CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
Study every current SY0-701 exam domain with original, concise flashcards for security concepts, threats, architecture, operations, and governance.
Über dieses Lernkartenset
Build reliable recall across all five current Security+ SY0-701 domains with 744 original, open-response cards. The deck follows the newest official objectives for the current exam series: Version 6.0, accessed on August 25, 2026.
What this deck covers
- General security concepts: control functions, core principles, zero trust, change management, cryptography, certificates, and PKI.
- Threats, vulnerabilities, and mitigations: threat actors, attack vectors, social engineering, platform and application weaknesses, malicious activity, indicators, and defensive choices.
- Security architecture: cloud and virtualization models, secure infrastructure, data protection, availability, backups, and recovery design.
- Security operations: hardening, asset and vulnerability management, monitoring, security tooling, identity and access, automation, incident response, and evidence sources.
- Program management and oversight: governance, risk, third-party security, compliance, privacy, audits, and awareness.
Prompts include concept-to-purpose recall, scenario-to-control or threat identification, and operational comparisons. Reverse prompts appear only when choosing a control, evidence source, or response is useful in practice. Prerequisites come before dependent ideas, while related variants are spaced apart.
The deck excludes multiple-choice practice, copied exam material, dumps, raw objective wording, vague term-only prompts, vendor trivia, and mechanically reversed duplicates. Use it after a course or primary study guide, then add hands-on labs and legitimate practice questions to test application.
Scope was reconciled against CompTIA Security+ SY0-701 Certification Exam: Exam Objectives Version 6.0. Current certification requirements and exam-series status are on the official CompTIA Security+ page.
This is an unofficial educational deck by Flashcards Open Source App. It is not affiliated with, endorsed by, or produced by CompTIA. All card wording and cover artwork are original; no exam questions, answer dumps, objective prose, logos, or trade dress were copied.
Karten in diesem Lernkartenset
Karte 1
Frage
What does an information security policy establish?
Antwort
Management's required direction, responsibilities, and high-level rules for protecting information and systems.
Karte 2
Frage
What is phishing?
Antwort
A deceptive message intended to make a target reveal information, open malware, or take an unsafe action.
Karte 3
Frage
What does a public-key certificate bind to an identity?
Antwort
A public key, together with identifying information and the issuer's signature.
Karte 4
Frage
What is data at rest?
Antwort
Data stored on media such as disks, databases, backups, or mobile devices.
Karte 5
Frage
How does policy-driven access control decide a zero-trust access request?
Antwort
Explicit policies or rules evaluate the access request and drive the allow-or-deny decision.
Karte 6
Frage
What does establishing a secure baseline produce?
Antwort
An approved, documented configuration that defines the required secure state for a class of computing resource.
Karte 7
Frage
What is hashing used to verify?
Antwort
Whether data has changed by comparing fixed-length digest values.
Karte 8
Frage
What is impersonation in social engineering?
Antwort
Pretending to be a trusted person or organization to obtain access, data, or action.
Karte 9
Frage
What is virtualization?
Antwort
Abstracting physical compute so multiple isolated guest systems can share a host.
Karte 10
Frage
What is chain of custody?
Antwort
A documented history of who collected, handled, transferred, stored, and examined evidence.
Karte 11
Frage
What is quantitative risk analysis?
Antwort
Estimating risk with numerical values such as money, frequency, or probability.
Karte 12
Frage
What is a phishing awareness campaign?
Antwort
A planned series of guidance, exercises, and reminders that builds recognition and safe reporting behavior.
Karte 13
Frage
What is high availability?
Antwort
Designing a service to remain accessible despite expected component failures.
Karte 14
Frage
What is a network security zone?
Antwort
A group of systems with similar trust, function, or control requirements.
Karte 15
Frage
What is risk transfer?
Antwort
Shifting some financial or operational consequence to another party, such as through insurance or contract.
Karte 16
Frage
What is media sanitization?
Antwort
Making stored data infeasible to recover for the intended level of protection.
Karte 17
Frage
What does CVSS provide?
Antwort
A standardized way to describe a vulnerability's technical severity characteristics.
Karte 18
Frage
What does security alerting do?
Antwort
It turns matched events or behavior into a notification that the right responder can review.
Karte 19
Frage
What does a firewall rule enforce?
Antwort
A permit, deny, or inspect decision for traffic that matches defined source, destination, service, protocol, direction, and state conditions.
Karte 20
Frage
What is deprovisioning?
Antwort
Disabling or removing accounts, credentials, sessions, and access when they are no longer needed.
Karte 21
Frage
How does inline placement differ from a tap or monitor port?
Antwort
Inline traffic passes through the control; a tap or monitor receives a copy for observation.
Karte 22
Frage
What is asymmetric encryption?
Antwort
Encryption that uses a mathematically related public and private key pair.
Karte 23
Frage
What does SPF authorize?
Antwort
Which mail servers may send mail for a domain in the SMTP envelope.
Karte 24
Frage
What is a possession factor?
Antwort
Something the claimant has, such as a cryptographic authenticator.
Karte 25
Frage
What does ordinary TLS usually protect and authenticate?
Antwort
It provides encryption and integrity protection, plus server authentication in the usual deployment. Client authentication is added when mutual TLS is configured.
Karte 26
Frage
What is single loss expectancy?
Antwort
The estimated loss from one occurrence of a risk event.
Karte 27
Frage
What does a certificate authority do?
Antwort
It validates certificate requests and signs certificates so relying parties can verify the binding between an identity and a public key.
Karte 28
Frage
What is a detective control meant to do?
Antwort
Identify that an unwanted event has happened or is happening.
Karte 29
Frage
What is the security purpose of change-control approval?
Antwort
Ensure authorized reviewers assess risk before the production change occurs.
Karte 30
Frage
What is shadow IT?
Antwort
Technology used for organizational work without required approval or oversight.
Karte 31
Frage
What is a buffer overflow vulnerability?
Antwort
A bounds-checking failure that lets input overwrite memory outside its intended buffer.
Karte 32
Frage
What is ransomware?
Antwort
Malware or an intrusion outcome that denies access to data or systems to extort the victim.
Karte 33
Frage
How does network segmentation limit an incident?
Antwort
It restricts communication paths and reduces lateral movement between zones.
Karte 34
Frage
How do load balancing and clustering support availability differently?
Antwort
Load balancing distributes requests across healthy instances; clustering makes systems cooperate as one service and tolerate member failure.
Karte 35
Frage
What is vendor due diligence?
Antwort
Evaluating a provider's security, capability, stability, and fit before commitment.
Karte 36
Frage
Who is a data subject?
Antwort
The person whose personal data is collected or processed.
Karte 37
Frage
What is attestation?
Antwort
A formal assertion or report about a subject matter, often supported by an independent examination.
Karte 38
Frage
What is a replay attack?
Antwort
Valid captured data is retransmitted to repeat an authenticated or authorized action.
Karte 39
Frage
What does a wireless site survey establish?
Antwort
Coverage, interference, channel use, access-point placement, and unauthorized radio sources in the real environment.
Karte 40
Frage
What is the time-of-check stage of a race-condition vulnerability?
Antwort
The application verifies a condition or resource state before acting on it.
Karte 41
Frage
What is a penetration test?
Antwort
An authorized attempt to exploit weaknesses and demonstrate practical impact.
Karte 42
Frage
What is a cold recovery site?
Antwort
A facility with basic space and utilities but little preinstalled technology or current data.
Karte 43
Frage
What is data in transit?
Antwort
Data moving between systems or across a network.
Karte 44
Frage
What is a vendor security questionnaire?
Antwort
A structured request for information about a provider's controls and practices.
Karte 45
Frage
How does an internal actor's starting position differ from an external actor's?
Antwort
An internal actor begins with some trusted access or proximity; an external actor must first cross the perimeter or obtain access.
Karte 46
Frage
What can unexpected account lockouts indicate?
Antwort
Password guessing, credential stuffing, user error, or a broken client.
Karte 47
Frage
How do permissions enforce access control?
Antwort
They specify which actions a subject may perform on a particular resource.
Karte 48
Frage
What is log aggregation?
Antwort
Central collection of logs from multiple sources for search, correlation, and retention.
Karte 49
Frage
Why plan a service restart as part of a change?
Antwort
The restart can interrupt dependent users or processes, so the plan needs timing, validation, and rollback steps.
Karte 50
Frage
What is infrastructure as code?
Antwort
Managing infrastructure through versioned, machine-readable definitions rather than manual configuration.
Karte 51
Frage
What should security-awareness program development start with?
Antwort
The audience's roles, risks, policies, incident lessons, desired behavior, and measurable outcomes.
Karte 52
Frage
What is a voice-based social-engineering attack called?
Antwort
Vishing.
Karte 53
Frage
What happens during incident-response preparation?
Antwort
Teams establish people, tools, access, communications, training, and procedures before an incident.
Karte 54
Frage
What does an offensive penetration-testing team do?
Antwort
It emulates authorized attacker behavior to discover and demonstrate exploitable paths.
Karte 55
Frage
What is federation?
Antwort
One security domain relies on identity assertions from another trusted domain.
Karte 56
Frage
What is asset classification?
Antwort
Grouping an asset by sensitivity, criticality, or required handling.
Karte 57
Frage
What is cross-site scripting?
Antwort
Injection of script-capable content that a browser executes in another site's security context.
Karte 58
Frage
What can IDS or IPS trends reveal?
Antwort
Changes in the frequency, source, target, or type of detected activity that one isolated event may not show.
Karte 59
Frage
What can unexpected resource inaccessibility indicate?
