Security, Compliance & Identity Concepts Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security, Compliance & Identity Concepts flashcards as text
Which security principle states that users should be granted only the minimum level of access necessary to perform their job functions?
Answer: Least privilege
Least privilege limits user access rights to only what is strictly required for their role, reducing the attack surface.
What type of attack involves an attacker intercepting and potentially altering communication between two parties without their knowledge?
Answer: Man-in-the-middle attack
A man-in-the-middle (MitM) attack occurs when an attacker secretly relays and possibly alters communications between two parties.
In the context of identity, what does the term 'federation' refer to?
Answer: A trust relationship between identity providers across organizations
Federation establishes a trust relationship between identity providers, allowing users from one organization to access resources in another without separate credentials.
Which of the following best describes 'data sovereignty'?
Answer: The legal concept that data is subject to the laws of the country where it is stored
Data sovereignty refers to the principle that digital data is subject to the laws and governance structures of the nation where it is physically stored.
What is the primary purpose of a Security Information and Event Management (SIEM) system?
Answer: To collect, analyze, and correlate security events across an organization
A SIEM system aggregates and analyzes log data from multiple sources to detect threats, generate alerts, and support incident response.
Which concept describes the practice of verifying every access request as though it originates from an untrusted network, regardless of location?
Answer: Zero trust
Zero trust assumes no implicit trust for any user or device, requiring continuous verification regardless of whether the request comes from inside or outside the network.
What is 'social engineering' in the context of cybersecurity?
Answer: Manipulating people into divulging confidential information or performing actions that compromise security
Social engineering exploits human psychology rather than technical vulnerabilities to trick individuals into revealing sensitive information or granting access.