CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
Study every current SY0-701 exam domain with original, concise flashcards for security concepts, threats, architecture, operations, and governance.
حول هذه الرزمة
Build reliable recall across all five current Security+ SY0-701 domains with 744 original, open-response cards. The deck follows the newest official objectives for the current exam series: Version 6.0, accessed on August 25, 2026.
What this deck covers
- General security concepts: control functions, core principles, zero trust, change management, cryptography, certificates, and PKI.
- Threats, vulnerabilities, and mitigations: threat actors, attack vectors, social engineering, platform and application weaknesses, malicious activity, indicators, and defensive choices.
- Security architecture: cloud and virtualization models, secure infrastructure, data protection, availability, backups, and recovery design.
- Security operations: hardening, asset and vulnerability management, monitoring, security tooling, identity and access, automation, incident response, and evidence sources.
- Program management and oversight: governance, risk, third-party security, compliance, privacy, audits, and awareness.
Prompts include concept-to-purpose recall, scenario-to-control or threat identification, and operational comparisons. Reverse prompts appear only when choosing a control, evidence source, or response is useful in practice. Prerequisites come before dependent ideas, while related variants are spaced apart.
The deck excludes multiple-choice practice, copied exam material, dumps, raw objective wording, vague term-only prompts, vendor trivia, and mechanically reversed duplicates. Use it after a course or primary study guide, then add hands-on labs and legitimate practice questions to test application.
Scope was reconciled against CompTIA Security+ SY0-701 Certification Exam: Exam Objectives Version 6.0. Current certification requirements and exam-series status are on the official CompTIA Security+ page.
This is an unofficial educational deck by Flashcards Open Source App. It is not affiliated with, endorsed by, or produced by CompTIA. All card wording and cover artwork are original; no exam questions, answer dumps, objective prose, logos, or trade dress were copied.
بطاقات هذه الرزمة
البطاقة ١
السؤال
What does an information security policy establish?
الإجابة
Management's required direction, responsibilities, and high-level rules for protecting information and systems.
البطاقة ٢
السؤال
What is phishing?
الإجابة
A deceptive message intended to make a target reveal information, open malware, or take an unsafe action.
البطاقة ٣
السؤال
What does a public-key certificate bind to an identity?
الإجابة
A public key, together with identifying information and the issuer's signature.
البطاقة ٤
السؤال
What is data at rest?
الإجابة
Data stored on media such as disks, databases, backups, or mobile devices.
البطاقة ٥
السؤال
How does policy-driven access control decide a zero-trust access request?
الإجابة
Explicit policies or rules evaluate the access request and drive the allow-or-deny decision.
البطاقة ٦
السؤال
What does establishing a secure baseline produce?
الإجابة
An approved, documented configuration that defines the required secure state for a class of computing resource.
البطاقة ٧
السؤال
What is hashing used to verify?
الإجابة
Whether data has changed by comparing fixed-length digest values.
البطاقة ٨
السؤال
What is impersonation in social engineering?
الإجابة
Pretending to be a trusted person or organization to obtain access, data, or action.
البطاقة ٩
السؤال
What is virtualization?
الإجابة
Abstracting physical compute so multiple isolated guest systems can share a host.
البطاقة ١٠
السؤال
What is chain of custody?
الإجابة
A documented history of who collected, handled, transferred, stored, and examined evidence.
البطاقة ١١
السؤال
What is quantitative risk analysis?
الإجابة
Estimating risk with numerical values such as money, frequency, or probability.
البطاقة ١٢
السؤال
What is a phishing awareness campaign?
الإجابة
A planned series of guidance, exercises, and reminders that builds recognition and safe reporting behavior.
البطاقة ١٣
السؤال
What is high availability?
الإجابة
Designing a service to remain accessible despite expected component failures.
البطاقة ١٤
السؤال
What is a network security zone?
الإجابة
A group of systems with similar trust, function, or control requirements.
البطاقة ١٥
السؤال
What is risk transfer?
الإجابة
Shifting some financial or operational consequence to another party, such as through insurance or contract.
البطاقة ١٦
السؤال
What is media sanitization?
الإجابة
Making stored data infeasible to recover for the intended level of protection.
البطاقة ١٧
السؤال
What does CVSS provide?
الإجابة
A standardized way to describe a vulnerability's technical severity characteristics.
البطاقة ١٨
السؤال
What does security alerting do?
الإجابة
It turns matched events or behavior into a notification that the right responder can review.
البطاقة ١٩
السؤال
What does a firewall rule enforce?
الإجابة
A permit, deny, or inspect decision for traffic that matches defined source, destination, service, protocol, direction, and state conditions.
البطاقة ٢٠
السؤال
What is deprovisioning?
الإجابة
Disabling or removing accounts, credentials, sessions, and access when they are no longer needed.
البطاقة ٢١
السؤال
How does inline placement differ from a tap or monitor port?
الإجابة
Inline traffic passes through the control; a tap or monitor receives a copy for observation.
البطاقة ٢٢
السؤال
What is asymmetric encryption?
الإجابة
Encryption that uses a mathematically related public and private key pair.
البطاقة ٢٣
السؤال
What does SPF authorize?
الإجابة
Which mail servers may send mail for a domain in the SMTP envelope.
البطاقة ٢٤
السؤال
What is a possession factor?
الإجابة
Something the claimant has, such as a cryptographic authenticator.
البطاقة ٢٥
السؤال
What does ordinary TLS usually protect and authenticate?
الإجابة
It provides encryption and integrity protection, plus server authentication in the usual deployment. Client authentication is added when mutual TLS is configured.
البطاقة ٢٦
السؤال
What is single loss expectancy?
الإجابة
The estimated loss from one occurrence of a risk event.
البطاقة ٢٧
السؤال
What does a certificate authority do?
الإجابة
It validates certificate requests and signs certificates so relying parties can verify the binding between an identity and a public key.
البطاقة ٢٨
السؤال
What is a detective control meant to do?
الإجابة
Identify that an unwanted event has happened or is happening.
البطاقة ٢٩
السؤال
What is the security purpose of change-control approval?
الإجابة
Ensure authorized reviewers assess risk before the production change occurs.
البطاقة ٣٠
السؤال
What is shadow IT?
الإجابة
Technology used for organizational work without required approval or oversight.
البطاقة ٣١
السؤال
What is a buffer overflow vulnerability?
الإجابة
A bounds-checking failure that lets input overwrite memory outside its intended buffer.
البطاقة ٣٢
السؤال
What is ransomware?
الإجابة
Malware or an intrusion outcome that denies access to data or systems to extort the victim.
البطاقة ٣٣
السؤال
How does network segmentation limit an incident?
الإجابة
It restricts communication paths and reduces lateral movement between zones.
البطاقة ٣٤
السؤال
How do load balancing and clustering support availability differently?
الإجابة
Load balancing distributes requests across healthy instances; clustering makes systems cooperate as one service and tolerate member failure.
البطاقة ٣٥
السؤال
What is vendor due diligence?
الإجابة
Evaluating a provider's security, capability, stability, and fit before commitment.
البطاقة ٣٦
السؤال
Who is a data subject?
الإجابة
The person whose personal data is collected or processed.
البطاقة ٣٧
السؤال
What is attestation?
الإجابة
A formal assertion or report about a subject matter, often supported by an independent examination.
البطاقة ٣٨
السؤال
What is a replay attack?
الإجابة
Valid captured data is retransmitted to repeat an authenticated or authorized action.
البطاقة ٣٩
السؤال
What does a wireless site survey establish?
الإجابة
Coverage, interference, channel use, access-point placement, and unauthorized radio sources in the real environment.
البطاقة ٤٠
السؤال
What is the time-of-check stage of a race-condition vulnerability?
الإجابة
The application verifies a condition or resource state before acting on it.
البطاقة ٤١
السؤال
What is a penetration test?
الإجابة
An authorized attempt to exploit weaknesses and demonstrate practical impact.
البطاقة ٤٢
السؤال
What is a cold recovery site?
الإجابة
A facility with basic space and utilities but little preinstalled technology or current data.
البطاقة ٤٣
السؤال
What is data in transit?
الإجابة
Data moving between systems or across a network.
البطاقة ٤٤
السؤال
What is a vendor security questionnaire?
الإجابة
A structured request for information about a provider's controls and practices.
البطاقة ٤٥
السؤال
How does an internal actor's starting position differ from an external actor's?
الإجابة
An internal actor begins with some trusted access or proximity; an external actor must first cross the perimeter or obtain access.
البطاقة ٤٦
السؤال
What can unexpected account lockouts indicate?
الإجابة
Password guessing, credential stuffing, user error, or a broken client.
البطاقة ٤٧
السؤال
How do permissions enforce access control?
الإجابة
They specify which actions a subject may perform on a particular resource.
البطاقة ٤٨
السؤال
What is log aggregation?
الإجابة
Central collection of logs from multiple sources for search, correlation, and retention.
البطاقة ٤٩
السؤال
Why plan a service restart as part of a change?
الإجابة
The restart can interrupt dependent users or processes, so the plan needs timing, validation, and rollback steps.
البطاقة ٥٠
السؤال
What is infrastructure as code?
الإجابة
Managing infrastructure through versioned, machine-readable definitions rather than manual configuration.
البطاقة ٥١
السؤال
What should security-awareness program development start with?
الإجابة
The audience's roles, risks, policies, incident lessons, desired behavior, and measurable outcomes.
البطاقة ٥٢
السؤال
What is a voice-based social-engineering attack called?
الإجابة
Vishing.
البطاقة ٥٣
السؤال
What happens during incident-response preparation?
الإجابة
Teams establish people, tools, access, communications, training, and procedures before an incident.
البطاقة ٥٤
السؤال
What does an offensive penetration-testing team do?
الإجابة
It emulates authorized attacker behavior to discover and demonstrate exploitable paths.
البطاقة ٥٥
السؤال
What is federation?
الإجابة
One security domain relies on identity assertions from another trusted domain.
البطاقة ٥٦
السؤال
What is asset classification?
الإجابة
Grouping an asset by sensitivity, criticality, or required handling.
البطاقة ٥٧
السؤال
What is cross-site scripting?
الإجابة
Injection of script-capable content that a browser executes in another site's security context.
البطاقة ٥٨
السؤال
What can IDS or IPS trends reveal?
الإجابة
Changes in the frequency, source, target, or type of detected activity that one isolated event may not show.
البطاقة ٥٩
السؤال
What can unexpected resource inaccessibility indicate?
الإجابة
Denial of service, destructive activity, ransomware, permission changes, or an ordinary outage.
البطاقة ٦٠
السؤال
What is a corrective control meant to do?
الإجابة
Limit damage and restore a secure state after an event.
البطاقة ٦١
السؤال
How do containers differ from virtual machines?
الإجابة
Containers share the host kernel; virtual machines normally run separate guest operating systems.
البطاقة ٦٢
السؤال
How does an active security device differ from a passive one?
الإجابة
An active device can alter or block traffic; a passive device observes and reports without changing the flow.
البطاقة ٦٣
السؤال
Why is unsupported software a persistent attack surface?
الإجابة
Known weaknesses may remain reachable because supported fixes and vendor help are no longer available.
البطاقة ٦٤
السؤال
What is annualized rate of occurrence?
الإجابة
The estimated number of times a risk event occurs per year.
البطاقة ٦٥
السؤال
What is an inherence factor?
الإجابة
A biometric characteristic of the claimant.
البطاقة ٦٦
السؤال
What do a threat actor's sophistication and capability describe?
الإجابة
The technical skill, tools, knowledge, resources, and operational discipline the actor can apply.
البطاقة ٦٧
السؤال
What is a SIEM?
الإجابة
A platform that centralizes security data and supports search, correlation, alerting, and investigation.
البطاقة ٦٨
السؤال
What is sideloading?
الإجابة
Installing software from outside the platform's approved distribution path.
البطاقة ٦٩
السؤال
What does an IDS or IPS signature match?
الإجابة
A known pattern in traffic or behavior associated with a threat, exploit, or policy violation.
البطاقة ٧٠
السؤال
Why are embedded systems often difficult to patch?
الإجابة
They may have long lifecycles, specialized firmware, limited downtime, or weak vendor support.
البطاقة ٧١
السؤال
What is a virtual private network?
الإجابة
An encrypted logical connection that carries private traffic across an untrusted or shared network.
البطاقة ٧٢
السؤال
What should an initial security-awareness report establish?
الإجابة
The starting participation, knowledge, behavior, incident, and reporting measures against which later results will be compared.
البطاقة ٧٣
السؤال
What is symmetric encryption?
الإجابة
Encryption that uses the same secret key to encrypt and decrypt data.
البطاقة ٧٤
السؤال
What happens during incident detection?
الإجابة
Monitoring or a report identifies activity that may meet the organization's incident criteria.
البطاقة ٧٥
السؤال
What is recovery time objective?
الإجابة
The target maximum time to restore a function after disruption.
البطاقة ٧٦
السؤال
Why prioritize password length?
الإجابة
Longer passwords expand the guessing space and support memorable passphrases without predictable substitutions.
البطاقة ٧٧
السؤال
What must sanitization accomplish before an asset leaves organizational control?
الإجابة
It must make the retained data infeasible to recover with the method appropriate to the media and risk.
البطاقة ٧٨
السؤال
What is a real-time operating system designed to provide?
الإجابة
Predictable response timing for tasks with strict deadlines.
البطاقة ٧٩
السؤال
What does fail-open behavior do when a control fails?
الإجابة
It permits traffic or access to preserve availability.
البطاقة ٨٠
السؤال
What is jailbreaking or rooting a mobile device?
الإجابة
Removing platform restrictions to gain privileged control over the operating system.
البطاقة ٨١
السؤال
What does network access control enforce?
الإجابة
Identity, device posture, and access policy at network connection time and during a session.
البطاقة ٨٢
السؤال
What does data loss prevention do?
الإجابة
Detects and may block sensitive data use or transfer that violates policy.
البطاقة ٨٣
السؤال
What security property does a blockchain provide?
الإجابة
A chained, tamper-evident record in which changing an earlier entry invalidates later cryptographic links.
البطاقة ٨٤
السؤال
What is recovery point objective?
الإجابة
The target maximum acceptable data loss measured backward in time.
البطاقة ٨٥
السؤال
How do ICS and SCADA relate?
الإجابة
An industrial control system controls physical processes; SCADA provides supervisory monitoring and control across distributed industrial equipment.
البطاقة ٨٦
السؤال
What does fail-closed behavior do when a control fails?
الإجابة
It denies traffic or access to preserve security.
البطاقة ٨٧
السؤال
Which keys create and verify a typical digital signature?
الإجابة
The signer creates it with a private key, and others verify it with the corresponding public key.
البطاقة ٨٨
السؤال
What is SQL injection?
الإجابة
Input that alters the structure or meaning of a database query because code and data were not safely separated.
البطاقة ٨٩
السؤال
What does DKIM verify?
الإجابة
That selected message content was signed by a domain and was not altered after signing.
البطاقة ٩٠
السؤال
What is post-incident activity?
الإجابة
Learning from the event and improving controls, plans, and recovery based on evidence.
البطاقة ٩١
السؤال
What characterizes an expansionary risk appetite?
الإجابة
A greater willingness to accept uncertainty and exposure in pursuit of growth, return, or strategic opportunity.
البطاقة ٩٢
السؤال
How do centralized and decentralized architectures differ?
الإجابة
Centralized architecture concentrates key services or decisions; decentralized architecture distributes them across independent components or locations.
البطاقة ٩٣
السؤال
What does a certificate revocation list publish?
الإجابة
Certificate serial numbers that the issuer has invalidated before their scheduled expiration.
