โ† All CTP Flashcard Decks

CTP Security & Risk Management Flashcards

6 cards from real CTP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CTP Security & Risk Management flashcards as text
  1. Which network security control inspects traffic at the application layer (Layer 7) to detect and block sophisticated attacks?

    Answer: Web Application Firewall (WAF)

    A WAF operates at Layer 7, inspecting HTTP/S traffic to detect and block application-layer attacks such as SQL injection and XSS.

  2. What is the difference between vulnerability scanning and vulnerability assessment?

    Answer: Scanning identifies potential vulnerabilities automatically; assessment includes manual analysis and business context

    Scanning uses automated tools to detect known vulnerabilities, while a full assessment adds manual validation, risk context, and remediation recommendations.

  3. In the context of risk management frameworks, what does NIST SP 800-30 provide?

    Answer: A guide for conducting risk assessments of federal information systems

    NIST SP 800-30 provides a structured methodology for conducting information security risk assessments for federal and enterprise systems.

  4. What security control does multi-factor authentication (MFA) primarily address?

    Answer: It reduces the risk of unauthorized access due to compromised credentials

    MFA requires multiple verification factors, so stolen passwords alone are insufficient for attackers to gain unauthorized system access.

  5. What is the purpose of a Security Information and Event Management (SIEM) system?

    Answer: To aggregate, correlate, and analyze security logs from multiple sources for threat detection

    A SIEM collects and correlates security events from across the environment in real time, enabling rapid detection of and response to security incidents.

  6. Which risk treatment strategy involves transferring the financial impact of a risk to a third party?

    Answer: Risk transfer (e.g., purchasing cyber insurance)

    Risk transfer shifts the financial consequences of a risk event to another party, most commonly through insurance or contractual agreements.