
Zero Trust & SASE · Domain 4
port mirroring
A switch feature that copies the traffic from one or more ports to another port, so a monitoring device such as an IDS can inspect it.
Defense Techniques & Solutions · Domain 4
posture assessment
A NAC check of a device’s health — such as OS patches, antivirus, and firewall status — before or after it is allowed onto the network.
Defense Techniques & Solutions · Domain 4
pretexting
Using an invented scenario or false identity to gain a victim’s trust and get information or access.
Network Attacks · Domain 4
private key
The secret half of an asymmetric key pair, kept only by its owner — it decrypts data sent to them or creates their digital signature.
Security Fundamentals · Domain 4
proxy
A server that forwards requests on behalf of a client, sitting between the client and its destination.
Defense Techniques & Solutions · Domain 4
public key
One half of an asymmetric key pair, which can be shared openly — it encrypts data for its owner or verifies the owner’s digital signature.
Security Fundamentals · Domain 4
quarantine network
A restricted network where devices that fail a NAC health check are placed, able to reach only what they need to fix the problem.
Defense Techniques & Solutions · Domain 4
ransomware
Malware that encrypts a victim’s data (or locks their system) and demands payment for the key.
Network Attacks · Domain 4
rate limiting
Capping how many requests or how much traffic a source can send in a set time, which reduces the effect of floods and password guessing.
Defense Techniques & Solutions · Domain 4
RBAC
Role-Based Access Control — granting permissions according to a user’s job role instead of assigning them one by one.
Zero Trust & SASE · Domain 4
reflection
A technique where an attacker forges the victim’s IP address as the source of requests sent to third-party servers, so all the replies go to the victim and the attacker stays hidden.
Network Attacks · Domain 4
reverse proxy
A proxy that sits in front of servers and handles inbound requests from the internet — hiding the servers and often balancing load or handling TLS.
Defense Techniques & Solutions · Domain 4
risk
The likelihood that a threat will exploit a vulnerability, combined with the damage it would cause if it did.
Security Fundamentals · Domain 4
rogue access point
A wireless access point connected to a network without authorization, creating an unsecured back door — it might be malicious or just an employee’s personal device.
Network Attacks · Domain 4
rogue DHCP server
An unauthorized DHCP server on the network that hands out false settings, such as the attacker’s default gateway or DNS server.
Network Attacks · Domain 4
root bridge
The switch elected as the central reference point of a Spanning Tree topology, chosen by the lowest bridge priority.
Network Attacks · Domain 4
root guard
A switch feature that blocks a port from accepting a switch that tries to become the root bridge, keeping the root where the administrator placed it.
Defense Techniques & Solutions · Domain 4
RSA
A widely used asymmetric encryption algorithm, common for key exchange and digital signatures.
Security Fundamentals · Domain 4
SASE
Secure Access Service Edge (pronounced “sassy”) — a cloud-delivered service that combines SD-WAN networking with security services such as SWG, CASB, ZTNA, and FWaaS.
Zero Trust & SASE · Domain 4
screened subnet
The modern name for a DMZ — a subnet for public-facing servers whose traffic is screened by firewall rules, keeping them separate from the internal network.
Defense Techniques & Solutions · Domain 4
SD-WAN
Software-Defined Wide Area Network — WAN connectivity managed by central software that steers traffic across multiple links, such as broadband, cellular, and MPLS, by application and link quality.
Zero Trust & SASE · Domain 4
separation of duties
Splitting a sensitive task among more than one person so no single person can complete it alone, which prevents fraud and errors.
Security Fundamentals · Domain 4
session hijacking
Taking over a user’s active, already-authenticated session, usually by stealing or guessing the session token, without needing the password.
Network Attacks · Domain 4
session token
A value, often stored in a cookie, that a website uses to recognize a logged-in user across requests.
Network Attacks · Domain 4
SHA
Secure Hash Algorithm — a family of hashing algorithms; SHA-1 is deprecated, and SHA-2 (such as SHA-256) is widely used.
Security Fundamentals · Domain 4
shadow IT
Cloud apps and services that employees use without the IT department’s knowledge or approval.
Zero Trust & SASE · Domain 4
shoulder surfing
Watching someone enter a password or PIN, or read a screen, from over their shoulder.
Network Attacks · Domain 4
signature-based
A detection method that matches traffic against known attack patterns — accurate for known threats, but blind to new ones.
Defense Techniques & Solutions · Domain 4
smishing
SMS phishing — social engineering carried out through text messages.
