Acronym Dictionary
316 acronyms from the SY0-701 exam objectives. Search by acronym, meaning, or description.
316 results
A
Framework for verifying identity, granting rights, and logging usage.
Ordered set of rules that permits or denies traffic or access to resources.
Modern symmetric block cipher used to encrypt data with 128, 192, or 256-bit keys.
IPSec protocol that provides integrity and authentication but not encryption.
Technology that enables machines to perform tasks requiring human-like reasoning, used in both defense and attacks.
CISA program for machine-speed exchange of cyber threat indicators between organizations.
Expected yearly monetary loss from a risk, calculated as SLE times ARO.
Device that lets wireless clients connect to a wired network.
Defined interface that lets software components communicate, and a common attack surface.
Well-funded, skilled adversary (often nation-state) that maintains long-term stealthy access to a target.
Estimated number of times a specific risk event will happen in a year.
Maps IP addresses to MAC addresses on a local network and can be poisoned for on-path attacks.
Memory protection that randomizes where code loads to make buffer overflow exploits harder.
MITRE knowledge base cataloging real-world attacker tactics and techniques.
Policy defining how employees may use company systems and data.
Software that detects and removes malicious software, typically using signatures and heuristics.
B
Common Linux command-line shell and scripting language used by admins and attackers alike.
Process of preparing an organization to keep critical operations running during a disruption.
Routing protocol that connects networks across the internet and can be hijacked to redirect traffic.
Assessment identifying critical business functions and the effect of their loss.
Legacy firmware that initializes hardware before the operating system boots.
Contract defining responsibilities and profit sharing between business partners.
Spanning Tree Protocol message exchanged by switches; BPDU guard protects against rogue switches.
Deployment model where employees use personal devices for work, raising management and data-control risks.
C
Trusted entity that issues and signs digital certificates in a PKI.
Challenge-response test that blocks automated bots from abusing web forms.
Document describing actions taken to fix a deficiency found during an audit or incident.
Enforcement point between users and cloud services that applies security policy to cloud use.
Block cipher mode that XORs each plaintext block with the previous ciphertext block.
AES-based encryption protocol used by WPA2 for wireless confidentiality and integrity.
Video surveillance system used as a physical security detective control.
Group responsible for responding to and coordinating handling of security incidents.
Block cipher mode that turns a block cipher into a self-synchronizing stream cipher.
Authentication method that proves knowledge of a password using a challenge and hash instead of sending it.
The three core goals of information security, known as the CIA triad.
Executive responsible for an organization's overall information technology strategy.
Team that investigates and manages the response to security incidents.
Software for creating and managing website content, a frequent target of web attacks.
Planning that ensures essential functions continue during and after an emergency.
Mobile deployment model where the company owns the device but allows personal use.
Preparing alternative courses of action for when normal operations fail.
Error-detecting code used to catch accidental changes to data in transit or storage.
CA-published list of certificates that have been revoked before expiration.
Executive responsible for the organization's overall security program.
Company that delivers cloud computing services such as IaaS, PaaS, or SaaS.
Message containing a public key and identity details sent to a CA to request a certificate.
Attack that tricks an authenticated user's browser into submitting unwanted requests to a site.
Device that terminates a digital WAN circuit at the customer premises.
Block cipher mode that encrypts a counter value to create a parallelizable stream cipher.
Executive responsible for an organization's technology direction and development.
Standardized identifier system for publicly known vulnerabilities.
Framework that scores vulnerability severity from 0 to 10 to help prioritize remediation.
Mobile model where employees pick a device from a company-approved list.
D
Access model where the resource owner decides who gets access.
Role responsible for managing, securing, and maintaining databases.
Attack that floods a target with traffic from many compromised systems to make it unavailable.
Memory protection that blocks code from running in regions marked as data.
Obsolete 56-bit symmetric cipher now considered too weak for use.
Protocol that automatically assigns IP addresses and network settings to hosts.
Email authentication that cryptographically signs messages to prove the sending domain.
Shared Windows code library that attackers abuse through DLL injection and sideloading.
Technology that detects and blocks sensitive data from leaving the organization.
Email policy standard that builds on SPF and DKIM to block spoofed messages.
