A server can have a vulnerability without being under attack. A failed login is a security event, but it isn't necessarily an incident. Keeping those distinctions straight helps you read alerts, describe bugs, and decide what needs investigation.
Start with what needs protection
An asset is something worth protecting: a customer record, source-code repository, laptop, service account, or working application. The CIA triad describes three properties you may need to protect:
- Confidentiality: only authorized people or systems can access information.
- Integrity: information and systems remain accurate and are not changed without authorization.
- Availability: authorized users can access a system or data when needed.
A stolen database copy affects confidentiality. An unauthorized change to a payment amount affects integrity. An outage affects availability. A single event can affect several properties: ransomware may make files unavailable and expose their contents.
A security control is a measure intended to reduce risk. It might be technical, such as an access restriction, or procedural, such as reviewing an access request before approving it. A preventive control aims to stop an unwanted action; a detective control helps reveal one; a recovery control helps restore normal operation. Controls reduce risk, but rarely eliminate it.

Describe the path from weakness to harm
A threat is a potential source of harm, whether that's a malicious actor, an accidental deletion, or a hardware failure. A vulnerability is a weakness that could be exploited or otherwise contribute to harm. An unpatched software flaw is one example; an application that grants a user more access than intended is another.
An exploit is a method or action that takes advantage of a vulnerability. An attack is a deliberate attempt to compromise a system. Not every vulnerability has a known exploit, and discovering a weakness does not mean anyone has used it. The attack surface covers the places where a system can be reached or influenced, including exposed services, application features, accounts, and physical access points.
Risk concerns the possibility of harm and its consequences. Context matters as much as technical severity: an exposed test service with no sensitive data and an exposed production service handling customer records may share the same flaw but pose different risks. Before deciding how to respond to a report, identify the affected asset, a plausible threat, the available path to harm, and the potential impact.
Understand identity and access
Authentication is not authorization
Authentication checks an identity claim: is this the account holder? A password, device-bound credential, or other factor may help answer that question. Authorization determines what the authenticated identity can do. A signed-in employee might be allowed to view a project but not delete it. A genuine account does not make every action permissible.
Multi-factor authentication (MFA) combines factors from different categories, commonly something you know, have, or are. Two passwords do not count as two different factors. MFA helps protect an account against some forms of credential compromise, but it cannot replace authorization checks.
The principle of least privilege means granting only the access a task requires. A service that reads a report, for example, should not automatically be able to edit it or administer its database. Privilege escalation occurs when someone or something gains access beyond its intended permissions, perhaps through a software flaw or an access-control mistake.
Accounts, secrets, and sessions
A credential is information or a mechanism used to establish identity. A secret is sensitive information that needs protection, such as a password, API key, or private cryptographic key. A session is the continuing authenticated interaction after sign-in, often represented by a token or cookie. Someone with a session token may be able to access an account without knowing its password, so the token needs protection too.
An API key may identify an application or authorize particular requests, depending on the service. It does not necessarily establish the identity of a human user. In a development project, keep keys out of publicly shared code and limit their permissions to what the application needs.
Read network and web terms precisely
An IP address identifies a network interface for routing traffic; on its own, it does not identify a person. A domain name is a human-readable name that can be resolved to network addresses through DNS (Domain Name System). A port helps direct traffic to a particular service on a device. An open port suggests a service may be reachable, not that it is vulnerable.
HTTP is a protocol for exchanging web requests and responses. HTTPS carries HTTP over TLS, protecting data in transit between communicating endpoints. It does not guarantee that a website is honest or its application code is secure. A firewall applies traffic rules at a network or device boundary, but an allowed connection can still carry unwanted activity if the service behind it is poorly secured.
Encryption converts readable data into a form that requires an appropriate key to recover. Hashing produces a fixed-length digest and is designed as a one-way operation, though its safety depends on the algorithm and how it is used. Encoding, such as Base64, changes how data is represented for compatibility; it is not encryption. If a value can be decoded without a secret, encoding alone has not kept it confidential.

Recognize common security activity
Malware is software intended to perform harmful or unauthorized actions. Ransomware is malware associated with extortion, often by disrupting access to data. Phishing is an attempt to deceive someone into disclosing information or taking an unsafe action. A phishing message might deliver malware, but phishing does not require it.
A security event is an observable occurrence relevant to security, such as a failed sign-in or a permission change. An alert is a notification generated when an event matches a detection rule. An incident is an event or series of events that threatens or compromises security under an organization's criteria. An alert calls for investigation; it is not proof of an incident.
A false positive flags harmless activity as suspicious. A false negative is harmful activity that a detection misses. Noisy alerts can bury useful signals, while missed activity can delay a response. An indicator of compromise (IOC) is an observable clue that may be associated with malicious activity, such as a known malicious file hash. A match still needs context and verification; it isn't a complete explanation.
Put the terms to work in an authorized lab
Suppose a lab application lets a signed-in student view another student's draft by changing a document identifier. The draft is an asset, and its confidentiality is at risk. Authentication worked, but authorization failed: the application did not check whether that student could access that specific document. The URL parameter is part of the attack surface, the missing check is the vulnerability, and viewing the other draft demonstrates the impact in this controlled example.
A useful report says more than “the site got hacked.” Record which test account you used, which lab document you accessed, the expected permission, the observed behavior, and the authorization check that should have blocked access. Keep the test within systems and accounts you own or are explicitly permitted to assess. That defined scope makes the finding safe to reproduce and address.
