Module 2 Glossary: Windows Security
Welcome! This alphabetized glossary contains many of the terms used in this course. These terms are essential for working in the industry, participating in user groups,
and participating in other certificate programs.
Term Definition
Active Directory A directory service developed by Microsoft, designed to help administrators
manage user accounts, computer systems, and network resources in a centralized
way on a network.
Administrator account An account that possesses full control over domain controllers and the authority to
manage resources across the entire domain.
Antimalware Programs created to scan computer systems for malicious softwares. It protects the
information technology (IT) by preventing, detecting, and removing malware.
BitLocker A security feature that provides encryption for entire volumes.
Consent prompt A prompt that verifies an action by asking the user's permission when an action
requires administrative privileges, such as installing software, changing system
settings, or accessing certain protected areas.
Credential prompt A prompt pop-up requesting administrative credentials when a standard user
attempts an action that requires administrative privileges.
Cybersecurity Security techniques to protect individuals and enterprises against cyber threats.
The internet-connected systems can be data, hardware, and software.
Cyberthreat A potential or actual malicious attempt to disrupt, damage, or steal digital data,
applications, or systems. Cyberthreats may target vulnerabilities to compromise
confidentiality, integrity, or availability of information..
Cryptography A method of protecting information and communication using codes that can be
read and processed only by the intended person.
Decryption Converting an encrypted data into its original form.
Domain Admin A Domain Admin account holds significant authority and control within an Active
Directory domain, essentially functioning as the master key.
Electronic data processing (EDP) Methods of using automated techniques to process commercial data.
Encryption A method of encoding data that can be comprehended only by the authorized
individuals.
Encrypting File System (EFS) A technique that transparently encrypts files and folders on NTFS volumes,
protecting the sensitive information stored in them.
Guest account An account that is significantly restricted and primarily intended for temporary
user access with minimal permissions.
HelpAssistant account A specialized account that is utilized by the IT support and technical teams for
remote assistance.
Internet Engineering Task Force (IETF) A body that defines standard internet operating protocols such as the TCP/IP
protocol. It is supervised by the Internet Society Internet Architecture Board
(IAB).
Key Distribution Center (KDC) A service that the entities employing Kerberos, including users, machines, and
various services, depend for essential operations.
Kerberos Ticket Generating Ticket Account (KRBTGT) A built-in account in a Windows Active Directory domain. It's used internally by
domain controllers to manage Kerberos authentication.
New technology file system (NTFS) A common file system standard for Windows supports advanced security features,
including file permissions and encryption.
Network administrators An account holder who can execute important tasks, such as creating and
managing user accounts, setting up and enforcing security policies across the
network, and installing or upgrading software across multiple devices.
Patch management A systematic approach to manage software updates and fixes. This approach
includes identifying, acquiring, installing, and verifying software applications and
system patches.
Phone book A list of names, addresses, and telephone numbers of people or businesses who
are part of your network.
Remote Authentication Dial-in User Service (RADIUS) A widely used network protocol for centralized authentication, permission, and
accounting. RADIUS enables remote access servers to communicate with a
central RADIUS server for user authentication.
Security auditing It thoroughly assesses the system's security measures to uncover vulnerabilities
and weaknesses. It identifies potential threats and suggests solutions to improve
security.
Single Sign-On (SSO) A user authentication method using a single set of log-on credentials to access
various applications and platforms.
Ticket-Granting Ticket (TGT) Files created by the key distribution center (KDC) of the Kerberos authentication
protocol.
Trusted Platform Module (TPM) A microchip that enables secure cryptographic key storage and processing as well
as other security-related functions.
Terminal Access Controller Access Control System (TACACS) An authentication method that is used in network security. TACACS helps with
separate authentication, permission, and accounting processes.
User account control (UAC) A layer of defense against unauthorized changes, malware, and other security
threats.
Virtual Private Network (VPN) A secure, encrypted connection (or tunnel) between a device and a network that
protects data transmissions over public or untrusted networks.
Windows Update Troubleshooter A tool that automatically diagnoses and fixes issues to ensure smooth updates.