Antwort
Denial of service, destructive activity, ransomware, permission changes, or an ordinary outage.
Karte 60
Frage
What is a corrective control meant to do?
Antwort
Limit damage and restore a secure state after an event.
Karte 61
Frage
How do containers differ from virtual machines?
Antwort
Containers share the host kernel; virtual machines normally run separate guest operating systems.
Karte 62
Frage
How does an active security device differ from a passive one?
Antwort
An active device can alter or block traffic; a passive device observes and reports without changing the flow.
Karte 63
Frage
Why is unsupported software a persistent attack surface?
Antwort
Known weaknesses may remain reachable because supported fixes and vendor help are no longer available.
Karte 64
Frage
What is annualized rate of occurrence?
Antwort
The estimated number of times a risk event occurs per year.
Karte 65
Frage
What is an inherence factor?
Antwort
A biometric characteristic of the claimant.
Karte 66
Frage
What do a threat actor's sophistication and capability describe?
Antwort
The technical skill, tools, knowledge, resources, and operational discipline the actor can apply.
Karte 67
Frage
What is a SIEM?
Antwort
A platform that centralizes security data and supports search, correlation, alerting, and investigation.
Karte 68
Frage
What is sideloading?
Antwort
Installing software from outside the platform's approved distribution path.
Karte 69
Frage
What does an IDS or IPS signature match?
Antwort
A known pattern in traffic or behavior associated with a threat, exploit, or policy violation.
Karte 70
Frage
Why are embedded systems often difficult to patch?
Antwort
They may have long lifecycles, specialized firmware, limited downtime, or weak vendor support.
Karte 71
Frage
What is a virtual private network?
Antwort
An encrypted logical connection that carries private traffic across an untrusted or shared network.
Karte 72
Frage
What should an initial security-awareness report establish?
Antwort
The starting participation, knowledge, behavior, incident, and reporting measures against which later results will be compared.
Karte 73
Frage
What is symmetric encryption?
Antwort
Encryption that uses the same secret key to encrypt and decrypt data.
Karte 74
Frage
What happens during incident detection?
Antwort
Monitoring or a report identifies activity that may meet the organization's incident criteria.
Karte 75
Frage
What is recovery time objective?
Antwort
The target maximum time to restore a function after disruption.
Karte 76
Frage
Why prioritize password length?
Antwort
Longer passwords expand the guessing space and support memorable passphrases without predictable substitutions.
Karte 77
Frage
What must sanitization accomplish before an asset leaves organizational control?
Antwort
It must make the retained data infeasible to recover with the method appropriate to the media and risk.
Karte 78
Frage
What is a real-time operating system designed to provide?
Antwort
Predictable response timing for tasks with strict deadlines.
Karte 79
Frage
What does fail-open behavior do when a control fails?
Antwort
It permits traffic or access to preserve availability.
Karte 80
Frage
What is jailbreaking or rooting a mobile device?
Antwort
Removing platform restrictions to gain privileged control over the operating system.
Karte 81
Frage
What does network access control enforce?
Antwort
Identity, device posture, and access policy at network connection time and during a session.
Karte 82
Frage
What does data loss prevention do?
Antwort
Detects and may block sensitive data use or transfer that violates policy.
Karte 83
Frage
What security property does a blockchain provide?
Antwort
A chained, tamper-evident record in which changing an earlier entry invalidates later cryptographic links.
Karte 84
Frage
What is recovery point objective?
Antwort
The target maximum acceptable data loss measured backward in time.
Karte 85
Frage
How do ICS and SCADA relate?
Antwort
An industrial control system controls physical processes; SCADA provides supervisory monitoring and control across distributed industrial equipment.
Karte 86
Frage
What does fail-closed behavior do when a control fails?
Antwort
It denies traffic or access to preserve security.
Karte 87
Frage
Which keys create and verify a typical digital signature?
Antwort
The signer creates it with a private key, and others verify it with the corresponding public key.
Karte 88
Frage
What is SQL injection?
Antwort
Input that alters the structure or meaning of a database query because code and data were not safely separated.
Karte 89
Frage
What does DKIM verify?
Antwort
That selected message content was signed by a domain and was not altered after signing.
Karte 90
Frage
What is post-incident activity?
Antwort
Learning from the event and improving controls, plans, and recovery based on evidence.
Karte 91
Frage
What characterizes an expansionary risk appetite?
Antwort
A greater willingness to accept uncertainty and exposure in pursuit of growth, return, or strategic opportunity.
Karte 92
Frage
How do centralized and decentralized architectures differ?
Antwort
Centralized architecture concentrates key services or decisions; decentralized architecture distributes them across independent components or locations.
Karte 93
Frage
What does a certificate revocation list publish?
Antwort
Certificate serial numbers that the issuer has invalidated before their scheduled expiration.
Karte 94
Frage
What is a legal hold?
Antwort
A directive to preserve potentially relevant information by suspending normal deletion or disposal.
Karte 95
Frage
What is exposure factor in quantitative risk analysis?
Antwort
The estimated percentage of an asset's value lost in one event.
Karte 96
Frage
What is decentralized architecture?
Antwort
Control or service responsibility is distributed across multiple independent components or locations.
Karte 97
Frage
What is tokenization?
Antwort
Replacing sensitive data with a non-sensitive token whose mapping is held separately.
Karte 98
Frage
How can automation act as a workforce multiplier?
Antwort
It handles repeatable work consistently so people can focus on judgment, exceptions, investigation, and improvement.
Karte 99
Frage
What can endpoint process logs reveal?
Antwort
Which programs ran, their parent-child relationships, users, timing, and command details when captured.
Karte 100
Frage
What does the CIA triad protect?
Antwort
Confidentiality protects against unauthorized disclosure, integrity protects accuracy and completeness, and availability protects reliable, timely access.
Karte 101
Frage
How does data masking protect information?
Antwort
It hides selected values or characters while preserving a usable representation.
Karte 102
Frage
How can a national requirement affect security governance?
Antwort
It can impose country-level duties that policies, controls, records, and oversight must satisfy.
Karte 103
Frage
What do integrations and APIs provide to security orchestration?
Antwort
Defined interfaces for exchanging data and triggering actions across tools without manual handoffs.
Karte 104
Frage
What makes a compliance report external?
Antwort
It is prepared for a regulator, customer, auditor, partner, or other party outside the organization.
Karte 105
Frage
What does a cryptographic algorithm define?
Antwort
The mathematical procedure used to encrypt, decrypt, hash, sign, or otherwise transform protected data.
Karte 106
Frage
Why compare systems with a secure baseline regularly?
Antwort
To detect drift, unauthorized changes, and missing hardening.
Karte 107
Frage
What does integrity protect?
Antwort
The accuracy and completeness of data and systems against unauthorized change.
Karte 108
Frage
What does vulnerability classification organize?
Antwort
Findings into meaningful types or categories so teams can route, compare, and remediate them consistently.
Karte 109
Frage
What does a password standard define?
Antwort
Mandatory, measurable requirements for creating, storing, using, and changing passwords.
Karte 110
Frage
What technology capacity must a recovery design plan for?
Antwort
The compute, storage, software, licenses, and supporting services needed to meet recovery demand.
Karte 111
Frage
What does a confidential data classification indicate?
Antwort
Disclosure is limited to authorized people because exposure could harm the organization or affected parties.
Karte 112
Frage
What makes a vendor assessment independent?
Antwort
The assessor is free from responsibility for the vendor activity being evaluated and reports evidence against defined criteria.
Karte 113
Frage
What lets a worm spread without attaching itself to another file?
Antwort
It is a standalone program that replicates across reachable systems or services.
Karte 114
Frage
What is microsegmentation?
Antwort
Fine-grained isolation of individual workloads or small groups with explicit communication policy.
Karte 115
Frage
What can application logs reveal?
Antwort
Transactions, errors, user actions, and application-specific security events.
Karte 116
Frage
What does deploying a secure baseline require?
Antwort
Applying the approved settings consistently to the intended resources and verifying the realized configuration.
Karte 117
Frage
How can resource-provisioning automation improve security?
Antwort
It creates infrastructure from approved templates with consistent ownership, logging, and baseline controls.
Karte 118
Frage
What does availability protect?
Antwort
Reliable, timely access to systems and data when authorized users need them.
Karte 119
Frage
Why must a change request describe business impact?
Antwort
So approvers can weigh the benefit, risk, outage, and affected users before authorizing it.
Karte 120
Frage
What does an authenticated vulnerability scan add?
Antwort
Credentialed inspection of local versions, settings, and missing patches that a remote scan may miss.
Karte 121
Frage
What does a change-management procedure specify?
Antwort
The required steps, roles, evidence, approvals, testing, implementation, validation, and rollback for a change.
Karte 122
Frage
What is a sanction for noncompliance?
Antwort
A formal penalty or restriction imposed by an authority for failing to meet a requirement.
Karte 123
Frage
How can email deliver a security attack?
Antwort
It can carry a malicious link, attachment, request, or embedded content designed to exploit software or manipulate a recipient.
Karte 124
Frage
What is an internal compliance audit?
Antwort
An organization-led examination of whether selected operations and controls meet defined requirements.
Karte 125
Frage
What is a Trojan?
Antwort
Malware disguised as legitimate or desirable software.
Karte 126
Frage
What is clustering?
Antwort
Multiple systems work together to provide a service and tolerate member failure.
Karte 127
Frage
What makes data regulated?
Antwort
A law or regulation imposes specific collection, handling, retention, protection, or disclosure duties.
Karte 128
Frage
What does a wireless heat map show?
Antwort
Measured or modeled signal strength and coverage across a physical area.
