Percipio - General Security Concepts Literacy

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/16

flashcard set

Earn XP

Description and Tags

CompTIA Security+ (SY0-701): General Security Concepts Literacy (Beginner Level) About this Skill Benchmark The General Security Concepts Literacy (Beginner Level) benchmark measures your understanding of the foundational elements of cybersecurity. You will be evaluated on your knowledge of the core principles that guide security practices, such as confidentiality, integrity, and availability (the CIA triad), and the types of security controls used to protect assets. A learner who scores high on this benchmark demonstrates literacy in many areas of this domain and understands the essential principles and policies that form the bedrock of information security, including the identification of security goals. Topics covered: Provide an overview of the CIA Triad which includes confidentiality, integrity, and availability Define non-repudiation Compare authentication, authorization, and accounting Outline how to authenticate people Outline how to authenticate systems Compare authorization models Compare control categories like technical, managerial, operational, and physical Compare control types including preventive, deterrent, detective, corrective, compensating, and directive Outline the use of gap analysis in the context of security Provide an overview of the Zero Trust control plane including adaptive identity, threat scope reduction, policy-driven access control, and Policy Administrator Provide an overview of the Zero Trust data plane which includes implicit trust zones, subject/system, and Policy Enforcement Points Compare deception technologies such as honeypots, honeynets, honeyfiles, and honeytokens Define preventative physical security controls like bollards, access control vestibule, access badges/cards, fencing, gates, mantraps, and security guards Outline detective physical security controls like video surveillance, lighting, and infrared, pressure, microwave, and ultrasonic sensors Outline change management business processes including approval, ownership, stakeholders, impact analysis, test results, backout plan, maintenance window, and standard operating procedures Define change management technical implications like allow lists, deny lists, restricted activities, downtime, service restart, application restart, legacy applications, and dependencies Understand the importance of comprehensive documentation and version control View less Why take a Skill Benchmark? Determine your skill level in a particular area โ€“ you canโ€™t fail Get personalized recommendations targeted to improving your skills Skip the material you already know Help your company gauge where to target its resources Challenge yourself to learn new skills and improve your score What to expect: Mostly multiple choice, but some matching and ranking questions Immediate results and learning recommendations Your scores not visible to other learners

Last updated 4:19 AM on 10/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

17 Terms

1
New cards

Which security goal controls an attacker's ability to get unauthorized access to data or information from an application or system?

Instruction:ย Choose the option that best answers the question.ย 

  • Non-repudiation

  • Integrity

  • Confidentiality

  • Availability


Confidentiality

2
New cards

Which security control enforces the inability of a subject to deny that they participated in a digital transaction, agreement, contract, or communication such as an email?

Instruction:ย Choose the option that best answers the question.ย 

  • Integrity

  • Availability

  • Non-repudiation

  • Confidentiality


Non-repudiation

3
New cards

What is the process of granting an authenticated entity permission to access a resource or perform a specific function?

Instruction:ย Choose the option that best answers the question.ย 

  • Availability

  • Authorization

  • Authentication

  • Accounting


Authorization

4
New cards

Which of these are common ways to authenticate people?

Instruction:ย Choose all options that best answer the question.ย 

  • A network interface MAC address

  • An X.509 device certificate

  • A QR or other code they present on a device

  • A smart card token or fob that they possess

  • A biometric attribute

  • A password, PIN, or passphrase they know


A QR or other code they present on a device

A smart card token or fob that they possess

A biometric attribute

A password, PIN, or passphrase they know

5
New cards

What is one way to enable authentication of non-traditional network endpoints such as smart card readers, HVAC systems, medical equipment, and IP-enabled door locks?

Instruction:ย Choose the option that best answers the question.ย 

  • Protected access files

  • Packet mode

  • Repudiation

  • Endpoint fingerprinting


Endpoint fingerprinting

6
New cards

What is a strict mathematical model where access to resources is determined by the system based on predefined security labels and rules?

Instruction:ย Choose the option that best answers the question.ย 

  • DAC

  • MAC

  • ABAC

  • RBAC


MAC

7
New cards

Which category of controls supports ongoing maintenance, due care, and continual improvement such as conducting tested patch management?

Instruction:ย Choose the option that best answers the question.ย 

  • Technical

  • Physical

  • Managerial

  • Operational


Operational

8
New cards

Which type of security control is made up of mandatory policies and regulations that are in place to maintain consistency and compliance?

Instruction:ย Choose the option that best answers the question.ย 

  • Preventative

  • Deterrent

  • Corrective

  • Directive


Directive

9
New cards

What is a comprehensive appraisal that helps organizations determine the difference between the current state of their information security to specific industry requirements guidance and best practices?

Instruction:ย Choose the option that best answers the question.ย 

  • External audit

  • Security controls assessment

  • Vulnerability assessment

  • Gap analysis


Gap analysis

10
New cards

What is the term for an evolving set of cybersecurity initiatives that move defenses from static, network-based perimeters to focus on users, assets, and resources?

Instruction:ย Choose the option that best answers the question.ย 

  • Zero trust

  • Trust but verify

  • Transitive trust

  • Zero-day malware


Zero trust

11
New cards

What is defined by explicit trust zones, such as data centers, DMZs, and the public Internet?

Instruction:ย Choose the option that best answers the question.ย 

  • Zero Trust data plane

  • Zero Trust service plane

  • Zero Trust control plane

  • Zero Trust management plane


Zero Trust data plane

12
New cards

What is a system (e.g., a web server) or resource that is designed to be attractive to potential attackers and intruders?

Instruction:ย Choose the option that best answers the question.ย 

  • Honey file

  • Honeynet

  • Honeypot

  • Honey token


Honeypot

13
New cards

Which are preventative physical security controls?

Instruction:ย Choose all options that best answer the question.ย 

  • IDS

  • Signage

  • Fences

  • Mantraps

  • Gates

  • Bollards


Signage

Fences

Mantraps

Gates

Bollards

14
New cards

Which lightning systems are designed for reserve or on-hold use or to supplement permanent systems?

Instruction:ย Choose the option that best answers the question.ย 

  • Continuous lighting

  • Moveable lighting hardware

  • Emergency lighting

  • Stand-by lighting


Stand-by lighting

15
New cards

What is the methodical approach to handling the transition or modification of an organization's goals, processes, or technologies?

Instruction:ย Choose the option that best answers the question.ย 

  • Change management

  • Configuration management

  • Problem management

  • Incident management


Change management

16
New cards

Which initiative consists of planned and unplanned downtime (e.g., an outage) and must be considered with technical change management when making modifications or performing migrations?

Instruction:ย Choose the option that best answers the question.ย 

  • Availability

  • Resiliency

  • Capacity

  • Durability


Availability

17
New cards

What is a set of data, tools, utilities, and processes used to support configuration management?

Instruction:ย Choose the option that best answers the question.ย 

  • CMS

  • CMDB

  • ITSM

  • CSP


CMS