البطاقة ٩٤
السؤال
What is a legal hold?
الإجابة
A directive to preserve potentially relevant information by suspending normal deletion or disposal.
البطاقة ٩٥
السؤال
What is exposure factor in quantitative risk analysis?
الإجابة
The estimated percentage of an asset's value lost in one event.
البطاقة ٩٦
السؤال
What is decentralized architecture?
الإجابة
Control or service responsibility is distributed across multiple independent components or locations.
البطاقة ٩٧
السؤال
What is tokenization?
الإجابة
Replacing sensitive data with a non-sensitive token whose mapping is held separately.
البطاقة ٩٨
السؤال
How can automation act as a workforce multiplier?
الإجابة
It handles repeatable work consistently so people can focus on judgment, exceptions, investigation, and improvement.
البطاقة ٩٩
السؤال
What can endpoint process logs reveal?
الإجابة
Which programs ran, their parent-child relationships, users, timing, and command details when captured.
البطاقة ١٠٠
السؤال
What does the CIA triad protect?
الإجابة
Confidentiality protects against unauthorized disclosure, integrity protects accuracy and completeness, and availability protects reliable, timely access.
البطاقة ١٠١
السؤال
How does data masking protect information?
الإجابة
It hides selected values or characters while preserving a usable representation.
البطاقة ١٠٢
السؤال
How can a national requirement affect security governance?
الإجابة
It can impose country-level duties that policies, controls, records, and oversight must satisfy.
البطاقة ١٠٣
السؤال
What do integrations and APIs provide to security orchestration?
الإجابة
Defined interfaces for exchanging data and triggering actions across tools without manual handoffs.
البطاقة ١٠٤
السؤال
What makes a compliance report external?
الإجابة
It is prepared for a regulator, customer, auditor, partner, or other party outside the organization.
البطاقة ١٠٥
السؤال
What does a cryptographic algorithm define?
الإجابة
The mathematical procedure used to encrypt, decrypt, hash, sign, or otherwise transform protected data.
البطاقة ١٠٦
السؤال
Why compare systems with a secure baseline regularly?
الإجابة
To detect drift, unauthorized changes, and missing hardening.
البطاقة ١٠٧
السؤال
What does integrity protect?
الإجابة
The accuracy and completeness of data and systems against unauthorized change.
البطاقة ١٠٨
السؤال
What does vulnerability classification organize?
الإجابة
Findings into meaningful types or categories so teams can route, compare, and remediate them consistently.
البطاقة ١٠٩
السؤال
What does a password standard define?
الإجابة
Mandatory, measurable requirements for creating, storing, using, and changing passwords.
البطاقة ١١٠
السؤال
What technology capacity must a recovery design plan for?
الإجابة
The compute, storage, software, licenses, and supporting services needed to meet recovery demand.
البطاقة ١١١
السؤال
What does a confidential data classification indicate?
الإجابة
Disclosure is limited to authorized people because exposure could harm the organization or affected parties.
البطاقة ١١٢
السؤال
What makes a vendor assessment independent?
الإجابة
The assessor is free from responsibility for the vendor activity being evaluated and reports evidence against defined criteria.
البطاقة ١١٣
السؤال
What lets a worm spread without attaching itself to another file?
الإجابة
It is a standalone program that replicates across reachable systems or services.
البطاقة ١١٤
السؤال
What is microsegmentation?
الإجابة
Fine-grained isolation of individual workloads or small groups with explicit communication policy.
البطاقة ١١٥
السؤال
What can application logs reveal?
الإجابة
Transactions, errors, user actions, and application-specific security events.
البطاقة ١١٦
السؤال
What does deploying a secure baseline require?
الإجابة
Applying the approved settings consistently to the intended resources and verifying the realized configuration.
البطاقة ١١٧
السؤال
How can resource-provisioning automation improve security?
الإجابة
It creates infrastructure from approved templates with consistent ownership, logging, and baseline controls.
البطاقة ١١٨
السؤال
What does availability protect?
الإجابة
Reliable, timely access to systems and data when authorized users need them.
البطاقة ١١٩
السؤال
Why must a change request describe business impact?
الإجابة
So approvers can weigh the benefit, risk, outage, and affected users before authorizing it.
البطاقة ١٢٠
السؤال
What does an authenticated vulnerability scan add?
الإجابة
Credentialed inspection of local versions, settings, and missing patches that a remote scan may miss.
البطاقة ١٢١
السؤال
What does a change-management procedure specify?
الإجابة
The required steps, roles, evidence, approvals, testing, implementation, validation, and rollback for a change.
البطاقة ١٢٢
السؤال
What is a sanction for noncompliance?
الإجابة
A formal penalty or restriction imposed by an authority for failing to meet a requirement.
البطاقة ١٢٣
السؤال
How can email deliver a security attack?
الإجابة
It can carry a malicious link, attachment, request, or embedded content designed to exploit software or manipulate a recipient.
البطاقة ١٢٤
السؤال
What is an internal compliance audit?
الإجابة
An organization-led examination of whether selected operations and controls meet defined requirements.
البطاقة ١٢٥
السؤال
What is a Trojan?
الإجابة
Malware disguised as legitimate or desirable software.
البطاقة ١٢٦
السؤال
What is clustering?
الإجابة
Multiple systems work together to provide a service and tolerate member failure.
البطاقة ١٢٧
السؤال
What makes data regulated?
الإجابة
A law or regulation imposes specific collection, handling, retention, protection, or disclosure duties.
البطاقة ١٢٨
السؤال
What does a wireless heat map show?
الإجابة
Measured or modeled signal strength and coverage across a physical area.
البطاقة ١٢٩
السؤال
How should vendor criticality affect due diligence?
الإجابة
Higher access, concentration, data sensitivity, or operational dependence warrants deeper evidence and stronger approval.
البطاقة ١٣٠
السؤال
How can a digital signature support non-repudiation?
الإجابة
It provides evidence that the holder of a private key signed specific data.
البطاقة ١٣١
السؤال
What should vulnerability prioritization consider beyond severity?
الإجابة
Exploitability, exposure, asset importance, environmental context, business impact, and available mitigations.
البطاقة ١٣٢
السؤال
What is a security guideline?
الإجابة
Recommended practice that allows judgment unless adopted as a requirement.
البطاقة ١٣٣
السؤال
What usually distinguishes a nation-state threat actor?
الإجابة
Strategic objectives, substantial resources, patience, and advanced operational capability.
البطاقة ١٣٤
السؤال
What is spyware?
الإجابة
Software that secretly collects information about a user or system.
البطاقة ١٣٥
السؤال
Why maintain an allow list for applications?
الإجابة
Only explicitly approved software is permitted to execute.
البطاقة ١٣٦
السؤال
How can an image become an attack vector?
الإجابة
It may exploit a decoder flaw, hide malicious data, or direct a user through an embedded code.
البطاقة ١٣٧
السؤال
What makes a security control technical?
الإجابة
It is enforced mainly by technology, such as a firewall rule or endpoint policy.
البطاقة ١٣٨
السؤال
What is identity proofing?
الإجابة
Establishing that a person is who they claim to be before issuing an account or credential.
البطاقة ١٣٩
السؤال
What is an automated security guardrail?
الإجابة
A policy control that prevents, flags, or corrects unsafe configuration, such as an overexposed security group.
البطاقة ١٤٠
السؤال
Why assign an owner to a planned change?
الإجابة
To make one party accountable for coordination, execution, and follow-through.
البطاقة ١٤١
السؤال
How can national privacy law affect data handling?
الإجابة
It can set country-level duties for collection, use, access, retention, transfer, security, and individual rights.
البطاقة ١٤٢
السؤال
What is continuity of operations?
الإجابة
Maintaining essential functions during disruption and restoring supporting capabilities in a planned order.
البطاقة ١٤٣
السؤال
What security tradeoff comes with BYOD?
الإجابة
The organization gains flexibility but has less control over personally owned device configuration, privacy, and lifecycle.
البطاقة ١٤٤
السؤال
How should policies and handbooks support security training?
الإجابة
They provide accessible, current rules and reporting steps that training can apply to real situations.
البطاقة ١٤٥
السؤال
What is a keylogger?
الإجابة
A tool that records keystrokes to capture data such as credentials.
البطاقة ١٤٦
السؤال
What makes information a trade secret?
الإجابة
It provides business value because it is not generally known and is protected through reasonable secrecy measures.
البطاقة ١٤٧
السؤال
What does authentication establish?
الإجابة
It verifies a presented authenticator or credential bound to the claimed identity. Identity proofing establishes the real-world identity behind the claim.
البطاقة ١٤٨
السؤال
What risk comes from an untrusted file attachment?
الإجابة
Opening or parsing it can execute malicious code or expose data.
البطاقة ١٤٩
السؤال
How does risk tolerance affect vulnerability remediation?
الإجابة
It sets how much residual exposure the organization will accept and how quickly a finding must be treated.
البطاقة ١٥٠
السؤال
How can a global requirement affect security governance?
الإجابة
It can require a common control and oversight approach across multiple countries while local obligations still apply.
البطاقة ١٥١
السؤال
Why should questionnaire answers be supported by evidence?
الإجابة
Self-assertions alone may not prove that controls are designed or operating effectively.
البطاقة ١٥٢
السؤال
What is an independent third-party audit?
الإجابة
An external party with suitable independence examines evidence against defined criteria.
البطاقة ١٥٣
السؤال
What do account provisioning and deprovisioning do?
الإجابة
Provisioning creates an identity and approved access; deprovisioning disables or removes accounts, credentials, sessions, and access when no longer needed.
البطاقة ١٥٤
السؤال
What is an unskilled attacker commonly called?
الإجابة
A script kiddie: someone who relies on tools or instructions created by others.
البطاقة ١٥٥
السؤال
What is a rootkit?
الإجابة
Software designed to maintain privileged, concealed access by altering or subverting the system.
البطاقة ١٥٦
السؤال
What does an access control list enforce?
الإجابة
Explicit permit or deny rules for subjects, traffic, or actions on a protected resource.
البطاقة ١٥٧
السؤال
What should system security monitoring observe?
الإجابة
Host state and behavior such as processes, authentication, configuration, resource use, and security events.
البطاقة ١٥٨
السؤال
What can operating-system security logs reveal?
الإجابة
Authentication, privilege use, policy changes, services, and other host security events.
البطاقة ١٥٩
السؤال
Why isolate operational technology from general business networks?
الإجابة
To limit attack paths into safety- and availability-critical processes.
البطاقة ١٦٠
السؤال
What is the COPE mobile deployment model?
الإجابة
The organization owns the device but permits defined personal use while retaining management control.
البطاقة ١٦١
السؤال
What security work belongs in asset acquisition and procurement?
الإجابة
Define security requirements before purchase, evaluate the product and vendor against them, and obtain approval before acquisition or deployment.
البطاقة ١٦٢
السؤال
How can user-provisioning automation improve security?
الإجابة
It creates, changes, and removes access from authoritative identity events with consistent approvals and logging.
البطاقة ١٦٣
السؤال
What people capacity must a continuity plan account for?
الإجابة
Enough trained staff, coverage, authority, and specialist knowledge to operate and recover essential services.
البطاقة ١٦٤
السؤال
What do authorization models define?
الإجابة
How permissions are assigned to authenticated subjects and evaluated for requested actions.
البطاقة ١٦٥
السؤال
Why are removable devices an attack vector?
الإجابة
They can introduce malware or remove data while bypassing network controls.
البطاقة ١٦٦
السؤال
What should predeployment change-test results show?
الإجابة
Whether the change meets its acceptance criteria without unacceptable functional, security, or operational effects.
البطاقة ١٦٧
السؤال
What is the time-of-use stage of a race-condition vulnerability?
الإجابة
The application acts on a resource after the check, creating a gap in which another process may change the resource.
البطاقة ١٦٨
السؤال
What is data in use?
الإجابة
Data actively processed in memory or by an application.
البطاقة ١٦٩
السؤال
What does open-source vulnerability intelligence contribute?
الإجابة
Public advisories, exploit reporting, research, and observable activity that help identify and prioritize exposure.
البطاقة ١٧٠
السؤال
What can file-integrity monitoring detect?
الإجابة
Unexpected changes to protected files, directories, or configuration.
البطاقة ١٧١
السؤال
Why should deprovisioning be prompt?
الإجابة
Former users or roles should not retain usable access.
البطاقة ١٧٢
السؤال
What is an acceptable use policy?
الإجابة
Rules for permitted and prohibited use of organizational systems, accounts, and data.
البطاقة ١٧٣
السؤال
What makes a compliance report internal?
الإجابة
It is prepared for the organization's owners, operators, management, or governance bodies to track compliance and action.
البطاقة ١٧٤
السؤال
What is a logic bomb?
الإجابة
Malicious code that activates when a specified condition or time is reached.
البطاقة ١٧٥
السؤال
What does a right-to-audit clause provide?
الإجابة
Contractual authority to inspect or obtain evidence about agreed controls.
البطاقة ١٧٦
السؤال
Where should a forward proxy sit in an enterprise traffic path?
الإجابة
Between clients and external services so outbound requests pass through policy and logging before reaching destinations.
البطاقة ١٧٧
السؤال
Which cues should make a message look suspicious?
الإجابة
Unexpected context, mismatched identity or links, unusual attachments, urgency, secrecy, and requests for credentials or payment.
البطاقة ١٧٨
السؤال
What makes a security control managerial?
الإجابة
It directs risk and governance through decisions such as policies, assessments, and oversight.
البطاقة ١٧٩
السؤال
What is the CYOD mobile deployment model?
الإجابة
The user selects from organization-approved device options that remain subject to corporate security requirements.
البطاقة ١٨٠
السؤال
How does client-based vulnerable software differ from an agentless exposure?
الإجابة
Client-based exposure depends on installed endpoint software, while an agentless service can be reached and assessed without a local agent.
البطاقة ١٨١
السؤال
What makes a risk assessment recurring?
الإجابة
It is repeated on a defined schedule so changes in threats, assets, controls, and impact are reevaluated.
البطاقة ١٨٢
السؤال
What does a defensive penetration-testing team practice?
الإجابة
Detection, investigation, containment, and improvement while authorized offensive activity tests the environment.
البطاقة ١٨٣
السؤال
In a zero-trust data plane, what can the subject or system represent?
الإجابة
The user, device, workload, or service requesting access to a protected resource.
البطاقة ١٨٤
السؤال
What primarily motivates a hacktivist?
الإجابة
A political, social, or ideological cause.
البطاقة ١٨٥
السؤال
What is bloatware?
الإجابة
Unnecessary preinstalled software that consumes resources and can expand the attack surface.
البطاقة ١٨٦
السؤال
Why keep endpoint-protection signatures and engines current?
الإجابة
They need current detection logic to recognize newly identified malware and exploit behavior.
البطاقة ١٨٧
السؤال
What should application security monitoring observe?
الإجابة
Application errors, authentication, requests, transactions, dependencies, and behavior that may indicate misuse or compromise.
البطاقة ١٨٨
السؤال
What is role-based access control?
الإجابة
Permissions are assigned to roles, and identities receive access through their roles.
البطاقة ١٨٩
السؤال
What is geographic dispersal?
الإجابة
Placing redundant resources in separate locations so one regional event does not affect all copies.
البطاقة ١٩٠
السؤال
What is a malicious update?
الإجابة
An update that has been intentionally altered or distributed to install harmful code through a trusted update path.
البطاقة ١٩١
السؤال
What does static application analysis inspect?
الإجابة
Source code, bytecode, or compiled code without executing the application.
البطاقة ١٩٢
السؤال
What does a firewall access list define?
