Cybersecurity Fundamentals & Concepts Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Fundamentals & Concepts flashcards as text
What distinguishes a zero-day vulnerability from other vulnerabilities?
Answer: It is exploited before the vendor is aware or has issued a patch
A zero-day vulnerability is one that is unknown to the software vendor and therefore has no patch available at the time of exploitation.
What is the role of threat intelligence in cybersecurity operations?
Answer: To provide context about threats enabling informed defensive decisions
Threat intelligence aggregates information about adversaries, TTPs, and indicators of compromise to help organizations anticipate and respond to threats.
A security team discovers that an attacker has been silently collecting data for months. This is characteristic of which threat type?
Answer: Advanced Persistent Threat (APT)
An APT is a prolonged, stealthy attack where an adversary remains undetected while continuously exfiltrating data.
Which hashing algorithm is currently recommended for password storage due to its resistance to brute-force attacks?
Answer: bcrypt
bcrypt is a password hashing algorithm that intentionally slows down computation, making brute-force attacks significantly harder.
What is the primary risk associated with using default credentials on network devices?
Answer: Unauthorized access since attackers know the default values
Default credentials are publicly known, making devices that retain them trivially exploitable by attackers.
Which security principle states that systems should fail in a secure state rather than an insecure one?
Answer: Fail-safe defaults
Fail-safe defaults ensure that when a system fails or encounters an error, access is denied rather than granted.
What is the key difference between symmetric and asymmetric encryption?
Answer: Symmetric uses one shared key; asymmetric uses a public-private key pair
Symmetric encryption uses the same key for encryption and decryption, while asymmetric uses mathematically related public and private keys.