โ† All CTE Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real CTE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. A CTE candidate reviews a supplier contract for a cloud-based network management system. Which clause is MOST critical for managing third-party cybersecurity risk?

    Answer: Right-to-audit and security assessment provisions

    Right-to-audit clauses allow the carrier to assess and verify a supplier's security posture, ensuring third-party controls meet required standards.

  2. What is the purpose of a 'purple team' exercise in a telecommunications security program?

    Answer: Combining red team offensive techniques with blue team defensive feedback in real-time

    Purple teaming integrates offensive red team tactics with defensive blue team operations simultaneously to improve detection and response capabilities.

  3. Which encryption standard is recommended by NIST for protecting data in transit across telecom backbone networks against future quantum computing threats?

    Answer: CRYSTALS-Kyber (post-quantum KEM)

    CRYSTALS-Kyber is NIST's selected post-quantum key encapsulation mechanism designed to resist attacks from quantum computers.

  4. A telecom provider's security operations center detects unusual GRE tunnel traffic originating from a core router. This pattern is MOST consistent with:

    Answer: An advanced persistent threat using GRE tunneling for command-and-control exfiltration

    APT actors commonly abuse GRE tunneling to encapsulate C2 traffic within legitimate-looking protocols and bypass perimeter detection.

  5. Under the telecom industry's shared responsibility model for cloud services, which security domain remains the carrier's responsibility when using IaaS for network functions?

    Answer: Operating system hardening and application security

    In IaaS, the cloud provider manages physical and hypervisor security while the customer is responsible for OS, middleware, and application-layer security.

  6. A telecom executive must implement a cybersecurity governance framework. Which document establishes the organization's overall security intent and management direction?

    Answer: Information security policy

    An information security policy is the top-level governance document that defines management's security objectives, principles, and responsibilities.

  7. Which attack technique specifically exploits trust relationships between telecom peering partners to inject malicious routes into a carrier's network?

    Answer: BGP prefix hijacking via peering session compromise

    BGP prefix hijacking through compromised peering sessions exploits the inherent trust between BGP peers to announce unauthorized routes into the global routing table.