โ† All CPA Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. What is the main goal of penetration testing?

    Answer: Simulating attacks to identify exploitable vulnerabilities

    Penetration testing involves authorized simulated attacks on a system to uncover security weaknesses before malicious actors can exploit them.

  2. Which security principle ensures that users can only access resources necessary for their job function?

    Answer: Least Privilege

    The Least Privilege principle limits user access rights to only what is strictly required to perform their duties.

  3. What does 'phishing' typically rely on to compromise a victim?

    Answer: Tricking users into revealing credentials via deceptive messages

    Phishing uses deceptive emails or messages that impersonate trusted entities to manipulate users into disclosing sensitive information.

  4. Which CIA Triad component is directly threatened when a database is altered without authorization?

    Answer: Integrity

    Integrity ensures data accuracy and trustworthiness; unauthorized modifications directly violate this principle.

  5. What is the purpose of network segmentation in cybersecurity?

    Answer: Limit lateral movement by containing breaches within smaller zones

    Network segmentation divides a network into smaller isolated zones so that a breach in one segment cannot easily spread to others.

  6. Which attack floods a target server with traffic to make it unavailable to legitimate users?

    Answer: Denial of Service (DoS)

    A Denial of Service attack overwhelms a server with excessive requests, exhausting resources and preventing legitimate access.

  7. In risk assessment, what does 'likelihood' refer to?

    Answer: The probability that a threat will successfully exploit a vulnerability

    Likelihood in risk assessment measures how probable it is that a given threat will actually exploit a vulnerability and cause harm.