NAT variant that rewrites the destination address, commonly used to publish internal services.
Service that translates domain names to IP addresses and is a target of poisoning and hijacking.
Attack that overwhelms or crashes a system so legitimate users cannot access it.
Role accountable for an organization's data privacy compliance, required under GDPR.
Documented procedures for restoring IT systems and data after a disaster.
Asymmetric algorithm standardized for creating digital signatures.
Broadband internet technology delivered over telephone lines.
E
Authentication framework supporting many methods, widely used in wireless and 802.1X.
Weakest block cipher mode because identical plaintext blocks produce identical ciphertext.
Asymmetric cryptography that achieves strong security with small keys, ideal for mobile and IoT.
Key exchange using ephemeral elliptic curve keys to provide forward secrecy.
Digital signature algorithm based on elliptic curve cryptography.
Endpoint tool that continuously monitors, detects, and responds to threats on hosts.
Windows feature for encrypting individual files and folders on NTFS volumes.
Integrated business software suite whose central role makes it a high-value target.
Unique identifier embedded in a mobile device by the manufacturer.
IPSec protocol that provides encryption plus integrity for tunneled traffic.
F
Per-file list of permissions defining which users can read, write, or execute it.
Encrypting an entire drive so data is protected if the device is lost or stolen.
Tool that alerts when critical files change unexpectedly, indicating possible compromise.
Reprogrammable hardware chip used in embedded systems and specialized appliances.
How often a biometric system wrongly rejects a legitimate user.
Legacy protocol for transferring files that sends credentials and data in cleartext.
FTP protected with TLS encryption for secure file transfers.
G
Authenticated block cipher mode providing both encryption and integrity in one pass.
EU law governing personal data protection with heavy fines for violations.
Free open-source implementation of PGP for encrypting and signing data and email.
Windows Active Directory mechanism for centrally enforcing configuration and security settings.
Satellite location service used for geofencing, geolocation, and device tracking.
Parallel processor that dramatically accelerates password cracking and hash computation.
Tunneling protocol that encapsulates packets but provides no encryption by itself.
H
Designing systems with redundancy so services stay up despite failures.
Magnetic spinning-platter storage device requiring wiping or destruction for secure disposal.
Software on a single host that detects and alerts on suspicious activity.
Host software that detects and actively blocks malicious activity on that machine.
Keyed hash that verifies both the integrity and authenticity of a message.
One-time password algorithm based on a counter and shared secret.
Dedicated tamper-resistant hardware for generating, storing, and using cryptographic keys.
Standard language for building web pages, often abused in phishing and injection attacks.
Unencrypted protocol for web traffic on port 80.
Web traffic encrypted with TLS on port 443.
Environmental control systems critical to data center availability and often network-connected.
I
Cloud model where the provider supplies virtualized compute, storage, and networking.
Managing infrastructure through machine-readable definition files for consistent, repeatable deployments.
Processes and tools for managing user identities and controlling what they can access.
Protocol for network diagnostics like ping, and a vector for floods and tunneling.
Systems that control industrial processes, often legacy and difficult to patch.
Symmetric block cipher historically used in PGP.
Wiring closet that connects local cabling back to the main distribution frame.
Service that authenticates users and asserts their identity to other applications in federation.
System that monitors traffic or hosts for malicious activity and raises alerts.
Standards body behind specifications such as 802.11 wireless and 802.1X.
Protocol that negotiates keys and security associations for IPSec tunnels.
Real-time chat communication that can leak data or deliver phishing links.
Email retrieval protocol that keeps messages synchronized on the server, port 143 or 993 with TLS.
Forensic artifacts such as hashes, IPs, or domains that signal a system has been breached.
Network-connected embedded devices that often ship with weak default security.
Core protocol that addresses and routes packets across networks.
Inline system that detects malicious traffic and actively blocks it.
Suite of protocols that encrypts and authenticates IP traffic, commonly used for VPNs.
Structured process for detecting, containing, eradicating, and recovering from security incidents.
Legacy chat protocol historically used for botnet command and control.
Documented playbook defining roles and steps for handling security incidents.
Body publishing standards such as ISO 27001 for information security management.
Company that provides organizations and individuals with internet connectivity.
