Security, Compliance & Identity Concepts Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security, Compliance & Identity Concepts flashcards as text
Which encryption type uses the same key for both encrypting and decrypting data?
Answer: Symmetric encryption
Symmetric encryption uses a single shared key for both encryption and decryption, making it faster but requiring secure key distribution.
What is the purpose of 'data classification' in a compliance framework?
Answer: To categorize data based on sensitivity to apply appropriate security controls
Data classification assigns sensitivity labels (such as public, internal, confidential, or highly confidential) to help organizations apply the correct security and compliance controls.
Which of the following is an example of a 'detective' security control?
Answer: Intrusion detection system alerting on suspicious activity
Detective controls identify and alert on security incidents after they occur; an IDS monitors network traffic and raises alerts when suspicious patterns are detected.
In identity management, what is a 'claim'?
Answer: A statement made by an identity provider about a user's attributes or permissions
A claim is an assertion made by an identity provider about a subject, such as their name, role, or group membership, contained within a security token.
What does 'non-repudiation' ensure in a security context?
Answer: That a user cannot deny having performed an action
Non-repudiation provides proof that a specific entity performed an action, preventing them from later denying it, often achieved through digital signatures.
Which type of malware disguises itself as legitimate software to trick users into installing it?
Answer: Trojan horse
A Trojan horse masquerades as legitimate or benign software while carrying a malicious payload that executes when the user installs or runs it.
What is the role of a 'Certificate Authority (CA)' in a Public Key Infrastructure?
Answer: To issue, sign, and revoke digital certificates that bind public keys to identities
A CA is a trusted entity that issues digital certificates, verifying that a public key belongs to the stated entity and enabling trust in encrypted communications.