Network Security & Vulnerability Management Flashcards
9 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Network Security & Vulnerability Management flashcards as text
What is the primary objective of network security?
Answer: To protect the network from unauthorized access
Network security's primary objective is to safeguard the integrity, confidentiality, and availability of network resources and data. This involves implementing measures like firewalls, encryption, and access controls to prevent unauthorized users from gaining entry or tampering with the network.
Which of the following is a key component of vulnerability management?
Answer: Identifying, assessing, and prioritizing vulnerabilities
Vulnerability management is a continuous process designed to reduce an organization's exposure to security risks. It involves systematically discovering security weaknesses, evaluating their potential impact, and ranking them to determine which ones need immediate attention and remediation.
What does a firewall do in network security?
Answer: It filters and blocks harmful traffic
A firewall acts as a barrier between a trusted internal network and untrusted external networks, like the internet. It examines incoming and outgoing network traffic against a set of predefined security rules, blocking malicious data packets and preventing unauthorized access.
What is a common method of detecting vulnerabilities in a network?
Answer: Performing vulnerability scanning
Vulnerability scanning is an automated process that identifies known security weaknesses in systems, applications, and networks. This proactive approach helps organizations discover potential entry points for attackers and address them before they can be exploited.
Why is patch management important in vulnerability management?
Answer: To keep systems up-to-date and secure
Patch management involves regularly applying software updates and fixes (patches) to systems and applications. These patches often address newly discovered security vulnerabilities, making it a critical component of vulnerability management to protect against exploits and maintain system integrity.
What is a Zero-Day vulnerability?
Answer: A newly discovered vulnerability with no patch
A Zero-Day vulnerability is a software flaw that is unknown to the vendor and for which no official patch or fix exists. Attackers can exploit these vulnerabilities before the vendor is aware or has developed a solution, making them particularly dangerous.
What does encryption do in network security?
Answer: It protects data by making it unreadable without a decryption key
Encryption is the process of converting information or data into a code to prevent unauthorized access. It scrambles data into an unreadable format, and only individuals with the correct decryption key can convert it back into its original, readable form, ensuring data confidentiality.
What is the purpose of a VPN in network security?
Answer: To protect privacy and encrypt data
A Virtual Private Network (VPN) creates a secure, encrypted connection over a less secure network, like the internet. It protects user privacy by masking their IP address and encrypts all data transmitted, making it unreadable to eavesdroppers and securing online communications.
What is a vulnerability assessment?
Answer: A detailed process of identifying vulnerabilities in a system
A vulnerability assessment is a systematic examination of an information system or network to identify security weaknesses. It involves using various tools and techniques to discover flaws that could be exploited by attackers, providing a comprehensive overview of potential risks.