Glossary
CySA+ 略語辞書(106語)
CompTIA CySA+ で押さえておきたい用語・略語を、正式名称・日本語訳・解説つきでまとめました。アプリでは、問題文中の略語をタップするとこの辞書がその場で開きます。
A
- APT高度で持続的な脅威Advanced Persistent Threat
- ATT&CK攻撃者の戦術・技術のナレッジベースMITRE ATT&CK
- AV資産価値/アンチウイルスAsset Value(リスク計算) / Antivirus
B
- BAS侵害・攻撃シミュレーションBreach and Attack Simulation
- Beaconingビーコン通信Beaconing
- BECビジネスメール詐欺Business Email Compromise
- Burp SuiteWebアプリケーション検査ツールBurp Suite (web application security testing tool)
C
- C2指令・制御(C&C)Command and Control
- CASBクラウドアクセスセキュリティブローカーCloud Access Security Broker
- Chain of Custody管理の連鎖(証拠の受け渡し記録)Chain of Custody
- CI/CD継続的インテグレーション/デリバリーContinuous Integration / Continuous Delivery
- CSRFクロスサイトリクエストフォージェリCross-Site Request Forgery
- CTIサイバー脅威インテリジェンスCyber Threat Intelligence
- CVE共通脆弱性識別子Common Vulnerabilities and Exposures
- CVSS共通脆弱性評価システムCommon Vulnerability Scoring System
- Cyber Kill ChainサイバーキルチェーンLockheed Martin Cyber Kill Chain
- CyberChefデータ変換・デコードツールCyberChef (data encoding and decoding tool)
D
- DAST動的アプリケーションセキュリティテストDynamic Application Security Testing
- Data Poisoningデータポイズニング(学習データ汚染)Data Poisoning
- DDoS分散型サービス妨害攻撃Distributed Denial of Service
- Diamond Modelダイヤモンドモデル(侵入分析モデル)Diamond Model of Intrusion Analysis
- DKIMドメイン認証署名DomainKeys Identified Mail
- DLP情報漏えい防止Data Loss Prevention
- DMARCドメインベースのメール認証・報告Domain-based Message Authentication, Reporting and Conformance
- DMZ非武装地帯Demilitarized Zone
E
- EDRエンドポイントでの検知と対応Endpoint Detection and Response
- EPSS悪用予測スコアリングシステムExploit Prediction Scoring System
- EVTXWindowsイベントログファイルWindows XML Event Log (.evtx)
H
I
- IaaSインフラストラクチャ・アズ・ア・サービスInfrastructure as a Service
- IaCコードによるインフラ管理Infrastructure as Code
- ICS産業制御システムIndustrial Control System
- IDS侵入検知システムIntrusion Detection System
- Impossible Travel不可能な移動(ありえない移動)Impossible Travel
- IoC侵害の痕跡Indicator of Compromise
- IPS侵入防止システムIntrusion Prevention System
- ISAC情報共有分析センターInformation Sharing and Analysis Center
K
L
- Legal Hold訴訟ホールド(法的保全)Legal Hold (Litigation Hold)
- LOLBin環境寄生型の正規ツール(悪用されるOS標準プログラム)Living Off the Land Binary
M
- MDMモバイルデバイス管理Mobile Device Management
- MetasploitエクスプロイトフレームワークMetasploit Framework (exploitation framework)
- MFA多要素認証Multi-Factor Authentication
- MISPオープンソースの脅威情報共有プラットフォームMalware Information Sharing Platform
- MOU覚書Memorandum of Understanding
- MTTC平均封じ込め時間Mean Time to Contain
- MTTD平均検知時間Mean Time to Detect
- MTTR平均修復時間Mean Time To Repair / Recover
N
- NACネットワークアクセス制御Network Access Control
- Nessus脆弱性スキャナーNessus (vulnerability scanner)
- NetFlowネットワークフロー情報NetFlow (network flow records)
- NGFW次世代ファイアウォールNext-Generation Firewall
- Nmapネットワーク・ポートスキャナーNmap (network scanner)
- NTPネットワーク時刻同期プロトコルNetwork Time Protocol
O
P
- PaaSプラットフォーム・アズ・ア・サービスPlatform as a Service
- PAM特権アクセス管理Privileged Access Management
- PCAPパケットキャプチャPacket Capture
- PCI DSSクレジットカード業界のデータセキュリティ基準Payment Card Industry Data Security Standard
- Playbookプレイブック(インシデント対応手順書)Incident Response Playbook
- Prompt InjectionプロンプトインジェクションPrompt Injection
- Pyramid of Pain痛みのピラミッドPyramid of Pain
R
S
- SaaSソフトウェア・アズ・ア・サービスSoftware as a Service
- SAMMソフトウェアセキュリティ保証成熟度モデルOWASP Software Assurance Maturity Model
- Sandboxサンドボックス(隔離実行環境)Sandbox
- SASEセキュアアクセスサービスエッジSecure Access Service Edge
- SAST静的アプリケーションセキュリティテストStatic Application Security Testing
- SBOMソフトウェア部品表Software Bill of Materials
- SCAソフトウェア構成分析Software Composition Analysis
- SCADA監視制御・データ収集システムSupervisory Control and Data Acquisition
- SHAセキュアハッシュアルゴリズムSecure Hash Algorithm
- SIEMセキュリティ情報・イベント管理Security Information and Event Management
- SLAサービスレベル合意Service Level Agreement
- SLOサービスレベル目標Service Level Objective
- SOARセキュリティのオーケストレーション・自動化・対応Security Orchestration, Automation and Response
- SOCセキュリティ監視センターSecurity Operations Center
- SPF送信者ポリシーフレームワークSender Policy Framework
- SQLiSQLインジェクションSQL Injection
- SSOシングルサインオンSingle Sign-On
- SSRFサーバーサイドリクエストフォージェリServer-Side Request Forgery
- STIX脅威情報の構造化記述形式Structured Threat Information eXpression
- STRIDESTRIDE脅威モデル(脅威の6分類)Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege
T
- Tabletop Exercise机上演習Tabletop Exercise
- TAXII脅威情報の自動交換プロトコルTrusted Automated eXchange of Intelligence Information
- Threat Hunting脅威ハンティングThreat Hunting
- TLPトラフィックライトプロトコル(情報共有範囲の表示)Traffic Light Protocol
- TLSトランスポート層セキュリティTransport Layer Security
- TTP戦術・技術・手順Tactics, Techniques, and Procedures
- TyposquattingタイポスクワッティングTyposquatting
U
V
- VirusTotalファイル・URLの多エンジン検査サービスVirusTotal (online malware scanning service)
- VLAN仮想LANVirtual Local Area Network
- VPN仮想プライベートネットワークVirtual Private Network
W
- WAFWebアプリケーションファイアウォールWeb Application Firewall
- Wiresharkパケットキャプチャ・解析ツールWireshark (network protocol analyzer)
X
Y
Z
- Zeekネットワーク監視・ログ生成ツール(旧称Bro)Zeek (network security monitoring tool)
- ZTNAゼロトラストネットワークアクセスZero Trust Network Access
広告
略語を覚えたら、問題で確認しましょう。
無料で演習を始める