Role responsible for maintaining the security posture of specific information systems.
Random value that makes each encryption unique; reuse (as in WEP) enables attacks.
K
Kerberos component that issues tickets for authenticating users to services.
Key used to encrypt and protect other cryptographic keys.
L
VPN tunneling protocol that requires pairing with IPSec for encryption.
Network covering a small geographic area such as an office or building.
Protocol for querying directory services like Active Directory; use LDAPS for encryption.
Deprecated Cisco wireless authentication protocol vulnerable to dictionary attacks.
M
Cloud-delivered service providing outsourced monitoring of systems and security events.
Access model where the system enforces labels and clearances that users cannot change; also refers to Media Access Control addresses and Message Authentication Codes.
Network spanning a city or campus, larger than a LAN but smaller than a WAN.
Legacy first sector of a disk containing boot code, a classic target for bootkits.
Broken 128-bit hash function that should not be used because collisions are easy to create.
Primary wiring point where external circuits connect to internal cabling.
Platform for centrally enforcing security policy, and remotely wiping, mobile devices.
Requiring two or more different factor types (know, have, are) to authenticate.
Combined printer, scanner, and fax device that stores data and needs hardening.
Networked printer with scan and copy features that can retain sensitive documents.
AI technique where systems learn from data, used in threat detection and adversarial attacks.
Mobile messaging for images and media, exploitable for phishing and malware delivery.
Formal document stating agreed terms and responsibilities between two parties.
Informal, usually non-binding, agreement outlining mutual intentions between parties.
Carrier WAN technology that routes traffic by labels for performance and traffic separation.
Overarching contract defining general terms that govern future work between parties.
Microsoft's CHAP variant, now considered weak and crackable.
Third party that operates a customer's IT infrastructure and represents supply chain risk.
Third party delivering outsourced security operations such as monitoring and management.
Average operating time between failures of a repairable system, a reliability metric.
Average lifespan before failure for a non-repairable component.
Average time needed to repair a failed system and restore service.
Largest packet size a network link can carry without fragmentation.
N
Technology that checks device health and identity before allowing network access.
Translates private internal IP addresses to public ones, hiding internal topology.
Legal contract binding parties to keep specified information confidential.
Short-range wireless used for contactless payments, vulnerable to skimming and relay attacks.
Firewall adding application awareness, deep packet inspection, and intrusion prevention.
Sensor that monitors network traffic for attacks and generates alerts.
Inline network sensor that blocks detected attacks in real time.
US agency that publishes security standards and frameworks such as the CSF and SP 800 series.
Windows file system supporting permissions, encryption, and auditing.
Legacy Windows authentication protocol susceptible to pass-the-hash attacks.
Synchronizes clocks across systems, which is essential for accurate log correlation.
O
Framework that lets applications get limited access to user resources without sharing passwords.
Real-time protocol for checking whether a certificate has been revoked.
Dotted-number identifier used in certificates and SNMP to name objects uniquely.
Core software managing hardware and applications, and the main target of hardening baselines.
Gathering intelligence from publicly available sources during reconnaissance.
Link-state interior routing protocol used within large enterprise networks.
Hardware and software controlling physical processes, such as ICS and SCADA environments.
Delivering updates or configuration to mobile devices wirelessly.
Standard language for describing and checking system vulnerability states.
P
File format bundling a certificate and its private key, usually password protected.
Decentralized networking between hosts, often associated with piracy and malware spread.
Cloud model providing a managed platform for developing and running applications.
Script that tells browsers which proxy to use, abusable to redirect traffic.
Controls that secure, vault, and monitor administrator and other privileged accounts.
Obsolete authentication method that transmits passwords in cleartext.
NAT variant that maps many internal hosts to one public IP using different ports.
Key-stretching function that applies many hash iterations to slow password cracking.
Corporate telephone switching system, a target of toll fraud and vishing.
Recorded network traffic file used for analysis and forensics.
Contractual security standard for any organization handling payment card data.
Rack device that distributes electrical power to data center equipment.
EAP method that wraps authentication inside a TLS tunnel for wireless networks.
Portable device such as a phone or tablet governed by mobile security policy.
