Cybersecurity & Risk Flashcards
7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
What is the main goal of penetration testing?
Answer: Simulating attacks to identify exploitable vulnerabilities
Penetration testing involves authorized simulated attacks on a system to uncover security weaknesses before malicious actors can exploit them.
Which security principle ensures that users can only access resources necessary for their job function?
Answer: Least Privilege
The Least Privilege principle limits user access rights to only what is strictly required to perform their duties.
What does 'phishing' typically rely on to compromise a victim?
Answer: Tricking users into revealing credentials via deceptive messages
Phishing uses deceptive emails or messages that impersonate trusted entities to manipulate users into disclosing sensitive information.
Which CIA Triad component is directly threatened when a database is altered without authorization?
Answer: Integrity
Integrity ensures data accuracy and trustworthiness; unauthorized modifications directly violate this principle.
What is the purpose of network segmentation in cybersecurity?
Answer: Limit lateral movement by containing breaches within smaller zones
Network segmentation divides a network into smaller isolated zones so that a breach in one segment cannot easily spread to others.
Which attack floods a target server with traffic to make it unavailable to legitimate users?
Answer: Denial of Service (DoS)
A Denial of Service attack overwhelms a server with excessive requests, exhausting resources and preventing legitimate access.
In risk assessment, what does 'likelihood' refer to?
Answer: The probability that a threat will successfully exploit a vulnerability
Likelihood in risk assessment measures how probable it is that a given threat will actually exploit a vulnerability and cause harm.