Network Attacks · Domain 4
social engineering
Manipulating people, instead of technology, into giving up information or access.
Network Attacks · Domain 4
spear phishing
Phishing aimed at a specific person or group, personalized with details like their name, role, or coworkers to look convincing.
Network Attacks · Domain 4
SQL injection
An attack that inserts database commands into a web form or URL so the application runs them, letting the attacker read or change data.
Defense Techniques & Solutions · Domain 4
SSE
Security Service Edge — the security half of SASE: cloud-delivered security services such as SWG, CASB, and ZTNA (often FWaaS), without the SD-WAN networking part.
Zero Trust & SASE · Domain 4
SSO
Single Sign-On — signing in once with one set of credentials to reach many applications, without signing in to each separately.
Zero Trust & SASE · Domain 4
stateful
A firewall that tracks the state of connections in a state table, so it automatically allows return traffic for connections that inside devices started and drops packets that don’t belong to a known connection.
Defense Techniques & Solutions · Domain 4
stateless
A firewall or filter that examines each packet on its own, by header details like IP address, port, and protocol, with no memory of earlier packets.
Defense Techniques & Solutions · Domain 4
STP manipulation
An attack that sends crafted BPDUs to win the root bridge election in Spanning Tree, letting the attacker redirect or disrupt traffic.
Network Attacks · Domain 4
supplicant
In 802.1X, the client device that requests access and must prove its identity.
Defense Techniques & Solutions · Domain 4
SWG
Secure Web Gateway — a service between users and the internet that filters web traffic, blocks malicious sites and downloads, and enforces acceptable use.
Zero Trust & SASE · Domain 4
symmetric encryption
Encryption that uses the same single secret key to encrypt and decrypt — fast, but the key has to be shared safely (AES is a common example).
Security Fundamentals · Domain 4
SYN flood
A DoS attack that sends a huge number of TCP connection requests (SYN packets) and never completes the handshake, tying up the server with half-open connections.
Network Attacks · Domain 4
TACACS+
Terminal Access Controller Access-Control System Plus — a Cisco-developed AAA protocol that keeps authentication, authorization, and accounting separate, used mainly for device administration (TCP port 49).
Security Fundamentals · Domain 4
tailgating
When an unauthorized person follows an authorized one through a secured door without using their own credentials.
Security Fundamentals · Domain 4
tamper detection
A feature or seal that shows when a device or its enclosure has been opened or altered.
Security Fundamentals · Domain 4
threat
Anything that could cause harm to a system or its data, such as an attacker, malware, or a natural disaster.
Security Fundamentals · Domain 4
TLS inspection
Decrypting HTTPS traffic so security tools can examine it for threats, then re-encrypting it before it continues.
Zero Trust & SASE · Domain 4
trojan
Malware disguised as legitimate or desirable software; it doesn’t self-replicate and relies on tricking the user into installing it.
Network Attacks · Domain 4
virus
Malware that attaches itself to a legitimate file or program and spreads when a user runs that file.
Network Attacks · Domain 4
vishing
Voice phishing — social engineering carried out over a phone call.
Network Attacks · Domain 4
VLAN hopping
An attack that lets an attacker reach VLANs they shouldn’t, using switch spoofing (trunk negotiation) or double tagging.
Network Attacks · Domain 4
vulnerability
A weakness in a system, process, or configuration that a threat could take advantage of, such as unpatched software or a default password.
Security Fundamentals · Domain 4
WAF
Web Application Firewall — a firewall that inspects HTTP and HTTPS requests to protect a web application from attacks like SQL injection and cross-site scripting.
Defense Techniques & Solutions · Domain 4
whaling
Spear phishing aimed at senior executives or other high-value targets.
Network Attacks · Domain 4
worm
Self-replicating malware that spreads across networks on its own, without any user action, often by exploiting vulnerabilities.
Network Attacks · Domain 4
zero trust
A security model that never trusts any user, device, or connection by default and verifies every access request — identity, device health, and context — no matter where it comes from: “never trust, always verify.”
Security Fundamentals · Domain 4
zero-day
A vulnerability the software’s vendor doesn’t know about yet, so no patch exists — attackers get to use it with zero days of warning for defenders.
Security Fundamentals · Domain 4
ZTNA
Zero Trust Network Access — a service that connects a verified user to specific applications, not the whole network, after checking identity, device health, and context.
Zero Trust & SASE · Domain 4