Cheat Sheets

Scannable references for the frameworks and concepts that matter, free, no sign-up needed.

Every sheet here is built for two moments: the one where you are studying something for the first time and want it laid out in one place, and the one where you half-remember it and need to check. That is why they are tables and comparisons rather than essays. Port 3389, the difference between a detective and a corrective control, which phase of the kill chain a scenario belongs to: these are things you look up until suddenly you do not.

Every sheet comes with a free one-page PDF you can print or keep open on a second screen. No email, no account, no gate. They are designed to be shared, so pass them to anyone studying alongside you.

Common Ports & Protocols
Networking

Common Ports & Protocols

All 200 well-known TCP/UDP ports grouped by service, with secure vs insecure pairs and the subset that actually turns up in exams.

Open
Preventive, Detective & Corrective Controls
Operations

Preventive, Detective & Corrective Controls

The 3 × 3 control matrix with 51 worked examples, plus deterrent, compensating and directive controls.

Open
The Cyber Kill Chain
Threat detection

The Cyber Kill Chain

The 7 phases of an intrusion with attacker tactics and defences, plus a scenario lookup for working out which phase an attack is in.

Open
MITRE ATT&CK Tactics & Technique IDs
Frameworks

MITRE ATT&CK Tactics & Technique IDs

All 14 Enterprise tactics with their TA IDs and the technique IDs worth recognising, from T1566 Phishing to T1486 Data Encrypted for Impact.

Open
Kill Chain vs ATT&CK vs D3FEND
Frameworks

Kill Chain vs ATT&CK vs D3FEND

How the three frameworks differ and which to reach for, mapped side by side from attacker stage to technique to countermeasure.

Open
Risk & Recovery Metrics
Risk

Risk & Recovery Metrics

RTO, RPO, MTTR and MTBF side by side, plus the SLE and ALE formulas with worked numbers and the distinctions exams actually test.

Open
Access Control Models
Access control

Access Control Models

DAC, MAC, RBAC, ABAC and RuBAC compared by who decides and on what basis, with the RBAC vs RuBAC distinction that catches people out.

Open
Malware Types & Classification
Threat analysis

Malware Types & Classification

Virus vs worm vs trojan and every other major type, compared by self-replication, host dependency and spread, with a scenario lookup.

Open

Reading a cheat sheet is not the same as knowing it

There is a gap between recognising something on a page and recalling it under time pressure, and it is the gap that costs marks in an exam and hesitation on the job. Rereading closes it far more slowly than most people expect, because recognition feels like knowledge while you are looking at the answer.

What does close it is retrieval: being asked, getting it wrong, and being asked again a few days later. That is what CyberQuizzer is built around, and it is why every sheet ends with a way to drill the thing you just read. Use the references to learn it, then practise until you stop needing them.

Turn these into instinct.

Ten minutes a day. Free forever, no card.

Create free account