← All TMP Flashcard Decks

Security & Risk Management Flashcards

7 cards from real TMP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Risk Management flashcards as text
  1. What is a zero-day vulnerability in the context of telecommunications security?

    Answer: A flaw that is unknown to the vendor and has no available patch at the time of discovery or exploitation

    A zero-day vulnerability is an unknown or unpatched flaw that attackers can exploit before the vendor or security community has had any time ('zero days') to develop and release a fix.

  2. Which security standard specifically governs the protection of cardholder data and applies to telecommunications companies that process payment transactions?

    Answer: PCI DSS (Payment Card Industry Data Security Standard)

    PCI DSS (Payment Card Industry Data Security Standard) defines security requirements for any organization that stores, processes, or transmits cardholder data, including telecommunications providers handling customer billing.

  3. What is the primary security purpose of a DMZ (Demilitarized Zone) in a telecommunications network architecture?

    Answer: To provide a buffer zone between the public internet and internal networks where publicly accessible services can be hosted securely

    A DMZ is a network segment that sits between the untrusted internet and the trusted internal network, allowing public-facing services (e.g., web portals, DNS) to be accessible while protecting internal resources from direct exposure.

  4. In cybersecurity, what is social engineering and why is it particularly dangerous for telecommunications organizations?

    Answer: Manipulating people through deception to divulge confidential information or perform insecure actions

    Social engineering exploits human psychology rather than technical vulnerabilities, making it dangerous because even the most technically secure telecommunications systems can be compromised by deceiving an employee.

  5. What does RBAC stand for, and how does it benefit access control in telecommunications management systems?

    Answer: Role-Based Access Control; assigns permissions based on job roles rather than individual users

    Role-Based Access Control (RBAC) simplifies permission management by assigning rights to predefined roles (e.g., network engineer, administrator), ensuring users only access resources relevant to their responsibilities.

  6. What is the primary goal of an Incident Response Plan (IRP) for a telecommunications service provider?

    Answer: To define structured procedures for detecting, containing, eradicating, and recovering from security incidents to minimize impact

    An IRP provides a predefined, structured approach to handling security incidents, ensuring that teams respond swiftly and consistently to minimize service disruption, data loss, and reputational damage.

  7. Which encryption standard is most commonly used to secure wireless telecommunications networks (Wi-Fi) as of current best practices?

    Answer: WPA3 (Wi-Fi Protected Access 3)

    WPA3 is the current Wi-Fi security standard, offering stronger encryption (SAE handshake replacing PSK), forward secrecy, and improved protection against brute-force attacks compared to its predecessors.