الإجابة
An ordered set of traffic-matching conditions and the action applied when a condition matches.
البطاقة ١٩٣
السؤال
What does a disaster recovery policy establish?
الإجابة
Management expectations for restoring technology and data after a disruptive event.
البطاقة ١٩٤
السؤال
How does logical segmentation separate workloads that share physical infrastructure?
الإجابة
It uses enforced network, identity, or virtualization boundaries to restrict communication without requiring separate hardware.
البطاقة ١٩٥
السؤال
How should IDS and IPS placement differ?
الإجابة
An IDS can monitor copied traffic out of band; an IPS must sit inline to block traffic.
البطاقة ١٩٦
السؤال
What should automated ticket creation capture?
الإجابة
The triggering evidence, affected resource, severity, owner, required action, and a traceable link to the source event.
البطاقة ١٩٧
السؤال
What makes information intellectual property?
الإجابة
It is a protected creation or intangible asset, such as copyrighted work, a patentable invention, a trademark, or a trade secret.
البطاقة ١٩٨
السؤال
What is a backout plan?
الإجابة
Predefined steps for safely reversing a failed or harmful change.
البطاقة ١٩٩
السؤال
Why is an unsecure wireless network an attack vector?
الإجابة
Nearby attackers may intercept traffic, impersonate access points, or reach exposed services when encryption and authentication are weak.
البطاقة ٢٠٠
السؤال
What is physical brute force?
الإجابة
Using force to defeat a lock, barrier, enclosure, or other physical control.
البطاقة ٢٠١
السؤال
What is application sandboxing?
الإجابة
Running code in a constrained environment with limited access to the host and data.
البطاقة ٢٠٢
السؤال
Why assign an asset owner?
الإجابة
One accountable party must decide its use, protection, and lifecycle.
البطاقة ٢٠٣
السؤال
What happens during risk identification?
الإجابة
Teams identify assets, objectives, threats, vulnerabilities, events, and dependencies that could create uncertainty or harm.
البطاقة ٢٠٤
السؤال
What should an SLA state about breach notification?
الإجابة
The triggering conditions, notification deadline, required content, contacts, update cadence, and cooperation duties.
البطاقة ٢٠٥
السؤال
How do due diligence and due care differ in compliance?
الإجابة
Due diligence investigates and monitors obligations or risk; due care takes the reasonable actions those findings require.
البطاقة ٢٠٦
السؤال
What is attribute-based access control?
الإجابة
Policy evaluates attributes of the subject, resource, action, and environment.
البطاقة ٢٠٧
السؤال
What does a zero-trust policy engine do?
الإجابة
It evaluates policy and signals to decide whether access should be allowed.
البطاقة ٢٠٨
السؤال
How does a cloud responsibility matrix allocate security duties?
الإجابة
It maps each security task to the provider, the customer, or both, according to the service model and agreement.
البطاقة ٢٠٩
السؤال
Where should a load balancer sit in a service path?
الإجابة
In front of service instances so it can route requests to healthy backends.
البطاقة ٢١٠
السؤال
What should the security team do with a reported suspicious message?
الإجابة
Triage it, protect other recipients, preserve useful evidence, and tell the reporter what action to take.
البطاقة ٢١١
السؤال
What makes an operating-system vulnerability high impact?
الإجابة
It can affect every application and security control that relies on the compromised OS.
البطاقة ٢١٢
السؤال
What does dynamic application analysis inspect?
الإجابة
The behavior and externally visible weaknesses of a running application.
البطاقة ٢١٣
السؤال
How can false-positive trends affect IDS or IPS tuning?
الإجابة
Repeated false positives reveal signatures, thresholds, or contexts that need adjustment; IPS errors also risk blocking legitimate traffic.
البطاقة ٢١٤
السؤال
What does a business continuity policy establish?
الإجابة
Management expectations for sustaining and restoring critical business functions.
البطاقة ٢١٥
السؤال
What is a hot recovery site?
الإجابة
A ready, synchronized environment intended to take over quickly.
البطاقة ٢١٦
السؤال
What makes an insider threat distinct?
الإجابة
The actor has legitimate access or organizational knowledge that can be misused.
البطاقة ٢١٧
السؤال
What is RFID cloning?
الإجابة
Copying an RFID credential's data so another token can impersonate it when the system lacks stronger protections.
البطاقة ٢١٨
السؤال
Why apply vendor security updates promptly?
الإجابة
They remove known weaknesses before attackers can exploit the unpatched exposure.
البطاقة ٢١٩
السؤال
What should infrastructure security monitoring observe?
الإجابة
Network, cloud, identity, facility, and platform signals that reveal availability, configuration, or attack activity.
البطاقة ٢٢٠
السؤال
What can firewall logs reveal?
الإجابة
Allowed or denied network connections across controlled boundaries.
البطاقة ٢٢١
السؤال
Why minimize open service ports?
الإجابة
Each reachable service adds code, configuration, and authentication paths an attacker can probe.
البطاقة ٢٢٢
السؤال
What is threat hunting?
الإجابة
A proactive search for evidence of malicious activity that existing detections have not confirmed.
البطاقة ٢٢٣
السؤال
What triggers an ad hoc risk assessment?
الإجابة
A specific change, incident, finding, or decision that requires evaluation outside the regular schedule.
البطاقة ٢٢٤
السؤال
What makes an assessment external?
الإجابة
A party outside the organization evaluates a defined scope against stated criteria and reports its conclusions.
البطاقة ٢٢٥
السؤال
What is data sovereignty?
الإجابة
The principle that data is subject to laws and governance of the jurisdiction where it is located or controlled.
البطاقة ٢٢٦
السؤال
What security boundary does a cellular connection create for a mobile device?
الإجابة
It uses the carrier network instead of local Wi-Fi, but still requires trusted applications, encrypted traffic, and managed device policy.
البطاقة ٢٢٧
السؤال
What makes a security control operational?
الإجابة
It is carried out mainly by people and processes, such as security-awareness training or incident-response procedures.
البطاقة ٢٢٨
السؤال
What is discretionary access control?
الإجابة
A resource owner can decide who receives access, within system policy.
البطاقة ٢٢٩
السؤال
How can careful automation support employee retention?
الإجابة
It reduces repetitive toil and alert handling while leaving meaningful judgment and improvement work with people.
البطاقة ٢٣٠
السؤال
Why does ease of deployment matter in an architecture decision?
الإجابة
A design that can be deployed consistently and safely reduces configuration error, rollout time, and operational burden.
البطاقة ٢٣١
السؤال
What tradeoff comes with placing an NGFW inline?
الإجابة
It can block application-aware threats, but failure or overload can interrupt traffic unless availability and fail-mode behavior are designed.
البطاقة ٢٣٢
السؤال
What does a zero-trust policy administrator do?
الإجابة
It carries out the policy engine's decision, such as creating or ending a session.
البطاقة ٢٣٣
السؤال
What should a master service agreement define for data return and deletion?
الإجابة
The format, timing, verification, retained copies, exceptions, and responsibilities when the service or contract ends.
البطاقة ٢٣٤
السؤال
What is an environmental physical attack?
الإجابة
Causing harmful conditions such as heat, water, fire, or power loss to disrupt equipment or facilities.
البطاقة ٢٣٥
السؤال
When should a maintenance window be chosen?
الإجابة
When disruption and rollback can be managed with the least business impact.
البطاقة ٢٣٦
السؤال
What is memory injection?
الإجابة
Placing malicious code or data into another process's memory so it executes in that process's context.
البطاقة ٢٣٧
السؤال
What does software composition analysis find?
الإجابة
Known risks and license information in third-party dependencies.
البطاقة ٢٣٨
السؤال
What is DNS filtering?
الإجابة
Blocking or redirecting DNS lookups for domains that policy considers malicious or inappropriate.
البطاقة ٢٣٩
السؤال
What should an incident response policy establish?
الإجابة
Authority, scope, reporting duties, and organizational commitment for incident handling.
البطاقة ٢٤٠
السؤال
How can noncompliance cause reputational damage?
الإجابة
Customers, partners, employees, or the public may lose trust when the organization fails a stated or required duty.
البطاقة ٢٤١
السؤال
What does full-disk encryption protect?
الإجابة
All data stored on the disk while the device is powered off or the disk is removed, subject to proper key protection.
البطاقة ٢٤٢
السؤال
Why are default credentials dangerous?
الإجابة
They are widely known or easily discovered and often remain unchanged.
البطاقة ٢٤٣
السؤال
What makes a risk assessment one-time?
الإجابة
It evaluates a defined decision or scope once without an established repeating cadence.
البطاقة ٢٤٤
السؤال
What is a warm recovery site?
الإجابة
A partially equipped environment that needs some data restoration or configuration before use.
البطاقة ٢٤٥
السؤال
What does application input validation do?
الإجابة
It checks that input matches the expected type, length, range, and format before use.
البطاقة ٢٤٦
السؤال
What should an asset inventory record besides a device name?
الإجابة
Identifiers, owner, location, status, classification, dependencies, and supported version as applicable.
البطاقة ٢٤٧
السؤال
What is mandatory access control?
الإجابة
A central authority enforces access through labels and rules that ordinary owners cannot override.
البطاقة ٢٤٨
السؤال
What security benefit does infrastructure as code provide?
الإجابة
Repeatable, reviewable deployments that reduce undocumented configuration drift.
البطاقة ٢٤٩
السؤال
When should a public service control fail closed?
الإجابة
When allowing unchecked traffic would create greater harm than an outage, the failed control should block the path.
البطاقة ٢٥٠
السؤال
What should users do with a suspicious message?
الإجابة
Report it through the approved channel without interacting with its links or attachments.
البطاقة ٢٥١
السؤال
What usually motivates organized cybercrime?
الإجابة
Financial gain through scalable or repeatable criminal activity.
البطاقة ٢٥٢
السؤال
How can malicious code support a network attack?
الإجابة
It can establish control, scan reachable systems, move laterally, or disrupt networked services after execution.
البطاقة ٢٥٣
السؤال
When is virtual patching useful?
الإجابة
When a network or application control can block exploit traffic before the underlying system can be patched.
البطاقة ٢٥٤
السؤال
What does security-monitoring reporting provide?
الإجابة
A summarized, audience-appropriate view of findings, trends, risk, and response status.
البطاقة ٢٥٥
السؤال
What does data geolocation identify?
الإجابة
The physical or legal location where data is stored, processed, or transmitted.
البطاقة ٢٥٦
السؤال
What does a zero-trust policy enforcement point do?
الإجابة
It enables, monitors, and terminates the connection between a subject and a resource.
البطاقة ٢٥٧
السؤال
What is cryptographic key exchange?
الإجابة
A method for parties to establish shared key material over an untrusted channel.
البطاقة ٢٥٨
السؤال
How can a vendor become a supply-chain attack vector?
الإجابة
An attacker can compromise the vendor's product, update, credentials, or support channel to reach the vendor's customers.
البطاقة ٢٥٩
السؤال
Why can legacy hardware remain vulnerable?
الإجابة
It may lack current security features, supported firmware, replacement parts, or compatibility with modern controls.
البطاقة ٢٦٠
السؤال
What can proprietary vulnerability intelligence add beyond open sources?
الإجابة
Curated analysis, customer-specific context, private telemetry, or earlier reporting available under a commercial or trusted relationship.
البطاقة ٢٦١
السؤال
How does a centralized proxy apply web filtering?
الإجابة
It receives client web requests at a shared enforcement point and applies policy before forwarding allowed traffic.
البطاقة ٢٦٢
السؤال
How can continuous integration and testing improve security automation?
الإجابة
Changes receive repeatable checks before deployment instead of reaching production unvalidated.
البطاقة ٢٦٣
السؤال
What is containment?
الإجابة
Limiting an incident's spread or damage while preserving necessary operations and evidence.
البطاقة ٢٦٤
السؤال
What is a software development lifecycle policy meant to ensure?
الإجابة
Security requirements and checks are integrated throughout design, development, release, and maintenance.
البطاقة ٢٦٥
السؤال
What makes risk assessment continuous?
الإجابة
Relevant signals and changes update the risk view as they occur instead of waiting for a scheduled review.
البطاقة ٢٦٦
السؤال
What is a memorandum of agreement?
الإجابة
A document that records agreed responsibilities and commitments between parties; its legal effect depends on its terms and jurisdiction.
البطاقة ٢٦٧
السؤال
What makes a penetration test integrated?
الإجابة
Offensive and defensive teams coordinate the exercise to test both attack paths and detection or response.
البطاقة ٢٦٨
السؤال
How does a DNS amplification attack magnify traffic?
الإجابة
It sends small spoofed queries that trigger larger replies toward the victim.
البطاقة ٢٦٩
السؤال
Why does ease of recovery matter in an architecture decision?
الإجابة
The design should let operators restore service and trusted state without fragile, slow, or undocumented steps.
البطاقة ٢٧٠
السؤال
What does 802.1X control before a device receives normal network access?
الإجابة
Port-based admission; the device or user must authenticate through the access device before ordinary traffic is allowed.
البطاقة ٢٧١
السؤال
What is rule-based access control?
الإجابة
System-wide rules grant or deny access based on conditions such as network, time, or action.
البطاقة ٢٧٢
السؤال
What is mobile device management?
الإجابة
Central enrollment, configuration, monitoring, and enforcement for managed mobile devices.
البطاقة ٢٧٣
السؤال
What tradeoff comes with a cold recovery site?
الإجابة
It costs less to maintain, but recovery takes longer because systems, data, and connectivity must be prepared after activation.
البطاقة ٢٧٤
السؤال
Why identify stakeholders before approving a security-sensitive change?
الإجابة
They can identify operational impact, dependencies, and acceptance criteria that the implementer may otherwise miss.
البطاقة ٢٧٥
السؤال
How do attestation and acknowledgement differ?
الإجابة
Attestation asserts that a condition or control is true; acknowledgement confirms receipt or understanding of a requirement.
البطاقة ٢٧٦
السؤال
What does zero-trust adaptive identity mean?
الإجابة
Access decisions adjust to current risk signals rather than relying only on a static login.
البطاقة ٢٧٧
السؤال
What makes a security control physical?
الإجابة
It protects facilities or equipment through a tangible barrier or mechanism.
البطاقة ٢٧٨
السؤال
What is geo-fencing for data?
الإجابة
Enforcing location-based boundaries on where data or services may be accessed or operated.
البطاقة ٢٧٩
السؤال
What does a Trusted Platform Module protect?
الإجابة
Hardware-backed keys and measurements used for device identity, disk protection, and boot-state attestation.
البطاقة ٢٨٠
السؤال
Why can a managed service provider amplify risk?
الإجابة
Its privileged access and shared tooling can provide a path into many customers.
البطاقة ٢٨١
السؤال
What does probability express in risk analysis?
الإجابة
A quantified chance that a defined event will occur within stated conditions or time.
البطاقة ٢٨٢
السؤال
Why can shadow IT create a threat?
الإجابة
It bypasses security review, inventory, monitoring, and supported configuration.
البطاقة ٢٨٣
السؤال
What is on-path interception?
الإجابة
An attacker positions between communicating parties to observe or alter traffic.
البطاقة ٢٨٤
السؤال
Why include encryption in a system-hardening baseline?
الإجابة
It limits data exposure if storage, traffic, or a protected secret is accessed outside the intended trust boundary.
البطاقة ٢٨٥
السؤال
Why tune security alerts?
الإجابة
To keep useful detections while reducing noise that wastes analyst attention.
البطاقة ٢٨٦
السؤال
What can IPS or IDS logs contribute to an investigation?
الإجابة
The matched rule or signature, source and destination, timestamp, action, and traffic context around detected activity.
