Cybersecurity Principles & Risk Management Flashcards
9 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Cybersecurity Principles & Risk Management flashcards as text
What is the primary goal of cybersecurity?
Answer: To prevent unauthorized access and protect digital assets
The primary goal of cybersecurity is to protect digital assets and systems from unauthorized access, use, disclosure, disruption, modification, or destruction. It aims to ensure the confidentiality, integrity, and availability of information. This protection is vital for individuals, organizations, and governments in the digital age.
What is a common method hackers use to gain access to systems?
Answer: Phishing
Phishing is a common social engineering tactic where hackers deceive individuals into revealing sensitive information, such as login credentials or financial details. They typically masquerade as a trustworthy entity in electronic communications, like emails or text messages. This method exploits human trust to gain unauthorized access to systems.
What is a firewall used for in cybersecurity?
Answer: To block unauthorized access and filter traffic
A firewall acts as a security barrier, monitoring and controlling incoming and outgoing network traffic based on predefined security rules. Its main purpose is to prevent unauthorized access to a private network from external sources, such as the internet. By filtering traffic, it protects systems from malicious attacks and data breaches.
Why is risk management important in cybersecurity?
Answer: To identify and mitigate potential threats
Risk management in cybersecurity is essential for proactively identifying, assessing, and prioritizing potential threats and vulnerabilities to an organization's digital assets. By understanding these risks, organizations can implement appropriate controls and mitigation strategies to reduce their likelihood and impact. This systematic approach helps protect critical information and systems effectively.
What is the role of encryption in data security?
Answer: To prevent data from being read by unauthorized users
Encryption transforms data into a coded format, making it unreadable to anyone without the correct decryption key. Its primary role in data security is to ensure confidentiality, preventing unauthorized users from accessing or understanding sensitive information. This protection is vital for data both in transit and at rest.
What is a vulnerability in cybersecurity?
Answer: A weakness that can be exploited by threats
In cybersecurity, a vulnerability is a weakness or flaw in a system, application, or process that can be exploited by a threat actor. These weaknesses could be software bugs, misconfigurations, or poor security practices. Identifying and addressing vulnerabilities is crucial to prevent successful cyberattacks and maintain system integrity.
What does multi-factor authentication (MFA) provide?
Answer: Additional verification for stronger access control
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more distinct verification factors to gain access. Instead of relying solely on a password, MFA combines different types of credentials, such as something you know (password), something you have (phone), or something you are (biometrics). This layered approach makes it much harder for unauthorized individuals to access accounts, even if one factor is compromised.
What is the purpose of a cybersecurity policy?
Answer: To define organizational security standards
A cybersecurity policy is a formal document that outlines an organization's rules, procedures, and guidelines for protecting its information assets. It defines acceptable use, data handling, and security practices for all employees. This policy serves as a foundational framework for maintaining a secure digital environment and ensuring compliance with regulations.
Which practice helps reduce insider threats?
Answer: Regular training and controlled access to sensitive data
Insider threats originate from individuals within an organization who have authorized access to systems and data. Reducing these threats involves implementing regular security awareness training to educate employees on best practices and potential risks, alongside strict access controls. Controlled access ensures individuals only have the necessary permissions for their roles, minimizing opportunities for misuse or malicious activity.