Cybersecurity & Risk Flashcards
7 cards from real CTE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
A telecom operator's 5G core network uses APIs exposed via HTTP/2. Which OWASP category represents the highest risk for these interfaces?
Answer: Broken Object Level Authorization (BOLA)
BOLA (formerly IDOR) is the top API security risk, where attackers access objects by manipulating resource identifiers in API calls.
What is the primary security concern with deploying Network Function Virtualization (NFV) in a telecommunications environment?
Answer: Hypervisor vulnerabilities can compromise multiple virtual network functions simultaneously
In NFV environments, a compromised hypervisor (VM escape) can expose all virtual network functions running on that physical host.
A CTE executive is establishing a Business Continuity Plan for cybersecurity incidents. Which metric defines the maximum acceptable time to restore a critical telecom service after a breach?
Answer: Recovery Time Objective (RTO)
RTO defines the maximum acceptable duration of a service outage before it causes unacceptable business impact.
Which type of cryptographic attack specifically targets the handshake process in TLS connections used to secure telecom management interfaces?
Answer: BEAST (Browser Exploit Against SSL/TLS)
BEAST exploits a vulnerability in TLS 1.0's CBC mode cipher implementation during the handshake to decrypt encrypted data.
An enterprise customer reports that calls originating from their PBX are being fraudulently redirected to international premium-rate numbers. This is best described as:
Answer: Toll fraud / PBX hacking
Toll fraud via PBX hacking involves unauthorized access to a PBX system to make calls to premium-rate or international numbers at the victim's expense.
In a telecom risk register, what does 'residual risk' represent after security controls are applied?
Answer: The risk that remains after existing controls are accounted for
Residual risk is the remaining exposure after all implemented controls have reduced the inherent risk to an acceptable level.
A telecom provider implements STIR/SHAKEN. What specific security problem does this framework address?
Answer: Authenticating caller ID to combat spoofed robocalls
STIR/SHAKEN uses digital certificates to cryptographically attest the legitimacy of caller ID information, combating illegal caller ID spoofing.