Study Guide: Knowledge Areas and Objective
Security Fundamentals (15 test items)
1. Describe Confidentiality, Integrity, and Availability (CIA Triad)
Explanation:
The CIA triad is the foundation of cybersecurity. It ensures that information and systems are protected, reliable, and accessible.
Confidentiality: Keeping data private and only accessible to authorized users.
Analogy: Like locking your diary with a key — only you or someone you trust can read it.
Example: Encrypting emails with SSL/TLS so hackers cannot read them.Integrity: Making sure data is accurate and hasn’t been tampered with.
Analogy: Imagine sending a recipe to a friend. Integrity ensures your friend gets the exact recipe you wrote, not something changed along the way.
Example: Using a hash function like SHA-256 to verify a downloaded file hasn’t been altered.Availability: Ensuring data and services are available when needed.
Analogy: Electricity in your house — if the power is out, you can’t use your devices. Availability ensures the power stays on.
Example: Using a backup server or UPS to keep a website online even during outages.
Practice Question:
If a hacker intercepts your email and changes the content before it reaches your friend, which part of the CIA triad is violated?
Answer: Integrity.
2. Describe measures for establishing digital trust
Explanation:
Digital trust ensures that people, systems, and devices are who they claim to be and that actions cannot be denied later.
Identity proofing: Verifying a user’s real identity before giving access.
Example: Banks requiring a photo ID before opening an account online.Non-repudiation: Preventing someone from denying they performed an action.
Analogy: A digital signature on a contract proves the signer cannot later claim they didn’t sign it.
Example: Signing a document with an electronic signature using a private key.Attestation: Verifying that a system or device is in a trustworthy state.
Example: A laptop confirms it has up-to-date antivirus before connecting to a company network.
Practice Question:
Which measure prevents someone from denying they sent a sensitive email?
Answer: Non-repudiation.
3. Explain authentication, authorization, and accounting (AAA)
Explanation:
AAA is about controlling and tracking access in networks:
Authentication: Proving who you are.
Example: Logging in with a username and password, or using a fingerprint scanner.Authorization: Determining what you can do after logging in.
Example: You may log in (authentication) but can only view some files, not edit them (authorization).Accounting: Tracking what you do in a system.
Example: Audit logs showing which files you accessed and when.
Analogy:
Think of a hotel:
Authentication = showing your ID at the front desk.
Authorization = the room key lets you access only your room, not others.
Accounting = the hotel keeps a record of which services you used.
Practice Question:
If a user can log in but cannot delete files, which AAA component is controlling this?
Answer: Authorization.
4. Provide examples of Zero Trust
Explanation:
Zero Trust is a security model that assumes no user or device is automatically trusted, even inside the network. Access is continuously verified.
Examples:
Requiring multi-factor authentication for every login.
Limiting access to only specific files or apps needed for a job.
Segmenting networks so even internal users cannot access all systems.
Analogy:
It’s like a building where every room has its own locked door, even if you are already inside. You must keep proving your right to enter each room.
Practice Question:
What Zero Trust principle is applied when a user must re-enter their password to access sensitive financial records?
Answer: Continuous verification / least trust by default.
5. Describe deception and disruption technology
Explanation:
Deception and disruption technology is about tricking attackers or wasting their time, so they cannot harm real assets.
Examples:
Honeypots: Fake systems designed to attract attackers.
Honeynets: Entire fake networks to study attackers’ methods.
Honeyfiles: Fake sensitive files that trigger alerts if accessed.
Analogy:
It’s like putting a fake treasure chest with an alarm in your house to catch burglars without risking real valuables.
Practice Question:
What is the purpose of a honeypot?
Answer: To attract attackers and monitor their activity without risking real systems.
6. Explain how binary, hexadecimal, and decimal are used in cryptography
Explanation:
Cryptography relies on numbers and coding systems to secure data.
Binary (0s and 1s): Computers use binary to process and store all data, including encrypted messages.
Hexadecimal (0–F): A shorthand for binary; easier to read and use in cryptography keys.
Decimal (0–9): Often used in PINs, passwords, or numeric cryptography schemes.
Example:
Encryption keys are often represented in hexadecimal because it’s shorter and easier to handle than long binary sequences.
Practice Question:
Why do cryptography systems often display keys in hexadecimal instead of binary?
Answer: Hexadecimal is shorter and easier for humans to read.
