โ† All CTE Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CTE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. Which security architecture principle requires that every access request in a telecom network be authenticated and authorized regardless of network location?

    Answer: Zero Trust Architecture

    Zero Trust Architecture operates on 'never trust, always verify,' eliminating implicit trust based on network location or IP address.

  2. A telecom executive reviews a penetration test report showing that SNMP v1 is still in use on network devices. What is the primary security risk?

    Answer: SNMP v1 lacks encryption and uses community strings as plaintext passwords

    SNMP v1 transmits community strings (effectively passwords) in plaintext and lacks authentication, making it vulnerable to eavesdropping and unauthorized device management.

  3. Under FCC regulations, what must a US carrier do within 30 days of a data breach affecting customer CPNI (Customer Proprietary Network Information)?

    Answer: Notify the FCC, affected customers, and law enforcement

    FCC CPNI rules require carriers to notify the FCC, law enforcement, and affected customers within 30 days of a CPNI breach.

  4. Which attack specifically targets the Diameter protocol used in 4G/LTE networks to track subscriber location?

    Answer: Diameter AVP location request abuse

    Diameter's location service messages can be abused by attackers with roaming interconnect access to query and track subscriber locations.

  5. A telecom company's CISO wants to quantify the financial impact of a potential ransomware attack. Which methodology assigns dollar values to assets and calculates annualized loss expectancy?

    Answer: FAIR (Factor Analysis of Information Risk)

    FAIR is a quantitative risk framework that translates cybersecurity risk into financial terms using probabilistic modeling of loss frequency and magnitude.

  6. In telecom network security, what is 'IMSI catching' and who is most at risk?

    Answer: Using a fake base station to intercept mobile device identifiers; subscribers in the coverage area

    An IMSI catcher (stingray) impersonates a legitimate cell tower to force nearby devices to connect, revealing their IMSI and enabling tracking or interception.

  7. A telecom operator uses threat intelligence feeds to identify indicators of compromise (IOCs). Which type of IOC provides the highest fidelity signal with the longest useful lifespan?

    Answer: Tactics, Techniques, and Procedures (TTPs)

    TTPs describe adversary behavior patterns that are expensive for attackers to change, giving defenders long-lasting, high-confidence detection capabilities.