LF11bV2 Deck 4 Flashcards

Betrieb und Sicherheit vernetzter Systeme gewährleisten (51 cards)

1
Q

Asymmetrische Verschlüsselung

A

Public Key + Private Key Paar Daten mit Public Key verschlüsselt nur Private Key entschlüsselt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Symmetrische Verschlüsselung

A

Ein Schlüssel für Verschlüsselung und Entschlüsselung AES 256 Bit schneller als Asymmetrie

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Public Key Infrastructure

A

PKI CA Zertifikate Schlüsselpaare Vertrauensanker für asymmetrische Krypto

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Certificate Authority

A

CA stellt digitale Zertifikate aus bindet Public Key an Identität

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

X.509 Zertifikat

A

Standardformat Public Key + Identität + Gültigkeitsdauer + Signatur CA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

SSL Secure Sockets Layer

A

Veraltetes Protokoll TLS-Vorgänger nicht mehr sicher

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TLS Transport Layer Security

A

Nachfolger SSL Verschlüsselung Authentifizierung Integrität Layer 6 OSI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

TLS Handshake

A

ClientHello ServerHello Zertifikat-Austausch Key Agreement Session Keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Perfect Forward Secrecy

A

PFS Ephemeral Keys Kompromittierung langer Session-Keys gefährdet nicht vergangene

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Diffie-Hellman Key Exchange

A

DH Schlüsselvereinbarung über unsicheren Kanal ohne direkten Schlüsselaustausch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

RSA Algorithmus

A

Ron Rivest Shamir Adleman Public Key Krypto Faktorisierung großer Primzahlen

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

AES Advanced Encryption Standard

A

Rijndael Algorithmus NIST-Standard Symmetrisch 128/192/256 Bit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SSH Secure Shell

A

Verschlüsselter Remote-Zugriff Port 22 ersetzt Telnet rsh rexec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SSH Key Pair

A

Public Key auf Server Private Key lokal Passphrasenschutz

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SSH Authorized Keys

A

~/.ssh/authorized_keys Public Keys autorisierter Benutzer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SFTP Secure File Transfer

A

SSH File Transfer Protocol verschlüsselter Dateitransfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

SCP Secure Copy

A

SSH-basierter Dateikopie zwischen Hosts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

OpenSSH

A

Open Source SSH Implementierung Standard auf Linux Servern

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

SSH Port Forwarding

A

Local Remote Dynamic Tunnel über SSH-Verbindung

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

VPN Virtual Private Network

A

Verschlüsselter Tunnel über öffentliche Netze

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

IPsec Internet Protocol Security

A

Suite für Netzwerkverschlüsselung AH ESP IKE

22
Q

AH Authentication Header

A

IPsec-Protokoll Integrität Authentifizierung keine Vertraulichkeit

23
Q

ESP Encapsulating Security Payload

A

IPsec-Protokoll Verschlüsselung Integrität Authentifizierung

24
Q

IKE Internet Key Exchange

A

IPsec-Schlüsselverhandlung Phase 1/2 Diffie-Hellman

25
IPsec Security Association
SA unidirektionale Vereinbarung SPI Keys Lifetime
26
ISAKMP Internet Security Association Key Management Protocol
IKE Phase 1 Authentifizierung SA Setup
27
PSK Pre-Shared Key
Statischer gemeinsamer Schlüssel für IPsec VPN
28
Certificate-based VPN
X.509 Zertifikate für IPsec Authentifizierung PKI
29
Site-to-Site VPN
IPsec-Tunnel zwischen zwei Gateways LAN-zu-LAN
30
Remote Access VPN
IPsec SSL VPN Client-zu-Gateway einzelne User
31
GRE Generic Routing Encapsulation
IPsec-Tunnel für nicht-IP-Protokolle Multiprotokoll
32
Dead Peer Detection
IPsec DPD Überwachung Live-Status Peer Rekeying
33
NAT Traversal
IPsec NAT-T UDP-Encapsulation hinter NAT Router
34
WireGuard
Modernes VPN-Protokoll ChaCha20 Poly1305 minimaler Codebase
35
OpenVPN
Open Source VPN SSL/TLS UDP/TCP flexibel
36
L2TP Layer 2 Tunneling Protocol
VPN-Protokoll häufig mit IPsec kombiniert
37
PPTP Point-to-Point Tunneling Protocol
Veraltetes unsicheres MS VPN-Protokoll
38
SSL VPN
Browser-basiertes VPN Portal Port 443 Clientless Access
39
DTLS Datagram TLS
UDP-basierte TLS-Version für VoIP Video
40
OCSP Online Certificate Status Protocol
Revocation Check Zertifikat Gültigkeit
41
CRL Certificate Revocation List
Offline-Liste widerrufener Zertifikate
42
HSTS HTTP Strict Transport Security
HTTPS-erzwungen MitM-Schutz
43
Certificate Pinning
App bindet expected Public Key gegen CA-Kompromittierung
44
Forward Secrecy
Ephemeral Diffie-Hellman Keys vergangene Sessions sicher
45
OCSP Stapling
Server liefert OCSP-Response Client reduziert Latency
46
HPKI Host Public Key Infrastructure
SSH CA für Server-Zertifikate
47
TOFU Trust On First Use
SSH Initial Public Key akzeptieren später prüfen
48
PGP Pretty Good Privacy
E-Mail Verschlüsselung Signatur Public Key Web of Trust
49
GPG GNU Privacy Guard
Open Source PGP Implementierung Linux Standard
50
S/MIME Secure MIME
E-Mail Verschlüsselung X.509 Zertifikate PKI
51
DKIM DomainKeys Identified Mail
DKIM-Signature E-Mail Authentifizierung SPF DMARC