โ† All CCP Flashcard Decks

Cybersecurity Fundamentals & Concepts Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity Fundamentals & Concepts flashcards as text
  1. Which cryptographic concept ensures that a sender cannot deny having sent a message?

    Answer: Non-repudiation

    Non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message.

  2. A company stores sensitive data encrypted at rest. Which security property is being protected?

    Answer: Confidentiality

    Encrypting data at rest protects confidentiality by preventing unauthorized access to stored information.

  3. What is the primary purpose of a Public Key Infrastructure (PKI)?

    Answer: To manage digital certificates and public-key encryption

    PKI manages the creation, distribution, and revocation of digital certificates that bind public keys to identities.

  4. Which attack type exploits trust relationships between a user's browser and a website to perform unauthorized actions?

    Answer: Cross-Site Request Forgery (CSRF)

    CSRF exploits the trust a web application has in an authenticated user's browser to perform unintended actions.

  5. In the context of access control, what does 'least privilege' mean?

    Answer: Users receive only the minimum permissions needed to perform their job

    Least privilege limits user access rights to only what is necessary to perform authorized tasks, reducing attack surface.

  6. What is the difference between a vulnerability and an exploit?

    Answer: A vulnerability is a weakness; an exploit is code or technique that takes advantage of it

    A vulnerability is a weakness in a system, while an exploit is a method or code that leverages that vulnerability to cause harm.

  7. Which security model enforces access based on classification labels and user clearance levels?

    Answer: Mandatory Access Control (MAC)

    MAC uses system-enforced labels (e.g., Top Secret, Secret) and user clearances to control access, common in government systems.