7. Explain the purpose of least privilege principles
Explanation:
Least privilege means giving users or programs only the access they need to perform their tasks, no more.
Analogy:
If you hire a delivery person, you give them access to the delivery area, not the entire office.
Example:
A user in accounting can view financial records but cannot access HR employee data or modify system settings.
Practice Question:
A marketing employee can only edit marketing files but not payroll. Which security principle is this?
Answer: Least privilege.
Cyber Threats and Vulnerabilities (20 test items)
1. Describe web and software sources of security vulnerabilities
Explanation:
Websites and software can have flaws that hackers exploit. These flaws are called vulnerabilities.
Examples:
Injections (e.g., SQL injection): Hackers insert malicious code into input fields to access data.
Buffer overflows: Software accepts more input than it can handle, causing crashes or giving attackers access.
Jailbreaking: Modifying a device’s OS to bypass security controls.
Race conditions: Exploiting timing issues in software to gain unauthorized access.
Analogy:
It’s like leaving a window unlocked or a gate broken in a house. Hackers can sneak in through these weak spots.
Practice Question:
If a hacker types code into a website search box and steals the database, what vulnerability is being exploited?
Answer: SQL Injection.
2. Discuss attributes of threat actors and their goals
Explanation:
Threat actors are people or groups trying to exploit vulnerabilities. They have different motivations.
Types and Goals:
Internal threats: Employees who misuse access (e.g., stealing company data).
External threats: Hackers outside the organization.
Financial gain: Stealing money, ransomware attacks.
Espionage: Spying on competitors or governments.
Data theft: Stealing personal, corporate, or intellectual property.
Analogy:
Think of a threat actor as a burglar (external) or a careless staff member (internal). Their goal could be money, secrets, or causing chaos.
Practice Question:
What type of threat actor might an employee who downloads sensitive files to sell to a competitor represent?
Answer: Internal threat for espionage.
3. Describe types of viruses
Explanation:
A virus is malware that attaches itself to files and spreads when the files are shared.
Types:
File infectors: Infect executable files (.exe).
Macro viruses: Infect documents like Word or Excel macros.
Boot sector viruses: Infect the startup section of disks.
Analogy:
A virus is like a contagious cold—it spreads from one person (file) to another.
Practice Question:
If a virus infects a Word document and spreads when opened, what type is it?
Answer: Macro virus.
4. Discuss types of security vulnerabilities
Explanation:
Vulnerabilities are weaknesses in software or systems that attackers exploit.
Types:
Backdoors: Hidden access points bypassing normal security.
Zero-day: Vulnerabilities unknown to the vendor, exploited before a fix exists.
Unpatched software: Missing updates make systems vulnerable.
Analogy:
Backdoors are like secret entrances to a house, zero-days are unknown cracks in the wall, and unpatched software is like leaving doors unlocked.
Practice Question:
What is a zero-day vulnerability?
Answer: A flaw unknown to the software vendor, exploited by attackers before a patch is available.
5. Discuss social engineering scams and attacks
Explanation:
Social engineering attacks trick people into revealing information or performing actions that compromise security.
Examples:
Phishing: Emails pretending to be from a trusted source to steal credentials.
Phone scams: Calls claiming to be tech support to get passwords.
Email scams: Fake offers or invoices to trick users into giving money or information.
Analogy:
It’s like a con artist pretending to be a friend to get access to your valuables.
Practice Question:
Receiving an email asking you to “verify your bank account” with a link is an example of?
Answer: Phishing attack.
6. Describe the purpose, methods, and mechanics of a DDoS attack
Explanation:
A Distributed Denial of Service (DDoS) attack floods a system with traffic to make it unavailable.
Purpose: Disrupt service for users, damage reputation, or distract from another attack.
Methods:
Using botnets (networks of infected devices) to send massive traffic.
Overwhelming servers or network bandwidth.
Analogy:
It’s like hundreds of people crowding a store entrance so no one can get in.
Practice Question:
A website becomes unreachable because thousands of infected devices are sending traffic at the same time. What attack is this?
Answer: DDoS attack.
7. Describe the characteristics of types of malware
Explanation:
Malware is malicious software designed to harm systems or steal data.
Types:
Viruses: Attach to files and spread.
Trojans: Pretend to be legitimate software but have hidden malware.
Worms: Spread automatically across networks.
