Information Security Basics Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security Basics flashcards as text
Which type of malware disguises itself as legitimate software to trick users into installing it?
Answer: Trojan horse
A Trojan horse masquerades as a benign or useful program to deceive users into executing it, after which it can perform malicious actions.
A security investigator needs to preserve volatile data on a running system. Which should be collected FIRST?
Answer: RAM contents and running processes
RAM, running processes, and network connections are volatile and lost when the system is powered off, so they must be captured first during live forensics.
What does the term 'attack surface' refer to in information security?
Answer: The sum of all points where an unauthorized user can try to enter or extract data
The attack surface encompasses all the different points where an attacker could try to enter, extract data from, or disrupt a system or network.
Which of the following is a characteristic of ransomware?
Answer: It encrypts victim files and demands payment for the decryption key
Ransomware encrypts a victim's files and displays a ransom demand, requiring payment (often in cryptocurrency) in exchange for the decryption key.
In terms of access control, what is the difference between authentication and authorization?
Answer: Authentication verifies identity; authorization determines what that identity can access
Authentication confirms who you are (identity verification), while authorization determines what resources and actions you are permitted to access.
Which regulation primarily governs the protection of health information in the United States?
Answer: HIPAA (Health Insurance Portability and Accountability Act)
HIPAA establishes national standards for protecting sensitive patient health information (PHI) from disclosure without patient consent.
What is a digital signature primarily used for in information security?
Answer: Verifying the authenticity and integrity of a message or document
A digital signature uses asymmetric cryptography to verify that a message came from a specific sender and was not altered in transit.