البطاقة ٢٨٧
السؤال
What is VM escape?
الإجابة
A vulnerability that lets code break out of a virtual machine and affect the host or another guest.
البطاقة ٢٨٨
السؤال
How can segmentation reduce vulnerability exposure before a patch is available?
الإجابة
It limits which systems and users can reach the vulnerable service and restricts paths for lateral movement.
البطاقة ٢٨٩
السؤال
Why should firewall policy name the required ports and protocols explicitly?
الإجابة
Explicit scope permits only the intended service traffic and avoids exposing unnecessary network paths.
البطاقة ٢٩٠
السؤال
What is a change management policy meant to control?
الإجابة
How changes are requested, assessed, approved, tested, implemented, and reviewed.
البطاقة ٢٩١
السؤال
What is a hybrid-cloud architecture?
الإجابة
An environment that integrates private or on-premises resources with public cloud services.
البطاقة ٢٩٢
السؤال
How do AH and ESP differ in the security services they can provide?
الإجابة
AH provides integrity and data-origin authentication without confidentiality. ESP can provide confidentiality and may also provide integrity and data-origin authentication. Actual services depend on AH or ESP, mode, algorithms, and policy/configuration.
البطاقة ٢٩٣
السؤال
What makes user behavior risky?
الإجابة
It creates avoidable exposure, such as bypassing controls, mishandling data, or using unapproved access paths.
البطاقة ٢٩٤
السؤال
What is least privilege?
الإجابة
Granting only the access needed for the required task and no more.
البطاقة ٢٩٥
السؤال
What do Secure, HttpOnly, and SameSite cookie attributes restrict?
الإجابة
Transmission to HTTPS, script access, and cross-site sending, respectively.
البطاقة ٢٩٦
السؤال
Why discover unmanaged assets?
الإجابة
Unknown systems cannot be patched, monitored, or governed reliably.
البطاقة ٢٩٧
السؤال
What is a service-level agreement?
الإجابة
Measurable service commitments and remedies, such as availability or response targets.
البطاقة ٢٩٨
السؤال
What should govern automated security escalation?
الإجابة
Clear severity criteria, ownership, evidence, rate limits, and a fallback path when the automation cannot decide safely.
البطاقة ٢٩٩
السؤال
What is platform diversity as a resilience strategy?
الإجابة
Using different implementations so one common flaw or failure is less likely to affect every copy.
البطاقة ٣٠٠
السؤال
How can replayed session material affect an application?
الإجابة
It can let an attacker reuse a captured token or request to impersonate a valid session or repeat an authorized action.
البطاقة ٣٠١
السؤال
What is an implicit trust zone in zero trust?
الإجابة
A boundary where access was previously trusted by location alone and must instead receive explicit policy enforcement.
البطاقة ٣٠٢
السؤال
What does salting a password hash accomplish?
الإجابة
It makes identical passwords hash differently and defeats precomputed hash tables.
البطاقة ٣٠٣
السؤال
What is spear phishing?
الإجابة
Phishing tailored to a specific person, role, or organization.
البطاقة ٣٠٤
السؤال
What is eradication?
الإجابة
Removing the attacker's access, malicious artifacts, and exploited conditions.
البطاقة ٣٠٥
السؤال
Who is a risk owner?
الإجابة
The person accountable for deciding and monitoring how a specific risk is handled.
البطاقة ٣٠٦
السؤال
What does a partially known penetration-test environment provide?
الإجابة
The tester receives limited information or access, modeling an attacker with some insider knowledge or initial foothold.
البطاقة ٣٠٧
السؤال
What is a microservices architecture?
الإجابة
An application is split into small independently deployable services with explicit interfaces and distributed trust boundaries.
البطاقة ٣٠٨
السؤال
What is a jump server?
الإجابة
A hardened intermediary used to reach systems in a restricted management network.
البطاقة ٣٠٩
السؤال
What can happen when a configuration change is made without dependency analysis?
الإجابة
A downstream service can fail even when the changed component works.
البطاقة ٣١٠
السؤال
What is resource reuse exposure?
الإجابة
Sensitive data from a previous use remains accessible when storage or memory is reassigned.
البطاقة ٣١١
السؤال
Why does financial information require explicit protection?
الإجابة
It can expose accounts, transactions, forecasts, or reporting and may create fraud, legal, or business risk if altered or disclosed.
البطاقة ٣١٢
السؤال
What does CVE provide?
الإجابة
A common identifier for a publicly disclosed vulnerability.
البطاقة ٣١٣
السؤال
Where can DLP controls operate?
الإجابة
On endpoints, networks, email, and cloud services, depending on the product and visibility.
البطاقة ٣١٤
السؤال
What does privileged password vaulting protect?
الإجابة
It stores and controls use of privileged secrets so users or automation do not need to know or retain the underlying password.
البطاقة ٣١٥
السؤال
What does an access-control standard define?
الإجابة
Mandatory, measurable requirements for identity, authentication, authorization, review, and removal of access.
البطاقة ٣١٦
السؤال
How can automation support compliance monitoring?
الإجابة
It can collect evidence, test controls, flag exceptions, and produce repeatable reports, with human review of context.
البطاقة ٣١٧
السؤال
What does static code analysis examine?
الإجابة
Source or compiled code for weakness patterns without executing the application.
البطاقة ٣١٨
السؤال
What actor attribute describes funding, time, and personnel?
الإجابة
Resources.
البطاقة ٣١٩
السؤال
What is DNS poisoning?
الإجابة
Introducing false DNS data so names resolve to attacker-chosen destinations.
البطاقة ٣٢٠
السؤال
Why change default credentials during hardening?
الإجابة
Default secrets are predictable and commonly targeted.
البطاقة ٣٢١
السؤال
What does quarantine do after a security alert?
الإجابة
It restricts a suspected asset or object while analysts validate and remediate the risk.
البطاقة ٣٢٢
السؤال
What does key stretching do for stored passwords?
الإجابة
It deliberately makes each password guess more computationally expensive.
البطاقة ٣٢٣
السؤال
What is smishing?
الإجابة
Phishing delivered through SMS or another text-messaging service.
البطاقة ٣٢٤
السؤال
What is qualitative risk analysis?
الإجابة
Using descriptive scales such as low, medium, and high to compare likelihood and impact.
البطاقة ٣٢٥
السؤال
What is a master service agreement?
الإجابة
An umbrella contract establishing general legal and commercial terms for ongoing work.
البطاقة ٣٢٦
السؤال
What is threat scope reduction?
الإجابة
Narrowing the systems, privileges, or paths an attacker can reach.
البطاقة ٣٢٧
السؤال
Why use a third-party cloud service instead of building locally?
الإجابة
It can provide faster deployment, elasticity, and managed capabilities, with added dependency and governance risk.
البطاقة ٣٢٨
السؤال
What should determine security-device placement?
الإجابة
The traffic or resource to observe or enforce, the trust boundary, failure behavior, reachability, and resilience needs.
البطاقة ٣٢٩
السؤال
What does situational awareness mean for a user?
الإجابة
Notice the people, devices, requests, location, and context around a task before acting.
البطاقة ٣٣٠
السؤال
What does a failover test validate?
الإجابة
That the service can transfer to the alternate component or site within the required recovery targets under the tested conditions.
البطاقة ٣٣١
السؤال
What is a preventive control meant to do?
الإجابة
Stop an unwanted event before it succeeds.
البطاقة ٣٣٢
السؤال
What is just-in-time privileged access?
الإجابة
Elevated access is granted only when needed and expires after a short approved period.
البطاقة ٣٣٣
السؤال
What safeguard should security-group automation enforce?
الإجابة
Least-privileged rules tied to an approved resource, owner, purpose, and review or expiration point.
البطاقة ٣٣٤
السؤال
How does a reflected DDoS attack hide and multiply sources?
الإجابة
The attacker spoofs the victim's address so many third-party services send their replies to the victim.
البطاقة ٣٣٥
السؤال
What is a security misconfiguration?
الإجابة
An unsafe setting, such as public storage, default access, or excessive permissions, that exposes a resource.
البطاقة ٣٣٦
السؤال
Why can the same vulnerability have different organizational impact?
الإجابة
Industry obligations, business processes, safety needs, data sensitivity, and asset criticality change the consequence of exploitation.
البطاقة ٣٣٧
السؤال
What does URL scanning evaluate before a user opens a web destination?
الإجابة
The address, redirect chain, reputation, category, and known threat indicators associated with the destination.
البطاقة ٣٣٨
السؤال
What is the board's security governance role?
الإجابة
Provide oversight, set risk direction, and hold executives accountable.
البطاقة ٣٣٩
السؤال
What does code signing establish?
الإجابة
That code came from the holder of the signing key and has not changed since signing.
البطاقة ٣٤٠
السؤال
How should an asset's classification affect security operations?
الإجابة
It should drive handling, access, monitoring, recovery, and disposal controls that match the asset's sensitivity and impact.
البطاقة ٣٤١
السؤال
How does encryption protect data?
الإجابة
It uses a cryptographic key to transform plaintext into ciphertext, which authorized parties can decrypt with the required key while unauthorized readers cannot feasibly recover the original data.
البطاقة ٣٤٢
السؤال
What is a secure enclave?
الإجابة
A hardware-isolated execution area intended to protect selected code and data from the rest of the system.
البطاقة ٣٤٣
السؤال
What is business email compromise?
الإجابة
Impersonation or takeover of a business identity to induce a fraudulent action, often a payment or data release.
البطاقة ٣٤٤
السؤال
What is recovery in incident response?
الإجابة
Restoring services safely, monitoring them, and returning to normal operations.
البطاقة ٣٤٥
السؤال
How is single loss expectancy commonly estimated?
الإجابة
Asset value multiplied by the exposure factor.
البطاقة ٣٤٦
السؤال
What does an unknown penetration-test environment provide?
الإجابة
The tester begins with little or no internal information, modeling an external attacker's discovery process.
البطاقة ٣٤٧
السؤال
What security boundary does a hypervisor provide?
الإجابة
It isolates virtual machines while controlling their access to shared hardware.
البطاقة ٣٤٨
السؤال
Why does a TLS tunnel not protect a compromised endpoint?
الإجابة
TLS protects data between endpoints; malware or misuse at either endpoint can access the data before encryption or after decryption.
البطاقة ٣٤٩
السؤال
Why update diagrams after an infrastructure change?
الإجابة
Operations and incident responders need the documentation to match the deployed environment.
البطاقة ٣٥٠
السؤال
What does privacy ownership assign?
الإجابة
An accountable role for privacy decisions, obligations, data inventory, and corrective action.
البطاقة ٣٥١
السؤال
What does a security control gap analysis compare?
الإجابة
The controls required for the target state with the controls currently in place.
البطاقة ٣٥٢
السؤال
Someone outside the organization steals an employee's VPN credentials and logs in. Is the actor internal or external?
الإجابة
External. Stolen internal credentials provide access but do not change the outsider's relationship to the organization.
البطاقة ٣٥٣
السؤال
What is application privilege escalation?
الإجابة
Exploiting a flaw or misconfiguration to gain permissions beyond those originally granted.
البطاقة ٣٥٤
السؤال
What risk remains when unnecessary software is left installed?
الإجابة
Its code, services, dependencies, and privileges add attack surface even when users do not need it.
البطاقة ٣٥٥
السؤال
What does SCAP standardize?
الإجابة
Formats and identifiers for expressing, checking, and scoring security configuration and vulnerability information.
البطاقة ٣٥٦
السؤال
What can packet capture reveal?
الإجابة
Protocol-level conversation details and payloads when traffic is not encrypted and collection is authorized.
البطاقة ٣٥٧
السؤال
What makes a privileged credential ephemeral?
الإجابة
It is created for a limited task or session and expires or is destroyed automatically after that use.
البطاقة ٣٥٨
السؤال
How do a statement of work and a work order differ?
الإجابة
A statement of work defines scope, deliverables, schedule, and responsibilities; a work order authorizes a defined unit of work under an agreement.
البطاقة ٣٥٩
السؤال
Why might multi-cloud improve resilience?
الإجابة
A provider-wide failure need not stop workloads that can run independently elsewhere.
البطاقة ٣٦٠
السؤال
How can a service provider introduce a supply-chain vulnerability?
الإجابة
Its privileged access, hosted service, or compromised integration can expose customers that depend on it.
البطاقة ٣٦١
السؤال
What is a false positive in vulnerability scanning?
الإجابة
A reported weakness that is not actually present or exploitable in the assessed context.
البطاقة ٣٦٢
السؤال
How do EDR and XDR differ?
الإجابة
EDR focuses on endpoint telemetry and response; XDR correlates detection and response across endpoints and other security domains.
البطاقة ٣٦٣
السؤال
What should onboarding and offboarding procedures coordinate?
الإجابة
Identity, access, equipment, data, training, approvals, and ownership changes at the start or end of a relationship.
البطاقة ٣٦٤
السؤال
How should an organization harden managed mobile devices?
الإجابة
Enforce an MDM baseline with timely updates, screen lock and encryption, least privilege, approved apps, and remote lock or wipe.
البطاقة ٣٦٥
السؤال
What is a certificate signing request?
الإجابة
A request containing a public key and subject information for a certificate authority to sign.
البطاقة ٣٦٦
السؤال
What is pretexting?
الإجابة
Using a fabricated role or situation to make a request seem legitimate.
البطاقة ٣٦٧
السؤال
How is annualized loss expectancy commonly estimated?
الإجابة
Single loss expectancy multiplied by annualized rate of occurrence.
البطاقة ٣٦٨
السؤال
What security consequence follows from containers sharing a kernel?
الإجابة
A host-kernel compromise can affect multiple containers, so kernel and runtime hardening matter.
البطاقة ٣٦٩
السؤال
Where does 802.1X enforce a network admission decision?
الإجابة
At the controlled switch port or wireless access point before normal network access is granted.
البطاقة ٣٧٠
السؤال
What should insider-threat awareness teach?
الإجابة
Recognize misuse or concerning behavior without profiling people, and report evidence through approved channels.
البطاقة ٣٧١
السؤال
What access action is suitable for careful automation?
الإجابة
Enabling or disabling a defined service or account from an approved lifecycle or incident event.
البطاقة ٣٧٢
السؤال
What is an evil twin?
الإجابة
A rogue wireless network made to resemble a legitimate one so users connect to it.
٧٤٤ بطاقة
CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
ادرس هذه الرزمة مجانًاسيفتح تطبيق Flashcards لتبدأ الدراسة.
البطاقة ٣٧٣
السؤال
Does non-human-readable data need less protection?
الإجابة
No. Encoded or machine-readable data can carry the same sensitive meaning and impact.
البطاقة ٣٧٤
السؤال
What does authenticating a system establish?
الإجابة
It verifies a presented authenticator or credential bound to the claimed device, workload, or service identity. Identity proofing or enrollment establishes what real-world entity that identity represents.
البطاقة ٣٧٥
السؤال
What does LDAP provide in identity systems?
الإجابة
A standard protocol for querying and modifying directory entries such as users, groups, and attributes.
البطاقة ٣٧٦
السؤال
What is a deterrent control meant to do?
الإجابة
Discourage an attacker from attempting an unwanted action.
البطاقة ٣٧٧
السؤال
Why update procedures after changing a security control?
الإجابة
Staff need accurate steps for operating, monitoring, and recovering the new control.
البطاقة ٣٧٨
السؤال
How does OCSP differ from a certificate revocation list?
الإجابة
OCSP returns status for a specific certificate, while a revocation list distributes a signed set of revoked certificate serial numbers.
البطاقة ٣٧٩
السؤال
What is the goal of data exfiltration?