Base64 text format for storing certificates and keys, marked by BEGIN/END headers.
Property ensuring past sessions stay secure even if the server's private key is later compromised.
Program using public key cryptography to encrypt and sign email and files.
Health-related personal data protected by regulations such as HIPAA.
Data that can identify a specific individual and requires privacy protection.
US federal smart card standard for physical and logical access.
Family of standards (PKCS #1, #7, #12, etc.) defining public key formats and operations.
System of CAs, certificates, and policies that binds public keys to identities.
Email retrieval protocol that downloads messages to the client, port 110 or 995 with TLS.
Traditional analog landline telephone network.
Layer 2 protocol for direct connections between two nodes, with optional authentication.
Obsolete VPN protocol with known cryptographic weaknesses.
Secret shared in advance and used to authenticate, as in WPA2-Personal wireless.
Camera capability allowing remote aiming and zooming for surveillance.
Software such as adware or toolbars installed alongside desired programs without clear consent.
R
PKI component that verifies certificate requesters' identities on behalf of the CA; also stands for Recovery Agent.
European research program associated with the RIPEMD hash family's origins.
Development methodology favoring fast prototyping over lengthy upfront planning.
Centralized AAA protocol widely used for network and wireless authentication.
Combining multiple disks for redundancy or performance to improve availability.
Server that accepts and authenticates inbound remote connections.
Malware giving attackers covert remote control of a victim's system.
Access model that assigns permissions to job roles rather than individuals; can also mean rule-based access control.
Broken stream cipher formerly used in WEP and SSL, now prohibited.
Microsoft protocol for remote GUI access on port 3389, a favorite ransomware entry point.
Wireless tag technology used in badges and inventory, vulnerable to cloning and skimming.
Family of cryptographic hash functions developed in Europe.
Financial metric comparing the benefit of an investment, including security spending, to its cost.
Maximum acceptable amount of data loss measured in time, driving backup frequency.
Widely used asymmetric algorithm for encryption and digital signatures based on factoring.
DDoS mitigation technique that drops attack traffic by routing it to a null destination.
Maximum acceptable downtime before a system must be restored after a disruption.
OS with deterministic timing used in embedded and industrial devices, often hard to patch.
Protocol carrying voice and video streams; SRTP is its secured version.
S
Standard for encrypting and digitally signing email using certificates.
Cloud model where the provider hosts and delivers complete applications over the internet.
WPA3 handshake that replaces the PSK exchange and resists offline dictionary attacks.
XML standard for exchanging authentication assertions, enabling web single sign-on.
Dedicated high-speed network providing block-level storage; also Subject Alternative Name on certificates.
Cloud-delivered architecture combining networking and security services for remote users.
System for monitoring and controlling industrial processes across large areas.
NIST suite of standards for automating vulnerability and configuration compliance checks.
Protocol for automatically enrolling devices for certificates, common in MDM.
Software-managed WAN that routes traffic intelligently across multiple links.
Bundle of tools and libraries for building software, which can introduce third-party risk.
Phased process for building software, with security ideally embedded in every phase.
Specific methodology, such as waterfall or agile, used to execute the SDLC.
Architecture separating the network control plane from the data plane for centralized programmability.
Linux kernel module enforcing mandatory access control policies.
Storage drives with built-in hardware encryption of all data at rest.
Windows error-handling mechanism that attackers abuse in memory exploitation.
File transfer over SSH providing encrypted authentication and data transfer on port 22.
Family of cryptographic hash functions; SHA-256 is a current standard while SHA-1 is deprecated.
Obsolete alternative to HTTPS for securing individual web messages.
Platform that aggregates and correlates logs from many sources to detect and alert on threats.
Card identifying a mobile subscriber, targeted in SIM-swapping attacks to steal MFA codes.
Contract defining measurable service commitments such as uptime and response times.
Expected monetary loss from one occurrence of a risk, asset value times exposure factor.
Text messaging, used for smishing attacks and considered a weak MFA channel.
Protocol for sending email between servers on port 25.
SMTP protected by TLS encryption, commonly on port 587 or 465.
Protocol for monitoring and managing network devices; use version 3 for security.
XML-based messaging protocol for web services, an older alternative to REST.