Logic bombs: Trigger malware when a condition is met (e.g., a specific date).
Analogy:
Virus: A contagious illness.
Trojan: A gift box hiding poison.
Worm: A self-propagating pest.
Logic bomb: A timed firework that explodes under certain conditions.
Practice Question:
Malware that spreads without user interaction across a network is called?
Answer: Worm.
8. Describe cryptographic attacks
Explanation:
Cryptographic attacks aim to break encryption or tamper with data.
Examples:
Downgrade attack: Forces a system to use weaker encryption.
Collision attack: Finds two inputs producing the same hash, breaking integrity.
Birthday attack: Uses probability to find hash collisions faster than brute force.
Analogy:
A collision attack is like finding two different keys that open the same lock.
Practice Question:
What attack finds two messages with the same hash to trick a system?
Answer: Collision attack.
9. Discuss vulnerabilities of wireless networks
Explanation:
Wireless networks are more exposed than wired networks because data is transmitted through the air.
Vulnerabilities:
Weak encryption (WEP, WPA) allows attackers to intercept traffic.
Rogue access points mimic legitimate Wi-Fi networks.
Man-in-the-middle attacks intercept or alter wireless data.
Analogy:
It’s like shouting secrets in a crowded room—anyone nearby could hear them.
Practice Question:
Connecting to a fake Wi-Fi hotspot set up by an attacker is an example of?
Answer: Rogue access point attack.
Security and Design (20 test items)
1. Explain how using cloud infrastructure affects system security
Explanation:
Cloud infrastructure allows companies to store data and run applications on remote servers rather than local machines. While it offers scalability and convenience, it also introduces security considerations.
Impacts on security:
Shared responsibility: The cloud provider secures the infrastructure, but the user is responsible for configuring access and protecting data.
Data exposure risks: Misconfigured cloud storage can allow public access.
Access control challenges: Multiple users accessing cloud resources require strict authentication and permissions.
Analogy:
Using the cloud is like renting a storage unit: the facility provides locks and cameras, but you’re responsible for your own box and who has the key.
Practice Question:
What is a major security concern when using cloud storage?
Answer: Misconfigured access controls that expose data publicly.
2. Discuss the security implications of microservice architecture
Explanation:
Microservices break applications into smaller, independent services instead of a single large program.
Security implications:
More attack surfaces: Each microservice can be a potential entry point for attackers.
Authentication complexity: Services must securely verify each other’s identity.
Increased complexity: Monitoring and updating multiple services is harder than a single monolithic app.
Analogy:
It’s like a city with many small houses (microservices) instead of one big building. Each house needs its own locks and security cameras.
Practice Question:
Why might microservices increase security risk compared to a monolithic app?
Answer: They create more attack surfaces because each service can be targeted.
3. Differentiate between logical and physical segmentation
Explanation:
Segmentation separates networks or systems to improve security.
Logical segmentation: Uses software to separate networks or systems (e.g., VLANs).
Physical segmentation: Uses separate hardware (e.g., separate servers or switches).
Analogy:
Logical segmentation is like assigning different floors of a building to different teams without building walls. Physical segmentation is like giving each team a separate building.
Practice Question:
Using VLANs to separate finance and HR systems is an example of which segmentation?
Answer: Logical segmentation.
4. Explain how containerization and virtualization can increase security
Explanation:
Virtualization: Creates virtual machines (VMs) that isolate operating systems and applications from the physical hardware.
Containerization: Packages applications with their dependencies in isolated containers that share the OS kernel but are separated from other containers.
Security benefits:
Isolation prevents a compromise in one VM/container from affecting others.
Easier to apply updates and security patches.
Restricts access to the host system.
Analogy:
Virtual machines are like separate apartments in a building, each with its own door. Containers are like fully self-contained hotel rooms—isolated, but sharing the same building infrastructure.
Practice Question:
If an attacker compromises a container, why might other containers remain safe?
Answer: Containers are isolated, so the attack does not spread to others.
5. Describe security risks and challenges associated with the Internet of Things (IoT)
Explanation:
IoT devices are everyday objects connected to the internet, such as smart thermostats, cameras, and wearables.
Security risks:
Weak passwords and default credentials.
Lack of encryption for data in transit.
Limited ability to patch or update devices.
Large attack surfaces due to many connected devices.
