Information Security Basics Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Security Basics flashcards as text
Which of the following best describes the principle of least privilege in information security?
Answer: Users are granted only the minimum access rights necessary to perform their job functions
The principle of least privilege limits user access rights to only what is strictly required for their role, reducing the attack surface.
A security investigator discovers that an employee copied sensitive files to a personal USB drive before resigning. This is an example of which type of threat?
Answer: Insider threat
An insider threat involves a current or former employee misusing authorized access to harm the organization.
What does 'data at rest' refer to in the context of information security?
Answer: Data stored on devices such as hard drives or databases
Data at rest refers to inactive data stored physically in any digital form, such as databases, data warehouses, or file systems.
Which encryption standard is currently recommended by NIST for protecting sensitive government information?
Answer: AES (Advanced Encryption Standard)
AES, particularly AES-256, is the NIST-approved standard for encrypting sensitive and classified government information.
During a security investigation, you find logs showing repeated failed login attempts followed by a successful login from an unusual location. This pattern most likely indicates:
Answer: A brute force attack that eventually succeeded
Repeated failed logins followed by success from an unusual location is a classic indicator of a brute force attack achieving account compromise.
What is the purpose of a hash function in information security?
Answer: To produce a fixed-size digest that verifies data integrity
Hash functions produce a fixed-length output (digest) from input data; any change to the input produces a different hash, verifying integrity.
Which of the following is an example of two-factor authentication (2FA)?
Answer: Entering a password and then a one-time code sent to a mobile phone
Two-factor authentication combines something you know (password) with something you have (OTP sent to phone), adding a second verification layer.