CompTIA Acronyms A–Z

120 acronyms from the CompTIA A+, Network+ and Security+ objective lists, with plain-English definitions. Study them as flashcards in the app.

Study these as flashcards ✨
AAA
Authentication, Authorization, and Accounting - A framework for intelligently controlling access to computer resources, enforcing policies, auditing usage, and providing the information necessary to bill for services.
AES
Advanced Encryption Standard - A symmetric encryption algorithm widely used to secure sensitive data.
APIPA
Automatic Private IP Addressing - A feature in operating systems that enables computers to automatically self-configure an IP address.
APT
Advanced Persistent Threat - A stealthy threat actor, typically a nation-state or state-sponsored group, which gains unauthorized access to a network.
ARP
Address Resolution Protocol - A communication protocol used for discovering the link layer address, such as a MAC address.
AUP
Acceptable Use Policy - A document stipulating constraints and practices that a user must agree to for access to a corporate network or the internet.
BCP
Business Continuity Plan - A document that consists of the critical information an organization needs to continue operating during an unplanned event.
BGP
Border Gateway Protocol - A standardized exterior gateway protocol designed to exchange routing and reachability information among autonomous systems.
BIA
Business Impact Analysis - A systematic process to determine and evaluate the potential effects of an interruption to critical business operations.
BIOS
Basic Input/Output System - Firmware used to perform hardware initialization during the booting process.
BYOD
Bring Your Own Device - A policy that allows employees to bring their own personal mobile devices to work.
CA
Certificate Authority - An entity that issues digital certificates.
CIA Triad
Confidentiality, Integrity, Availability - The three core principles of information security.
CPU
Central Processing Unit - The primary component of a computer that acts as its processing core.
CSIRT
Computer Security Incident Response Team - A group of experts that handles security incidents.
CSR
Certificate Signing Request - A message sent from an applicant to a certificate authority in order to apply for a digital identity certificate.
CTI
Cyber Threat Intelligence - Information describing threats and threat actors that helps mitigate a cyberattack.
CVE
Common Vulnerabilities and Exposures - A list of entries for publicly known cybersecurity vulnerabilities.
CVSS
Common Vulnerability Scoring System - An industry standard for assessing the severity of computer system security vulnerabilities.
CWE
Common Weakness Enumeration - A category system for software weaknesses and vulnerabilities.
DAM
Database Activity Monitoring - A database security technology for monitoring and analyzing database activity.
DDoS
Distributed Denial of Service - A cyberattack where multiple compromised systems attack a target to cause a denial of service.
DHCP
Dynamic Host Configuration Protocol - A network management protocol used to automatically assign IP addresses to devices.
DIMM
Dual Inline Memory Module - A module that contains one or several random access memory (RAM) chips.
DLP
Data Loss Prevention - A set of tools and processes used to ensure that sensitive data is not lost, misused, or accessed by unauthorized users.
DMZ
Demilitarized Zone - A physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network.
DNS
Domain Name System - The phonebook of the internet, translating domain names (like google.com) to IP addresses.
DRM
Digital Rights Management - A set of access control technologies for restricting the use of proprietary hardware and copyrighted works.
DRP
Disaster Recovery Plan - A documented process or set of procedures to execute an organization's disaster recovery processes and recover and protect a business IT infrastructure.
DVI
Digital Visual Interface - A video display interface developed by the Digital Display Working Group.
EAP
Extensible Authentication Protocol - An authentication framework frequently used in network and internet connections.
ECC
Error Correction Code - A type of data storage that uses an algorithm to detect and correct single-bit errors.
EDR
Endpoint Detection and Response - A cyber technology that monitors and responds to cyber threats.
EIGRP
Enhanced Interior Gateway Routing Protocol - An advanced distance-vector routing protocol that is used on a computer network for automating routing decisions and configuration.
FIM
File Integrity Monitoring - An internal control or process that validates the integrity of operating system and application software files.
FTP
File Transfer Protocol - Standard network protocol used for the transfer of computer files between a client and server.
GDPR
General Data Protection Regulation - A legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union.
GPU
Graphics Processing Unit - Specialized electronic circuit designed to manipulate and alter memory to accelerate the creation of images.
GRC
Governance, Risk, and Compliance - A strategy for managing an organization's overall governance, enterprise risk management and compliance with regulations.