Analogy:
IoT devices are like many small doors to your house. If each door is weak, it’s easier for an intruder to get in.
Practice Question:
Why are IoT devices often targeted by attackers?
Answer: They have weak security, are widely connected, and often lack updates.
6. Describe the concepts of backups, RAID, and UPS
Explanation:
Backups: Copies of data stored elsewhere to recover from loss.
RAID (Redundant Array of Independent Disks): Combines multiple drives for fault tolerance and improved performance.
UPS (Uninterruptible Power Supply): Provides temporary power during outages to prevent data loss.
Analogy:
Backups = photocopying important documents.
RAID = storing multiple copies of documents across drawers in case one drawer fails.
UPS = a generator that keeps lights on during a power outage.
Practice Question:
Which device provides temporary power during a blackout to prevent data loss?
Answer: UPS.
7. Identify examples of the CIA triad in network design
Explanation:
The CIA triad (Confidentiality, Integrity, Availability) is applied in network design:
Confidentiality: Encrypting data in transit with HTTPS or VPN.
Integrity: Using checksums or hashes to verify data hasn’t been modified.
Availability: Using UPS, redundant servers, or load balancers to ensure uptime.
Analogy:
Confidentiality = locking your mailbox.
Integrity = stamping letters to ensure they aren’t tampered with.
Availability = having multiple mailboxes in case one is broken.
Practice Question:
Using encryption to protect data in transit ensures which part of the CIA triad?
Answer: Confidentiality.
8. Explain the role of testing in building secure cyber architecture
Explanation:
Testing verifies that security measures are effective and identifies weaknesses before attackers can exploit them.
Examples:
Penetration testing: Simulating attacks to find vulnerabilities.
Vulnerability scanning: Automated checks for missing patches or misconfigurations.
Stress testing: Ensuring systems handle high loads or attacks.
Analogy:
Testing security is like performing fire drills and safety inspections in a building before a real fire occurs.
Practice Question:
What type of test simulates an attacker attempting to exploit vulnerabilities?
Answer: Penetration testing.
Next, we can move to Network and Data Security (15 test items).
Do you want me to continue with that section now?
You said:
yes
ChatGPT said:
Great! Let’s go through Network and Data Security thoroughly, with explanations, examples, analogies, and practice questions so it’s easy to understand.
Network and Data Security (15 test items)
1. Describe the purpose of cryptography
Explanation:
Cryptography is the practice of securing information by transforming it so only authorized people can understand it.
Purpose:
Protect confidentiality (keep data secret).
Ensure integrity (data hasn’t been changed).
Verify identity (authentication).
Analogy:
It’s like putting your letter in a locked box; only someone with the key can read it.
Practice Question:
What is the main goal of cryptography?
Answer: To protect data from unauthorized access and tampering.
2. Differentiate between public and private key cryptography
Explanation:
Public key cryptography: Uses a pair of keys – a public key to encrypt data and a private key to decrypt it. Good for sending messages securely.
Private key cryptography (symmetric): Uses the same key to encrypt and decrypt data. Faster but requires secure key sharing.
Analogy:
Public key: Like a mailbox – anyone can drop a letter in, but only the owner can open it.
Private key: Like a single lock on a diary – only someone with the key can open it.
Practice Question:
Which type of cryptography uses the same key for encryption and decryption?
Answer: Private key (symmetric) cryptography.
3. Discuss shift ciphers, Caesar ciphers, and substitution ciphers
Explanation:
These are basic encryption techniques:
Shift cipher: Moves letters in the alphabet by a set number.
Caesar cipher: A type of shift cipher, usually shifting 3 letters.
Substitution cipher: Replaces each letter with another symbol or letter.
Analogy:
It’s like writing a secret code in class so only your friend knows how to read it.
Practice Question:
If “A” is shifted 3 letters to “D,” what type of cipher is being used?
Answer: Caesar cipher.
4. Describe the three states of data
Explanation:
Data exists in three main states:
Data at rest: Stored on disks, databases, or devices.
Data in transit: Moving across networks.
Data in use: Being processed in memory or CPU.
Analogy:
At rest: A book on a shelf.
In transit: A book being delivered by mail.
In use: A book being read.
Practice Question:
Encrypting data while it is sent over the internet protects which state?
Answer: Data in transit.
5. Describe the importance and use of access control models
Explanation:
Access control ensures only authorized users access resources.
