Cybersecurity & Risk Flashcards
7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
What is the primary difference between a vulnerability and an exploit?
Answer: A vulnerability is a weakness; an exploit is code or technique that takes advantage of it
A vulnerability is an existing flaw or weakness in a system, while an exploit is the method or code used to leverage that vulnerability maliciously.
Which security concept describes ensuring that systems and data remain accessible to authorized users when needed?
Answer: Availability
Availability ensures that information systems remain operational and accessible to authorized users whenever required.
What is 'patch management' in cybersecurity?
Answer: Systematically updating software to fix known vulnerabilities
Patch management is the process of identifying, acquiring, testing, and applying software updates to address security vulnerabilities and bugs.
A developer stores passwords as plain text in a database. Which security practice does this violate?
Answer: Password Hashing
Passwords should always be stored using a strong cryptographic hash function so they cannot be read directly if the database is compromised.
Which attack injects malicious scripts into web pages viewed by other users?
Answer: Cross-Site Scripting (XSS)
Cross-Site Scripting (XSS) injects malicious client-side scripts into web pages, which then execute in the browsers of unsuspecting users.
What is the purpose of an Intrusion Detection System (IDS)?
Answer: Monitoring network or system activity to detect malicious behavior
An IDS monitors network traffic and system activity, generating alerts when it detects suspicious or malicious behavior.
In risk management, which term describes the potential damage or loss resulting from a threat exploiting a vulnerability?
Answer: Impact
Impact refers to the magnitude of harm — financial, operational, or reputational — that would result if a threat successfully exploits a vulnerability.