Mixed Deck — All CSS Topics Flashcards
100 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CSS Topics flashcards as text
Which cloud deployment model provides an organization with the highest level of control over its infrastructure?
Answer: Private cloud
A private cloud is dedicated exclusively to one organization, granting the greatest control over security configurations and infrastructure.
Which indicator in endpoint telemetry MOST strongly suggests process injection has occurred?
Answer: A legitimate system process (e.g., svchost.exe) spawning unusual network connections or child processes
Process injection hijacks trusted processes, so suspicious network behavior or unusual child processes spawned by normally benign system processes is a strong indicator.
Which attack targets authentication systems by using previously captured valid authentication tokens?
Answer: Pass-the-ticket / pass-the-hash attack
Pass-the-hash and pass-the-ticket attacks use stolen authentication tokens to authenticate as a victim without knowing the actual password.
What is the first step in incident response?
Answer: Identifying and assessing the incident
The first and most crucial step in incident response is to accurately identify that a security incident has occurred and then thoroughly assess its nature, scope, and severity. This initial phase, often called detection and analysis, is vital for understanding the situation, determining the appropriate response actions, and allocating resources effectively before proceeding to subsequent steps like containment or eradication.
Which technique allows an attacker to bypass network-based intrusion detection by splitting a TCP packet payload across multiple fragments?
Answer: IP fragmentation evasion
Splitting a malicious payload across fragmented packets can evade IDS/IPS systems that do not properly reassemble TCP streams before inspecting content.
Which stakeholder group is MOST critical to include during the initial development of an enterprise information security policy?
Answer: Senior leadership and legal counsel
Senior leadership provides authority and strategic alignment, while legal counsel ensures regulatory compliance — both are essential at the policy creation stage.
What is the security benefit of using software-defined networking (SDN) in enterprise environments?
Answer: Centralized control plane enables consistent policy enforcement and rapid response to threats
SDN's centralized control plane allows security policies to be applied uniformly across the network and updated dynamically in response to threats.
Which IAM control helps prevent privilege escalation by ensuring users cannot grant themselves higher permissions than they currently hold?
Answer: Constrained delegation and permission boundary enforcement
Constrained delegation and IAM permission boundaries ensure that even if an account is compromised, the attacker cannot escalate to permissions beyond those already assigned.
Which key management practice ensures that encryption keys are protected from the data they encrypt?
Answer: Storing keys in a separate hardware security module (HSM)
An HSM is a dedicated hardware device that stores and processes cryptographic keys in a tamper-resistant environment, separate from the data.
An attacker uses Living-off-the-Land (LotL) techniques. Which detection approach is MOST effective against this?
Answer: Behavioral monitoring of legitimate system tools like PowerShell and WMI
LotL attacks abuse built-in OS tools, so behavioral monitoring of how those tools are used (unusual parent processes, encoded commands) is more effective than signature scanning.
What is the primary purpose of key escrow in enterprise cryptography?
Answer: Allows authorized parties to recover encrypted data if the original key is lost
Key escrow stores a copy of encryption keys with a trusted third party, enabling data recovery in case of key loss or employee departure.
What is the significance of a 'right to audit' clause in a cloud service contract?
Answer: It gives the customer the contractual right to audit the cloud provider's security controls and compliance posture
A right-to-audit clause allows the customer to independently verify that the cloud provider's security controls and compliance posture meet contractual and regulatory obligations.
What is the purpose of continuous compliance monitoring in a security program?
Answer: Provides real-time visibility into the compliance posture of systems rather than point-in-time assessments
Continuous compliance monitoring uses automated tools to track controls and configurations in real time, reducing the gap between audits when non-compliance might go undetected.
Which metric is used to measure the effectiveness of an incident response team's detection capabilities?
Answer: Mean Time to Detect (MTTD)
MTTD measures the average time from when an incident occurs to when it is detected, directly reflecting detection capability effectiveness.
Which security concern is MOST unique to multi-tenant cloud environments?
Answer: Data isolation and tenant separation failures
Multi-tenancy creates the risk of data leaking between co-located tenants, making proper logical isolation the defining security concern.
Why is it important to assess both internal and external risks in a security risk assessment?
Answer: Because both internal and external risks contribute to overall security
A comprehensive security risk assessment must consider both internal and external risks because both can significantly impact an organization's security posture. Internal risks often stem from employees, processes, or systems within the organization, while external risks originate from outside sources like cyber attackers or natural disasters. Addressing both categories provides a holistic view and ensures robust protection against a wider range of potential threats.
How does technology influence security policy enforcement?
Answer: By automating and enhancing enforcement through monitoring tools
Technology plays a crucial role in security policy enforcement by providing tools for automation, monitoring, and control. Solutions like Identity and Access Management (IAM), Data Loss Prevention (DLP), and Security Information and Event Management (SIEM) systems can automatically enforce policies, detect violations, and provide real-time alerts. This makes enforcement more efficient, consistent, and comprehensive than manual methods alone.
Which vulnerability assessment approach tests systems from outside the network perimeter without credentials, simulating an external attacker's perspective?
Answer: Black-box external scan
A black-box external scan is performed without credentials or insider knowledge, replicating what an unauthenticated external attacker would discover.
What is a 'right to erasure' (right to be forgotten) under GDPR?
Answer: An individual's right to request deletion of their personal data when it is no longer necessary for its original purpose
GDPR Article 17 grants individuals the right to request that their personal data be deleted under certain circumstances, such as when consent is withdrawn.
When performing a supply chain risk assessment, which practice helps an organization verify that third-party software has not been tampered with?
Answer: Validating cryptographic hashes and digital signatures of software artifacts
Cryptographic hash verification and digital signature validation confirm the integrity and authenticity of software, detecting any tampering in the supply chain.