Models:
MAC (Mandatory Access Control): System controls access based on security policies.
DAC (Discretionary Access Control): Owner controls access to their resources.
RBAC (Role-Based Access Control): Access is based on user roles.
Analogy:
MAC: A security guard enforces strict rules.
DAC: You decide who can enter your room.
RBAC: People with certain jobs get access to certain areas.
Practice Question:
Which access control model allows the system to enforce strict security rules without user control?
Answer: MAC.
6. Discuss authentication and authorization of network resources
Explanation:
Authentication: Verifying a user’s identity (e.g., passwords, tokens, biometrics).
Authorization: Determining what resources an authenticated user can access.
Analogy:
Authentication: Showing your ID to enter a building.
Authorization: Your ID badge lets you enter certain rooms, not all.
Practice Question:
Logging in with a password confirms your identity. What is this called?
Answer: Authentication.
7. Describe how blockchains and hashing can be used for authentication and data integrity
Explanation:
Hashing: Converts data into a fixed-length string (hash) to verify integrity.
Blockchain: A chain of records secured by hashing; ensures data cannot be altered without detection.
Use in security:
Verify that data hasn’t been changed.
Authenticate transactions without a central authority.
Analogy:
Hash: Like a fingerprint for data.
Blockchain: Like a ledger where each page is sealed with a unique stamp—changing one page breaks the chain.
Practice Question:
What cryptographic technique ensures that data has not been altered?
Answer: Hashing.
Security Operations and Management (10 test items)
1. Describe common security policies
Explanation:
Security policies are formal rules that guide how an organization protects its information and systems.
Examples:
Acceptable Use Policy (AUP): Rules for how employees can use company devices and networks.
Information Security Policy: Outlines how data should be protected.
Business Continuity Plan (BCP): Ensures essential business functions continue during disruptions.
Disaster Recovery Plan (DRP): Steps to restore systems and data after disasters.
Analogy:
Policies are like traffic rules—they guide behavior to prevent accidents and maintain order.
Practice Question:
Which policy outlines the steps to recover data after a natural disaster?
Answer: Disaster Recovery Plan (DRP).
2. Discuss elements of disaster prevention and recovery plans
Explanation:
Disaster prevention and recovery plans prepare organizations to handle unexpected events.
Key Elements:
Risk assessment: Identify potential threats (fire, cyberattack).
Prevention: Firewalls, backups, UPS systems.
Recovery: Procedures to restore operations and data.
Testing: Drills to ensure the plan works.
Analogy:
It’s like having a fire escape plan, fire extinguishers, and backup water supply ready in a building.
Practice Question:
What is the purpose of testing a disaster recovery plan?
Answer: To ensure it works effectively during an actual disaster.
3. Describe types of firewalls
Explanation:
Firewalls monitor and control network traffic to protect systems.
Types:
Network-based firewalls: Protect the network perimeter.
Next-Generation Firewalls (NGFW): Inspect traffic deeper, including application-level threats.
Web Application Firewall (WAF): Protects web applications from attacks like SQL injection or XSS.
Analogy:
Firewall = Security guard at the entrance of a building.
NGFW = Guard who also checks bags for hidden weapons.
WAF = Guard specialized in checking online forms and transactions.
Practice Question:
Which firewall type protects a website specifically from attacks like SQL injection?
Answer: Web Application Firewall (WAF).
4. Explain the use of firewall access lists and rules to increase security
Explanation:
Firewalls use access control lists (ACLs) or rules to allow or block specific traffic.
Example Rules:
Block traffic from certain IP addresses.
Allow only certain services (e.g., web traffic on port 80).
Analogy:
It’s like a bouncer checking a guest list—some people are allowed in, others are denied.
Practice Question:
If a firewall blocks all traffic except HTTP and HTTPS, what type of control is this?
Answer: Access control list (ACL) rule.
5. Describe best practices for company messaging, email, and data security
Explanation:
Organizations implement rules to reduce risks from email and messaging.
Best Practices:
Avoid clicking unknown links (prevents phishing).
Encrypt sensitive emails.
Use company-approved communication tools.
Educate employees on social engineering.
Analogy:
It’s like teaching employees not to open suspicious packages or letters.
Practice Question:
Why should sensitive emails be encrypted?
Answer: To protect data confidentiality during transmission.
