Cyberstudy

Acronyms from your guide

258 acronyms the PDF spells out, each with the page where it first appears. This list is built from your PDF's own text, so it isn't the full official Security+ acronym list. Anything the guide never expands won't be here.

A

A/A Active/Active — Clustering PDF p.197
A/P Active/Passive — Clustering PDF p.197
ABAC Attribute-Based Access Control — Role- and Attribute-Based Access Control PDF p.94
ACL Access Control List — Firewalls PDF p.132
ALE Annualized Loss Expectancy — Risk Identification and Assessment PDF p.397
APIs Application Programming Interfaces — Capabilities of Automation and Scripting PDF p.393
APT Advanced Persistent Threat — Nation-State Actors PDF p.31
ARP Address Resolution Protocol — Routing Infrastructure Considerations PDF p.118
AS Authentication Service — Single Sign-on Authentication PDF p.104
ASLR Address space layout randomization — Application Vulnerabilities PDF p.226
AUP Acceptable Use Policy — Common Organizational Policies PDF p.370
AVT Advanced Volatile Threat — Computer Worms and Fileless Malware PDF p.336

B

BC Business Continuity — Continuity of Operations PDF p.191
BEC Business email compromise — Business Email Compromise PDF p.47
BIA Business Impact Analysis — Business Impact Analysis PDF p.403
BLE Bluetooth Low Energy — Bluetooth Connection Methods PDF p.275
BPA Business Process Analysis — Business Impact Analysis PDF p.403
BPA Business Partnership Agreement — Legal Agreements PDF p.409
BSC Bluetooth Secure Connections — Bluetooth Connection Methods PDF p.275
BYOD Bring Your Own Device — Mobile Hardening Techniques PDF p.267

C

CA Certificate Authority — Certificate Authorities PDF p.58
CAs Certificate Authorities — Transport Layer Security (TLS) PDF p.279
CASB Cloud Access Security Brokers — Cloud-based Application Attacks PDF p.230
CBT Computer-Based Training — Training Topics and Techniques PDF p.435
CDNs Content Delivery Networks — Cloud Architecture PDF p.163
CER Crossover Error Rate — Biometric Authentication PDF p.86
CIs Configuration Items — Asset Protection Concepts PDF p.183
CISO Chief Information Security Officer — Information Security Roles and Responsibilities PDF p.21
CMDB Configuration Management Database — Asset Tracking PDF p.181
CMS Configuration Management System — Asset Protection Concepts PDF p.183
COOP Continuity of operations — Continuity of Operations PDF p.190
COOP Continuity of Operations Plans — Common Organizational Policies PDF p.370
CRL Certificate Revocation List — Certificate Revocation PDF p.63
CSA Cloud Security Alliance — Internet of Things PDF p.176
CSP Cloud Service Provider — Responsibility Matrix PDF p.157
CSPs Cloud Service Providers — Resilient Architecture Concepts PDF p.160
CSR Certificate Signing Request — Certificate Signing Requests PDF p.61
CSRF Cross-Site Request Forgery — Forgery Attacks PDF p.363
CVE Common Vulnerabilities and Exposures — Common Vulnerabilities and Exposures PDF p.240
CVSS Common Vulnerability Scoring System — Common Vulnerabilities and Exposures PDF p.240
CYOD Choose Your Own Device — Mobile Hardening Techniques PDF p.268

D

DAC Discretionary Access Control — Discretionary and Mandatory Access Control PDF p.92
DCS Distributed Control Systems — Industrial Control Systems PDF p.172
DDoS Distributed Denial of Service — Distributed Denial of Service Attacks PDF p.348
DEP Data Execution Prevention — Application Vulnerabilities PDF p.226
DHE Diffie-Hellman Ephemeral — Perfect Forward Secrecy PDF p.75
DISA Defense Information Systems Agency — Benchmarks and Secure Configuration Guides PDF p.246
DKIM Domain Keys Identified Mail — Email Security PDF p.286
DLP Data Loss Prevention — Email Data Loss Prevention PDF p.287
DN Distinguished Name — Subject Name Attributes PDF p.62
DNs Distinguished names — Directory Services PDF p.103
DNS Domain Name System — Network Infrastructure PDF p.115
DOM Document Object Model — Web Application Attacks PDF p.229
DR Disaster Recovery — High Availability PDF p.195

E

EAP Extensible Authentication Protocol — Port Security PDF p.124
ECDHE Elliptic Curve DHE — Perfect Forward Secrecy PDF p.75
EDR Endpoint Detection and Response — Advanced Endpoint Protection PDF p.260
EPPs Endpoint Protection Platforms — Monitoring Systems and Applications PDF p.331
ERM Enterprise Risk Management — Risk Management Processes PDF p.401
ESP Encapsulating Security Payload — Internet Protocol Security Tunneling PDF p.146
ETSI European Telecommunications Standards Institute — Internet of Things PDF p.176

