Access Control
A security mechanism that determines who or what is allowed to access a resource, system, or information.
Understand the terminology behind cybersecurity, networking, ethical hacking, penetration testing, digital forensics, and defensive security.
Use the alphabetical index to navigate through common cybersecurity concepts.
A security mechanism that determines who or what is allowed to access a resource, system, or information.
A Microsoft directory service used to manage users, computers, groups, policies, and resources within a Windows domain environment.
The collection of points where an unauthorized user could potentially attempt to interact with or compromise a system.
The process of verifying the identity of a user, device, application, or system.
The process of determining what an authenticated identity is permitted to access or perform.
A mechanism that can provide access to a system while bypassing normal authentication or security controls.
A technique that attempts many possible credentials or values until a valid one is discovered.
A collection of tools commonly used for testing and analyzing web applications.
A foundational security model consisting of Confidentiality, Integrity, and Availability.
The study and application of techniques used to protect information through mathematical transformations and security protocols.
Common Vulnerabilities and Exposures is a system for identifying publicly known cybersecurity vulnerabilities.
Common Vulnerability Scoring System provides a standardized framework for describing and scoring the severity of vulnerabilities.
Distributed Denial-of-Service is an attack in which multiple systems generate traffic or requests intended to make a service unavailable.
The process of collecting, preserving, examining, and analyzing digital evidence.
Domain Name System translates domain names into IP addresses and supports name resolution across networks.
Endpoint Detection and Response technology monitors endpoint activity to help detect, investigate, and respond to security threats.
The process of transforming readable information into a protected form that requires appropriate cryptographic information to recover.
Authorized security testing performed to identify weaknesses and improve the security of systems.
A security control that monitors and controls network traffic according to defined rules.
File Transfer Protocol is a network protocol designed for transferring files between systems.
A one-way transformation that produces a fixed-length value from input data.
A deliberately exposed or simulated system designed to attract, detect, or study unauthorized activity.
Hypertext Transfer Protocol is a foundational protocol used for communication between web clients and servers.
HTTP communication protected using TLS encryption.
Intrusion Detection System monitors activity and generates alerts when potentially malicious or suspicious behavior is detected.
Intrusion Prevention System detects potentially malicious traffic and can take action to block or prevent it.
The organized process of detecting, analyzing, containing, and recovering from cybersecurity incidents.
A Linux distribution designed for security testing, digital forensics, research, and related cybersecurity tasks.
A network authentication protocol that uses tickets and cryptographic mechanisms to authenticate identities.
Lightweight Directory Access Protocol is used to access and manage directory information.
A principle where users, applications, and systems receive only the permissions required to perform their intended tasks.
The process of identifying authorized paths through which a lower-privileged Linux context could obtain higher privileges.
Malicious software designed to perform unauthorized or harmful actions.
A knowledge base that organizes adversary tactics, techniques, and procedures observed in real-world attacks.
Multi-Factor Authentication requires multiple authentication factors to verify an identity.
Network Address Translation modifies network address information as traffic passes between networks.
A network discovery and security auditing tool commonly used to identify hosts, services, and network characteristics in authorized environments.
The practice of dividing a network into separate segments to control communication and reduce security risk.
An authorization framework that enables applications to obtain limited access to resources without directly handling a user's credentials.
An organization that provides open resources, projects, standards, and educational material focused on application security.
A widely used awareness resource describing important categories of web application security risks.
An authorized security assessment in which controlled testing is performed to identify and validate security weaknesses.
A social-engineering technique that attempts to trick people into revealing information or performing an unintended action.
The process of obtaining permissions beyond those initially available to an account or process.
An intermediary that receives and forwards requests between a client and another system or service.
Malicious software that typically prevents access to data or systems and demands some form of payment or action.
The information-gathering phase of a security assessment used to understand the authorized target environment.
The process of analyzing software or systems to understand their internal structure and behavior.
Security Information and Event Management systems collect, correlate, analyze, and present security-related events and logs.
The use of psychological or social manipulation to influence people into revealing information or performing actions.
A class of vulnerability where untrusted input can interfere with the intended structure of a database query.
Secure Shell is a protocol commonly used for secure remote administration and communication.
Cryptographic protocols used to provide confidentiality, integrity, and authentication for network communication.
Information and analysis about threats that can help organizations understand, detect, and respond to security risks.
Transport Layer Security is a cryptographic protocol used to secure communications over networks.
A value used by an application or protocol to represent authentication, authorization, or a session context.
A weakness in a system, application, process, or configuration that could potentially be exploited.
A process used to identify, analyze, and prioritize vulnerabilities in an authorized environment.
Virtual Private Network technology creates a protected communication path across an underlying network.
Web Application Firewall monitors and filters HTTP traffic to help protect web applications from malicious requests.
A network protocol analyzer used to capture and inspect network traffic in authorized environments.
The practice of identifying and mitigating security risks in applications delivered through web technologies.
Cross-Site Scripting is a class of web vulnerability where attacker-controlled content can execute in a victim's browser context.
The glossary explains the terminology. The roadmap shows you when and where these concepts fit into your cybersecurity learning journey.