📖 IT Certification Glossary

Master the terminology that powers your certification journey. Expert definitions with pro-tips directly from the Sensei.

🔍

ISACA Certified Information Systems Auditor (CISA)

View All →

Acceptable Use Policy

An Acceptable Use Policy (AUP) is a documented set of rules specifying permissible and prohibited uses of an organization’s information assets, including hardware, software, and data. It defines user responsibilities and outlines consequences for policy violations, promoting responsible technology usage.

Access Control List (ACL)

An Access Control List (ACL) is a set of rules specifying which users or system entities are granted access to specific objects or resources. ACLs define permissions – read, write, execute – controlling what actions are allowed on those resources, providing granular control over data access.

Administrative Control

Administrative Controls are management-level policies, procedures, and guidelines designed to define the organization's security posture. These controls focus on the human element, such as security awareness training, hiring practices, and employee handbooks.

Agile Methodology

Agile methodology is an iterative approach to project management and software development emphasizing flexibility, collaboration, and rapid response to change. It breaks down projects into smaller, manageable sprints, delivering incremental value and incorporating feedback throughout the development process, unlike traditional waterfall methods.

Application Controls

Application Controls are automated or manual security controls specific to a particular software application. They ensure the completeness, accuracy, and validity of the data processed by the application, such as input validation and sequence checks.

Attribute Sampling

Attribute sampling is a statistical sampling approach evaluating the presence or absence of a specified attribute within a population. It determines the rate of occurrences for characteristics like proper authorization or adherence to policy. Results are expressed as a percentage of items possessing the attribute.

ISC2 Certified Information Systems Security Professional (CISSP)

View All →

Acceptable Use Policy (AUP)

An Acceptable Use Policy (AUP) defines the rules and guidelines for appropriate use of an organization’s information assets. It details permitted activities, prohibited behaviors, and consequences for violations, covering areas like internet access, data handling, and device usage to mitigate risk and maintain security.

Access Control

Access Control defines and enforces policies governing who or what can access specific resources. It’s a fundamental security principle ensuring confidentiality, integrity, and availability. Implementation spans administrative procedures, physical barriers, and technical mechanisms like authentication and authorization protocols.

Air Gap

Air Gap is a security measure that ensures a secure computer network is physically isolated from unsecured networks, such as the public internet or an unsecured local area network. This physical separation prevents remote attacks and unauthorized data exfiltration.

Annual Loss Expectancy (ALE)

Annual Loss Expectancy (ALE) is the yearly expected financial loss from a specific risk. It is calculated by multiplying the Single Loss Expectancy (SLE) by the Annual Rate of Occurrence (ARO). This metric helps organizations prioritize security investments based on quantitative risk analysis.

Annual Rate of Occurrence (ARO)

Annual Rate of Occurrence (ARO) is the estimated frequency with which a specific threat is expected to occur within a single year. It is expressed as a number, such as 0.1 for once every ten years or 2 for twice a year.

Asymmetric Encryption

Asymmetric encryption utilizes a key pair – a public key for encryption and a corresponding private key for decryption. This method eliminates the need for secure key exchange, as the public key can be freely distributed. Algorithms include RSA and ECC, though they are computationally intensive and slower than symmetric methods.

ISACA Certified Information Security Manager (CISM)

View All →

Acceptable Use Policy

An Acceptable Use Policy (AUP) defines permissible and prohibited uses of an organization’s resources, including networks, systems, and data. It outlines user responsibilities, legal compliance expectations, and potential consequences for violations, establishing clear boundaries for appropriate technology usage and mitigating organizational risk.

Access Control

Access control defines and manages who or what entity has the authority to access specific information resources. This involves implementing mechanisms like authentication, authorization, and accounting to enforce security policies and protect data confidentiality, integrity, and availability.

Annualized Loss Expectancy (ALE)

Annualized Loss Expectancy (ALE) is the total expected monetary loss for an asset over one year. It is calculated by multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO) to determine the yearly risk cost.

