← All TMP Flashcard Decks

Security & Risk Management Flashcards

7 cards from real TMP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Risk Management flashcards as text
  1. What is the primary purpose of a risk assessment in telecommunications network management?

    Answer: To identify, evaluate, and prioritize potential threats and vulnerabilities

    A risk assessment systematically identifies threats, evaluates vulnerabilities, and prioritizes risks so that appropriate mitigation strategies can be applied to protect the network.

  2. Which security framework is most widely adopted in the telecommunications industry for managing cybersecurity risks?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach to managing cybersecurity and is widely adopted across telecommunications for its Identify, Protect, Detect, Respond, and Recover functions.

  3. In information security, what does the CIA triad represent?

    Answer: Confidentiality, Integrity, and Availability

    The CIA triad—Confidentiality, Integrity, and Availability—represents the three core principles of information security that guide policies and controls in telecommunications systems.

  4. Which type of attack involves an unauthorized party secretly intercepting and potentially altering communications between two parties?

    Answer: Man-in-the-Middle (MitM) attack

    A Man-in-the-Middle attack occurs when an attacker secretly positions themselves between two communicating parties, enabling eavesdropping or data manipulation without either party's knowledge.

  5. What is the primary function of a Security Operations Center (SOC) in a telecommunications company?

    Answer: Centralized monitoring and response to security incidents in real time

    A SOC provides 24/7 centralized monitoring of security events, analyzes alerts, and coordinates incident response to protect the organization's telecommunications assets.

  6. Which protocol suite is used to provide encryption, authentication, and integrity for IP-based telecommunications traffic?

    Answer: IPsec

    IPsec (Internet Protocol Security) provides a framework for encrypting and authenticating IP traffic, making it widely used for securing VPNs and sensitive telecommunications data in transit.

  7. Which element is a critical component of a Business Continuity Plan (BCP) for a telecommunications service provider?

    Answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) definitions

    RTOs and RPOs define the maximum acceptable downtime and data loss after a disruption, making them foundational metrics that drive all recovery strategies within a BCP.