Cybersecurity & Digital Surveillance Flashcards
7 cards from real CSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity & Digital Surveillance flashcards as text
A surveillance system administrator wants to ensure that only authorized applications run on the surveillance server. Which security control best achieves this?
Answer: Application whitelisting
Application whitelisting allows only pre-approved software to execute on a system, blocking unauthorized or malicious programs from running even if they bypass antivirus detection.
What does 'end-to-end encryption' mean in the context of a networked surveillance system?
Answer: Video data is encrypted from the camera all the way to the final viewing or storage destination without decryption in transit
End-to-end encryption ensures video streams remain encrypted throughout their entire journey from the camera to the endpoint, preventing interception at intermediate network points.
Which of the following is a social engineering attack that could compromise a surveillance system's cybersecurity?
Answer: Tricking an employee into revealing login credentials over the phone
Social engineering attacks manipulate people rather than systems — tricking employees into disclosing credentials bypasses technical security controls entirely.
In cybersecurity, what is 'least privilege' as applied to surveillance system user accounts?
Answer: Users are granted only the minimum permissions necessary to perform their job functions
The principle of least privilege limits user access rights to only what is required for their specific role, reducing the potential damage from compromised accounts or insider threats.
What is the significance of CVE (Common Vulnerabilities and Exposures) numbers in managing surveillance device security?
Answer: They identify specific publicly known security vulnerabilities in hardware and software
CVE numbers are standardized identifiers for publicly disclosed security vulnerabilities, allowing surveillance teams to track, prioritize, and patch known flaws in their devices and software.
Why should surveillance system administrators use a dedicated management network (out-of-band management) when possible?
Answer: To separate device administration traffic from surveillance data traffic, reducing attack exposure
Out-of-band management isolates administrative access on a separate network, ensuring that even if the main surveillance network is compromised, management interfaces remain protected.
What is a 'zero-day vulnerability' in the context of surveillance system cybersecurity?
Answer: A security flaw that is unknown to the vendor and has no available patch
A zero-day vulnerability is a software or hardware flaw that the vendor is unaware of and for which no patch exists, giving defenders zero days to prepare before it can be exploited.