Annualized Rate of Occurrence (ARO)

Annualized Rate of Occurrence (ARO) is the estimated frequency with which a specific threat is expected to occur within a single year. This value is a critical input for quantitative risk calculations to determine the annual potential loss.

Audit

An audit is a systematic, independent examination of an organization’s information systems, controls, and processes. It assesses adherence to established policies, standards, and regulations, providing objective evidence of effectiveness and identifying areas for improvement. Audit findings inform risk mitigation strategies.

Audit Trail

An audit trail is a sequential record of system events, logging user actions, system changes, and access attempts. It provides a forensic history for security analysis, compliance verification, and incident response. Comprehensive audit trails are crucial for reconstructing activities and identifying potential breaches.

CompTIA Security+ Certification Exam (SY0-701)

View All →

Acceptable Use Policy (AUP)

An Acceptable Use Policy (AUP) is a document defining permissible and prohibited uses of an organization’s technology assets. It details expectations for user behavior regarding network access, data handling, and software usage. AUPs aim to minimize legal risks and maintain a secure computing environment.

Advanced Persistent Threat

Advanced Persistent Threats (APTs) are sophisticated, long-term cyberattacks targeting specific entities. These attacks involve stealthy intrusion, sustained presence, and focused objectives, typically data exfiltration or espionage. APTs utilize multiple attack vectors and adapt to security measures, requiring advanced detection and response strategies.

Air Gap

An air gap is a security measure implementing physical isolation of a computer or network from all other networks, including the internet. This is achieved by physically disconnecting all communication pathways, preventing data transfer and remote access, and mitigating the risk of remote exploitation.

ARP Poisoning

ARP Poisoning is a Man-in-the-Middle attack exploiting the Address Resolution Protocol. Attackers send spoofed ARP messages, associating their MAC address with the IP address of a legitimate network host, intercepting network traffic and potentially stealing sensitive information.

Asymmetric Encryption

Asymmetric encryption, also known as public-key cryptography, employs a key pair: a public key for encryption and a private key for decryption. The public key can be freely distributed, while the private key must remain confidential. This enables secure communication and digital signatures.

Attack Surface

The attack surface encompasses all potential entry points and vulnerabilities that an attacker could exploit to compromise a system or network. This includes hardware, software, network protocols, and human factors. Reducing the attack surface minimizes exposure to threats and enhances overall security posture.

CompTIA A+ Certification Exam Core 1 (220-1101)

View All →

802.11ax (Wi-Fi 6)

802.11ax, commonly known as Wi-Fi 6, is a wireless networking standard designed to increase efficiency and throughput in high-density environments. It introduces technologies like OFDMA and MU-MIMO to allow multiple devices to communicate simultaneously with a single access point.

Access Point

An access point (AP) enables wireless devices to connect to a wired network using Wi-Fi protocols. It acts as a bridge, translating wireless signals to wired connections and vice versa, extending network reach without requiring direct cable connections for every device.

APIPA (Automatic Private IP Addressing)

APIPA (Automatic Private IP Addressing) is a feature that allows a Windows computer to automatically assign itself an IP address when a DHCP server is unavailable. These addresses always fall within the specific 169.254.0.1 to 169.254.255.254 range.

Bandwidth

Bandwidth defines the data transfer capacity of a network connection, measured in bits per second (bps). It represents the maximum amount of data that can be transmitted over a connection in a given timeframe. Higher bandwidth enables faster data transfer speeds and supports more simultaneous connections.

BIOS

The Basic Input/Output System (BIOS) is firmware embedded on a motherboard that initializes hardware during the boot process. It performs a power-on self-test (POST) and loads the operating system. Modern systems increasingly utilize UEFI, a more advanced successor to BIOS.

Bluetooth

Bluetooth is a wireless technology standard enabling short-range data exchange between devices. Utilizing the 2.4 GHz ISM band, it creates personal area networks (PANs) for applications like audio streaming, file transfer, and peripheral connections with limited power consumption.

