Confidentiality & Data Security Flashcards
7 cards from real CET practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Confidentiality & Data Security flashcards as text
A technician receives a USB drive from an unknown source to use for a firmware update. The safest first step is to:
Answer: Scan it with up-to-date antivirus/antimalware software on an isolated system
Unknown USB drives are a common malware delivery vector; scanning on an isolated system before use prevents potential infection of critical equipment.
Which of the following best describes 'data integrity' in an electronics security context?
Answer: Ensuring data has not been altered or corrupted without authorization
Data integrity ensures that information remains accurate and unmodified except through authorized processes, often verified using checksums or hashing.
An employee reuses the same password across multiple work systems. This practice is dangerous primarily because:
Answer: A breach on one system exposes all systems using that password
Password reuse means a single compromised credential can grant attackers access to every system where that password is used, a technique known as credential stuffing.
In the context of secure data disposal, degaussing is effective for:
Answer: Magnetic storage media such as HDDs and magnetic tape
Degaussing uses powerful magnetic fields to erase data on magnetic media; it is ineffective on SSDs, flash memory, or optical media.
What is the role of a firewall in a networked electronics environment?
Answer: To monitor and control incoming and outgoing network traffic based on security rules
A firewall filters network traffic according to defined rules, blocking unauthorized connections while permitting legitimate communication.
Which of the following is an example of a 'man-in-the-middle' (MitM) attack?
Answer: Intercepting and potentially altering communications between two parties without their knowledge
In a MitM attack, an attacker secretly positions themselves between two communicating parties to intercept, read, or modify their exchange.
A company policy requires technicians to log out of all systems before leaving their workstation. This practice primarily protects against:
Answer: Unauthorized physical access to systems by other individuals
Logging out prevents unauthorized users from accessing systems through an unattended, already-authenticated session—a basic but critical physical security measure.