الإجابة
Remove data from its authorized environment without permission.
البطاقة ٣٨٠
السؤال
What is a watering-hole attack?
الإجابة
Compromising a site frequented by the intended targets so their visits expose them.
البطاقة ٣٨١
السؤال
How can a hardware provider introduce a supply-chain vulnerability?
الإجابة
A compromised component, firmware image, manufacturing step, or delivery path can weaken the device before deployment.
البطاقة ٣٨٢
السؤال
What is application forgery?
الإجابة
Creating or altering a request, token, or object so the application treats it as authentic.
البطاقة ٣٨٣
السؤال
How does least privilege mitigate compromise?
الإجابة
It limits the actions and resources available to a compromised account or process.
البطاقة ٣٨٤
السؤال
What is serverless computing?
الإجابة
A model where the provider manages servers and the customer deploys event-driven code or functions.
البطاقة ٣٨٥
السؤال
What makes an infrastructure control effective for a specific risk?
الإجابة
Its placement, failure behavior, visibility, enforcement scope, and operating cost match the protected path and threat.
البطاقة ٣٨٦
السؤال
What does parallel recovery processing test?
الإجابة
Whether primary and alternate environments can run together consistently before a controlled cutover.
البطاقة ٣٨٧
السؤال
Which password-authentication method does WPA3-Personal use?
الإجابة
Simultaneous Authentication of Equals, which replaces WPA2-Personal's PSK authentication and resists offline password guessing.
البطاقة ٣٨٨
السؤال
How does data retention affect asset disposal?
الإجابة
Required data must be preserved for its retention period, while expired data should be sanitized before reuse or destruction.
البطاقة ٣٨٩
السؤال
What is a false negative in vulnerability scanning?
الإجابة
A real weakness that the assessment fails to report.
البطاقة ٣٩٠
السؤال
What does recurring security scanning add to monitoring?
الإجابة
Periodic discovery of exposed services, missing fixes, weak configurations, or other detectable changes.
البطاقة ٣٩١
السؤال
What should guide port selection for a secure protocol?
الإجابة
Use the documented service port or an explicitly managed alternative, and expose it only on the required interfaces and paths.
البطاقة ٣٩٢
السؤال
What does forensic acquisition create?
الإجابة
A controlled, documented copy or collection of relevant evidence while preserving its integrity and context.
البطاقة ٣٩٣
السؤال
How do system owners and data owners divide security accountability?
الإجابة
A system owner is accountable for the system's risk, access, operation, and lifecycle; a data owner sets the data's classification, access, handling, and retention requirements.
البطاقة ٣٩٤
السؤال
What does likelihood express in risk analysis?
الإجابة
A reasoned estimate of how plausible or frequent an event is, often stated qualitatively when precise probability is unavailable.
البطاقة ٣٩٥
السؤال
What is a memorandum of understanding?
الإجابة
A documented understanding of intentions and responsibilities, whose legal effect depends on its terms and jurisdiction.
البطاقة ٣٩٦
السؤال
What does the right to be forgotten generally require?
الإجابة
Deletion of qualifying personal data when the applicable law grants the right and no overriding retention duty applies.
البطاقة ٣٩٧
السؤال
What does an audit committee oversee?
الإجابة
Audit independence, plans, significant findings, management responses, and corrective-action follow-through.
البطاقة ٣٩٨
السؤال
What does identity interoperability require?
الإجابة
Compatible protocols, attribute meanings, trust, and lifecycle behavior across connected systems.
البطاقة ٣٩٩
السؤال
How does a bollard protect a facility?
الإجابة
It blocks or redirects vehicles before they can reach a protected area.
البطاقة ٤٠٠
السؤال
How can hashing protect a downloaded file?
الإجابة
A trusted digest lets the recipient detect whether the file changed.
البطاقة ٤٠١
السؤال
What is a credential replay attack?
الإجابة
Using captured valid credentials or tokens again without needing to discover the secret.
البطاقة ٤٠٢
السؤال
How can automation complexity create security risk?
الإجابة
Hidden dependencies and branching behavior can make failures difficult to predict, diagnose, contain, or reverse.
البطاقة ٤٠٣
السؤال
What must an architecture provide when a component cannot be patched?
الإجابة
Compensating isolation, restricted access, monitoring, and a replacement plan that reduce exposure until the component can be retired.
البطاقة ٤٠٤
السؤال
What makes remote access secure?
الإجابة
Controlled, authenticated, encrypted access to a private resource from outside its local trusted network.
البطاقة ٤٠٥
السؤال
What should users verify before connecting removable media or a cable?
الإجابة
That the device and connection are approved, expected, and handled under organizational policy.
البطاقة ٤٠٦
السؤال
What is a self-signed certificate?
الإجابة
A certificate signed by its own private key rather than by a separate trusted issuer.
البطاقة ٤٠٧
السؤال
What is brand impersonation?
الإجابة
Using a trusted organization's identity or look to deceive people.
البطاقة ٤٠٨
السؤال
What characterizes a conservative risk appetite?
الإجابة
A preference for lower uncertainty and exposure, even when that limits speed, return, or opportunity.
البطاقة ٤٠٩
السؤال
What should a managed mobile device verify before using Wi-Fi?
الإجابة
The expected network identity, strong encryption, trusted authentication, and policy compliance before sending sensitive traffic.
البطاقة ٤١٠
السؤال
What is a zero-day vulnerability?
الإجابة
A flaw previously unknown to the vendor or defenders, or one without an available fix when discovered. A zero-day exploit is code or a technique that attacks such a flaw.
البطاقة ٤١١
السؤال
What does verification confirm after vulnerability remediation?
الإجابة
Retesting confirms that the remediation removed or reduced the finding as intended within the tested scope.
البطاقة ٤١٢
السؤال
What is user and entity behavior analytics?
الإجابة
Analysis that identifies deviations from expected behavior for users, accounts, hosts, or services.
البطاقة ٤١٣
السؤال
What does a physical security policy establish?
الإجابة
Required protection for facilities, people, equipment, entry, monitoring, and response to physical events.
البطاقة ٤١٤
السؤال
What does a UPS provide?
الإجابة
Immediate short-term power and power conditioning while systems shut down or alternate power starts.
البطاقة ٤١٥
السؤال
What is a nondisclosure agreement?
الإجابة
A contract restricting use and disclosure of defined confidential information.
البطاقة ٤١٦
السؤال
What should be checked before assigning a user permission?
الإجابة
The user's approved duties, the resource and action allowed, separation-of-duties conflicts, and the impact if the permission is misused.
البطاقة ٤١٧
السؤال
How does espionage differ from ordinary theft?
الإجابة
It seeks confidential intelligence for strategic advantage, often while remaining hidden.
البطاقة ٤١٨
السؤال
What is password spraying?
الإجابة
Trying a small set of common passwords across many accounts to avoid lockouts.
البطاقة ٤١٩
السؤال
What is the purpose of system isolation during an incident?
الإجابة
Stop harmful communication while preserving the system for response and investigation.
البطاقة ٤٢٠
السؤال
What is a security benchmark?
الإجابة
A documented set of recommended configuration checks for a platform or product.
البطاقة ٤٢١
السؤال
Which metadata fields give a log record investigative context?
الإجابة
Fields such as timestamp and time zone, source system, user or process identity, event ID or type, severity, and correlation ID.
البطاقة ٤٢٢
السؤال
What does an access-control vestibule prevent?
الإجابة
It limits tailgating by allowing controlled passage through one door at a time.
البطاقة ٤٢٣
السؤال
What is version control's security value for configuration?
الإجابة
It preserves attributable history and enables review or rollback of changes.
البطاقة ٤٢٤
السؤال
Why use both internal and external compliance monitoring?
الإجابة
Internal monitoring supports continuous correction; external review adds independent or regulatory scrutiny.
البطاقة ٤٢٥
السؤال
What distinguishes on-premises architecture?
الإجابة
The organization operates the infrastructure in facilities it controls and retains the associated physical and platform duties.
البطاقة ٤٢٦
السؤال
What risk can split tunneling add to a VPN?
الإجابة
The endpoint can reach the protected network and an untrusted network at the same time, creating a path around centralized inspection.
البطاقة ٤٢٧
السؤال
What is a certificate root of trust?
الإجابة
A trusted root certificate or key from which a client validates a certificate chain.
البطاقة ٤٢٨
السؤال
What is typosquatting?
الإجابة
Registering a look-alike domain based on common typing errors or visual similarity.
البطاقة ٤٢٩
السؤال
What is root-cause analysis?
الإجابة
Identifying the underlying conditions that allowed an incident, not just its visible symptoms.
البطاقة ٤٣٠
السؤال
What is risk tolerance?
الإجابة
The acceptable variation or boundary around a specific objective or risk area.
البطاقة ٤٣١
السؤال
What is a security self-assessment?
الإجابة
A structured internal evaluation in which the organization measures its own controls against selected criteria.
البطاقة ٤٣٢
السؤال
What does data masking change?
الإجابة
It replaces sensitive values with altered but usable representations, often preserving format for testing or display.
البطاقة ٤٣٣
السؤال
How do wireless authentication protocols let clients prove identity securely?
الإجابة
They define how a client proves control of a credential, such as a password-derived secret or a certificate's private key; stronger choices also validate the server and protect the exchange.
البطاقة ٤٣٤
السؤال
Why reconcile inventory with network discovery?
الإجابة
Differences expose missing records, retired systems, or unauthorized devices.
البطاقة ٤٣٥
السؤال
Why does sideloading raise mobile risk?
الإجابة
It can bypass store review, signing policy, and managed application controls.
البطاقة ٤٣٦
السؤال
What does an information-sharing organization add to vulnerability management?
الإجابة
Sector or community intelligence about relevant threats, incidents, and defensive action.
البطاقة ٤٣٧
السؤال
What does a web-filter block rule specify?
الإجابة
The URL, domain, category, reputation, content, user, or context that should prevent a web request.
البطاقة ٤٣٨
السؤال
How do data custodians and data stewards differ?
الإجابة
Custodians implement and operate technical safeguards for data; stewards guide its definitions, quality, handling, and proper use under the owner’s direction.
البطاقة ٤٣٩
السؤال
What is a brute-force password attack?
الإجابة
Systematically trying many candidate secrets against an account or protected value.
البطاقة ٤٤٠
السؤال
What is a compensating control?
الإجابة
An alternative safeguard used when the preferred control is impractical or unavailable.
البطاقة ٤٤١
السؤال
How can location act as an authentication factor?
الإجابة
A system can evaluate where the claimant is, but location signals are usually contextual and spoofable rather than sufficient alone.
البطاقة ٤٤٢
السؤال
Why must security automation remain supportable?
الإجابة
Owners must be able to update dependencies, understand failures, rotate credentials, and adapt the workflow as systems change.
البطاقة ٤٤٣
السؤال
What does a standby generator provide?
الإجابة
Longer-duration power during a utility outage, after a startup delay.
البطاقة ٤٤٤
السؤال
What makes an architecture air-gapped?
الإجابة
It has no direct network path to less-trusted networks, although removable media and maintenance workflows can still cross the boundary.
البطاقة ٤٤٥
السؤال
What is a software-defined WAN?
الإجابة
A centrally managed overlay that selects wide-area paths by policy across underlying network links.
البطاقة ٤٤٦
السؤال
What password-management behavior should awareness training reinforce?
الإجابة
Use unique long passwords through an approved manager and report suspected compromise promptly.
البطاقة ٤٤٧
السؤال
What security value does fencing provide?
الإجابة
It defines and delays entry across a physical perimeter.
البطاقة ٤٤٨
السؤال
What is a wildcard certificate?
الإجابة
A certificate that can match multiple hosts at one domain level, such as subdomains of an example domain.
البطاقة ٤٤٩
السؤال
How does misinformation differ from disinformation?
الإجابة
Misinformation is false regardless of intent; disinformation is deliberately false or misleading.
البطاقة ٤٥٠
السؤال
What is a risk threshold?
الإجابة
A defined level that triggers escalation, treatment, or another required response.
البطاقة ٤٥١
السؤال
What does a vendor penetration test contribute to assessment?
الإجابة
Authorized evidence of exploitable paths in the vendor's relevant environment under agreed scope.
البطاقة ٤٥٢
السؤال
What is the objective of a service-disruption attack?
الإجابة
Make a system or business function unavailable or unreliable.
البطاقة ٤٥٣
السؤال
What is directory traversal?
الإجابة
Manipulating a file path to reach files outside the directory the application intended to expose.
البطاقة ٤٥٤
السؤال
Why decommission an unsupported system?
الإجابة
Removing it eliminates an exposure that can no longer be patched or securely maintained.
البطاقة ٤٥٥
السؤال
Why archive security-monitoring data?
الإجابة
To preserve evidence for investigations, trend analysis, compliance, and retention requirements beyond the live system.
البطاقة ٤٥٦
السؤال
What role does RADIUS commonly play in enterprise Wi-Fi?
الإجابة
It centralizes authentication, authorization information, and accounting for network access.
البطاقة ٤٥٧
السؤال
Why separate the requester and approver of a high-risk change?
الإجابة
To reduce error, fraud, and unilateral unauthorized modification.
البطاقة ٤٥٨
السؤال
Why can a jailbroken device violate a security baseline?
الإجابة
It weakens platform isolation and allows unapproved privileged changes.
البطاقة ٤٥٩
السؤال
When is tokenization especially useful?
الإجابة
When a system needs a surrogate value without retaining the original sensitive value in that workflow.
البطاقة ٤٦٠
السؤال
Why can dark-web intelligence affect vulnerability priority?
الإجابة
Discussion, exploit sales, or leaked access can signal attacker interest, but the evidence must be validated.
البطاقة ٤٦١
السؤال
What firewall policy should govern traffic from a screened subnet to internal systems?
الإجابة
Deny it by default and allow only explicitly required flows.
البطاقة ٤٦٢
السؤال
What does SAML commonly carry?
الإجابة
XML assertions about authentication and attributes between an identity provider and service provider; signatures commonly protect their authenticity and integrity.
البطاقة ٤٦٣
السؤال
What does a security governance committee do?
الإجابة
It coordinates stakeholders, reviews risk and performance, and makes or recommends decisions within its charter.
البطاقة ٤٦٤
السؤال
How can global privacy requirements affect one data process?
الإجابة
A shared process may need to satisfy overlapping duties across jurisdictions where people, systems, or data are located.
البطاقة ٤٦٥
السؤال
What characterizes an IoT device?
الإجابة
It combines sensing or actuation with network connectivity, often under tight resource and update constraints.
البطاقة ٤٦٦
السؤال
What is a unified threat management appliance?
الإجابة
One device combines several controls, such as firewalling, intrusion prevention, filtering, and malware inspection.
البطاقة ٤٦٧
السؤال
What does a hardware security module provide?
الإجابة
A dedicated, tamper-resistant environment for generating, storing, and using cryptographic keys.
البطاقة ٤٦٨
السؤال
A remotely reachable API is fixed, but its desktop client stays vulnerable. What exposure remains?
الإجابة
Client-based exposure remains because the installed endpoint software is still vulnerable; fixing the remote API does not remediate the client.
البطاقة ٤٦٩
السؤال
What is a tabletop exercise?
الإجابة
A discussion-based walkthrough of a scenario to test decisions, roles, and procedures.
البطاقة ٤٧٠
السؤال
What does a risk exemption authorize?
الإجابة
A documented release from a requirement for a defined scope, owner, rationale, controls, review, and expiration.
البطاقة ٤٧١
السؤال
What is a regulatory examination?
الإجابة
An authorized regulator reviews records, controls, and practices to determine whether the organization meets applicable requirements.
