1/23
Practice question-and-answer flashcards based on lecture notes covering fundamental cybersecurity concepts, threat history, the CIA triad, key roles, and major governing bodies.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the definition of Cybersecurity according to the lecture notes?
The practice of protecting systems, networks, and data from digital attacks (akin to locking doors, setting up cameras, and securing valuables in a digital space).
How do Cybersecurity, IT Security, and Information Security (Infosec) differ from one another?
Cybersecurity focuses specifically on defending against digital threats like hackers, malware, and phishing. IT Security has a broader scope covering all tech assets including physical server rooms, hardware maintenance, and infrastructure. Information Security is the overarching umbrella covering both digital and physical data protection.
What are the four core objectives of Information Security?
Which legal and regulatory compliance standards are explicitly mentioned in the notes?
HIPAA for healthcare privacy and PCI-DSS for credit card processing.
What digital threat emerged in the 1970s according to the historical timeline?
The Creeper virus, which was the first digital threat and displayed a non-malicious message.
Which disruptive malware affected the early internet in the 1980s?
The Morris Worm.
What common security threats characterized the 1990s–2000s era?
The rise of phishing emails and Distributed Denial of Service (DDoS) attacks taking down websites.
What threats and defense mechanisms characterize the 2010s–Present timeline?
State-sponsored targeted attacks, ransomware targeting critical sectors (healthcare, schools), cloud misconfigurations, and AI-driven defense mechanisms.
What specific software exploits does Application Security protect against?
SQL injection and buffer overflows.
Under what operational model does Cloud Security protect cloud infrastructure and workloads?
The Shared Responsibility Model.
What is the role of Identity & Access Management (IAM)?
Ensures only authorized users access appropriate resources.
What are the three pillars of the CIA Triad?
Confidentiality, Integrity, and Availability.
How is Confidentiality maintained within the CIA Triad?
By ensuring information is accessible only to authorized individuals using encryption, access controls, and data classification labels.
How is Integrity defined and enforced in the CIA Triad?
It ensures data remains accurate, trustworthy, and unaltered using hashing, checks, and digital signatures.
How is Availability defined and enforced in the CIA Triad?
It ensures systems and data are operational and accessible when needed using redundancy, automated backups, and DDoS protection.
What are the primary responsibilities of a Chief Information Security Officer (CISO)?
Sets overall security vision, policies, team management, and executive reporting.
What are the primary responsibilities and tools associated with a Security Analyst?
Frontline detection, monitoring networks using SIEM tools, and incident response.
What is the primary difference between a Security Engineer and a Security Architect?
Engineers build firewalls/scans, while Architects design long-term infrastructure.
What tools are mentioned for a Penetration Tester (Ethical Hacker)?
Nmap and Metasploit.
Which standards does a Risk & Compliance Officer enforce adherence to?
ISO 27001 and GDPR.
What certifications are offered by (ISC)²?
CISSP (the gold-standard), CC, SSCP, CCSP, and CCSLP.
When was ISACA founded, what is its focus, and what framework does it utilize?
ISACA was founded in 1969; it focuses on auditing, IT governance (using the COBIT framework), and risk.
What key certifications are offered by ISACA?
CISA, CISM, and CRISC.
When was EC-Council founded, what simulation platform does it use, and what is its famous certification?
Founded in 2001; it focuses on hands-on practical/technical skills via CyberQ simulations and is famous for the CEH (Certified Ethical Hacker) certification.