Platform that automates incident response workflows with playbooks and runbooks.
Single chip integrating processor, memory, and peripherals, common in embedded devices.
Team and facility that monitors and responds to security events around the clock; SOC 2 also names an audit report on service provider controls.
Document defining the specific tasks, deliverables, and timeline for a project engagement.
DNS record listing servers authorized to send email for a domain, countering spoofing.
Unsolicited messages delivered over instant messaging platforms.
Standard language for querying relational databases.
Attack inserting malicious SQL into inputs to read or modify a database; prevented by parameterized queries.
Encrypted version of RTP protecting voice and video streams.
Flash-based storage whose wear leveling makes secure erasure require special sanitization methods.
Encrypted protocol for remote command-line access and file transfer on port 22.
Deprecated predecessor of TLS; the name persists but TLS should be used.
Authenticating once to gain access to multiple applications without re-entering credentials.
Standardized language for describing cyber threat intelligence.
Proxy that filters user web traffic to enforce policy and block malicious content.
T
Cisco AAA protocol that encrypts the full session and separates authentication from authorization.
Transport protocol for sharing STIX threat intelligence between systems.
Foundational protocol suite for reliable communication across the internet.
Kerberos ticket obtained at login and used to request service tickets; theft enables golden ticket attacks.
Deprecated per-packet keying protocol used by WPA as a stopgap after WEP.
Standard protocol encrypting data in transit, the successor to SSL.
Race condition where a resource changes between when it is checked and when it is used.
One-time password derived from a shared secret and the current time, typically valid 30 seconds.
Motherboard chip that stores keys and supports secure boot and disk encryption like BitLocker.
Behavior patterns that characterize how a specific threat actor operates.
U
Final testing phase where end users verify software meets requirements before release.
Drone that can be used for physical surveillance or wireless attack reconnaissance.
Connectionless transport protocol that is fast but unreliable and easy to spoof.
Modern firmware replacing BIOS, supporting Secure Boot to block tampered bootloaders.
Single platform for managing and securing desktops, laptops, and mobile devices.
Battery backup providing short-term power so systems can ride out or shut down through outages.
String that identifies a resource by name, location, or both.
Web address specifying where a resource lives, often manipulated in phishing attacks.
Common peripheral interface exploited by malicious drives and data exfiltration.
Feature letting mobile devices act as USB hosts to connect drives and peripherals directly.
All-in-one security appliance combining firewall, IPS, antivirus, and content filtering.
Common copper network cabling that is susceptible to interference and eavesdropping.
V
Scripting language in Office documents commonly abused for macro malware.
The virtualized desktop environment a user interacts with in a VDI deployment.
Hosting user desktops on central servers so data stays in the data center rather than on endpoints.
Logical network segmentation on switches that separates traffic without separate hardware.
Subnetting technique using different mask lengths to allocate address space efficiently.
Software-emulated computer; risks include VM escape and VM sprawl.
Telephone calls carried over IP networks, vulnerable to eavesdropping and vishing.
Logically isolated private network segment within a public cloud.
Encrypted tunnel providing secure remote access or site-to-site connectivity over untrusted networks.
Real-time video meeting technology that needs protection against hijacking and eavesdropping.
W
Firewall that inspects HTTP traffic to block application attacks like SQL injection and XSS.
Device that bridges wireless clients onto a wired network; rogue WAPs are a common threat.
Broken original Wi-Fi encryption standard, easily cracked due to weak IV handling.
System that monitors radio traffic to detect rogue access points and wireless attacks.
System that detects and actively blocks wireless threats such as rogue APs.
Document authorizing specific work to be performed, often under a master agreement.
Family of Wi-Fi security standards; WPA3 is the current strongest version.
Push-button Wi-Fi joining feature whose PIN can be brute-forced, so it should be disabled.
X
Detection platform correlating telemetry across endpoints, network, and cloud beyond EDR.
Structured data format subject to injection and external entity (XXE) attacks.
Bitwise operation fundamental to many ciphers and used by malware for simple obfuscation.
Alternate abbreviation for CSRF, forcing a logged-in user's browser to perform unwanted actions.
Injecting malicious scripts into web pages viewed by other users; mitigated by output encoding.