البطاقة ٤٧٢
السؤال
What does physical video surveillance primarily provide?
الإجابة
Detection and evidence of activity in monitored areas.
البطاقة ٤٧٣
السؤال
What is a birthday attack against a hash?
الإجابة
Using collision probability to find any two matching digests much faster than targeting one exact preimage.
البطاقة ٤٧٤
السؤال
Why keep backups both onsite and offsite?
الإجابة
Onsite copies support fast recovery, while offsite copies survive a site-wide loss.
البطاقة ٤٧٥
السؤال
How does technical debt affect security automation?
الإجابة
Outdated assumptions, dependencies, and workarounds make the workflow harder to change and more likely to fail unsafely.
البطاقة ٤٧٦
السؤال
What should switch hardening restrict first?
الإجابة
Administrative access, unused ports, insecure management protocols, and unauthorized changes to switching configuration.
البطاقة ٤٧٧
السؤال
What should happen when an asset changes owners?
الإجابة
Inventory, access, support responsibility, and data handling should be updated.
البطاقة ٤٧٨
السؤال
What does evidence of a vendor's internal audits contribute?
الإجابة
It shows how the vendor tests its own controls, records findings, assigns remediation, and follows issues to closure.
البطاقة ٤٧٩
السؤال
What is identity attestation?
الإجابة
Evidence that an identity, device, authenticator, or claim has been verified by a trusted process.
البطاقة ٤٨٠
السؤال
Why can standard enterprise patching be unsafe for an RTOS device?
الإجابة
A change can disrupt timing guarantees or certified operational behavior.
البطاقة ٤٨١
السؤال
What is secure access service edge?
الإجابة
A cloud-delivered architecture that combines wide-area connectivity with policy-driven security services near users and resources.
البطاقة ٤٨٢
السؤال
What social-engineering habit should awareness training reinforce?
الإجابة
Pause and independently verify unusual requests instead of trusting urgency, authority, or familiarity.
البطاقة ٤٨٣
السؤال
How can a software provider introduce a supply-chain vulnerability?
الإجابة
A compromised package, build system, dependency, or update channel can deliver vulnerable or malicious code to customers.
البطاقة ٤٨٤
السؤال
Why include internet exposure in remediation priority?
الإجابة
A reachable vulnerable service usually has more attack opportunity than an isolated one.
البطاقة ٤٨٥
السؤال
What does a mail gateway inspect?
الإجابة
Inbound and outbound email for threats, policy violations, spoofing, and sensitive data.
البطاقة ٤٨٦
السؤال
What is a data controller?
الإجابة
The entity that determines why and how personal data is processed.
البطاقة ٤٨٧
السؤال
How does blackmail motivate a cyberattack?
الإجابة
The attacker threatens disclosure or harm unless the victim complies.
البطاقة ٤٨٨
السؤال
What is a downgrade attack?
الإجابة
Forcing parties to use an older or weaker protocol or security mode.
البطاقة ٤٨٩
السؤال
How does encryption mitigate data exposure?
الإجابة
It makes captured data unreadable without the required key.
البطاقة ٤٩٠
السؤال
How do network and web vulnerability scanners differ?
الإجابة
Network scanners assess reachable hosts, services, versions, and configurations; web scanners exercise running web behavior for application weaknesses.
البطاقة ٤٩١
السؤال
How can vulnerability-scan data support an investigation?
الإجابة
It shows which weaknesses, versions, services, and exposures were known on the affected systems near the incident timeline.
البطاقة ٤٩٢
السؤال
What is key escrow?
الإجابة
Controlled storage of a recoverable copy of a cryptographic key by an authorized party.
البطاقة ٤٩٣
السؤال
Which human vector commonly uses a fake sign-in page to harvest credentials?
الإجابة
Phishing; the message sends the target to an imitation service that captures the submitted credentials.
البطاقة ٤٩٤
السؤال
What is risk avoidance?
الإجابة
Stopping or not starting the activity that creates the risk.
البطاقة ٤٩٥
السؤال
What is data obfuscation?
الإجابة
Making data harder to understand while preserving some utility, without necessarily providing cryptographic secrecy.
البطاقة ٤٩٦
السؤال
What is a directive control?
الإجابة
A safeguard that tells people what behavior or action is required.
البطاقة ٤٩٧
السؤال
What does a security guard add that a camera cannot?
الإجابة
Human judgment and an immediate physical response.
البطاقة ٤٩٨
السؤال
Why define restricted activities in change management?
الإجابة
High-risk actions can then require extra authorization, separation of duties, or a prohibited window.
البطاقة ٤٩٩
السؤال
What contractual impact can noncompliance create?
الإجابة
It can trigger remediation duties, service credits, indemnity, audit rights, suspension, termination, or claims for breach.
البطاقة ٥٠٠
السؤال
What should determine backup frequency?
الإجابة
The recovery point objective, data-change rate, business impact, and available replication or storage capacity.
البطاقة ٥٠١
السؤال
What should router hardening protect?
الإجابة
Administrative access, routing configuration, exposed services, and the integrity of traffic-control policy.
البطاقة ٥٠٢
السؤال
What problem does OAuth 2.0 address?
الإجابة
Delegated authorization: a client obtains limited access to a resource without receiving the user's password.
البطاقة ٥٠٣
السؤال
What does SCADA do?
الإجابة
It provides supervisory monitoring and control across distributed industrial equipment.
البطاقة ٥٠٤
السؤال
How does a Layer 3/4 firewall rule differ from a Layer 7 rule?
الإجابة
Layer 3/4 evaluates IP addresses plus transport protocols and ports; Layer 7 evaluates application content or actions.
البطاقة ٥٠٥
السؤال
What distinguishes a computer virus?
الإجابة
It attaches to a host file or program and spreads when that infected host executes or is shared.
البطاقة ٥٠٦
السؤال
What does a key management system coordinate?
الإجابة
Secure key creation, storage, access, rotation, revocation, recovery, and destruction.
البطاقة ٥٠٧
السؤال
How can an unsecure wired network expose traffic?
الإجابة
An unauthorized device on the network may observe, redirect, or inject traffic when access control and link protections are weak.
البطاقة ٥٠٨
السؤال
Why is vulnerable device firmware hard to remediate?
الإجابة
Firmware updates may be rare, vendor-dependent, or impossible after support ends.
البطاقة ٥٠٩
السؤال
What does patching change in vulnerability remediation?
الإجابة
It installs the vendor's corrected code or configuration to remove the underlying software weakness.
البطاقة ٥١٠
السؤال
What does DMARC add to SPF and DKIM?
الإجابة
Domain alignment, receiver policy, and reporting for messages claiming the visible From domain.
البطاقة ٥١١
السؤال
How does automation improve security efficiency?
الإجابة
It performs repeatable actions quickly and consistently while reducing manual handoffs and rework.
البطاقة ٥١٢
السؤال
What is a simulation exercise?
الإجابة
A more realistic practice in which participants respond to injected events using operational processes.
البطاقة ٥١٣
السؤال
What is a data processor?
الإجابة
An entity that processes personal data on behalf of a controller.
البطاقة ٥١٤
السؤال
What is risk mitigation?
الإجابة
Reducing likelihood, impact, or both through controls or process changes.
البطاقة ٥١٥
السؤال
Why monitor a vendor after onboarding?
الإجابة
Security posture, ownership, services, incidents, and dependencies can change.
البطاقة ٥١٦
السؤال
What does a physical penetration test assess?
الإجابة
Whether authorized testers can bypass facility, personnel, and physical access controls under agreed rules.
البطاقة ٥١٧
السؤال
Why use access badges at a facility?
الإجابة
To associate entry attempts with authorized identities and enforce access rules.
البطاقة ٥١٨
السؤال
How does permission restriction protect data?
الإجابة
Only authorized identities receive the actions and scope their roles require.
البطاقة ٥١٩
السؤال
What is the usual objective of ransomware extortion?
الإجابة
Force payment by denying access, threatening disclosure, or both.
البطاقة ٥٢٠
السؤال
What does impossible travel indicate?
الإجابة
One identity appears to authenticate from distant locations too quickly for legitimate travel.
البطاقة ٥٢١
السؤال
What is configuration enforcement?
الإجابة
Continuously applying or restoring approved settings so systems do not remain in an insecure state.
البطاقة ٥٢٢
السؤال
What does a web vulnerability scanner inspect?
الإجابة
Running web behavior for issues such as unsafe input handling and insecure configuration.
البطاقة ٥٢٣
السؤال
How does cost affect an architecture choice?
الإجابة
It constrains acquisition, operation, staffing, resilience, and recovery options across the system's life.
البطاقة ٥٢٤
السؤال
What does EAP provide with 802.1X?
الإجابة
A framework for carrying an authentication method between the supplicant and authentication infrastructure.
البطاقة ٥٢٥
السؤال
What should operational-security training help users protect?
الإجابة
Sensitive routines, capabilities, locations, relationships, and small details that an observer could combine into useful intelligence.
البطاقة ٥٢٦
السؤال
What does a time-of-day access rule do?
الإجابة
Allows or denies a requested action according to an approved schedule.
البطاقة ٥٢٧
السؤال
What should cloud infrastructure hardening establish?
الإجابة
Secure identities, network boundaries, logging, encryption, approved configurations, and continuous checks for drift.
البطاقة ٥٢٨
السؤال
What should an asset owner ensure during offboarding?
الإجابة
Assigned assets, access, data, and custody records are returned, transferred, or disposed of under the approved process.
البطاقة ٥٢٩
السؤال
Why encrypt backups?
الإجابة
Backup media and transfers can expose the same sensitive data as production systems.
البطاقة ٥٣٠
السؤال
What is steganography?
الإجابة
Hiding the existence of data inside another medium rather than merely encrypting its contents.
البطاقة ٥٣١
السؤال
Which human vector uses a fabricated authority role to justify a sensitive request?
الإجابة
Pretexting; the attacker invents a credible role and situation to make the request seem legitimate.
البطاقة ٥٣٢
السؤال
Why does risk transfer not remove accountability?
الإجابة
The organization can retain legal, reputational, operational, and oversight consequences.
البطاقة ٥٣٣
السؤال
Why validate a change after deployment?
الإجابة
To confirm the intended result occurred without introducing unacceptable side effects.
البطاقة ٥٣٤
السؤال
What makes end-of-life hardware a security vulnerability?
الإجابة
The vendor no longer supplies fixes or support, so known weaknesses can persist without a reliable remediation path.
البطاقة ٥٣٥
السؤال
What does an audit add to remediation validation?
الإجابة
Independent evidence that the approved fix, process, and documentation were completed and remain effective.
البطاقة ٥٣٦
السؤال
Why can SPF pass while a message still impersonates a brand?
الإجابة
SPF checks the envelope domain, which may differ from the visible From domain.
البطاقة ٥٣٧
السؤال
What role can a government entity have in security governance?
الإجابة
It can establish, enforce, or oversee legal and regulatory requirements within its authority.
البطاقة ٥٣٨
السؤال
How do data inventory and retention support privacy governance?
الإجابة
The inventory records what data is processed and where; retention rules define how long it is kept and when it is deleted or anonymized.
البطاقة ٥٣٩
السؤال
What can concurrent sessions from distant regions indicate?
الإجابة
A stolen account or shared credential, subject to VPN and proxy context.
البطاقة ٥٤٠
السؤال
What does supply-chain analysis examine?
الإجابة
Upstream providers, components, dependencies, concentration, and compromise paths that can affect the purchased service.
البطاقة ٥٤١
السؤال
What is the purpose of facility lighting as a control?
الإجابة
Deter covert activity and improve observation of people and areas.
البطاقة ٥٤٢
السؤال
What architecture quality keeps a service usable during component failure?
الإجابة
Availability.
البطاقة ٥٤٣
السؤال
When is fail-open behavior preferable to fail-closed behavior?
الإجابة
When preserving availability during control failure is more important than blocking uninspected traffic, based on the system's risk decision.
البطاقة ٥٤٤
السؤال
Which control function does a login-failure alert provide?
الإجابة
Detection; it reveals suspicious authentication activity.
البطاقة ٥٤٥
السؤال
What does a biometric MFA implementation verify?
الإجابة
A measured physical or behavioral characteristic presented by the user, matched against an enrolled template.
البطاقة ٥٤٦
السؤال
How can automation enforce a security baseline?
الإجابة
It compares realized settings with the approved state and reports or corrects unauthorized drift.
البطاقة ٥٤٧
السؤال
How do wireless cryptographic protocols protect network traffic?
الإجابة
They encrypt frames over the air and add integrity protection, reducing eavesdropping and tampering when a secure protocol and configuration are used.
البطاقة ٥٤٨
السؤال
Why segment sensitive data stores?
الإجابة
It limits reachable paths and separates them from lower-trust workloads.
البطاقة ٥٤٩
السؤال
What must remain secret in an asymmetric key pair?
الإجابة
The private key; disclosure lets another party impersonate the owner or decrypt data intended for that key, depending on its use.
البطاقة ٥٥٠
السؤال
How can a supplier become a supply-chain attack vector?
الإجابة
A compromised material, component, credential, or delivery process can weaken products before they reach the organization.
البطاقة ٥٥١
السؤال
What is e-discovery?
الإجابة
Identifying, preserving, collecting, reviewing, and producing electronically stored information for a legal matter.
البطاقة ٥٥٢
السؤال
What characterizes a neutral risk appetite?
الإجابة
A balanced willingness to accept uncertainty when expected value and controls justify the exposure.
البطاقة ٥٥٣
السؤال
What is passive reconnaissance?
الإجابة
Gathering information without directly interacting with the target's systems.
البطاقة ٥٥٤
السؤال
What does a philosophical motive mean for a threat actor?
الإجابة
The actor acts to advance a belief or moral position rather than primarily for money.
البطاقة ٥٥٥
السؤال
What does unexpected resource consumption indicate?
الإجابة
Possible malware, denial of service, cryptomining, or a malfunction that needs investigation.
البطاقة ٥٥٦
السؤال
What does a host-based intrusion prevention system do?
الإجابة
It monitors activity on one host and can block behavior that matches exploit or attack rules.
البطاقة ٥٥٧
السؤال
How does agent-based monitoring differ from agentless monitoring?
الإجابة
An agent collects local detail on the host; agentless monitoring uses remote interfaces and may have less visibility.
البطاقة ٥٥٨
السؤال
What can network logs contribute to an investigation?
الإجابة
Connection timing, endpoints, protocols, routing, name resolution, and other evidence of communication across the environment.
البطاقة ٥٥٩
السؤال
What is the purpose of a backup restore test?
الإجابة
Demonstrate under tested conditions that required data and systems can be recovered within expectations.
البطاقة ٥٦٠
السؤال
Why can obsolete hardware become a security risk?
الإجابة
It may lack supported firmware, modern protections, or replacement parts.
البطاقة ٥٦١
السؤال
What does rescanning confirm after remediation?
الإجابة
Whether the scanner can still detect the original finding on the affected asset.
البطاقة ٥٦٢
السؤال
What should a secure transport method provide?
الإجابة
Authenticated endpoints where required, confidentiality, integrity, replay resistance, and supported cryptography for the traffic.
البطاقة ٥٦٣
السؤال
How can law affect security governance?
الإجابة
It can impose mandatory duties based on jurisdiction, data, industry, or activity.
البطاقة ٥٦٤
السؤال
What does resilience mean for a security architecture?
الإجابة
The ability to withstand disruption, adapt, and recover while preserving essential functions.
البطاقة ٥٦٥
السؤال
Why minimize an infrastructure's attack surface?
الإجابة
Fewer exposed services and paths leave fewer opportunities for exploitation.