CompTIA Network+ Certification Exam (N10-009)

View All →

802.1Q (VLAN Tagging)

802.1Q is the industry-standard protocol for VLAN tagging on an Ethernet network. It inserts a tag into the Ethernet frame header to identify which VLAN the traffic belongs to, allowing multiple VLANs to share a single physical link, known as a trunk.

802.1X (Port-based Network Access Control)

802.1X is an IEEE standard for port-based network access control that provides an authentication mechanism to devices wishing to attach to a LAN or WLAN. It uses the Extensible Authentication Protocol (EAP) to ensure only authorized devices can access the network.

AAA

AAA, representing Authentication, Authorization, and Accounting, is a comprehensive framework for controlling network access. Authentication verifies user identity, authorization determines permitted access levels, and accounting tracks user activity for auditing and billing purposes, enhancing network security.

ARP

Address Resolution Protocol resolves IP addresses to corresponding MAC addresses on a local network. It broadcasts ARP requests to identify the hardware address associated with a known IP address, enabling communication within the same network segment. ARP is fundamental to Ethernet network operation.

Autonomous System (AS)

An Autonomous System (AS) is a collection of IP networks and routers under the control of a single administrative entity, such as an ISP. Each AS is identified by a unique, globally recognized Autonomous System Number (ASN).

BGP

Border Gateway Protocol is the path vector routing protocol used to exchange routing information between autonomous systems (AS) on the Internet. It determines the best path for data packets based on policies and attributes, ensuring efficient and reliable internet routing. BGP is essential for global network connectivity.

CompTIA A+ Certification Exam Core 2 (220-1102)

View All →

Acceptable Use Policy (AUP)

An Acceptable Use Policy (AUP) is a set of rules applied by the owner or administrator of a network or service that restricts the ways in which the network may be used. It outlines prohibited activities and the consequences of violations.

Active Directory

Active Directory is Microsoft’s directory service that manages users, computers, and other network resources in a Windows domain environment. It centralizes authentication, authorization, and policy enforcement, simplifying administration and enhancing security across the network.

Antivirus

Antivirus software safeguards systems by identifying, preventing, and removing malicious software like viruses, worms, and Trojans. Modern solutions utilize signature-based detection alongside heuristic analysis and behavioral monitoring to combat evolving threats. Regular updates are crucial for maintaining effectiveness against new malware.

Bandwidth

Bandwidth represents the data transfer capacity of a network connection, measured in bits per second (bps). It defines the maximum rate at which data can be transmitted. Higher bandwidth enables faster data transfer speeds and supports more simultaneous network activity. It is not a measure of speed itself.

bash (Bourne Again Shell)

bash (Bourne Again Shell) is the default command-line interpreter and shell for most Linux distributions. It allows users to interact with the operating system by typing commands, executing scripts, and managing files via a text-based interface.

BIOS

BIOS (Basic Input/Output System) is firmware pre-installed on the motherboard. It initializes hardware during the boot process, performs a Power-On Self-Test (POST), and loads the operating system. Modern systems increasingly utilize UEFI, a more advanced successor to BIOS, offering enhanced features and security.

ISTQB Certified Tester Foundation Level (CTFL-v4.0)

View All →

2-Value Boundary Value Analysis

2-Value Boundary Value Analysis is an approach where two values are tested for each boundary: the boundary value itself and the closest value immediately adjacent to the boundary in the neighboring partition.

Absence-of-Errors Fallacy

The Absence-of-Errors Fallacy is the incorrect belief that finding and fixing a large number of defects will ensure the success of a system. Even if software is 100% defect-free, it may still fail if it does not meet the users' needs and expectations.

Acceptance Testing

Acceptance Testing is formal testing conducted to determine whether a system satisfies its acceptance criteria and to enable the customer or user to decide whether to accept the system. It focuses on validating that the software meets business needs and is ready for deployment.

