ITF+ Information Security Principles Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 ITF+ Information Security Principles flashcards as text
Which of the following is an example of access control based on a user's job function?
Answer: Role-Based Access Control (RBAC)
RBAC assigns permissions based on job roles, so all users in the same role receive the same access rights.
What is a zero-day vulnerability?
Answer: A flaw that is unknown to the software vendor and has no available patch
A zero-day vulnerability is an unknown flaw that vendors have had zero days to fix, making it especially dangerous.
Which security practice involves testing your own systems by simulating an attacker's approach?
Answer: Penetration testing
Penetration testing (ethical hacking) simulates real-world attacks to identify and fix security weaknesses before malicious actors can exploit them.
A website uses HTTPS instead of HTTP. What does the 'S' indicate?
Answer: The connection is encrypted using SSL/TLS
HTTPS uses SSL/TLS to encrypt data between the browser and web server, protecting it from interception.
What is the CIA triad in information security?
Answer: Confidentiality, Integrity, and Availability
The CIA triad — Confidentiality, Integrity, and Availability — represents the three core goals of information security.
Which of the following BEST describes a strong password policy?
Answer: Passwords should be long, complex, and changed regularly
Strong password policies require sufficient length, complexity (mixed character types), and periodic changes to resist guessing and brute force.
What does the term 'patch management' refer to in cybersecurity?
Answer: The process of regularly updating software to fix security vulnerabilities
Patch management involves identifying, acquiring, and applying software updates that fix known security flaws and bugs.