← All CPA Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. What is 'social engineering' in the context of cybersecurity?

    Answer: Manipulating people psychologically to divulge confidential information

    Social engineering exploits human psychology rather than technical vulnerabilities to gain unauthorized access or information.

  2. Which type of firewall inspects the state of active connections to filter traffic?

    Answer: Stateful Inspection Firewall

    A stateful inspection firewall tracks the state of network connections and uses this context to determine whether to allow or block packets.

  3. What is 'data exfiltration'?

    Answer: Unauthorized transfer of data from an organization to an external destination

    Data exfiltration is the unauthorized copying or transfer of sensitive data from a system, typically carried out by attackers.

  4. Which cryptographic concept ensures a sender cannot deny having sent a message?

    Answer: Non-Repudiation

    Non-repudiation provides proof of the origin and delivery of data, preventing a sender from falsely denying they sent a message.

  5. What is a 'honeypot' used for in network security?

    Answer: Decoy systems designed to attract and detect attackers

    A honeypot is a decoy system intentionally made to look attractive to attackers, allowing defenders to observe and study attack techniques.

  6. Which risk treatment strategy involves purchasing insurance to offset potential financial losses from a security incident?

    Answer: Risk Transfer

    Risk Transfer shifts the financial burden of a risk to a third party — such as an insurer — without eliminating the underlying risk.

  7. What does 'multi-factor authentication (MFA)' require from a user?

    Answer: Two or more verification factors from different categories

    MFA requires users to provide two or more independent authentication factors (something you know, have, or are) before granting access.