Security & Compliance Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
Which compliance regulation primarily governs the protection of cardholder data in payment processing systems?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) sets requirements for protecting cardholder data in payment card environments.
During a penetration test on an integrated system, the tester finds an open Telnet port. Why is this a critical security concern?
Answer: Telnet transmits data including credentials in plaintext
Telnet sends all data, including usernames and passwords, unencrypted, making it trivial for an attacker to intercept credentials via packet capture.
A system integrator is asked to implement multi-factor authentication (MFA). Which combination represents true MFA?
Answer: PIN and fingerprint scan
True MFA combines factors from different categories: something you know (PIN) and something you are (fingerprint), satisfying two distinct authentication factors.
What is the role of a Certificate Authority (CA) in a Public Key Infrastructure (PKI)?
Answer: To issue and manage digital certificates that bind public keys to identities
A CA is a trusted entity that issues digital certificates, validating the association between a public key and the identity of its owner.
In the context of physical security for integrated systems, what is 'tailgating'?
Answer: An unauthorized person following an authorized person through a secured door
Tailgating is a physical security breach where an unauthorized individual gains access to a restricted area by following closely behind an authorized person.
A regulatory audit requires demonstrating data retention policies. Which document type best satisfies this requirement?
Answer: Data classification and retention policy
A data classification and retention policy formally defines how long different types of data must be kept and how they should be handled, satisfying audit requirements.
Which attack method involves an adversary intercepting and potentially altering communication between two parties without their knowledge?
Answer: Man-in-the-middle (MitM) attack
A man-in-the-middle attack occurs when an attacker secretly intercepts and possibly modifies communications between two parties who believe they are communicating directly.