HDMI
High-Definition Multimedia Interface - A proprietary audio/video interface for transmitting uncompressed video data.
HIDS
Host-based Intrusion Detection System - An intrusion detection system that monitors and analyzes the internals of a computing system.
HIPAA
Health Insurance Portability and Accountability Act - A US law designed to provide privacy standards to protect patients' medical records and other health information.
HOTP
HMAC-based One-Time Password - An OTP algorithm based on the HMAC algorithm.
HSM
Hardware Security Module - A physical computing device that safeguards and manages digital keys for strong authentication and provides crypto-processing.
HTTP
Hypertext Transfer Protocol - An application protocol for distributed, collaborative, hypermedia information systems.
HTTPS
Hypertext Transfer Protocol Secure - An extension of HTTP that is used for secure communication over a computer network.
IDS
Intrusion Detection System - A device or software application that monitors a network or systems for malicious activity or policy violations.
IOC
Indicator of Compromise - Forensic evidence on a device or network that suggests a security breach has occurred.
IP
Internet Protocol - The principal communications protocol in the Internet protocol suite for relaying datagrams across network boundaries.
IPS
Intrusion Prevention System - A network security/threat prevention technology that examines network traffic flows to detect and prevent vulnerability exploits.
IPv4
Internet Protocol version 4 - The fourth version of the Internet Protocol, using 32-bit addresses.
IPv6
Internet Protocol version 6 - The most recent version of the Internet Protocol, using 128-bit addresses.
ISO
International Organization for Standardization - An international standard-setting body composed of representatives from various national standards organizations.
LAN
Local Area Network - A computer network that interconnects computers within a limited area.
MAC
Media Access Control - A unique identifier assigned to a network interface controller (NIC) for use as a network address.
MAN
Metropolitan Area Network - A computer network that interconnects users with computer resources in a geographic region of the size of a metropolitan area.
MDM
Mobile Device Management - An industry term for the administration of mobile devices.
MFA
Multi-Factor Authentication - An electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more pieces of evidence.
MOA
Memorandum of Agreement - A document written between parties to cooperatively work together on an agreed upon project or meet an agreed upon objective.
MOU
Memorandum of Understanding - A type of agreement between two or more (bilateral/multilateral) parties.
MTTR
Mean Time To Repair - The average time required to repair a failed component or device.
NAS
Network Attached Storage - A file-level computer data storage server connected to a computer network.
NAT
Network Address Translation - A method of mapping an IP address space into another by modifying network address information.
NDA
Non-Disclosure Agreement - A legal contract between at least two parties that outlines confidential material, knowledge, or information that the parties wish to share with one another for certain purposes.
NFC
Near Field Communication - A set of communication protocols that enable two electronic devices to establish communication within 4 cm.
NGFW
Next-Generation Firewall - A part of the third generation of firewall technology, combining a traditional firewall with other network device filtering functions.
NIDS
Network Intrusion Detection System - An intrusion detection system that attempts to detect hacking activities, denial of service attacks or port scans on a computer network.
NIST
National Institute of Standards and Technology - A non-regulatory government agency that produces standards and guidelines.
NOC
Network Operations Center - A centralized location where IT technicians can directly support the efforts of remote monitoring and management (RMM) software.
NVMe
Non-Volatile Memory Express - Interface specification for accessing computer non-volatile storage media attached via PCI Express.
OSI Model
Open Systems Interconnection Model - A conceptual framework used to describe the functions of a networking system (7 layers).
OSINT
Open-Source Intelligence - Data collected from publicly available sources to be used in an intelligence context.
OSPF
Open Shortest Path First - A routing protocol for Internet Protocol networks; it uses a link state routing algorithm.
OWASP
Open Web Application Security Project - An online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security.
PAN
Personal Area Network - A computer network for interconnecting electronic devices within an individual person's workspace.
PAT
Port Address Translation - An extension to network address translation that permits multiple devices on a LAN to be mapped to a single public IP address.
PCI DSS
Payment Card Industry Data Security Standard - An information security standard for organizations that handle branded credit cards.
PKI
Public Key Infrastructure - A set of roles, policies, and hardware/software needed to create, manage, and revoke digital certificates.
POE
Power over Ethernet - A technology for wired Ethernet LANs that allows the electrical current necessary for the operation of each device to be carried by the data cables.