Action (Decision Table)

An Action is the expected output or behavior triggered by a specific combination of conditions in a decision table. Actions are listed in the bottom half of the table and dictate what the system must do when a rule is met.

Agile Software Development

Agile Software Development is a group of iterative and incremental methodologies focused on flexibility, continuous improvement, and rapid delivery of working software. It relies on cross-functional teams, close collaboration with stakeholders, and adaptability to changing requirements.

Anomaly

Any condition that deviates from expectation based on requirements specifications, design documents, user documents, standards, or from someone's perception or experience.

Microsoft 365 Administrator (MS-102)

View All →

Access Packages

Access packages are bundles of resources, including group memberships, applications, and SharePoint sites, that can be assigned to users. They enable a self-service request process for access, often integrated with an approval workflow to maintain strict security boundaries.

App Protection Policies (MAM)

App Protection Policies, often referred to as Mobile Application Management (MAM), allow administrators to manage and protect organizational data within specific apps without requiring full device enrollment. These policies prevent data leakage by controlling actions like copy-pasting between corporate and personal applications.

Co-management

Co-management is a management state where Windows 10/11 devices are managed by both Microsoft Configuration Manager and Microsoft Intune. This allows organizations to transition workloads, such as compliance policies or app deployment, from on-premises management to the cloud.

Communication Compliance

Communication Compliance is a tool within Microsoft Purview that monitors internal and external communications for policy violations. It identifies inappropriate content, harassment, or sensitive data leaks across Teams, Exchange, and Viva Engage to maintain a professional and safe workplace.

Compliance Manager

Compliance Manager is a tool within the Microsoft Purview compliance portal that helps organizations track and improve their regulatory compliance posture. It provides a compliance score and a list of actionable recommendations to meet specific legal or industry standards.

Compliance Policies (Intune)

Compliance Policies are rules defined in Microsoft Intune that determine whether a device is compliant based on specific security settings. Non-compliant devices can be blocked from accessing corporate resources via integration with Conditional Access.

Microsoft Azure Fundamentals (AZ-900)

View All →

Agility

Agility in cloud computing is the ability to rapidly develop, test, and deploy applications to respond quickly to market changes. It is enabled by the speed at which virtual resources can be provisioned compared to traditional physical hardware procurement.

Availability Zones

Availability Zones are physically separate locations within an Azure region, each with independent power, networking, and cooling. Deploying applications across multiple zones enhances fault tolerance and ensures high availability, minimizing downtime during localized failures.

Azure Active Directory (Azure AD)

Azure Active Directory is Microsoft’s cloud-based identity and access management (IAM) service. It provides authentication, authorization, and user management for Azure resources and cloud applications, supporting single sign-on (SSO) and multi-factor authentication (MFA) for enhanced security.

Azure Active Directory Domain Services (Azure AD DS)

A fully managed domain service that provides domain join capabilities for VMs in Azure.

Azure Active Directory (Entra ID)

Azure Active Directory (Entra ID) is Microsoft’s cloud-based identity and access management service. It provides authentication, authorization, and user management for accessing Azure resources, Microsoft 365 applications, and other cloud services, enabling single sign-on and multi-factor authentication.

Azure Advisor

Azure Advisor analyzes your Azure configuration and resource usage to provide personalized recommendations. These recommendations span cost optimization, security hardening, high availability improvements, performance enhancements, and operational excellence best practices, helping you align with Azure’s well-architected framework.

AWS Certified Cloud Practitioner (CLF-C02)

View All →

Amazon AppStream 2.0

Amazon AppStream 2.0 is a fully managed non-persistent application streaming service that allows users to access desktop applications through a web browser. It streams the application interface to the user without installing software locally.

Amazon Aurora

Amazon Aurora is a MySQL and PostgreSQL-compatible relational database engine built for the cloud. It provides the performance and availability of high-end commercial databases with the simplicity and cost-effectiveness of open-source databases, featuring automatic scaling and replication.