Karte 129
Frage
How should vendor criticality affect due diligence?
Antwort
Higher access, concentration, data sensitivity, or operational dependence warrants deeper evidence and stronger approval.
Karte 130
Frage
How can a digital signature support non-repudiation?
Antwort
It provides evidence that the holder of a private key signed specific data.
Karte 131
Frage
What should vulnerability prioritization consider beyond severity?
Antwort
Exploitability, exposure, asset importance, environmental context, business impact, and available mitigations.
Karte 132
Frage
What is a security guideline?
Antwort
Recommended practice that allows judgment unless adopted as a requirement.
Karte 133
Frage
What usually distinguishes a nation-state threat actor?
Antwort
Strategic objectives, substantial resources, patience, and advanced operational capability.
Karte 134
Frage
What is spyware?
Antwort
Software that secretly collects information about a user or system.
Karte 135
Frage
Why maintain an allow list for applications?
Antwort
Only explicitly approved software is permitted to execute.
Karte 136
Frage
How can an image become an attack vector?
Antwort
It may exploit a decoder flaw, hide malicious data, or direct a user through an embedded code.
Karte 137
Frage
What makes a security control technical?
Antwort
It is enforced mainly by technology, such as a firewall rule or endpoint policy.
Karte 138
Frage
What is identity proofing?
Antwort
Establishing that a person is who they claim to be before issuing an account or credential.
Karte 139
Frage
What is an automated security guardrail?
Antwort
A policy control that prevents, flags, or corrects unsafe configuration, such as an overexposed security group.
Karte 140
Frage
Why assign an owner to a planned change?
Antwort
To make one party accountable for coordination, execution, and follow-through.
Karte 141
Frage
How can national privacy law affect data handling?
Antwort
It can set country-level duties for collection, use, access, retention, transfer, security, and individual rights.
Karte 142
Frage
What is continuity of operations?
Antwort
Maintaining essential functions during disruption and restoring supporting capabilities in a planned order.
Karte 143
Frage
What security tradeoff comes with BYOD?
Antwort
The organization gains flexibility but has less control over personally owned device configuration, privacy, and lifecycle.
Karte 144
Frage
How should policies and handbooks support security training?
Antwort
They provide accessible, current rules and reporting steps that training can apply to real situations.
Karte 145
Frage
What is a keylogger?
Antwort
A tool that records keystrokes to capture data such as credentials.
Karte 146
Frage
What makes information a trade secret?
Antwort
It provides business value because it is not generally known and is protected through reasonable secrecy measures.
Karte 147
Frage
What does authentication establish?
Antwort
It verifies a presented authenticator or credential bound to the claimed identity. Identity proofing establishes the real-world identity behind the claim.
Karte 148
Frage
What risk comes from an untrusted file attachment?
Antwort
Opening or parsing it can execute malicious code or expose data.
Karte 149
Frage
How does risk tolerance affect vulnerability remediation?
Antwort
It sets how much residual exposure the organization will accept and how quickly a finding must be treated.
Karte 150
Frage
How can a global requirement affect security governance?
Antwort
It can require a common control and oversight approach across multiple countries while local obligations still apply.
Karte 151
Frage
Why should questionnaire answers be supported by evidence?
Antwort
Self-assertions alone may not prove that controls are designed or operating effectively.
Karte 152
Frage
What is an independent third-party audit?
Antwort
An external party with suitable independence examines evidence against defined criteria.
Karte 153
Frage
What do account provisioning and deprovisioning do?
Antwort
Provisioning creates an identity and approved access; deprovisioning disables or removes accounts, credentials, sessions, and access when no longer needed.
Karte 154
Frage
What is an unskilled attacker commonly called?
Antwort
A script kiddie: someone who relies on tools or instructions created by others.
Karte 155
Frage
What is a rootkit?
Antwort
Software designed to maintain privileged, concealed access by altering or subverting the system.
Karte 156
Frage
What does an access control list enforce?
Antwort
Explicit permit or deny rules for subjects, traffic, or actions on a protected resource.
Karte 157
Frage
What should system security monitoring observe?
Antwort
Host state and behavior such as processes, authentication, configuration, resource use, and security events.
Karte 158
Frage
What can operating-system security logs reveal?
Antwort
Authentication, privilege use, policy changes, services, and other host security events.
Karte 159
Frage
Why isolate operational technology from general business networks?
Antwort
To limit attack paths into safety- and availability-critical processes.
Karte 160
Frage
What is the COPE mobile deployment model?
Antwort
The organization owns the device but permits defined personal use while retaining management control.
Karte 161
Frage
What security work belongs in asset acquisition and procurement?
Antwort
Define security requirements before purchase, evaluate the product and vendor against them, and obtain approval before acquisition or deployment.
Karte 162
Frage
How can user-provisioning automation improve security?
Antwort
It creates, changes, and removes access from authoritative identity events with consistent approvals and logging.
Karte 163
Frage
What people capacity must a continuity plan account for?
Antwort
Enough trained staff, coverage, authority, and specialist knowledge to operate and recover essential services.
Karte 164
Frage
What do authorization models define?
Antwort
How permissions are assigned to authenticated subjects and evaluated for requested actions.
Karte 165
Frage
Why are removable devices an attack vector?
Antwort
They can introduce malware or remove data while bypassing network controls.
Karte 166
Frage
What should predeployment change-test results show?
Antwort
Whether the change meets its acceptance criteria without unacceptable functional, security, or operational effects.
Karte 167
Frage
What is the time-of-use stage of a race-condition vulnerability?
Antwort
The application acts on a resource after the check, creating a gap in which another process may change the resource.
Karte 168
Frage
What is data in use?
Antwort
Data actively processed in memory or by an application.
Karte 169
Frage
What does open-source vulnerability intelligence contribute?
Antwort
Public advisories, exploit reporting, research, and observable activity that help identify and prioritize exposure.
Karte 170
Frage
What can file-integrity monitoring detect?
Antwort
Unexpected changes to protected files, directories, or configuration.
Karte 171
Frage
Why should deprovisioning be prompt?
Antwort
Former users or roles should not retain usable access.
Karte 172
Frage
What is an acceptable use policy?
Antwort
Rules for permitted and prohibited use of organizational systems, accounts, and data.
Karte 173
Frage
What makes a compliance report internal?
Antwort
It is prepared for the organization's owners, operators, management, or governance bodies to track compliance and action.
Karte 174
Frage
What is a logic bomb?
Antwort
Malicious code that activates when a specified condition or time is reached.
Karte 175
Frage
What does a right-to-audit clause provide?
Antwort
Contractual authority to inspect or obtain evidence about agreed controls.
Karte 176
Frage
Where should a forward proxy sit in an enterprise traffic path?
Antwort
Between clients and external services so outbound requests pass through policy and logging before reaching destinations.
Karte 177
Frage
Which cues should make a message look suspicious?
Antwort
Unexpected context, mismatched identity or links, unusual attachments, urgency, secrecy, and requests for credentials or payment.
Karte 178
Frage
What makes a security control managerial?
Antwort
It directs risk and governance through decisions such as policies, assessments, and oversight.
Karte 179
Frage
What is the CYOD mobile deployment model?
Antwort
The user selects from organization-approved device options that remain subject to corporate security requirements.
Karte 180
Frage
How does client-based vulnerable software differ from an agentless exposure?
Antwort
Client-based exposure depends on installed endpoint software, while an agentless service can be reached and assessed without a local agent.
Karte 181
Frage
What makes a risk assessment recurring?
Antwort
It is repeated on a defined schedule so changes in threats, assets, controls, and impact are reevaluated.
Karte 182
Frage
What does a defensive penetration-testing team practice?
Antwort
Detection, investigation, containment, and improvement while authorized offensive activity tests the environment.
Karte 183
Frage
In a zero-trust data plane, what can the subject or system represent?
Antwort
The user, device, workload, or service requesting access to a protected resource.
Karte 184
Frage
What primarily motivates a hacktivist?
Antwort
A political, social, or ideological cause.
Karte 185
Frage
What is bloatware?
Antwort
Unnecessary preinstalled software that consumes resources and can expand the attack surface.
Karte 186
Frage
Why keep endpoint-protection signatures and engines current?
Antwort
They need current detection logic to recognize newly identified malware and exploit behavior.
Karte 187
Frage
What should application security monitoring observe?
Antwort
Application errors, authentication, requests, transactions, dependencies, and behavior that may indicate misuse or compromise.
Karte 188
Frage
What is role-based access control?
Antwort
Permissions are assigned to roles, and identities receive access through their roles.
Karte 189
Frage
What is geographic dispersal?
Antwort
Placing redundant resources in separate locations so one regional event does not affect all copies.
Karte 190
Frage
What is a malicious update?
Antwort
An update that has been intentionally altered or distributed to install harmful code through a trusted update path.
Karte 191
Frage
What does static application analysis inspect?
Antwort
Source code, bytecode, or compiled code without executing the application.
Karte 192
Frage
What does a firewall access list define?
Antwort
An ordered set of traffic-matching conditions and the action applied when a condition matches.
Karte 193
Frage
What does a disaster recovery policy establish?
Antwort
Management expectations for restoring technology and data after a disruptive event.
Karte 194
Frage
How does logical segmentation separate workloads that share physical infrastructure?
Antwort
It uses enforced network, identity, or virtualization boundaries to restrict communication without requiring separate hardware.
Karte 195
Frage
How should IDS and IPS placement differ?
Antwort
An IDS can monitor copied traffic out of band; an IPS must sit inline to block traffic.
Karte 196
Frage
What should automated ticket creation capture?
Antwort
The triggering evidence, affected resource, severity, owner, required action, and a traceable link to the source event.