POST
Power-On Self-Test - Diagnostic testing sequence that a computer's firmware executes before the OS runs.
PSU
Power Supply Unit - Hardware component that supplies power to an electrical device.
QoS
Quality of Service - The description or measurement of the overall performance of a service, particularly the performance seen by the users of the network.
RADIUS
Remote Authentication Dial-In User Service - A networking protocol that provides centralized Authentication, Authorization, and Accounting management.
RAID
Redundant Array of Independent Disks - A data storage virtualization technology that combines multiple physical disk drive components.
RAM
Random Access Memory - Volatile memory used for temporary storage while the computer is running.
RFID
Radio Frequency Identification - Uses electromagnetic fields to automatically identify and track tags attached to objects.
RIP
Routing Information Protocol - One of the oldest distance-vector routing protocols which employs the hop count as a routing metric.
ROE
Rules of Engagement - Internal rules or directives among military forces (also used in Pen Testing) that define the circumstances, conditions, degree, and manner in which the use of force, or actions, may be applied.
RPO
Recovery Point Objective - The maximum acceptable amount of data loss measured in time.
RTO
Recovery Time Objective - The targeted duration of time and a service level within which a business process must be restored.
SAN
Storage Area Network - A specialized, high-speed network that provides block-level network access to storage.
SATA
Serial AT Attachment - Bus interface that connects host bus adapters to mass storage devices.
SCAP
Security Content Automation Protocol - A method for using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation.
SIEM
Security Information and Event Management - A solution that provides real-time analysis of security alerts generated by applications and hardware.
SLA
Service Level Agreement - A commitment between a service provider and a client.
SOAR
Security Orchestration, Automation, and Response - Technologies that enable organizations to collect inputs and automate security responses.
SOC
Security Operations Center - A centralized unit that deals with security issues on an organizational and technical level.
SODIMM
Small Outline Dual Inline Memory Module - A smaller alternative to a DIMM, roughly half the size, often used in laptops.
SSD
Solid State Drive - A storage device that uses flash memory to store data, offering faster speeds than traditional HDDs.
SSH
Secure Shell - A cryptographic network protocol for operating network services securely over an unsecured network.
STIX
Structured Threat Information eXpression - A language and serialization format used to exchange cyber threat intelligence.
STP
Spanning Tree Protocol - A network protocol that builds a logical loop-free topology for Ethernet networks.
TACACS+
Terminal Access Controller Access-Control System Plus - A separate protocol that handles authentication, authorization, and accounting services.
TAXII
Trusted Automated eXchange of Indicator Information - An application layer protocol for the communication of cyber threat information in a simple and scalable manner.
TCP
Transmission Control Protocol - A standard that defines how to establish and maintain a network conversation via which application programs can exchange data.
TOTP
Time-based One-Time Password - A computer algorithm that generates a one-time password (OTP) that uses the current time as a source of uniqueness.
TPM
Trusted Platform Module - A specialized chip on an endpoint device that stores RSA encryption keys specific to the host system for hardware authentication.
TTP
Tactics, Techniques, and Procedures - Describes the behavior of a threat actor.
UBA
User Behavior Analytics - A cybersecurity process about detection of insider threats, targeted attacks, and financial fraud.
UDP
User Datagram Protocol - A communications protocol that is primarily used for establishing low-latency and loss-tolerating connections.
UEBA
User and Entity Behavior Analytics - An extension of UBA that also tracks devices and other entities.
UEFI
Unified Extensible Firmware Interface - A modern replacement for BIOS that supports larger hard drives and faster boot times.
USB
Universal Serial Bus - An industry standard that establishes specifications for cables, connectors and protocols.
VGA
Video Graphics Array - A standard analog computer display standard.
VLAN
Virtual Local Area Network - A logical subnetwork that groups a collection of devices from different physical LANs.
VPN
Virtual Private Network - Extends a private network across a public network and enables users to send and receive data across shared or public networks.
WAF
Web Application Firewall - A specific form of application firewall that filters, monitors, and blocks HTTP traffic to and from a web service.
WAN
Wide Area Network - A telecommunications network that extends over a large geographical area.
WPA
Wi-Fi Protected Access - A security standard for users of computers equipped with Wi-Fi wireless connections.
XDR
Extended Detection and Response - A SaaS-based, vendor-specific, security threat detection and incident response tool that integrates multiple security products into a cohesive security operations system.