โ† All APRP Flashcard Decks

Physical and Information Security Flashcards

5 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 5 Physical and Information Security flashcards as text
  1. Which of the following is the most effective method to protect sensitive payment information stored on servers?

    Answer: Encrypting data at rest

    Encrypting data at rest is the most effective method to protect sensitive payment information stored on servers. Even if an attacker gains unauthorized access to the server or the storage media, the encrypted data remains unreadable and unusable without the decryption key. While firewalls, strong passwords, and antivirus software are important, they primarily protect against unauthorized access or malware, not directly the data once it's compromised on the storage medium.

  2. Which principle ensure that users only have access to the information and resources necessary for their job functions?

    Answer: Least privilege

    The principle of 'least privilege' ensures that users, processes, or systems are granted only the minimum level of access and permissions required to perform their legitimate job functions. This security best practice limits the potential impact of a compromise by restricting what an attacker or a malicious insider can do. It reduces the attack surface and minimizes the damage from unauthorized actions.

  3. Which type of attack involves intercepting and potentially altering communication between two parties without their knowledge?

    Answer: Man-in-the-middle attack

    A Man-in-the-Middle (MitM) attack involves an attacker secretly relaying and potentially altering the communication between two parties who believe they are directly communicating with each other. The attacker intercepts the communication, reads or modifies it, and then passes it on, making both parties unaware of the interception. This allows for eavesdropping, data manipulation, and impersonation.

  4. What is the primary purpose of implementing a comprehensive security police in an organization?

    Answer: To protect the organization's assets

    A comprehensive security policy's fundamental goal is to safeguard an organization's valuable assets, including data, systems, and physical infrastructure. It establishes rules and procedures to protect against threats like cyberattacks, fraud, and unauthorized access. While compliance and error prevention are important, they serve the overarching purpose of asset protection, ensuring business continuity and maintaining trust.

  5. Which of the following is a common physical security measure to protect against unauthorized access to a data center?

    Answer: Biometric access control

    Biometric access control, such as fingerprint or retina scanners, is a robust physical security measure designed to prevent unauthorized individuals from entering restricted areas like data centers. It verifies unique biological characteristics, making it significantly harder to bypass than traditional methods. This directly enhances the physical protection of sensitive facilities and their contents.