Amazon Bedrock

Amazon Bedrock is a fully managed service that makes foundation models (FMs) from leading AI companies available via an API. It allows developers to build and scale generative AI applications without managing the underlying infrastructure.

Amazon CloudFront

Amazon CloudFront is a globally distributed content delivery network (CDN) service designed to accelerate the delivery of static and dynamic web content. It caches data at strategically located edge locations, reducing latency and improving performance for end-users worldwide, enhancing application responsiveness.

Amazon CloudWatch

Amazon CloudWatch is a monitoring and observability service providing metrics, logs, and alarms for AWS resources and applications. It enables real-time monitoring of performance, resource utilization, and operational health, facilitating proactive identification and resolution of issues within the AWS environment.

Amazon Cognito

Amazon Cognito provides authentication, authorization, and user management for web and mobile applications. It allows users to sign in using a password or social identity providers and manages user profiles and access tokens.

AWS Certified Solutions Architect - Associate (SAA-C03)

View All →

Amazon API Gateway

Amazon API Gateway is a fully managed service enabling developers to create, publish, maintain, monitor, and secure APIs at any scale. It handles tasks like authentication, authorization, request validation, and traffic management, simplifying API development and deployment for microservices and serverless applications.

Amazon Athena

Amazon Athena is an interactive query service enabling analysis of data directly in Amazon S3 using standard SQL. It is serverless, meaning no infrastructure is required, and you pay only for the data scanned during query execution, making it cost-effective for ad-hoc analysis of large datasets.

Amazon Aurora

Amazon Aurora is a MySQL and PostgreSQL-compatible relational database engineered for high performance and availability. It delivers up to five times the throughput of standard MySQL while offering full compatibility with existing database applications. Aurora automatically scales storage and provides point-in-time recovery.

Amazon CloudFront

Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to users globally with low latency. It leverages a global network of edge locations to cache content closer to the end-user.

Amazon CloudWatch

Amazon CloudWatch is a monitoring and observability service providing metrics, logs, and events for AWS resources and applications. It enables real-time monitoring, automated actions, and anomaly detection to optimize performance and troubleshoot issues.

Amazon Cognito

Amazon Cognito delivers secure user authentication, authorization, and management for web and mobile applications. It offers User Pools for managing user directories and Identity Pools for granting access to AWS resources. Cognito simplifies user sign-up, sign-in, and provides integration with social identity providers like Google and Facebook.

ISC2 CCSP Certification Exam (CCSP)

View All →

API Gateway

An API Gateway is a management tool that sits between a client and a collection of backend services, acting as a single entry point for API requests. It handles critical functions such as request routing, protocol translation, rate limiting, authentication, and monitoring to ensure secure and scalable API consumption.

Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is an authorization model that grants access rights based on a combination of attributes. These attributes can include user characteristics, resource properties, and environmental conditions, providing more granular control than traditional role-based systems.

Block Storage

Block storage is a data storage architecture that breaks data into evenly sized blocks, each with its own unique address. It is primarily used for high-performance applications like databases and virtual machine disks because it allows for low-latency access and efficient modification of specific data chunks.

Bring Your Own Key (BYOK)

Bring Your Own Key (BYOK) is a cloud security model where the customer generates and manages their own cryptographic keys rather than relying on keys generated by the cloud service provider. This provides the customer with greater control over data access and key rotation.

Business Continuity Planning (BCP)

Business Continuity Planning (BCP) is the process of creating systems of prevention and recovery to ensure that essential business functions continue during and after a disaster. In the cloud, BCP focuses on redundancy, failover mechanisms, and geographical distribution to maintain high availability.

Cloud Bursting

Cloud Bursting is a configuration where an application runs in a private cloud or data center and 'bursts' into a public cloud when demand for computing capacity spikes. This allows organizations to handle peak loads without investing in permanent on-premises hardware.

CompTIA PenTest+ Certification Exam (PT0-002)

View All →

Adversary Emulation

Adversary Emulation is the practice of simulating the specific tactics, techniques, and procedures (TTPs) of a known threat actor to test a network's defenses. It differs from general penetration testing by focusing on realistic, threat-informed scenarios.