F

FAR False Acceptance Rate — Biometric Authentication PDF p.86
FDE Full-disk encryption — Disk and File Encryption PDF p.70
FDE Full Disk Encryption — Endpoint Protection PDF p.259
FER Failure to Enroll Rate — Biometric Authentication PDF p.87
FIDO Fast Identity Online — Hard Authentication Tokens PDF p.88
FIM File integrity monitoring — Advanced Endpoint Protection PDF p.261
FRR False Rejection Rate — Biometric Authentication PDF p.86
FTP File Transfer Protocol — File Transfer Services PDF p.282

G

GPS Global Positioning System — Location Services PDF p.270

H

HDDs Hard Disk Drives — Secure Data Destruction PDF p.188
HMAC Hash-based Message Authentication Code — Transport Encryption and Key Exchange PDF p.74
HR Human Resources — Preparation PDF p.298
HSM Hardware Security Module — Cryptoprocessors and Secure Enclaves PDF p.66
HSMs Hardware Security Modules — Cryptoprocessors and Secure Enclaves PDF p.66

I

IAM Identity and Access Management — Access Control PDF p.16
ICS Industrial Control Systems — Industrial Control Systems PDF p.172
IDS Intrusion detection systems — Device Placement PDF p.129
IETF Internet Engineering Task Force — Digital Certificates PDF p.59
IIC Industrial Internet Consortium — Internet of Things PDF p.175
IKE Internet Key Exchange — Internet Key Exchange PDF p.147
IM Instant Messaging — Message-Based Vectors PDF p.39
IoCs Indicators of Compromise — TTPs and IoCs PDF p.342
IoTSF Internet of Things Security Foundation — Internet of Things PDF p.175
IP Intellectual property — Data Classifications PDF p.418
IPS Intrusion Prevention Systems — Intrusion Detection Systems PDF p.138
IPS Indoor Positioning System — Location Services PDF p.270
ISACs Information Sharing and Analysis Centers — Threat Feeds PDF p.235
ISSO Information Systems Security Officer — Information Security Roles and Responsibilities PDF p.22

J

K

KMIP Key Management Interoperability Protocol — Key Management PDF p.65
KRA Key Recovery Agent — Key Escrow PDF p.68
KRIs Key Risk Indicators — Risk Management Processes PDF p.401

L

LAN Local Area Network — Network Infrastructure PDF p.114
LDAP Lightweight Directory Access Protocol — Directory Services PDF p.103
LOC Low-Observable Characteristics — Computer Worms and Fileless Malware PDF p.336
LSASS Local Security Authority Subsystem Service — Local, Network, and Remote Authentication PDF p.102

M

MBSA Microsoft Baseline Security Analyzer — Endpoint Hardening PDF p.258
MDM Mobile Device Management — Asset Tracking PDF p.181
MEF Mission Essential Functions — Business Impact Analysis PDF p.403
MFA Multifactor authentication — Multifactor Authentication PDF p.85
ML Machine Learning — Alert Tuning PDF p.329
MOA Memorandum of Agreement — Legal Agreements PDF p.408
MOU Memorandum of Understanding — Legal Agreements PDF p.408
MSA Master Service Agreement — Legal Agreements PDF p.409
MSPs Managed Service Providers — Supply Chain Attack Surface PDF p.41
MTBF Mean Time Between Failures — Business Impact Analysis PDF p.404
MTD Maximum Tolerable Downtime — High Availability PDF p.195
MTTR Mean Time to Repair — Business Impact Analysis PDF p.404
MUA Mail user agent — Metadata PDF p.324

N

NAC Network Access Control — Network Access Control (NAC) PDF p.251
NDA Nondisclosure Agreement — Legal Agreements PDF p.408
NDAs Non-disclosure agreements — Data Types PDF p.416
NFV Network Functions Virtualization — Software Defined Networking PDF p.166
NIST National Institute of Standards and Technology — Cybersecurity Framework PDF p.14
NTA Network Traffic Analysis — IDS and IPS Detection Methods PDF p.255
NVD National Vulnerability Database — Common Vulnerabilities and Exposures PDF p.240

O

OCSP Online Certificate Status Protocol — Certificate Revocation PDF p.63
OSINT Open-Source Intelligence — Threat Feeds PDF p.235
OU Organizational Unit — Subject Name Attributes PDF p.62
OVAL Open Vulnerability and Assessment Language — Benchmarks PDF p.332

P

PAKE Password-Authenticated Key Exchange — Wi-Fi Authentication Methods PDF p.250
PAM Privileged access management — Privileged Access Management PDF p.100
PAM Pluggable Authentication Module — Local, Network, and Remote Authentication PDF p.102
PBF Primary Business Functions — Business Impact Analysis PDF p.403
PBKDF2 Password-Based Key Derivation Function 2 — Salting and Key Stretching PDF p.76
PDUs Power Distribution Units — Power Redundancy PDF p.199
PFS Perfect Forward Secrecy — Perfect Forward Secrecy PDF p.75
PKCS Public Key Cryptography Standards — Digital Certificates PDF p.59
PKI Public key infrastructure — Certificate Authorities PDF p.57
PoLP Principle of Least Privilege — Endpoint Configuration PDF p.262
PPTP Point-to-Point Tunneling Protocol — Remote Access Architecture PDF p.144
PUAs Potentially Unwanted Applications — Malware Classification PDF p.334
PUE Power Usage Effectiveness — Cloud Architecture Features PDF p.169
PUPs Potentially Unwanted Programs — Malware Classification PDF p.334