Karte 197
Frage
What makes information intellectual property?
Antwort
It is a protected creation or intangible asset, such as copyrighted work, a patentable invention, a trademark, or a trade secret.
Karte 198
Frage
What is a backout plan?
Antwort
Predefined steps for safely reversing a failed or harmful change.
Karte 199
Frage
Why is an unsecure wireless network an attack vector?
Antwort
Nearby attackers may intercept traffic, impersonate access points, or reach exposed services when encryption and authentication are weak.
Karte 200
Frage
What is physical brute force?
Antwort
Using force to defeat a lock, barrier, enclosure, or other physical control.
Karte 201
Frage
What is application sandboxing?
Antwort
Running code in a constrained environment with limited access to the host and data.
Karte 202
Frage
Why assign an asset owner?
Antwort
One accountable party must decide its use, protection, and lifecycle.
Karte 203
Frage
What happens during risk identification?
Antwort
Teams identify assets, objectives, threats, vulnerabilities, events, and dependencies that could create uncertainty or harm.
Karte 204
Frage
What should an SLA state about breach notification?
Antwort
The triggering conditions, notification deadline, required content, contacts, update cadence, and cooperation duties.
Karte 205
Frage
How do due diligence and due care differ in compliance?
Antwort
Due diligence investigates and monitors obligations or risk; due care takes the reasonable actions those findings require.
Karte 206
Frage
What is attribute-based access control?
Antwort
Policy evaluates attributes of the subject, resource, action, and environment.
Karte 207
Frage
What does a zero-trust policy engine do?
Antwort
It evaluates policy and signals to decide whether access should be allowed.
Karte 208
Frage
How does a cloud responsibility matrix allocate security duties?
Antwort
It maps each security task to the provider, the customer, or both, according to the service model and agreement.
Karte 209
Frage
Where should a load balancer sit in a service path?
Antwort
In front of service instances so it can route requests to healthy backends.
Karte 210
Frage
What should the security team do with a reported suspicious message?
Antwort
Triage it, protect other recipients, preserve useful evidence, and tell the reporter what action to take.
Karte 211
Frage
What makes an operating-system vulnerability high impact?
Antwort
It can affect every application and security control that relies on the compromised OS.
Karte 212
Frage
What does dynamic application analysis inspect?
Antwort
The behavior and externally visible weaknesses of a running application.
Karte 213
Frage
How can false-positive trends affect IDS or IPS tuning?
Antwort
Repeated false positives reveal signatures, thresholds, or contexts that need adjustment; IPS errors also risk blocking legitimate traffic.
Karte 214
Frage
What does a business continuity policy establish?
Antwort
Management expectations for sustaining and restoring critical business functions.
Karte 215
Frage
What is a hot recovery site?
Antwort
A ready, synchronized environment intended to take over quickly.
Karte 216
Frage
What makes an insider threat distinct?
Antwort
The actor has legitimate access or organizational knowledge that can be misused.
Karte 217
Frage
What is RFID cloning?
Antwort
Copying an RFID credential's data so another token can impersonate it when the system lacks stronger protections.
Karte 218
Frage
Why apply vendor security updates promptly?
Antwort
They remove known weaknesses before attackers can exploit the unpatched exposure.
Karte 219
Frage
What should infrastructure security monitoring observe?
Antwort
Network, cloud, identity, facility, and platform signals that reveal availability, configuration, or attack activity.
Karte 220
Frage
What can firewall logs reveal?
Antwort
Allowed or denied network connections across controlled boundaries.
Karte 221
Frage
Why minimize open service ports?
Antwort
Each reachable service adds code, configuration, and authentication paths an attacker can probe.
Karte 222
Frage
What is threat hunting?
Antwort
A proactive search for evidence of malicious activity that existing detections have not confirmed.
Karte 223
Frage
What triggers an ad hoc risk assessment?
Antwort
A specific change, incident, finding, or decision that requires evaluation outside the regular schedule.
Karte 224
Frage
What makes an assessment external?
Antwort
A party outside the organization evaluates a defined scope against stated criteria and reports its conclusions.
Karte 225
Frage
What is data sovereignty?
Antwort
The principle that data is subject to laws and governance of the jurisdiction where it is located or controlled.
Karte 226
Frage
What security boundary does a cellular connection create for a mobile device?
Antwort
It uses the carrier network instead of local Wi-Fi, but still requires trusted applications, encrypted traffic, and managed device policy.
Karte 227
Frage
What makes a security control operational?
Antwort
It is carried out mainly by people and processes, such as security-awareness training or incident-response procedures.
Karte 228
Frage
What is discretionary access control?
Antwort
A resource owner can decide who receives access, within system policy.
Karte 229
Frage
How can careful automation support employee retention?
Antwort
It reduces repetitive toil and alert handling while leaving meaningful judgment and improvement work with people.
Karte 230
Frage
Why does ease of deployment matter in an architecture decision?
Antwort
A design that can be deployed consistently and safely reduces configuration error, rollout time, and operational burden.
Karte 231
Frage
What tradeoff comes with placing an NGFW inline?
Antwort
It can block application-aware threats, but failure or overload can interrupt traffic unless availability and fail-mode behavior are designed.
Karte 232
Frage
What does a zero-trust policy administrator do?
Antwort
It carries out the policy engine's decision, such as creating or ending a session.
Karte 233
Frage
What should a master service agreement define for data return and deletion?
Antwort
The format, timing, verification, retained copies, exceptions, and responsibilities when the service or contract ends.
Karte 234
Frage
What is an environmental physical attack?
Antwort
Causing harmful conditions such as heat, water, fire, or power loss to disrupt equipment or facilities.
Karte 235
Frage
When should a maintenance window be chosen?
Antwort
When disruption and rollback can be managed with the least business impact.
Karte 236
Frage
What is memory injection?
Antwort
Placing malicious code or data into another process's memory so it executes in that process's context.
Karte 237
Frage
What does software composition analysis find?
Antwort
Known risks and license information in third-party dependencies.
Karte 238
Frage
What is DNS filtering?
Antwort
Blocking or redirecting DNS lookups for domains that policy considers malicious or inappropriate.
Karte 239
Frage
What should an incident response policy establish?
Antwort
Authority, scope, reporting duties, and organizational commitment for incident handling.
Karte 240
Frage
How can noncompliance cause reputational damage?
Antwort
Customers, partners, employees, or the public may lose trust when the organization fails a stated or required duty.
Karte 241
Frage
What does full-disk encryption protect?
Antwort
All data stored on the disk while the device is powered off or the disk is removed, subject to proper key protection.
Karte 242
Frage
Why are default credentials dangerous?
Antwort
They are widely known or easily discovered and often remain unchanged.
Karte 243
Frage
What makes a risk assessment one-time?
Antwort
It evaluates a defined decision or scope once without an established repeating cadence.
Karte 244
Frage
What is a warm recovery site?
Antwort
A partially equipped environment that needs some data restoration or configuration before use.
Karte 245
Frage
What does application input validation do?
Antwort
It checks that input matches the expected type, length, range, and format before use.
Karte 246
Frage
What should an asset inventory record besides a device name?
Antwort
Identifiers, owner, location, status, classification, dependencies, and supported version as applicable.
Karte 247
Frage
What is mandatory access control?
Antwort
A central authority enforces access through labels and rules that ordinary owners cannot override.
Karte 248
Frage
What security benefit does infrastructure as code provide?
Antwort
Repeatable, reviewable deployments that reduce undocumented configuration drift.
Karte 249
Frage
When should a public service control fail closed?
Antwort
When allowing unchecked traffic would create greater harm than an outage, the failed control should block the path.
Karte 250
Frage
What should users do with a suspicious message?
Antwort
Report it through the approved channel without interacting with its links or attachments.
Karte 251
Frage
What usually motivates organized cybercrime?
Antwort
Financial gain through scalable or repeatable criminal activity.
Karte 252
Frage
How can malicious code support a network attack?
Antwort
It can establish control, scan reachable systems, move laterally, or disrupt networked services after execution.
Karte 253
Frage
When is virtual patching useful?
Antwort
When a network or application control can block exploit traffic before the underlying system can be patched.
Karte 254
Frage
What does security-monitoring reporting provide?
Antwort
A summarized, audience-appropriate view of findings, trends, risk, and response status.
Karte 255
Frage
What does data geolocation identify?
Antwort
The physical or legal location where data is stored, processed, or transmitted.
Karte 256
Frage
What does a zero-trust policy enforcement point do?
Antwort
It enables, monitors, and terminates the connection between a subject and a resource.
Karte 257
Frage
What is cryptographic key exchange?
Antwort
A method for parties to establish shared key material over an untrusted channel.
Karte 258
Frage
How can a vendor become a supply-chain attack vector?
Antwort
An attacker can compromise the vendor's product, update, credentials, or support channel to reach the vendor's customers.
Karte 259
Frage
Why can legacy hardware remain vulnerable?
Antwort
It may lack current security features, supported firmware, replacement parts, or compatibility with modern controls.
Karte 260
Frage
What can proprietary vulnerability intelligence add beyond open sources?
Antwort
Curated analysis, customer-specific context, private telemetry, or earlier reporting available under a commercial or trusted relationship.
Karte 261
Frage
How does a centralized proxy apply web filtering?
Antwort
It receives client web requests at a shared enforcement point and applies policy before forwarding allowed traffic.
Karte 262
Frage
How can continuous integration and testing improve security automation?
Antwort
Changes receive repeatable checks before deployment instead of reaching production unvalidated.
Karte 263
Frage
What is containment?