6. Describe the impact of change management on security
Explanation:
Change management ensures system changes are implemented securely and consistently.
Benefits:
Prevents accidental vulnerabilities.
Ensures patches, updates, or configuration changes don’t break security.
Tracks who made changes for accountability.
Analogy:
It’s like following instructions when renovating a building so you don’t accidentally remove load-bearing walls.
Practice Question:
Why is change management important in cybersecurity?
Answer: It ensures updates and changes do not introduce new security risks.
Security Protocols and Threat Mitigation (20 test items)
1. Provide examples of secure protocols
Explanation:
Secure protocols ensure that data transmitted over networks is protected from eavesdropping and tampering.
Examples:
SSH (Secure Shell): Secure remote login to servers.
HTTPS (Hypertext Transfer Protocol Secure): Secure web browsing using encryption.
TLS (Transport Layer Security): Encrypts data in transit, often used with HTTPS.
WPA2 (Wi-Fi Protected Access 2): Secures wireless networks.
Analogy:
Using secure protocols is like sending letters in a locked envelope rather than a postcard.
Practice Question:
Which protocol would you use to securely connect to a server remotely?
Answer: SSH.
2. Describe the purpose of intrusion prevention and detection systems
Explanation:
Intrusion Detection System (IDS): Monitors network traffic for suspicious activity and alerts administrators.
Intrusion Prevention System (IPS): Detects and actively blocks threats before they cause harm.
Analogy:
IDS = a security camera that records suspicious behavior.
IPS = a security system that detects intruders and locks the doors automatically.
Practice Question:
What is the difference between IDS and IPS?
Answer: IDS alerts on attacks, while IPS blocks them automatically.
3. Describe policies and practices to prevent viruses, phishing, and email scams
Explanation:
Install antivirus and anti-malware software.
Educate users to recognize phishing emails.
Use email filters to block suspicious messages.
Keep software updated to patch vulnerabilities.
Analogy:
It’s like using bug spray, locks, and caution signs to prevent pests and intruders from entering your house.
Practice Question:
What is a common way to prevent phishing attacks?
Answer: Educating users to recognize suspicious emails.
4. Explain methods of obfuscation
Explanation:
Obfuscation hides sensitive data so it cannot be easily understood if intercepted.
Methods:
Tokenization: Replaces sensitive data with a unique token.
Data masking: Shows fake or masked data to protect real information.
Steganography: Hides data within other files (like images).
Analogy:
It’s like writing a secret message in invisible ink or replacing personal information with codes.
Practice Question:
Which method replaces sensitive information with a placeholder for security?
Answer: Tokenization.
5. Describe how strong passwords increase security
Explanation:
Strong passwords reduce the risk of unauthorized access.
Best practices:
Long and complex (letters, numbers, symbols).
Unique for each account.
Avoid dictionary words or common patterns.
Analogy:
A strong password is like a heavy-duty lock on your front door—it’s harder for attackers to break.
Practice Question:
Why should you avoid using “password123” for your accounts?
Answer: It’s weak and easily guessed by attackers.
6. Describe the purpose of digital certificates and Certificate Authorities (CAs)
Explanation:
Digital certificates: Verify the identity of websites or users and enable encrypted communication.
Certificate Authorities (CAs): Trusted entities that issue digital certificates.
Analogy:
A CA is like a government office issuing official IDs, proving your identity to others.
Practice Question:
What role does a Certificate Authority play in securing web communications?
Answer: It verifies and issues digital certificates to ensure trust.
7. Describe the importance of patches, updates, and version control for security
Explanation:
Patches and updates: Fix vulnerabilities in software and operating systems.
Version control: Tracks changes in software to manage security and stability.
Analogy:
Updating software is like repairing cracks in your house’s foundation before burglars exploit them.
Practice Question:
Why is it risky to use outdated software?
Answer: Because unpatched vulnerabilities can be exploited by attackers.
8. Explain the use of pen testing for increasing security
Explanation:
Penetration testing simulates real attacks to identify weaknesses before attackers exploit them.
Benefits:
Reveals security gaps.
Tests response procedures.
Helps prioritize security improvements.
Analogy:
It’s like hiring someone to try to break into your house to find weak spots so you can fix them before a real burglar comes.
Practice Question:
What is the main goal of penetration testing?
Answer: To identify and fix vulnerabilities before attackers exploit them.