โ† All CSI Flashcard Decks

Information Security Basics Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security Basics flashcards as text
  1. In information security, what does 'non-repudiation' mean?

    Answer: Preventing a party from denying that they sent or received a message

    Non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message, often achieved through digital signatures.

  2. A CSI investigator is reviewing chain of custody for digital evidence. Why is maintaining chain of custody critical?

    Answer: It ensures evidence admissibility by documenting who handled it and when

    Chain of custody documents every person who handled evidence and when, ensuring its integrity and admissibility in legal proceedings.

  3. Which of the following best describes social engineering in the context of information security?

    Answer: Manipulating people psychologically to divulge confidential information

    Social engineering exploits human psychology rather than technical vulnerabilities to trick individuals into revealing sensitive information or taking harmful actions.

  4. What is a vulnerability assessment?

    Answer: A systematic review of security weaknesses in an information system

    A vulnerability assessment systematically identifies, quantifies, and prioritizes security weaknesses in systems without actively exploiting them.

  5. During an investigation, an analyst finds that an attacker used SQL injection. Which security principle was most directly violated?

    Answer: Input validation and secure coding practices

    SQL injection exploits failures in input validation and secure coding, where user-supplied data is incorrectly trusted and passed to a database interpreter.

  6. Which of the following is the primary purpose of an Intrusion Detection System (IDS)?

    Answer: To monitor network traffic and alert on suspicious activity

    An IDS monitors network traffic or system activity and generates alerts when it detects suspicious patterns, but does not actively block threats like an IPS does.

  7. What is 'defense in depth' as applied to information security?

    Answer: Implementing multiple overlapping layers of security controls

    Defense in depth employs multiple security layers so that if one control fails, others remain in place to protect assets.