Antwort
Limiting an incident's spread or damage while preserving necessary operations and evidence.
Karte 264
Frage
What is a software development lifecycle policy meant to ensure?
Antwort
Security requirements and checks are integrated throughout design, development, release, and maintenance.
Karte 265
Frage
What makes risk assessment continuous?
Antwort
Relevant signals and changes update the risk view as they occur instead of waiting for a scheduled review.
Karte 266
Frage
What is a memorandum of agreement?
Antwort
A document that records agreed responsibilities and commitments between parties; its legal effect depends on its terms and jurisdiction.
Karte 267
Frage
What makes a penetration test integrated?
Antwort
Offensive and defensive teams coordinate the exercise to test both attack paths and detection or response.
Karte 268
Frage
How does a DNS amplification attack magnify traffic?
Antwort
It sends small spoofed queries that trigger larger replies toward the victim.
Karte 269
Frage
Why does ease of recovery matter in an architecture decision?
Antwort
The design should let operators restore service and trusted state without fragile, slow, or undocumented steps.
Karte 270
Frage
What does 802.1X control before a device receives normal network access?
Antwort
Port-based admission; the device or user must authenticate through the access device before ordinary traffic is allowed.
Karte 271
Frage
What is rule-based access control?
Antwort
System-wide rules grant or deny access based on conditions such as network, time, or action.
Karte 272
Frage
What is mobile device management?
Antwort
Central enrollment, configuration, monitoring, and enforcement for managed mobile devices.
Karte 273
Frage
What tradeoff comes with a cold recovery site?
Antwort
It costs less to maintain, but recovery takes longer because systems, data, and connectivity must be prepared after activation.
Karte 274
Frage
Why identify stakeholders before approving a security-sensitive change?
Antwort
They can identify operational impact, dependencies, and acceptance criteria that the implementer may otherwise miss.
Karte 275
Frage
How do attestation and acknowledgement differ?
Antwort
Attestation asserts that a condition or control is true; acknowledgement confirms receipt or understanding of a requirement.
Karte 276
Frage
What does zero-trust adaptive identity mean?
Antwort
Access decisions adjust to current risk signals rather than relying only on a static login.
Karte 277
Frage
What makes a security control physical?
Antwort
It protects facilities or equipment through a tangible barrier or mechanism.
Karte 278
Frage
What is geo-fencing for data?
Antwort
Enforcing location-based boundaries on where data or services may be accessed or operated.
Karte 279
Frage
What does a Trusted Platform Module protect?
Antwort
Hardware-backed keys and measurements used for device identity, disk protection, and boot-state attestation.
Karte 280
Frage
Why can a managed service provider amplify risk?
Antwort
Its privileged access and shared tooling can provide a path into many customers.
Karte 281
Frage
What does probability express in risk analysis?
Antwort
A quantified chance that a defined event will occur within stated conditions or time.
Karte 282
Frage
Why can shadow IT create a threat?
Antwort
It bypasses security review, inventory, monitoring, and supported configuration.
Karte 283
Frage
What is on-path interception?
Antwort
An attacker positions between communicating parties to observe or alter traffic.
Karte 284
Frage
Why include encryption in a system-hardening baseline?
Antwort
It limits data exposure if storage, traffic, or a protected secret is accessed outside the intended trust boundary.
Karte 285
Frage
Why tune security alerts?
Antwort
To keep useful detections while reducing noise that wastes analyst attention.
Karte 286
Frage
What can IPS or IDS logs contribute to an investigation?
Antwort
The matched rule or signature, source and destination, timestamp, action, and traffic context around detected activity.
Karte 287
Frage
What is VM escape?
Antwort
A vulnerability that lets code break out of a virtual machine and affect the host or another guest.
Karte 288
Frage
How can segmentation reduce vulnerability exposure before a patch is available?
Antwort
It limits which systems and users can reach the vulnerable service and restricts paths for lateral movement.
Karte 289
Frage
Why should firewall policy name the required ports and protocols explicitly?
Antwort
Explicit scope permits only the intended service traffic and avoids exposing unnecessary network paths.
Karte 290
Frage
What is a change management policy meant to control?
Antwort
How changes are requested, assessed, approved, tested, implemented, and reviewed.
Karte 291
Frage
What is a hybrid-cloud architecture?
Antwort
An environment that integrates private or on-premises resources with public cloud services.
Karte 292
Frage
How do AH and ESP differ in the security services they can provide?
Antwort
AH provides integrity and data-origin authentication without confidentiality. ESP can provide confidentiality and may also provide integrity and data-origin authentication. Actual services depend on AH or ESP, mode, algorithms, and policy/configuration.
Karte 293
Frage
What makes user behavior risky?
Antwort
It creates avoidable exposure, such as bypassing controls, mishandling data, or using unapproved access paths.
Karte 294
Frage
What is least privilege?
Antwort
Granting only the access needed for the required task and no more.
Karte 295
Frage
What do Secure, HttpOnly, and SameSite cookie attributes restrict?
Antwort
Transmission to HTTPS, script access, and cross-site sending, respectively.
Karte 296
Frage
Why discover unmanaged assets?
Antwort
Unknown systems cannot be patched, monitored, or governed reliably.
Karte 297
Frage
What is a service-level agreement?
Antwort
Measurable service commitments and remedies, such as availability or response targets.
Karte 298
Frage
What should govern automated security escalation?
Antwort
Clear severity criteria, ownership, evidence, rate limits, and a fallback path when the automation cannot decide safely.
Karte 299
Frage
What is platform diversity as a resilience strategy?
Antwort
Using different implementations so one common flaw or failure is less likely to affect every copy.
Karte 300
Frage
How can replayed session material affect an application?
Antwort
It can let an attacker reuse a captured token or request to impersonate a valid session or repeat an authorized action.
Karte 301
Frage
What is an implicit trust zone in zero trust?
Antwort
A boundary where access was previously trusted by location alone and must instead receive explicit policy enforcement.
Karte 302
Frage
What does salting a password hash accomplish?
Antwort
It makes identical passwords hash differently and defeats precomputed hash tables.
Karte 303
Frage
What is spear phishing?
Antwort
Phishing tailored to a specific person, role, or organization.
Karte 304
Frage
What is eradication?
Antwort
Removing the attacker's access, malicious artifacts, and exploited conditions.
Karte 305
Frage
Who is a risk owner?
Antwort
The person accountable for deciding and monitoring how a specific risk is handled.
Karte 306
Frage
What does a partially known penetration-test environment provide?
Antwort
The tester receives limited information or access, modeling an attacker with some insider knowledge or initial foothold.
Karte 307
Frage
What is a microservices architecture?
Antwort
An application is split into small independently deployable services with explicit interfaces and distributed trust boundaries.
Karte 308
Frage
What is a jump server?
Antwort
A hardened intermediary used to reach systems in a restricted management network.
Karte 309
Frage
What can happen when a configuration change is made without dependency analysis?
Antwort
A downstream service can fail even when the changed component works.
Karte 310
Frage
What is resource reuse exposure?
Antwort
Sensitive data from a previous use remains accessible when storage or memory is reassigned.
Karte 311
Frage
Why does financial information require explicit protection?
Antwort
It can expose accounts, transactions, forecasts, or reporting and may create fraud, legal, or business risk if altered or disclosed.
Karte 312
Frage
What does CVE provide?
Antwort
A common identifier for a publicly disclosed vulnerability.
Karte 313
Frage
Where can DLP controls operate?
Antwort
On endpoints, networks, email, and cloud services, depending on the product and visibility.
Karte 314
Frage
What does privileged password vaulting protect?
Antwort
It stores and controls use of privileged secrets so users or automation do not need to know or retain the underlying password.
Karte 315
Frage
What does an access-control standard define?
Antwort
Mandatory, measurable requirements for identity, authentication, authorization, review, and removal of access.
Karte 316
Frage
How can automation support compliance monitoring?
Antwort
It can collect evidence, test controls, flag exceptions, and produce repeatable reports, with human review of context.
Karte 317
Frage
What does static code analysis examine?
Antwort
Source or compiled code for weakness patterns without executing the application.
Karte 318
Frage
What actor attribute describes funding, time, and personnel?
Antwort
Resources.
Karte 319
Frage
What is DNS poisoning?
Antwort
Introducing false DNS data so names resolve to attacker-chosen destinations.
Karte 320
Frage
Why change default credentials during hardening?
Antwort
Default secrets are predictable and commonly targeted.
Karte 321
Frage
What does quarantine do after a security alert?
Antwort
It restricts a suspected asset or object while analysts validate and remediate the risk.
Karte 322
Frage
What does key stretching do for stored passwords?
Antwort
It deliberately makes each password guess more computationally expensive.
Karte 323
Frage
What is smishing?
Antwort
Phishing delivered through SMS or another text-messaging service.
Karte 324
Frage
What is qualitative risk analysis?
Antwort
Using descriptive scales such as low, medium, and high to compare likelihood and impact.
Karte 325
Frage
What is a master service agreement?
Antwort
An umbrella contract establishing general legal and commercial terms for ongoing work.
Karte 326
Frage
What is threat scope reduction?
Antwort
Narrowing the systems, privileges, or paths an attacker can reach.
Karte 327
Frage
Why use a third-party cloud service instead of building locally?
Antwort
It can provide faster deployment, elasticity, and managed capabilities, with added dependency and governance risk.
Karte 328
Frage
What should determine security-device placement?
Antwort
The traffic or resource to observe or enforce, the trust boundary, failure behavior, reachability, and resilience needs.
Karte 329
Frage
What does situational awareness mean for a user?
Antwort
Notice the people, devices, requests, location, and context around a task before acting.
