โ† All TMP Flashcard Decks

Security & Risk Management Flashcards

7 cards from real TMP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Risk Management flashcards as text
  1. In telecommunications security, what distinguishes a 'threat' from a 'vulnerability'?

    Answer: A threat is a potential harmful event or actor; a vulnerability is a weakness that could be exploited

    A threat is any potential event or actor that could harm a system, while a vulnerability is a specific weakness or gap that a threat can exploit to cause damage.

  2. Which multi-factor authentication (MFA) method is generally considered the most secure for protecting telecommunications management systems?

    Answer: Hardware security key (FIDO2/U2F)

    Hardware security keys using FIDO2/U2F are resistant to phishing and man-in-the-middle attacks because they use cryptographic verification tied to the specific site, making them the strongest commonly available MFA option.

  3. What is the primary security benefit of network segmentation in a telecommunications environment?

    Answer: It limits the lateral spread of an attack by isolating network zones

    By dividing the network into isolated segments, network segmentation ensures that if one segment is compromised, attackers cannot freely move to other critical systems, containing the blast radius of a breach.

  4. What does SIEM stand for, and what is its role in telecommunications security?

    Answer: Security Information and Event Management; aggregates and analyzes log data to detect threats

    SIEM (Security Information and Event Management) collects and correlates log data from across the network to provide real-time analysis of security events and support threat detection and compliance reporting.

  5. Which type of firewall provides the deepest inspection by analyzing traffic at the application layer (Layer 7)?

    Answer: Next-Generation Firewall (NGFW)

    A Next-Generation Firewall (NGFW) performs deep packet inspection at the application layer, identifying applications and users rather than just ports and protocols, enabling more granular and effective security policies.

  6. What is the primary objective of penetration testing in a telecommunications organization?

    Answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do

    Penetration testing (ethical hacking) proactively simulates attacker techniques to discover and validate vulnerabilities so organizations can remediate them before a real attack occurs.

  7. What does the principle of least privilege (PoLP) require in a telecommunications network management context?

    Answer: Users and systems should be granted only the minimum access rights needed to perform their job functions

    The principle of least privilege restricts user and system permissions to the bare minimum required, reducing the attack surface and limiting damage if credentials are compromised.