البطاقة ٥٦٦
السؤال
What does executing a security-awareness program require?
الإجابة
Delivering the approved content to the intended audiences, tracking participation, handling exceptions, and measuring outcomes.
البطاقة ٥٦٧
السؤال
What does an infrared security sensor detect?
الإجابة
A change in infrared energy, often the heat pattern created by a person moving through its field of view.
البطاقة ٥٦٨
السؤال
What is a knowledge factor?
الإجابة
Something the claimant knows, such as a password.
البطاقة ٥٦٩
السؤال
Why review allow-list and deny-list impact before a change?
الإجابة
Adding or removing an entry can unexpectedly grant access, block users, or interrupt dependencies.
البطاقة ٥٧٠
السؤال
What does partition-level encryption protect?
الإجابة
One selected disk partition, leaving other partitions outside that encryption boundary.
البطاقة ٥٧١
السؤال
How can instant messaging deliver a security attack?
الإجابة
It can deliver a malicious link, file, request, or impersonated conversation through a fast, trusted-looking channel.
البطاقة ٥٧٢
السؤال
What can repeated blocked-content events indicate?
الإجابة
Malware, policy bypass, a misconfigured application, or a user repeatedly reaching prohibited resources.
البطاقة ٥٧٣
السؤال
What should a server-hardening baseline reduce?
الإجابة
Unnecessary services, exposed administration, weak identity controls, insecure defaults, and unmonitored configuration change.
البطاقة ٥٧٤
السؤال
When is physical media destruction appropriate?
الإجابة
When reuse is unnecessary or sanitization cannot provide adequate assurance.
البطاقة ٥٧٥
السؤال
What is mean time to repair?
الإجابة
The average time required to restore a failed component or service.
البطاقة ٥٧٦
السؤال
Why disclose conflicts of interest during vendor selection?
الإجابة
A personal or financial relationship can bias evaluation away from the organization's requirements.
البطاقة ٥٧٧
السؤال
What is a fine for noncompliance?
الإجابة
A monetary penalty imposed for failing to meet a legal, regulatory, or contractual requirement.
البطاقة ٥٧٨
السؤال
What does a public data classification authorize?
الإجابة
Approved disclosure without confidentiality restrictions, while integrity and availability requirements may still apply.
البطاقة ٥٧٩
السؤال
What security benefit comes from standard infrastructure configurations?
الإجابة
They reduce variation, make review repeatable, and let the same approved controls be applied across resources.
البطاقة ٥٨٠
السؤال
How does horizontal scaling increase capacity?
الإجابة
It adds more service instances and distributes work among them.
البطاقة ٥٨١
السؤال
Why can added connectivity weaken segmentation?
الإجابة
Each allowed path can become a route for lateral movement or data escape.
البطاقة ٥٨٢
السؤال
What coding practice is central to preventing SQL injection?
الإجابة
Use parameterized queries so untrusted values remain data rather than executable query syntax.
البطاقة ٥٨٣
السؤال
When is a compensating control appropriate for a vulnerability?
الإجابة
When timely removal or patching is infeasible and another control can reduce the risk.
البطاقة ٥٨٤
السؤال
How does agent-based web filtering enforce policy?
الإجابة
Software on the endpoint evaluates or redirects web traffic, including traffic that does not pass through a central network proxy.
البطاقة ٥٨٥
السؤال
How can regulation differ from an internal policy?
الإجابة
Regulation is externally enforceable; internal policy is an organizational rule that may implement external duties.
البطاقة ٥٨٦
السؤال
What is a storage snapshot?
الإجابة
A point-in-time representation of data or system state, whose independence depends on how it is stored.
البطاقة ٥٨٧
السؤال
What does password age measure?
الإجابة
How long the current password has existed, which policy may use to prevent immediate reuse or trigger a risk-based change.
البطاقة ٥٨٨
السؤال
What does an ethical motive mean in vulnerability research?
الإجابة
The researcher intends to improve security, typically through authorized testing and responsible disclosure.
البطاقة ٥٨٩
السؤال
What can missing security logs indicate?
الإجابة
Logging failure, tampering, retention misconfiguration, or an inactive source.
البطاقة ٥٩٠
السؤال
Why disable unused ports and protocols?
الإجابة
They expose unnecessary communication paths and code that attackers can reach.
البطاقة ٥٩١
السؤال
What does antivirus contribute to monitoring?
الإجابة
It scans files, memory, or behavior and reports suspected malicious code.
البطاقة ٥٩٢
السؤال
What is a honeypot?
الإجابة
A decoy system or service designed to attract and observe malicious activity.
البطاقة ٥٩٣
السؤال
What does file-level encryption protect?
الإجابة
Selected files independently of whether the rest of the disk or volume is encrypted.
البطاقة ٥٩٤
السؤال
How can SMS deliver a security attack?
الإجابة
A text message can carry a malicious link or urgent request that exploits the recipient's trust in the phone channel.
البطاقة ٥٩٥
السؤال
What happens during incident analysis?
الإجابة
Responders validate the event, determine scope and impact, build a timeline, and identify the systems, accounts, and data involved.
البطاقة ٥٩٦
السؤال
What is mean time between failures?
الإجابة
The average operating time between repairable failures.
البطاقة ٥٩٧
السؤال
What is active reconnaissance?
الإجابة
Probing or interacting with target systems to discover services and behavior.
البطاقة ٥٩٨
السؤال
What constraint should guide ICS or SCADA hardening?
الإجابة
Safety and process availability must be preserved while access, services, network paths, and changes are tightly controlled.
البطاقة ٥٩٩
السؤال
Which control function does restoring a clean system image provide?
الإجابة
Correction; it returns the system to a known-good state.
البطاقة ٦٠٠
السؤال
What does responsiveness mean in an architecture decision?
الإجابة
How quickly the system and its operators can adapt to demand, failure, or attack.
البطاقة ٦٠١
السؤال
How does out-of-band access strengthen remote administration?
الإجابة
It uses a management path separate from production traffic, preserving controlled access during an outage or compromise.
البطاقة ٦٠٢
السؤال
What makes user behavior unexpected?
الإجابة
It differs materially from the person's normal role, timing, location, resource use, or established work pattern.
البطاقة ٦٠٣
السؤال
What is a work order?
الإجابة
A document authorizing a defined unit of work under an existing agreement.
البطاقة ٦٠٤
السؤال
What can out-of-cycle logging indicate?
الإجابة
Unexpected activity outside a system's normal schedule, including misuse, compromise, or an unplanned job.
البطاقة ٦٠٥
السؤال
Why update a standard operating procedure after a change?
الإجابة
It keeps routine work aligned with the new approved state and reduces inconsistent or unsafe execution.
البطاقة ٦٠٦
السؤال
What coding practice limits cross-site scripting?
الإجابة
Context-appropriate output encoding, supported by safe templating and input handling.
البطاقة ٦٠٧
السؤال
What does a restricted data classification indicate?
الإجابة
Access is tightly limited because unauthorized disclosure, alteration, or loss would create serious harm.
البطاقة ٦٠٨
السؤال
How does a bug bounty support responsible disclosure?
الإجابة
It defines eligible systems, rules, reporting, and possible rewards for external researchers.
البطاقة ٦٠٩
السؤال
What does web-filter content categorization provide?
الإجابة
A policy label for a site or page based on its subject, function, or risk so access rules can treat categories consistently.
البطاقة ٦١٠
السؤال
How do hard and soft authentication tokens differ?
الإجابة
A hard token is a separate physical device; a soft token is implemented in software on a general-purpose device.
البطاقة ٦١١
السؤال
How can industry requirements affect security governance?
الإجابة
Industry standards, shared practices, assurance expectations, and sector-specific risks can shape required policies and controls.
البطاقة ٦١٢
السؤال
How can noncompliance cause loss of a license?
الإجابة
An authority may suspend or revoke the permission needed to operate, sell, or perform regulated work.
البطاقة ٦١٣
السؤال
What does volume-level encryption protect?
الإجابة
All data within a selected logical storage volume.
البطاقة ٦١٤
السؤال
How can impersonation exploit familiarity?
الإجابة
The attacker imitates a known person or routine communication style so the request receives less scrutiny.
البطاقة ٦١٥
السؤال
How does RTO guide recovery design?
الإجابة
It sets the target maximum time to restore the function, driving recovery automation, staffing, capacity, and site choices.
البطاقة ٦١٦
السؤال
What is a honeynet?
الإجابة
A network of decoy systems used to study or divert attackers.
البطاقة ٦١٧
السؤال
What does backup replication provide?
الإجابة
Additional synchronized or copied recovery data in another system or location.
البطاقة ٦١٨
السؤال
What lets automation scale securely?
الإجابة
Bounded permissions, validated inputs, rate controls, audit records, and consistent policy at every new resource.
البطاقة ٦١٩
السؤال
Why monitor a hardened computing resource continuously?
الإجابة
New drift, failures, attacks, and unsupported changes can appear after a secure baseline is deployed.
البطاقة ٦٢٠
السؤال
Why keep a certificate of destruction?
الإجابة
It documents that a disposal provider handled specified media under the agreed process.
البطاقة ٦٢١
السؤال
Why consider patch availability before selecting a platform?
الإجابة
Unsupported or difficult-to-update components accumulate known exposure.
البطاقة ٦٢٢
السؤال
Why should remote administration use an encrypted, authenticated protocol?
الإجابة
It keeps credentials and commands confidential in transit. When correctly configured with integrity protection, the protocol also detects tampering and authenticates the intended endpoint.
البطاقة ٦٢٣
السؤال
How can revenge motivate an insider incident?
الإجابة
A disgruntled person may damage systems or disclose data to punish the organization.
البطاقة ٦٢٤
السؤال
What is a published or documented indicator of malicious activity?
الإجابة
A malicious observable or behavior—such as a hash, domain, IP address, or TTP—shared through threat intelligence, an advisory, or an incident report to help identify related malicious activity.
البطاقة ٦٢٥
السؤال
Why monitor a system more closely when a mitigation exception is accepted?
الإجابة
Monitoring can reveal exploitation or control failure while the documented exception remains open.
البطاقة ٦٢٦
السؤال
What is an SNMP trap?
الإجابة
An unsolicited device notification sent to a management system when a configured event occurs.
البطاقة ٦٢٧
السؤال
How can an automated report support an investigation?
الإجابة
It assembles repeatable findings, trends, or control results that investigators can correlate with the incident timeline.
البطاقة ٦٢٨
السؤال
What is a security key?
الإجابة
A hardware authenticator that uses cryptographic proof, often bound to the legitimate service origin.
البطاقة ٦٢٩
السؤال
What does database-level encryption protect?
الإجابة
A database or selected database structures through controls managed at the database layer.
البطاقة ٦٣٠
السؤال
How does brand impersonation exploit trust?
الإجابة
It copies a familiar organization's identity so a fraudulent message, site, or account appears legitimate.
البطاقة ٦٣١
السؤال
What browser-side impact can a cross-site scripting vulnerability create?
الإجابة
It can run attacker-controlled script in a trusted site's origin and access data or actions available to the victim's session.
البطاقة ٦٣٢
السؤال
How can a system or process audit identify vulnerabilities?
الإجابة
It compares evidence with required configuration and procedure to reveal control gaps.
البطاقة ٦٣٣
السؤال
What security role can Group Policy provide?
الإجابة
Centralized Windows configuration of account, application, audit, and system security settings.
البطاقة ٦٣٤
السؤال
What should incident-response training prepare people to do?
الإجابة
Recognize their role, use the communication and escalation paths, preserve evidence, and perform approved response actions.
البطاقة ٦٣٥
السؤال
Why must governance track local or regional requirements?
الإجابة
They may impose location-specific duties that differ from national, global, industry, or contractual rules.
البطاقة ٦٣٦
السؤال
How can a dependency become a useful key risk indicator?
الإجابة
A measurable change in its availability, capacity, control state, or concentration can warn that exposure is increasing.
البطاقة ٦٣٧
السؤال
What is a business partners agreement?
الإجابة
An agreement defining how business partners will work together, including responsibilities and security or data-handling terms.
البطاقة ٦٣٨
السؤال
What makes an audit regulatory?
الإجابة
It evaluates compliance with requirements established or enforced by a government or delegated authority.
البطاقة ٦٣٩
السؤال
What is a honeyfile?
الإجابة
A decoy file whose access can reveal unauthorized activity.
البطاقة ٦٤٠
السؤال
Why does legal information require explicit protection?
الإجابة
It may contain privileged advice, case strategy, evidence, or regulated records whose disclosure or alteration creates legal risk.
البطاقة ٦٤١
السؤال
Which indicator can mass file renaming and encryption produce?
الإجابة
Resource inaccessibility; users may be unable to open files after an attacker encrypts or renames them.
البطاقة ٦٤٢
السؤال
What remains with an organization after transferring architecture risk?
الإجابة
Oversight and residual risk remain, even when a provider or insurer accepts defined responsibility or financial consequences.
البطاقة ٦٤٣
السؤال
When does local console placement provide useful administrative access?
الإجابة
When network management is unavailable or unsafe, a physically controlled console offers a direct recovery path.
البطاقة ٦٤٤
السؤال
What makes a harmful user action unintentional?
الإجابة
The user causes exposure or policy violation through error or misunderstanding rather than deliberate misuse.
البطاقة ٦٤٥
السؤال
How should an organization harden workstations?
الإجابة
Apply a managed secure baseline: patch the OS and applications, remove unnecessary software and services, enforce least privilege, and enable endpoint protection and a host firewall.
البطاقة ٦٤٦
السؤال
What is journaling in recovery?
الإجابة
Recording ordered changes so data can be replayed or restored to a consistent point.
البطاقة ٦٤٧
السؤال
What downtime must a change plan account for?
الإجابة
The period when the affected service will be unavailable or degraded, including the impact on users and dependent systems.
البطاقة ٦٤٨
السؤال
Why must a privacy program map local or regional law to data flows?
الإجابة
The applicable duties can change with the location of the person, organization, processing, or stored data.
البطاقة ٦٤٩
السؤال
Why combine independent preventive controls at different layers?
الإجابة
A failure at one layer does not automatically let the same attack succeed at the next layer.
البطاقة ٦٥٠
السؤال
What is passwordless authentication?
الإجابة
A flow that does not require the user to enter a memorized password, often using public-key credentials.
البطاقة ٦٥١
السؤال
How can automation improve security reaction time?
الإجابة
It can collect context and perform preapproved containment or routing as soon as a reliable trigger occurs.
البطاقة ٦٥٢
السؤال
What does record-level encryption protect?
الإجابة
Individual records or fields, allowing finer protection than encrypting the entire database.
البطاقة ٦٥٣
السؤال
How can business email compromise misuse urgency?
الإجابة
It pressures an employee to bypass normal verification for a payment, credential, or data request.
البطاقة ٦٥٤
السؤال
What does impact measure in risk analysis?
الإجابة
The consequence to objectives, such as financial, operational, safety, legal, or reputational harm.
البطاقة ٦٥٥
السؤال
What makes cyber activity part of warfare?
الإجابة
It supports military or state conflict objectives such as disruption, intelligence, or influence.
البطاقة ٦٥٦
السؤال
Which indicator can a newly created privileged account produce outside the normal change window?
الإجابة
Out-of-cycle logging; the account event appears at a time when no authorized administrative change was scheduled.
البطاقة ٦٥٧
السؤال
How can configuration enforcement validate a deployed mitigation?
الإجابة
It compares the realized settings with the approved state and corrects or reports drift.
البطاقة ٦٥٨
السؤال
How does validating an alert improve alert tuning?
الإجابة
The analyst can identify which conditions, thresholds, or context caused noise or missed important evidence.