Karte 330
Frage
What does a failover test validate?
Antwort
That the service can transfer to the alternate component or site within the required recovery targets under the tested conditions.
Karte 331
Frage
What is a preventive control meant to do?
Antwort
Stop an unwanted event before it succeeds.
Karte 332
Frage
What is just-in-time privileged access?
Antwort
Elevated access is granted only when needed and expires after a short approved period.
Karte 333
Frage
What safeguard should security-group automation enforce?
Antwort
Least-privileged rules tied to an approved resource, owner, purpose, and review or expiration point.
Karte 334
Frage
How does a reflected DDoS attack hide and multiply sources?
Antwort
The attacker spoofs the victim's address so many third-party services send their replies to the victim.
Karte 335
Frage
What is a security misconfiguration?
Antwort
An unsafe setting, such as public storage, default access, or excessive permissions, that exposes a resource.
Karte 336
Frage
Why can the same vulnerability have different organizational impact?
Antwort
Industry obligations, business processes, safety needs, data sensitivity, and asset criticality change the consequence of exploitation.
Karte 337
Frage
What does URL scanning evaluate before a user opens a web destination?
Antwort
The address, redirect chain, reputation, category, and known threat indicators associated with the destination.
Karte 338
Frage
What is the board's security governance role?
Antwort
Provide oversight, set risk direction, and hold executives accountable.
Karte 339
Frage
What does code signing establish?
Antwort
That code came from the holder of the signing key and has not changed since signing.
Karte 340
Frage
How should an asset's classification affect security operations?
Antwort
It should drive handling, access, monitoring, recovery, and disposal controls that match the asset's sensitivity and impact.
Karte 341
Frage
How does encryption protect data?
Antwort
It uses a cryptographic key to transform plaintext into ciphertext, which authorized parties can decrypt with the required key while unauthorized readers cannot feasibly recover the original data.
Karte 342
Frage
What is a secure enclave?
Antwort
A hardware-isolated execution area intended to protect selected code and data from the rest of the system.
Karte 343
Frage
What is business email compromise?
Antwort
Impersonation or takeover of a business identity to induce a fraudulent action, often a payment or data release.
Karte 344
Frage
What is recovery in incident response?
Antwort
Restoring services safely, monitoring them, and returning to normal operations.
Karte 345
Frage
How is single loss expectancy commonly estimated?
Antwort
Asset value multiplied by the exposure factor.
Karte 346
Frage
What does an unknown penetration-test environment provide?
Antwort
The tester begins with little or no internal information, modeling an external attacker's discovery process.
Karte 347
Frage
What security boundary does a hypervisor provide?
Antwort
It isolates virtual machines while controlling their access to shared hardware.
Karte 348
Frage
Why does a TLS tunnel not protect a compromised endpoint?
Antwort
TLS protects data between endpoints; malware or misuse at either endpoint can access the data before encryption or after decryption.
Karte 349
Frage
Why update diagrams after an infrastructure change?
Antwort
Operations and incident responders need the documentation to match the deployed environment.
Karte 350
Frage
What does privacy ownership assign?
Antwort
An accountable role for privacy decisions, obligations, data inventory, and corrective action.
Karte 351
Frage
What does a security control gap analysis compare?
Antwort
The controls required for the target state with the controls currently in place.
Karte 352
Frage
Someone outside the organization steals an employee's VPN credentials and logs in. Is the actor internal or external?
Antwort
External. Stolen internal credentials provide access but do not change the outsider's relationship to the organization.
Karte 353
Frage
What is application privilege escalation?
Antwort
Exploiting a flaw or misconfiguration to gain permissions beyond those originally granted.
Karte 354
Frage
What risk remains when unnecessary software is left installed?
Antwort
Its code, services, dependencies, and privileges add attack surface even when users do not need it.
Karte 355
Frage
What does SCAP standardize?
Antwort
Formats and identifiers for expressing, checking, and scoring security configuration and vulnerability information.
Karte 356
Frage
What can packet capture reveal?
Antwort
Protocol-level conversation details and payloads when traffic is not encrypted and collection is authorized.
Karte 357
Frage
What makes a privileged credential ephemeral?
Antwort
It is created for a limited task or session and expires or is destroyed automatically after that use.
Karte 358
Frage
How do a statement of work and a work order differ?
Antwort
A statement of work defines scope, deliverables, schedule, and responsibilities; a work order authorizes a defined unit of work under an agreement.
Karte 359
Frage
Why might multi-cloud improve resilience?
Antwort
A provider-wide failure need not stop workloads that can run independently elsewhere.
Karte 360
Frage
How can a service provider introduce a supply-chain vulnerability?
Antwort
Its privileged access, hosted service, or compromised integration can expose customers that depend on it.
Karte 361
Frage
What is a false positive in vulnerability scanning?
Antwort
A reported weakness that is not actually present or exploitable in the assessed context.
Karte 362
Frage
How do EDR and XDR differ?
Antwort
EDR focuses on endpoint telemetry and response; XDR correlates detection and response across endpoints and other security domains.
Karte 363
Frage
What should onboarding and offboarding procedures coordinate?
Antwort
Identity, access, equipment, data, training, approvals, and ownership changes at the start or end of a relationship.
Karte 364
Frage
How should an organization harden managed mobile devices?
Antwort
Enforce an MDM baseline with timely updates, screen lock and encryption, least privilege, approved apps, and remote lock or wipe.
Karte 365
Frage
What is a certificate signing request?
Antwort
A request containing a public key and subject information for a certificate authority to sign.
Karte 366
Frage
What is pretexting?
Antwort
Using a fabricated role or situation to make a request seem legitimate.
Karte 367
Frage
How is annualized loss expectancy commonly estimated?
Antwort
Single loss expectancy multiplied by annualized rate of occurrence.
Karte 368
Frage
What security consequence follows from containers sharing a kernel?
Antwort
A host-kernel compromise can affect multiple containers, so kernel and runtime hardening matter.
Karte 369
Frage
Where does 802.1X enforce a network admission decision?
Antwort
At the controlled switch port or wireless access point before normal network access is granted.
Karte 370
Frage
What should insider-threat awareness teach?
Antwort
Recognize misuse or concerning behavior without profiling people, and report evidence through approved channels.
Karte 371
Frage
What access action is suitable for careful automation?
Antwort
Enabling or disabling a defined service or account from an approved lifecycle or incident event.
Karte 372
Frage
What is an evil twin?
Antwort
A rogue wireless network made to resemble a legitimate one so users connect to it.
744 Karten
CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
Mit diesem Lernkartenset kostenlos lernenFlashcards wird geöffnet, damit du mit dem Lernen beginnen kannst.
Karte 373
Frage
Does non-human-readable data need less protection?
Antwort
No. Encoded or machine-readable data can carry the same sensitive meaning and impact.
Karte 374
Frage
What does authenticating a system establish?
Antwort
It verifies a presented authenticator or credential bound to the claimed device, workload, or service identity. Identity proofing or enrollment establishes what real-world entity that identity represents.
Karte 375
Frage
What does LDAP provide in identity systems?
Antwort
A standard protocol for querying and modifying directory entries such as users, groups, and attributes.
Karte 376
Frage
What is a deterrent control meant to do?
Antwort
Discourage an attacker from attempting an unwanted action.
Karte 377
Frage
Why update procedures after changing a security control?
Antwort
Staff need accurate steps for operating, monitoring, and recovering the new control.
Karte 378
Frage
How does OCSP differ from a certificate revocation list?
Antwort
OCSP returns status for a specific certificate, while a revocation list distributes a signed set of revoked certificate serial numbers.
Karte 379
Frage
What is the goal of data exfiltration?
Antwort
Remove data from its authorized environment without permission.
Karte 380
Frage
What is a watering-hole attack?
Antwort
Compromising a site frequented by the intended targets so their visits expose them.
Karte 381
Frage
How can a hardware provider introduce a supply-chain vulnerability?
Antwort
A compromised component, firmware image, manufacturing step, or delivery path can weaken the device before deployment.
Karte 382
Frage
What is application forgery?
Antwort
Creating or altering a request, token, or object so the application treats it as authentic.
Karte 383
Frage
How does least privilege mitigate compromise?
Antwort
It limits the actions and resources available to a compromised account or process.
Karte 384
Frage
What is serverless computing?
Antwort
A model where the provider manages servers and the customer deploys event-driven code or functions.
Karte 385
Frage
What makes an infrastructure control effective for a specific risk?
Antwort
Its placement, failure behavior, visibility, enforcement scope, and operating cost match the protected path and threat.
Karte 386
Frage
What does parallel recovery processing test?
Antwort
Whether primary and alternate environments can run together consistently before a controlled cutover.
Karte 387
Frage
Which password-authentication method does WPA3-Personal use?
Antwort
Simultaneous Authentication of Equals, which replaces WPA2-Personal's PSK authentication and resists offline password guessing.
Karte 388
Frage
How does data retention affect asset disposal?
Antwort
Required data must be preserved for its retention period, while expired data should be sanitized before reuse or destruction.
Karte 389
Frage
What is a false negative in vulnerability scanning?
Antwort
A real weakness that the assessment fails to report.
Karte 390
Frage
What does recurring security scanning add to monitoring?
Antwort
Periodic discovery of exposed services, missing fixes, weak configurations, or other detectable changes.
Karte 391
Frage
What should guide port selection for a secure protocol?
Antwort
Use the documented service port or an explicitly managed alternative, and expose it only on the required interfaces and paths.
Karte 392
Frage
What does forensic acquisition create?
Antwort
A controlled, documented copy or collection of relevant evidence while preserving its integrity and context.
