โ† All CST Flashcard Decks

CST Network Security & Cybersecurity for Surveillance Flashcards

6 cards from real CST practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CST Network Security & Cybersecurity for Surveillance flashcards as text
  1. What is the BEST method to verify the integrity of a firmware update file before installing it on a surveillance device?

    Answer: Verify the file's cryptographic hash (MD5/SHA) against the manufacturer's published value

    Comparing the cryptographic hash of the downloaded file against the manufacturer's published hash confirms the file has not been tampered with.

  2. What is the function of a DMZ (demilitarized zone) in a surveillance network architecture?

    Answer: To expose specific surveillance services to the internet while protecting the internal network

    A DMZ isolates publicly accessible surveillance components (like remote viewing servers) from the internal protected network.

  3. Which practice helps protect against brute-force attacks on IP camera login portals?

    Answer: Enabling account lockout after a set number of failed login attempts

    Account lockout policies limit the number of failed login attempts, making brute-force credential attacks impractical.

  4. What is role-based access control (RBAC) in the context of a surveillance system?

    Answer: Assigning specific permissions to users based on their job function

    RBAC limits each user's access to only the features and data necessary for their role, reducing insider threat risk.

  5. Why should unused network ports on a surveillance switch be administratively disabled?

    Answer: To prevent unauthorized devices from being plugged into the network

    Disabling unused switch ports prevents an attacker or unauthorized device from gaining network access by physically connecting to an open port.

  6. A CST technician is asked to perform a security audit on a surveillance system. Which tool would BEST identify open, potentially vulnerable ports on surveillance devices?

    Answer: A port scanner such as Nmap

    A port scanner like Nmap probes network devices to identify open ports and running services that may present security vulnerabilities.