Term 511
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
Acronym study
Terms 511–540 of 1222 SK0-005 acronyms and key terms. Each entry includes a plain-English definition and a link to the full 800-word glossary page with exam context and practice questions.
Term 511
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
Term 512
Image scanning is the automated process of inspecting container images for known vulnerabilities, misconfigurations, and malware before they are deployed into production environments.
Term 513
IMAP is an email retrieval protocol that keeps messages on the server, enabling access from multiple devices with synchronized state.
Term 514
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Term 515
Impersonation is a security attack where an attacker pretends to be a legitimate person or system to gain unauthorized access, steal data, or commit fraud.
Term 516
Implicit deny is a security rule that automatically blocks any network traffic that is not explicitly allowed by an access control list or firewall rule.
Term 517
Incident documentation is the practice of recording every detail of a cybersecurity or IT incident, from detection to resolution, to ensure accurate analysis, legal compliance, and process improvement.
Term 518
Incident management is the process of identifying, logging, prioritizing, and resolving IT service disruptions to restore normal operations as quickly as possible with minimal business impact.
Term 519
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Term 520
Incident severity is a classification used in IT incident management to describe the level of impact and urgency of an event, guiding response priority.
Term 521
An indicator of compromise is a piece of digital evidence—such as a suspicious file hash, IP address, or unusual network pattern—that suggests a system may have been breached by an attacker.
Term 522
Information security management is the systematic process of developing, implementing, monitoring, and improving policies, procedures, and controls to protect an organization's information assets from threats and ensure confidentiality, integrity, and availability.
Term 523
Infrastructure as code scanning is the automated process of checking infrastructure configuration files for security misconfigurations, compliance violations, and potential vulnerabilities before deployment.
Term 524
Inherent risk is the level of risk that exists in a process or system before any security controls or mitigations are applied.
Term 525
An application security vulnerability that occurs when untrusted user data is deserialized without proper validation, potentially allowing an attacker to manipulate the application or execute malicious code.
Term 526
Insider Risk Management is the practice of identifying, assessing, and mitigating threats that originate from within an organization, such as employees, contractors, or partners who have legitimate access to systems and data.
Term 527
insmod is a Linux command used to insert a kernel module into the running Linux kernel without resolving dependencies.
Term 528
An inspector is a tool or role that checks systems, configurations, or data against a set of rules to ensure they are secure and compliant.
Term 529
Instance store is temporary, block-level storage physically attached to a cloud virtual machine that provides high performance but loses all data when the instance is stopped or terminated.
Term 530
An instance type is a specific configuration of virtual hardware resources, like CPU, memory, and storage, offered by AWS for running a virtual server in the cloud.
Term 531
The International Organization for Standardization, or ISO, is an independent global body that creates and publishes voluntary standards to ensure quality, safety, and efficiency in products, services, and systems across many industries, including IT.
Term 532
The Internet is a global network of interconnected computers that communicate using standardized protocols to share information and services.
Term 533
IGMP is a communication protocol used by devices on a network to report their membership in multicast groups to nearby routers, enabling efficient group data delivery.
Term 534
Internet Mail Access Protocol (IMAP) is a standard email protocol that lets you read and manage emails stored on a mail server from multiple devices, keeping everything synchronized.
Term 535
Internet Protocol Address Management (IPAM) is the practice of planning, tracking, and managing the assignment and use of IP addresses on a network to ensure devices can communicate without conflict.
Term 536
Internet Protocol Security (IPsec) is a suite of protocols that encrypts and authenticates data packets sent over IP networks to ensure private and secure communication.
Term 537
An Intrusion Detection System (IDS) is a security tool that monitors network traffic or system activities for malicious actions or policy violations and sends alerts to administrators.
Term 538
An Intrusion Prevention System (IPS) is a network security tool that monitors network traffic and actively blocks threats like malware and cyberattacks in real time.
Term 539
Inventory management is the process of tracking, organizing, and maintaining records of all hardware, software, licenses, and digital assets an organization owns, ensuring availability and compliance.
Term 540
IOA (Indicator of Attack) is a security concept that focuses on detecting the intent and sequence of actions leading up to a cyber attack, rather than just the artifacts left behind after a breach.