โ† All CCISO Flashcard Decks

Core IT Security Flashcards

7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Core IT Security flashcards as text
  1. Which network security device inspects traffic at the application layer and can make forwarding decisions based on the content of HTTP requests?

    Answer: Web Application Firewall (WAF)

    A WAF operates at Layer 7 and inspects HTTP/HTTPS content to detect and block application-layer attacks like SQL injection and XSS.

  2. An IDS generates an alert for traffic that is actually legitimate business activity. This is an example of which type of IDS error?

    Answer: False positive

    A false positive occurs when an IDS incorrectly identifies benign traffic as malicious, triggering an unnecessary alert.

  3. A CISO wants to test the organization's security posture by simulating a real-world attack with full knowledge of internal systems. Which assessment type should be used?

    Answer: White-box penetration test

    A white-box test gives the tester full knowledge of internal architecture, source code, and configurations to conduct a thorough assessment.

  4. Which secure network architecture places public-facing servers in an isolated segment that is separate from both the internal network and the internet?

    Answer: DMZ (Demilitarized Zone)

    A DMZ isolates public-facing servers so that if compromised, attackers cannot directly reach the internal corporate network.

  5. An organization implements PKI to manage digital certificates. Which entity is responsible for issuing and revoking certificates within the PKI hierarchy?

    Answer: Certificate Authority (CA)

    The CA is the trusted entity that issues digital certificates and maintains revocation records within the PKI trust hierarchy.

  6. A security team wants to identify unauthorized devices connecting to the corporate network. Which technology provides real-time visibility into connected endpoints?

    Answer: Network Access Control (NAC)

    NAC enforces endpoint compliance and controls which devices are permitted to access the network, providing visibility into all connected assets.

  7. Which type of malware conceals its presence by modifying operating system functions or kernel components, making it extremely difficult to detect?

    Answer: Rootkit

    Rootkits embed themselves in the OS kernel or bootloader, hiding their presence by intercepting and modifying system calls.