Air Gap

An Air Gap is a security measure that ensures a computer or network is physically isolated from all other networks, including the public internet. This is typically used for high-security systems, such as those controlling nuclear power plants or classified government databases.

ARP Poisoning

ARP Poisoning is a technique used to associate an attacker's MAC address with the IP address of another host, such as the default gateway. This enables the attacker to intercept, modify, or stop traffic flowing between two devices on a local area network.

Attack Surface

The attack surface is the total sum of all possible points, known as attack vectors, where an unauthorized user can attempt to enter or extract data from an environment. Reducing the attack surface involves disabling unused services, closing unnecessary ports, and limiting user permissions.

Authenticated Vulnerability Scan

An Authenticated Vulnerability Scan is a security assessment where the scanner is provided with valid credentials to access the target system. This allows the scanner to identify internal vulnerabilities, missing patches, and configuration issues that are invisible from the network perimeter.

Baiting

Baiting is a social engineering technique that promises a reward to lure a victim into a trap, such as leaving a malware-infected USB drive in a public area. The attacker relies on the victim's curiosity or greed to prompt them to plug the device in.

CompTIA CASP+ Certification Exam (CAS-004)

View All →

Address Space Layout Randomization (ASLR)

Address Space Layout Randomization (ASLR) is a security technique that randomly arranges the address space positions of key data areas of a process. This makes it difficult for an attacker to predict the memory address of specific functions or libraries, hindering the success of exploit code.

Air Gap

Air Gap is a security measure that ensures a computer or network is physically isolated from all other networks, including the internet. This creates a physical barrier that prevents remote attacks, making it essential for highly sensitive systems like industrial control systems.

API Gateway

An API Gateway is a management tool that sits between a client and a collection of backend services, acting as a reverse proxy to route requests and enforce security policies. It provides centralized functions like rate limiting, authentication, and protocol translation for microservices.

Attestation

Attestation is the process by which a system proves its identity and integrity to another system or entity, often using a hardware root of trust. It provides a cryptographically signed statement of the system's current state, ensuring the boot process and software have not been tampered with.

Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is an authorization model that grants access rights to users based on a combination of attributes. These attributes can include user characteristics, resource properties, environmental conditions, and specific action types, offering more granularity than RBAC.

Biba Integrity Model

Biba Integrity Model is a formal state transition model of computer security policy that focuses on maintaining data integrity. It operates on the principle of 'no write up, no read down,' preventing unauthorized users from modifying high-integrity data and preventing high-integrity subjects from reading low-integrity data.

CompTIA CySA+ Certification Exam (CS0-003)

View All →

Address Space Layout Randomization (ASLR)

Address Space Layout Randomization (ASLR) is a security technique that randomly arranges the address space positions of key data areas of a process. This makes it difficult for an attacker to predict the memory address of specific functions or libraries. It effectively mitigates the reliability of memory-based exploits.

Agent-based Scanning

Agent-based Scanning is a vulnerability management approach where software agents are installed locally on endpoints to perform security assessments. This method provides deeper visibility into the system and eliminates the need for open network ports or credential management required by remote scanners.

Air Gapping

Air Gapping is a security measure that ensures a computer or network is physically isolated from all other networks, including the public internet. This creates a physical barrier that prevents remote hacking attempts and unauthorized data exfiltration.

Attack Surface

Attack Surface refers to the total sum of all possible points, or vectors, where an unauthorized user can try to enter data to or extract data from an environment. Reducing the attack surface involves disabling unnecessary services and closing unused ports.

Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is a flexible access control model that grants access based on attributes of the user, the resource, and the environment. It uses policies that combine these attributes to make fine-grained authorization decisions in real-time.

Baseline

A Baseline is a documented set of performance and configuration metrics that represent the normal state of a system or network. Analysts use baselines to identify anomalies, which may indicate a security breach, misconfiguration, or system failure.