Cybersecurity Fundamentals & Concepts Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Fundamentals & Concepts flashcards as text
What is the primary function of a Security Information and Event Management (SIEM) system?
Answer: To aggregate and correlate security logs for real-time analysis
A SIEM collects and analyzes log data from across an organization's infrastructure to detect threats and generate alerts.
Which type of malware disguises itself as legitimate software to trick users into installing it?
Answer: Trojan Horse
A Trojan Horse masquerades as legitimate software while secretly performing malicious actions.
What is 'defense in depth' as a cybersecurity strategy?
Answer: Layering multiple security controls so that failure of one does not compromise the system
Defense in depth uses multiple overlapping security controls so an attacker must defeat several layers to succeed.
Which protocol is used to securely transfer files and provides encrypted channel over SSH?
Answer: SFTP
SFTP (SSH File Transfer Protocol) uses SSH to provide encrypted, secure file transfer capabilities.
An attacker intercepts communications between two parties without their knowledge. This is an example of what attack?
Answer: Man-in-the-Middle (MitM)
A Man-in-the-Middle attack involves secretly intercepting and potentially altering communications between two parties.
What is the purpose of a Certificate Revocation List (CRL)?
Answer: To identify certificates that have been revoked before their expiration date
A CRL is a list published by a Certificate Authority that identifies digital certificates that have been revoked and should no longer be trusted.
Which concept describes the process of verifying the integrity of software using cryptographic hashes?
Answer: File hashing
File hashing generates a fixed-length digest of a file; comparing hash values confirms whether a file has been altered.