البطاقة ٦٥٩
السؤال
What data-layer impact can a SQL injection vulnerability create?
الإجابة
It can let untrusted input alter a database query, exposing or changing data and sometimes executing administrative operations.
البطاقة ٦٦٠
السؤال
What environmental variables can change vulnerability priority?
الإجابة
Local exposure, configuration, existing controls, asset importance, and the effect on the organization's actual environment.
البطاقة ٦٦١
السؤال
What security role does SELinux provide?
الإجابة
Mandatory access controls that confine processes according to centrally defined policy.
البطاقة ٦٦٢
السؤال
Why review governance documents periodically?
الإجابة
Business, technology, threats, and external obligations change.
البطاقة ٦٦٣
السؤال
Why evaluate power requirements for a system design?
الإجابة
Power capacity and redundancy constrain availability and recovery.
البطاقة ٦٦٤
السؤال
When is IPsec a better tunnel choice than TLS?
الإجابة
Choose IPsec when policy must protect IP traffic broadly below individual applications—for example, across a site-to-site gateway tunnel. Choose TLS for a specific service connection.
البطاقة ٦٦٥
السؤال
What is a honeytoken?
الإجابة
A fake credential or data element that generates a high-confidence alert when used.
البطاقة ٦٦٦
السؤال
What should embedded-system hardening prioritize?
الإجابة
Trusted firmware, restricted interfaces, secure defaults, minimal services, and a supported update path.
البطاقة ٦٦٧
السؤال
Why must sanitization address data remanence?
الإجابة
Residual data may remain recoverable after ordinary deletion, so the sanitization method must make recovery infeasible for the media and risk.
البطاقة ٦٦٨
السؤال
Why require rules of engagement for vendor testing?
الإجابة
Authorized scope, timing, methods, contacts, and stop conditions prevent unsafe or mistaken activity.
البطاقة ٦٦٩
السؤال
What does a private data classification indicate?
الإجابة
The information concerns an individual or limited internal audience and should not be exposed publicly.
البطاقة ٦٧٠
السؤال
What does a tabletop recovery exercise test?
الإجابة
Participants walk through a scenario and decisions without switching production systems, exposing plan and coordination gaps.
البطاقة ٦٧١
السؤال
Why prevent password reuse?
الإجابة
One compromised password should not unlock other accounts or services.
البطاقة ٦٧٢
السؤال
Which malicious-activity indicator is unexplained sustained CPU or memory use?
الإجابة
Abnormal resource consumption, such as unusual CPU, memory, power, storage, or network-bandwidth use.
البطاقة ٦٧٣
السؤال
What does transport encryption protect?
الإجابة
It protects data-in-transit confidentiality: captured or intercepted traffic is unreadable without the key. Encryption does not prevent interception or, by itself, provide integrity or authenticate endpoints.
البطاقة ٦٧٤
السؤال
How can a voice call become an attack vector?
الإجابة
An attacker can use a live or synthetic voice to impersonate a trusted party and request secrets, money, or unsafe actions.
البطاقة ٦٧٥
السؤال
What should a digital-forensics report document?
الإجابة
The question examined, methods, evidence sources, timeline, findings, limitations, and the basis for each conclusion.
البطاقة ٦٧٦
السؤال
What tradeoff comes with an expansionary risk appetite?
الإجابة
It accepts more uncertainty and exposure to pursue growth or return, so limits and monitoring must remain explicit.
البطاقة ٦٧٧
السؤال
What does a known penetration-test environment provide?
الإجابة
The tester receives substantial internal knowledge or access so the exercise can focus on deeper control and attack-path testing.
البطاقة ٦٧٨
السؤال
Why evaluate compute requirements before deployment?
الإجابة
Insufficient resources can cause failure, while excessive resources increase cost and attack surface.
البطاقة ٦٧٩
السؤال
Why place sensors at network choke points?
الإجابة
They can observe traffic crossing important trust boundaries.
البطاقة ٦٨٠
السؤال
What should hybrid or remote-work security training emphasize?
الإجابة
Trusted networks and devices, physical privacy, secure communication, reporting, data handling, and separation of work from shared environments.
البطاقة ٦٨١
السؤال
Why plan an application restart separately from a service restart?
الإجابة
The application may need its own state handling, user coordination, health checks, and rollback point.
البطاقة ٦٨٢
السؤال
What is a cryptographic vulnerability?
الإجابة
A weakness in algorithm choice, key handling, implementation, or protocol use that defeats the intended protection.
البطاقة ٦٨٣
السؤال
Why report findings by asset owner?
الإجابة
Owners need clear accountability and a prioritized remediation queue.
البطاقة ٦٨٤
السؤال
What should guide selection of a secure protocol?
الإجابة
The protocol must protect the required data flow, authenticate the right endpoints, use supported cryptography, and fit operational constraints.
البطاقة ٦٨٥
السؤال
How do centralized and decentralized governance structures differ?
الإجابة
Centralized governance sets decisions from one authority; decentralized governance delegates them and needs strong coordination for consistency.
البطاقة ٦٨٦
السؤال
How does privacy-aware design limit data retention?
الإجابة
It records a justified retention period and makes deletion or anonymization part of the normal data lifecycle.
البطاقة ٦٨٧
السؤال
What does a pressure security sensor detect?
الإجابة
Force or weight applied to a protected surface, such as a floor mat or fence line.
البطاقة ٦٨٨
السؤال
What automation costs should a security team plan for?
الإجابة
Development, licensing, infrastructure, monitoring, maintenance, failure recovery, and the staff needed to own the workflow.
البطاقة ٦٨٩
السؤال
What should RTOS hardening preserve while reducing attack surface?
الإجابة
Deterministic timing and safety requirements, with only necessary services, privileges, interfaces, and validated updates enabled.
البطاقة ٦٩٠
السؤال
What is the goal of disruption-for-chaos activity?
الإجابة
Create instability or damage itself rather than pursue a clear financial or intelligence return.
البطاقة ٦٩١
السؤال
Which indicator can repeated password guessing produce?
الإجابة
Unexpected account lockout; repeated failed attempts can trigger the account's lockout policy.
البطاقة ٦٩٢
السؤال
How does removing unnecessary software harden a system?
الإجابة
It eliminates code, services, dependencies, and privileges that an attacker could otherwise target.
البطاقة ٦٩٣
السؤال
What does NetFlow provide?
الإجابة
Metadata summarizing network conversations, such as endpoints, ports, timing, protocol, and byte counts.
البطاقة ٦٩٤
السؤال
How can a dashboard support an investigation?
الإجابة
It brings selected current and historical signals together so investigators can spot changes, patterns, and affected scope.
البطاقة ٦٩٥
السؤال
When should a password be expired?
الإجابة
When compromise is suspected, policy or risk requires a change, or the credential no longer meets the approved authentication standard.
البطاقة ٦٩٦
السؤال
Why does cryptographic key length matter?
الإجابة
It affects the work required to search the key space, although security also depends on the algorithm and implementation.
البطاقة ٦٩٧
السؤال
How can an unsecure Bluetooth connection become an attack vector?
الإجابة
Weak pairing, discoverability, or vulnerable services can let a nearby attacker connect, intercept data, or issue commands.
البطاقة ٦٩٨
السؤال
What is a key risk indicator?
الإجابة
A metric that signals changing exposure or increasing likelihood of an adverse outcome.
البطاقة ٦٩٩
السؤال
What should vendor monitoring verify when a contract ends?
الإجابة
Vendor accounts, credentials, connections, data access, and retained assets are removed or transferred as approved.
البطاقة ٧٠٠
السؤال
What does a sensitive data classification indicate?
الإجابة
The information needs safeguards because unauthorized access, change, or loss could cause harm.
البطاقة ٧٠١
السؤال
What does software-defined networking separate?
الإجابة
The control plane that decides traffic behavior from the data plane that forwards traffic.
البطاقة ٧٠٢
السؤال
Where should a web application firewall be placed?
الإجابة
In the path of web requests before they reach the protected application.
البطاقة ٧٠٣
السؤال
What does a simulated recovery exercise test?
الإجابة
Participants perform realistic response actions in a controlled environment without disrupting production.
البطاقة ٧٠٤
السؤال
How can a team verify that a detective control is effective?
الإجابة
Trigger a known test event and confirm that the control records it, alerts the right responder, and supplies useful evidence.
البطاقة ٧٠٥
السؤال
How should defenders apply a published or documented indicator to telemetry and validate it before escalating?
الإجابة
Search relevant telemetry for matches, then confirm the indicator's relevance, context, and freshness before escalating.
البطاقة ٧٠٦
السؤال
What makes a vulnerability cloud-specific?
الإجابة
It arises from cloud service configuration, shared responsibility, control-plane exposure, tenancy, or provider-specific behavior.
البطاقة ٧٠٧
السؤال
How can insurance respond to vulnerability risk?
الإجابة
It may transfer defined financial consequences, but it does not remove the weakness or the organization's duties.
البطاقة ٧٠٨
السؤال
How does reputation improve web filtering?
الإجابة
It uses prior observations about a domain, address, certificate, or hosting pattern to identify destinations with elevated risk.
البطاقة ٧٠٩
السؤال
What does an encryption policy establish?
الإجابة
Which data and communications require encryption, approved methods, key responsibilities, exceptions, and review duties.
البطاقة ٧١٠
السؤال
How does a microwave security sensor detect movement?
الإجابة
It emits microwave energy and detects changes in the reflected signal caused by motion.
البطاقة ٧١١
السؤال
What should IoT-device hardening change before deployment?
الإجابة
Default credentials, unnecessary services, insecure communication, unmanaged updates, and unrestricted network access.
البطاقة ٧١٢
السؤال
Why track software licenses as assets?
الإجابة
License ownership, permitted use, updates, and end-of-support status affect compliance and risk.
البطاقة ٧١٣
السؤال
What does a password manager improve?
الإجابة
It can generate and store unique long passwords so users do not memorize or reuse them.
البطاقة ٧١٤
السؤال
What makes a ledger open and public?
الإجابة
Anyone can inspect its recorded entries, while its consensus and integrity controls determine who can add valid entries.
البطاقة ٧١٥
السؤال
What should a payment-change request trigger?
الإجابة
Independent verification through a known channel before any account or payment detail is changed.
البطاقة ٧١٦
السؤال
What does preserving digital evidence require?
الإجابة
Protecting its integrity, context, access history, and availability from collection through final disposition.
البطاقة ٧١٧
السؤال
What should a risk report tell decision-makers?
الإجابة
The risk, uncertainty, business impact, owner, treatment, trend, and decision required.
البطاقة ٧١٨
السؤال
What should an external assessment report provide?
الإجابة
Its scope, criteria, evidence, findings, limitations, conclusions, and responsible follow-up actions.
البطاقة ٧١٩
السؤال
What is a centralized design's main resilience risk?
الإجابة
A central dependency can become a bottleneck or single point of failure.
البطاقة ٧٢٠
السؤال
What does mutual TLS add to a TLS-protected service connection?
الإجابة
It adds client authentication, commonly with a client certificate, so the client and server authenticate each other.
البطاقة ٧٢١
السؤال
What should recurring security-awareness reporting show?
الإجابة
Changes in participation, knowledge, behavior, reporting, and incidents, with gaps assigned to owners and follow-up actions.
البطاقة ٧٢٢
السؤال
Why do legacy applications require extra change planning?
الإجابة
They may depend on undocumented behavior, unsupported components, or fragile integrations that make failure and rollback more likely.
البطاقة ٧٢٣
السؤال
How do a data controller and a data processor differ?
الإجابة
A controller decides why and how personal data is processed. A processor handles that data on the controller’s behalf.
البطاقة ٧٢٤
السؤال
How can orchestration become a single point of failure?
الإجابة
Many security workflows may depend on one engine, credential path, or integration hub whose outage stops all of them.
البطاقة ٧٢٥
السؤال
Why should defenses account for a threat actor's sophistication and capability?
الإجابة
Those attributes indicate which techniques the actor can sustain and which controls are likely to slow or expose them.
البطاقة ٧٢٦
السؤال
How does an injection attack make an application execute unintended instructions?
الإجابة
It sends crafted input that an interpreter treats as code or commands instead of data.
البطاقة ٧٢٧
السؤال
What does a host-based firewall control?
الإجابة
Inbound and outbound network traffic for one endpoint according to local rules.
البطاقة ٧٢٨
السؤال
Why revise alerting after an incident?
الإجابة
The incident can reveal missing telemetry, logic, thresholds, or response paths that should produce a better future alert.
البطاقة ٧٢٩
السؤال
Why include security duties in procurement criteria?
الإجابة
Security is easier to require before selection than to retrofit after dependency and data transfer begin.
البطاقة ٧٣٠
السؤال
What does a critical data classification indicate?
الإجابة
The information is essential to vital operations, safety, or mission outcomes and needs the strongest availability and recovery controls.
البطاقة ٧٣١
السؤال
What infrastructure capacity must support failover?
الإجابة
The alternate site, network, power, cooling, and facility resources needed to carry the transferred load.
البطاقة ٧٣٢
السؤال
Why does shared cloud context matter when evaluating a cloud-specific vulnerability?
الإجابة
The affected service model and responsibility boundary determine who can observe, patch, configure, or compensate for the weakness.
البطاقة ٧٣٣
السؤال
How does a remediation exemption differ from an exception?
الإجابة
Terminology follows the governing policy. A common convention is that an exemption removes a requirement for an approved scope, while an exception permits a time-bounded deviation.
البطاقة ٧٣٤
السؤال
Why should automated EDR or XDR blocking have an exception and rollback path?
الإجابة
A false positive can isolate a critical endpoint or stop a legitimate process, so operators need controlled recovery without disabling protection broadly.
البطاقة ٧٣٥
السؤال
What does a security playbook provide?
الإجابة
A repeatable set of roles, decisions, and actions for handling a defined operational scenario.
البطاقة ٧٣٦
السؤال
How does an ultrasonic security sensor detect movement?
الإجابة
It emits high-frequency sound and detects changes in the returning sound pattern caused by motion.
البطاقة ٧٣٧
السؤال
What should a managed mobile device require for Bluetooth connections?
الإجابة
Intentional pairing, non-discoverable operation when unused, trusted peers, current software, and only necessary Bluetooth profiles.
البطاقة ٧٣٨
السؤال
How do password complexity rules differ from password length?
الإجابة
Complexity rules require selected character types; length measures total characters. Current policy should prioritize sufficient length and block weak or compromised choices instead of relying on composition alone.
البطاقة ٧٣٩
السؤال
What makes a certificate third-party trusted?
الإجابة
A certificate authority outside the subject organization signs it and chains it to a root trusted by relying systems.
البطاقة ٧٤٠
السؤال
Why is an out-of-band check effective against impersonation?
الإجابة
It verifies the request through a separate, previously trusted communication path.
البطاقة ٧٤١
السؤال
What does a risk exception authorize?
الإجابة
A documented deviation from a requirement for a defined scope, rationale, controls, owner, review, and expiration.
البطاقة ٧٤٢
السؤال
What security challenge grows in a decentralized design?
الإجابة
Consistent policy, inventory, monitoring, and patching become harder.
البطاقة ٧٤٣
السؤال
How should controls be selected for an unused network path?
الإجابة
Choose controls that block it by default, expose only approved connectivity, and make exceptions explicit and reviewable.
البطاقة ٧٤٤
السؤال
How can a buffer-overflow attack affect an application?
الإجابة
It writes past a buffer boundary to corrupt memory, which can crash the application or redirect execution.
٧٤٤ بطاقة
CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
سيفتح تطبيق Flashcards لتبدأ الدراسة.