ITF+ Information Security Principles Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ITF+ Information Security Principles flashcards as text
Which of the following BEST describes ransomware?
Answer: Malware that encrypts a victim's files and demands payment for the decryption key
Ransomware encrypts victim files and demands a ransom payment, typically in cryptocurrency, to restore access.
What is the primary purpose of a firewall?
Answer: To monitor and control incoming and outgoing network traffic based on rules
A firewall filters network traffic using predefined rules to block unauthorized access while allowing legitimate traffic.
A user writes their password on a sticky note and places it on their monitor. Which security concept does this violate?
Answer: Physical security / confidentiality
Writing passwords in visible locations violates confidentiality and physical security by exposing credentials to anyone nearby.
Which type of malware disguises itself as legitimate software to trick users into installing it?
Answer: Trojan horse
A Trojan horse appears to be legitimate software but contains hidden malicious code that executes when installed.
What is the goal of a social engineering attack?
Answer: To manipulate people into revealing confidential information or performing actions
Social engineering targets human psychology rather than technical vulnerabilities to extract information or gain unauthorized access.
Which of the following BEST describes data integrity?
Answer: Ensuring data has not been altered or tampered with in an unauthorized manner
Data integrity means the data remains accurate and unmodified except through authorized processes.
An employee receives a phone call from someone claiming to be IT support and asking for their password. What should the employee do?
Answer: Refuse to provide the password and report the call to security
Legitimate IT staff never ask for user passwords; this is likely a vishing (voice phishing) social engineering attempt.