R

RAT Remote Access Trojan — Malware Classification PDF p.334
RBAC Rule-based access control — Rule-Based Access Control PDF p.94
RCA Risk and Control Assessment — Risk Management Processes PDF p.401
RCSA Risk and Control Self-Assessment — Risk Management Processes PDF p.401
RDP Remote Desktop Protocol — Remote Desktop PDF p.149
REST Representational State Transfer — Open Authorization (OAuth) PDF p.110
RNA Retrospective Network Analysis — Packet Captures PDF p.322
RoE Rules of Engagement — Legal Agreements PDF p.409
RPO Recovery Point Objective — Business Impact Analysis PDF p.404
RTO Recovery Time Objective — Business Impact Analysis PDF p.404
RTOS Real-Time Operating Systems — Embedded Systems PDF p.171

S

S/MIME Secure/Multipurpose Internet Mail Extensions — Email Security PDF p.286
SA Security Association — Internet Key Exchange PDF p.147
SAML Security Assertion Markup Language — Security Assertion Markup Language (SAML) PDF p.108
SAMM Software Assurance Maturity Model — Secure Coding Techniques PDF p.291
SAN Subject Alternative Name — Subject Name Attributes PDF p.62
SASL Simple Authentication and Security Layer — Secure Directory Services PDF p.280
SAW Secure Administrative Workstations — Privileged Access Management PDF p.100
SAWs Secure Administrative Workstations — Out-of-Band Management and Jump Servers PDF p.152
SBOM Software Bill of Materials — Supply Chain PDF p.232
SCADA Supervisory Control and Data Acquisition — Industrial Control Systems PDF p.172
SCAP Security Content Automation Protocol — Common Vulnerabilities and Exposures PDF p.240
SDL Security Development Lifecycle — Secure Coding Techniques PDF p.291
SDLC Software Development Life Cycle — Common Organizational Policies PDF p.370
SDN Software Defined Networking — Software Defined Networking PDF p.166
SED Self-Encrypting Drives — Endpoint Protection PDF p.259
SEDs Self-encrypting drives — Disk and File Encryption PDF p.70
SEH Structured Exception Handling — Application Protections PDF p.293
SFTP Secure File Transfer Protocol — File Transfer Services PDF p.282
SHA Secure Hash Algorithm — Hashing PDF p.55
SIEM Security Information and Event Management — Security Information and Event Management PDF p.325
SLA Service-level Agreement — Legal Agreements PDF p.409
SLAs Service-Level Agreements — Cloud Architecture Features PDF p.168
SMS Short Message Service — Message-Based Vectors PDF p.39
SMTP Simple Mail Transfer Protocol — Email Services PDF p.284
SNMP Simple Network Management Protocol — Simple Network Management Protocol Security PDF p.281
SOAP Simple Object Access Protocol — Security Assertion Markup Language (SAML) PDF p.108
SOC Security Operations Center — Information Security Business Units PDF p.24
SOPs Standard Operating Procedures — Change Management Concepts PDF p.387
SOW Statement of Work — Legal Agreements PDF p.409
SPF Sender Policy Framework — Email Security PDF p.286
SSDs Solid-State Drives — Secure Data Destruction PDF p.189
SSRF Server-Side Request Forgery — Forgery Attacks PDF p.363

T

TAP Test Access Point — Device Attributes PDF p.131
TCO Total Cost of Ownership — Asset Tracking PDF p.181
TDE Transparent Data Encryption — Database Encryption PDF p.72
TEE Trusted execution environment — Cryptoprocessors and Secure Enclaves PDF p.67
TEEs Trusted execution environments — Data Protection PDF p.429
TGS Ticket Granting Service — Single Sign-on Authentication PDF p.104
TGT Ticket Granting Ticket — Single Sign-on Authentication PDF p.105
TPMs Trusted Platform Modules — Cryptoprocessors and Secure Enclaves PDF p.66
TRNGs True random number generators — Cryptoprocessors and Secure Enclaves PDF p.66

U

U2F Universal 2nd Factor — Hard Authentication Tokens PDF p.88
UAC User Account Control — Rule-Based Access Control PDF p.95
UBA User Behavior Analytics — Advanced Endpoint Protection PDF p.261
UEBA User and Entity Behavior Analytics — IDS and IPS Detection Methods PDF p.255
UPSs Uninterruptible Power Supplies — Power Redundancy PDF p.199
URL Uniform Resource Locator — URL Analysis PDF p.367

V

W

Z

ZSP Zero Standing Privileges — Privileged Access Management PDF p.100
ZTA Zero Trust architectures — Deperimeterization and Zero Trust PDF p.176