Karte 393
Frage
How do system owners and data owners divide security accountability?
Antwort
A system owner is accountable for the system's risk, access, operation, and lifecycle; a data owner sets the data's classification, access, handling, and retention requirements.
Karte 394
Frage
What does likelihood express in risk analysis?
Antwort
A reasoned estimate of how plausible or frequent an event is, often stated qualitatively when precise probability is unavailable.
Karte 395
Frage
What is a memorandum of understanding?
Antwort
A documented understanding of intentions and responsibilities, whose legal effect depends on its terms and jurisdiction.
Karte 396
Frage
What does the right to be forgotten generally require?
Antwort
Deletion of qualifying personal data when the applicable law grants the right and no overriding retention duty applies.
Karte 397
Frage
What does an audit committee oversee?
Antwort
Audit independence, plans, significant findings, management responses, and corrective-action follow-through.
Karte 398
Frage
What does identity interoperability require?
Antwort
Compatible protocols, attribute meanings, trust, and lifecycle behavior across connected systems.
Karte 399
Frage
How does a bollard protect a facility?
Antwort
It blocks or redirects vehicles before they can reach a protected area.
Karte 400
Frage
How can hashing protect a downloaded file?
Antwort
A trusted digest lets the recipient detect whether the file changed.
Karte 401
Frage
What is a credential replay attack?
Antwort
Using captured valid credentials or tokens again without needing to discover the secret.
Karte 402
Frage
How can automation complexity create security risk?
Antwort
Hidden dependencies and branching behavior can make failures difficult to predict, diagnose, contain, or reverse.
Karte 403
Frage
What must an architecture provide when a component cannot be patched?
Antwort
Compensating isolation, restricted access, monitoring, and a replacement plan that reduce exposure until the component can be retired.
Karte 404
Frage
What makes remote access secure?
Antwort
Controlled, authenticated, encrypted access to a private resource from outside its local trusted network.
Karte 405
Frage
What should users verify before connecting removable media or a cable?
Antwort
That the device and connection are approved, expected, and handled under organizational policy.
Karte 406
Frage
What is a self-signed certificate?
Antwort
A certificate signed by its own private key rather than by a separate trusted issuer.
Karte 407
Frage
What is brand impersonation?
Antwort
Using a trusted organization's identity or look to deceive people.
Karte 408
Frage
What characterizes a conservative risk appetite?
Antwort
A preference for lower uncertainty and exposure, even when that limits speed, return, or opportunity.
Karte 409
Frage
What should a managed mobile device verify before using Wi-Fi?
Antwort
The expected network identity, strong encryption, trusted authentication, and policy compliance before sending sensitive traffic.
Karte 410
Frage
What is a zero-day vulnerability?
Antwort
A flaw previously unknown to the vendor or defenders, or one without an available fix when discovered. A zero-day exploit is code or a technique that attacks such a flaw.
Karte 411
Frage
What does verification confirm after vulnerability remediation?
Antwort
Retesting confirms that the remediation removed or reduced the finding as intended within the tested scope.
Karte 412
Frage
What is user and entity behavior analytics?
Antwort
Analysis that identifies deviations from expected behavior for users, accounts, hosts, or services.
Karte 413
Frage
What does a physical security policy establish?
Antwort
Required protection for facilities, people, equipment, entry, monitoring, and response to physical events.
Karte 414
Frage
What does a UPS provide?
Antwort
Immediate short-term power and power conditioning while systems shut down or alternate power starts.
Karte 415
Frage
What is a nondisclosure agreement?
Antwort
A contract restricting use and disclosure of defined confidential information.
Karte 416
Frage
What should be checked before assigning a user permission?
Antwort
The user's approved duties, the resource and action allowed, separation-of-duties conflicts, and the impact if the permission is misused.
Karte 417
Frage
How does espionage differ from ordinary theft?
Antwort
It seeks confidential intelligence for strategic advantage, often while remaining hidden.
Karte 418
Frage
What is password spraying?
Antwort
Trying a small set of common passwords across many accounts to avoid lockouts.
Karte 419
Frage
What is the purpose of system isolation during an incident?
Antwort
Stop harmful communication while preserving the system for response and investigation.
Karte 420
Frage
What is a security benchmark?
Antwort
A documented set of recommended configuration checks for a platform or product.
Karte 421
Frage
Which metadata fields give a log record investigative context?
Antwort
Fields such as timestamp and time zone, source system, user or process identity, event ID or type, severity, and correlation ID.
Karte 422
Frage
What does an access-control vestibule prevent?
Antwort
It limits tailgating by allowing controlled passage through one door at a time.
Karte 423
Frage
What is version control's security value for configuration?
Antwort
It preserves attributable history and enables review or rollback of changes.
Karte 424
Frage
Why use both internal and external compliance monitoring?
Antwort
Internal monitoring supports continuous correction; external review adds independent or regulatory scrutiny.
Karte 425
Frage
What distinguishes on-premises architecture?
Antwort
The organization operates the infrastructure in facilities it controls and retains the associated physical and platform duties.
Karte 426
Frage
What risk can split tunneling add to a VPN?
Antwort
The endpoint can reach the protected network and an untrusted network at the same time, creating a path around centralized inspection.
Karte 427
Frage
What is a certificate root of trust?
Antwort
A trusted root certificate or key from which a client validates a certificate chain.
Karte 428
Frage
What is typosquatting?
Antwort
Registering a look-alike domain based on common typing errors or visual similarity.
Karte 429
Frage
What is root-cause analysis?
Antwort
Identifying the underlying conditions that allowed an incident, not just its visible symptoms.
Karte 430
Frage
What is risk tolerance?
Antwort
The acceptable variation or boundary around a specific objective or risk area.
Karte 431
Frage
What is a security self-assessment?
Antwort
A structured internal evaluation in which the organization measures its own controls against selected criteria.
Karte 432
Frage
What does data masking change?
Antwort
It replaces sensitive values with altered but usable representations, often preserving format for testing or display.
Karte 433
Frage
How do wireless authentication protocols let clients prove identity securely?
Antwort
They define how a client proves control of a credential, such as a password-derived secret or a certificate's private key; stronger choices also validate the server and protect the exchange.
Karte 434
Frage
Why reconcile inventory with network discovery?
Antwort
Differences expose missing records, retired systems, or unauthorized devices.
Karte 435
Frage
Why does sideloading raise mobile risk?
Antwort
It can bypass store review, signing policy, and managed application controls.
Karte 436
Frage
What does an information-sharing organization add to vulnerability management?
Antwort
Sector or community intelligence about relevant threats, incidents, and defensive action.
Karte 437
Frage
What does a web-filter block rule specify?
Antwort
The URL, domain, category, reputation, content, user, or context that should prevent a web request.
Karte 438
Frage
How do data custodians and data stewards differ?
Antwort
Custodians implement and operate technical safeguards for data; stewards guide its definitions, quality, handling, and proper use under the owner’s direction.
Karte 439
Frage
What is a brute-force password attack?
Antwort
Systematically trying many candidate secrets against an account or protected value.
Karte 440
Frage
What is a compensating control?
Antwort
An alternative safeguard used when the preferred control is impractical or unavailable.
Karte 441
Frage
How can location act as an authentication factor?
Antwort
A system can evaluate where the claimant is, but location signals are usually contextual and spoofable rather than sufficient alone.
Karte 442
Frage
Why must security automation remain supportable?
Antwort
Owners must be able to update dependencies, understand failures, rotate credentials, and adapt the workflow as systems change.
Karte 443
Frage
What does a standby generator provide?
Antwort
Longer-duration power during a utility outage, after a startup delay.
Karte 444
Frage
What makes an architecture air-gapped?
Antwort
It has no direct network path to less-trusted networks, although removable media and maintenance workflows can still cross the boundary.
Karte 445
Frage
What is a software-defined WAN?
Antwort
A centrally managed overlay that selects wide-area paths by policy across underlying network links.
Karte 446
Frage
What password-management behavior should awareness training reinforce?
Antwort
Use unique long passwords through an approved manager and report suspected compromise promptly.
Karte 447
Frage
What security value does fencing provide?
Antwort
It defines and delays entry across a physical perimeter.
Karte 448
Frage
What is a wildcard certificate?
Antwort
A certificate that can match multiple hosts at one domain level, such as subdomains of an example domain.
Karte 449
Frage
How does misinformation differ from disinformation?
Antwort
Misinformation is false regardless of intent; disinformation is deliberately false or misleading.
Karte 450
Frage
What is a risk threshold?
Antwort
A defined level that triggers escalation, treatment, or another required response.
Karte 451
Frage
What does a vendor penetration test contribute to assessment?
Antwort
Authorized evidence of exploitable paths in the vendor's relevant environment under agreed scope.
Karte 452
Frage
What is the objective of a service-disruption attack?
Antwort
Make a system or business function unavailable or unreliable.
Karte 453
Frage
What is directory traversal?
Antwort
Manipulating a file path to reach files outside the directory the application intended to expose.
Karte 454
Frage
Why decommission an unsupported system?
Antwort
Removing it eliminates an exposure that can no longer be patched or securely maintained.
Karte 455
Frage
Why archive security-monitoring data?
Antwort
To preserve evidence for investigations, trend analysis, compliance, and retention requirements beyond the live system.
Karte 456
Frage
What role does RADIUS commonly play in enterprise Wi-Fi?
Antwort
It centralizes authentication, authorization information, and accounting for network access.
Karte 457
Frage
Why separate the requester and approver of a high-risk change?
Antwort
To reduce error, fraud, and unilateral unauthorized modification.
