โ† All APCSP Flashcard Decks

Cybersecurity Flashcards

7 cards from real APCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity flashcards as text
  1. Which protocol is used to securely access a remote computer's command line over an encrypted connection?

    Answer: SSH

    SSH (Secure Shell) encrypts remote terminal sessions, replacing insecure protocols like Telnet that transmit data in plain text.

  2. An attacker embeds malicious code in a website's comment field, which then executes in other users' browsers. This is known as:

    Answer: Cross-site scripting (XSS)

    XSS injects malicious scripts into web content viewed by other users, executing in the victim's browser context.

  3. What does the concept of 'security through obscurity' refer to, and why is it considered insufficient?

    Answer: Relying on keeping system details secret for security; weak because secrecy can be discovered

    Security through obscurity depends solely on secrecy of design rather than robust mechanisms, and fails once the secret is revealed.

  4. Which of the following is a characteristic of ransomware?

    Answer: It encrypts victim files and demands payment for the decryption key

    Ransomware encrypts the victim's files and demands a ransom payment, typically in cryptocurrency, to restore access.

  5. What is the difference between authentication and authorization in cybersecurity?

    Answer: Authentication verifies identity; authorization determines what an authenticated user can access

    Authentication confirms who you are, while authorization determines what resources and actions you are permitted to use after being authenticated.

  6. A vulnerability scanner identifies an open port running an outdated service on a server. Why is this a security concern?

    Answer: Outdated services may contain known, unpatched vulnerabilities that attackers can exploit

    Outdated services often have publicly known vulnerabilities with available exploits, making them easy targets for attackers.

  7. Which of the following best describes the CIA triad in information security?

    Answer: Confidentiality, Integrity, and Availability

    The CIA triad represents the three core goals of information security: keeping data secret (confidentiality), accurate (integrity), and accessible (availability).