โ† All CPA Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. Which attack technique involves intercepting communication between two parties without their knowledge?

    Answer: Man-in-the-Middle (MitM)

    A Man-in-the-Middle attack positions the attacker between two communicating parties to intercept or alter data in transit.

  2. What is the primary purpose of a Security Information and Event Management (SIEM) system?

    Answer: Aggregating and analyzing security logs in real time

    A SIEM collects, correlates, and analyzes log data from multiple sources to detect and respond to security threats in real time.

  3. Which type of malware disguises itself as legitimate software to trick users into installing it?

    Answer: Trojan Horse

    A Trojan Horse masquerades as benign or useful software while secretly performing malicious actions once executed.

  4. In the context of risk management, what does 'residual risk' mean?

    Answer: Risk that remains after controls have been applied

    Residual risk is the level of risk that persists even after security controls and mitigation measures have been implemented.

  5. Which protocol is commonly used to securely transmit data over the web by encrypting HTTP traffic?

    Answer: HTTPS

    HTTPS (HTTP Secure) uses TLS/SSL encryption to protect data transmitted between a web browser and server.

  6. What is 'privilege escalation' in cybersecurity?

    Answer: Gaining higher access rights than originally authorized

    Privilege escalation occurs when an attacker exploits a vulnerability to gain elevated permissions beyond what was originally granted.

  7. Which of the following best describes a 'zero-day' vulnerability?

    Answer: A vulnerability unknown to the vendor with no available patch

    A zero-day vulnerability is an unknown security flaw for which the vendor has had zero days to prepare a fix.