Karte 458
Frage
Why can a jailbroken device violate a security baseline?
Antwort
It weakens platform isolation and allows unapproved privileged changes.
Karte 459
Frage
When is tokenization especially useful?
Antwort
When a system needs a surrogate value without retaining the original sensitive value in that workflow.
Karte 460
Frage
Why can dark-web intelligence affect vulnerability priority?
Antwort
Discussion, exploit sales, or leaked access can signal attacker interest, but the evidence must be validated.
Karte 461
Frage
What firewall policy should govern traffic from a screened subnet to internal systems?
Antwort
Deny it by default and allow only explicitly required flows.
Karte 462
Frage
What does SAML commonly carry?
Antwort
XML assertions about authentication and attributes between an identity provider and service provider; signatures commonly protect their authenticity and integrity.
Karte 463
Frage
What does a security governance committee do?
Antwort
It coordinates stakeholders, reviews risk and performance, and makes or recommends decisions within its charter.
Karte 464
Frage
How can global privacy requirements affect one data process?
Antwort
A shared process may need to satisfy overlapping duties across jurisdictions where people, systems, or data are located.
Karte 465
Frage
What characterizes an IoT device?
Antwort
It combines sensing or actuation with network connectivity, often under tight resource and update constraints.
Karte 466
Frage
What is a unified threat management appliance?
Antwort
One device combines several controls, such as firewalling, intrusion prevention, filtering, and malware inspection.
Karte 467
Frage
What does a hardware security module provide?
Antwort
A dedicated, tamper-resistant environment for generating, storing, and using cryptographic keys.
Karte 468
Frage
A remotely reachable API is fixed, but its desktop client stays vulnerable. What exposure remains?
Antwort
Client-based exposure remains because the installed endpoint software is still vulnerable; fixing the remote API does not remediate the client.
Karte 469
Frage
What is a tabletop exercise?
Antwort
A discussion-based walkthrough of a scenario to test decisions, roles, and procedures.
Karte 470
Frage
What does a risk exemption authorize?
Antwort
A documented release from a requirement for a defined scope, owner, rationale, controls, review, and expiration.
Karte 471
Frage
What is a regulatory examination?
Antwort
An authorized regulator reviews records, controls, and practices to determine whether the organization meets applicable requirements.
Karte 472
Frage
What does physical video surveillance primarily provide?
Antwort
Detection and evidence of activity in monitored areas.
Karte 473
Frage
What is a birthday attack against a hash?
Antwort
Using collision probability to find any two matching digests much faster than targeting one exact preimage.
Karte 474
Frage
Why keep backups both onsite and offsite?
Antwort
Onsite copies support fast recovery, while offsite copies survive a site-wide loss.
Karte 475
Frage
How does technical debt affect security automation?
Antwort
Outdated assumptions, dependencies, and workarounds make the workflow harder to change and more likely to fail unsafely.
Karte 476
Frage
What should switch hardening restrict first?
Antwort
Administrative access, unused ports, insecure management protocols, and unauthorized changes to switching configuration.
Karte 477
Frage
What should happen when an asset changes owners?
Antwort
Inventory, access, support responsibility, and data handling should be updated.
Karte 478
Frage
What does evidence of a vendor's internal audits contribute?
Antwort
It shows how the vendor tests its own controls, records findings, assigns remediation, and follows issues to closure.
Karte 479
Frage
What is identity attestation?
Antwort
Evidence that an identity, device, authenticator, or claim has been verified by a trusted process.
Karte 480
Frage
Why can standard enterprise patching be unsafe for an RTOS device?
Antwort
A change can disrupt timing guarantees or certified operational behavior.
Karte 481
Frage
What is secure access service edge?
Antwort
A cloud-delivered architecture that combines wide-area connectivity with policy-driven security services near users and resources.
Karte 482
Frage
What social-engineering habit should awareness training reinforce?
Antwort
Pause and independently verify unusual requests instead of trusting urgency, authority, or familiarity.
Karte 483
Frage
How can a software provider introduce a supply-chain vulnerability?
Antwort
A compromised package, build system, dependency, or update channel can deliver vulnerable or malicious code to customers.
Karte 484
Frage
Why include internet exposure in remediation priority?
Antwort
A reachable vulnerable service usually has more attack opportunity than an isolated one.
Karte 485
Frage
What does a mail gateway inspect?
Antwort
Inbound and outbound email for threats, policy violations, spoofing, and sensitive data.
Karte 486
Frage
What is a data controller?
Antwort
The entity that determines why and how personal data is processed.
Karte 487
Frage
How does blackmail motivate a cyberattack?
Antwort
The attacker threatens disclosure or harm unless the victim complies.
Karte 488
Frage
What is a downgrade attack?
Antwort
Forcing parties to use an older or weaker protocol or security mode.
Karte 489
Frage
How does encryption mitigate data exposure?
Antwort
It makes captured data unreadable without the required key.
Karte 490
Frage
How do network and web vulnerability scanners differ?
Antwort
Network scanners assess reachable hosts, services, versions, and configurations; web scanners exercise running web behavior for application weaknesses.
Karte 491
Frage
How can vulnerability-scan data support an investigation?
Antwort
It shows which weaknesses, versions, services, and exposures were known on the affected systems near the incident timeline.
Karte 492
Frage
What is key escrow?
Antwort
Controlled storage of a recoverable copy of a cryptographic key by an authorized party.
Karte 493
Frage
Which human vector commonly uses a fake sign-in page to harvest credentials?
Antwort
Phishing; the message sends the target to an imitation service that captures the submitted credentials.
Karte 494
Frage
What is risk avoidance?
Antwort
Stopping or not starting the activity that creates the risk.
Karte 495
Frage
What is data obfuscation?
Antwort
Making data harder to understand while preserving some utility, without necessarily providing cryptographic secrecy.
Karte 496
Frage
What is a directive control?
Antwort
A safeguard that tells people what behavior or action is required.
Karte 497
Frage
What does a security guard add that a camera cannot?
Antwort
Human judgment and an immediate physical response.
Karte 498
Frage
Why define restricted activities in change management?
Antwort
High-risk actions can then require extra authorization, separation of duties, or a prohibited window.
Karte 499
Frage
What contractual impact can noncompliance create?
Antwort
It can trigger remediation duties, service credits, indemnity, audit rights, suspension, termination, or claims for breach.
Karte 500
Frage
What should determine backup frequency?
Antwort
The recovery point objective, data-change rate, business impact, and available replication or storage capacity.
Karte 501
Frage
What should router hardening protect?
Antwort
Administrative access, routing configuration, exposed services, and the integrity of traffic-control policy.
Karte 502
Frage
What problem does OAuth 2.0 address?
Antwort
Delegated authorization: a client obtains limited access to a resource without receiving the user's password.
Karte 503
Frage
What does SCADA do?
Antwort
It provides supervisory monitoring and control across distributed industrial equipment.
Karte 504
Frage
How does a Layer 3/4 firewall rule differ from a Layer 7 rule?
Antwort
Layer 3/4 evaluates IP addresses plus transport protocols and ports; Layer 7 evaluates application content or actions.
Karte 505
Frage
What distinguishes a computer virus?
Antwort
It attaches to a host file or program and spreads when that infected host executes or is shared.
Karte 506
Frage
What does a key management system coordinate?
Antwort
Secure key creation, storage, access, rotation, revocation, recovery, and destruction.
Karte 507
Frage
How can an unsecure wired network expose traffic?
Antwort
An unauthorized device on the network may observe, redirect, or inject traffic when access control and link protections are weak.
Karte 508
Frage
Why is vulnerable device firmware hard to remediate?
Antwort
Firmware updates may be rare, vendor-dependent, or impossible after support ends.
Karte 509
Frage
What does patching change in vulnerability remediation?
Antwort
It installs the vendor's corrected code or configuration to remove the underlying software weakness.
Karte 510
Frage
What does DMARC add to SPF and DKIM?
Antwort
Domain alignment, receiver policy, and reporting for messages claiming the visible From domain.
Karte 511
Frage
How does automation improve security efficiency?
Antwort
It performs repeatable actions quickly and consistently while reducing manual handoffs and rework.
Karte 512
Frage
What is a simulation exercise?
Antwort
A more realistic practice in which participants respond to injected events using operational processes.
Karte 513
Frage
What is a data processor?
Antwort
An entity that processes personal data on behalf of a controller.
Karte 514
Frage
What is risk mitigation?
Antwort
Reducing likelihood, impact, or both through controls or process changes.
Karte 515
Frage
Why monitor a vendor after onboarding?
Antwort
Security posture, ownership, services, incidents, and dependencies can change.
Karte 516
Frage
What does a physical penetration test assess?
Antwort
Whether authorized testers can bypass facility, personnel, and physical access controls under agreed rules.
Karte 517
Frage
Why use access badges at a facility?
Antwort
To associate entry attempts with authorized identities and enforce access rules.
Karte 518
Frage
How does permission restriction protect data?
Antwort
Only authorized identities receive the actions and scope their roles require.
Karte 519
Frage
What is the usual objective of ransomware extortion?
Antwort
Force payment by denying access, threatening disclosure, or both.
Karte 520
Frage
What does impossible travel indicate?
Antwort
One identity appears to authenticate from distant locations too quickly for legitimate travel.
Karte 521
Frage
What is configuration enforcement?
Antwort
Continuously applying or restoring approved settings so systems do not remain in an insecure state.
Karte 522
Frage
What does a web vulnerability scanner inspect?
Antwort
Running web behavior for issues such as unsafe input handling and insecure configuration.
Karte 523
Frage
How does cost affect an architecture choice?
Antwort
It constrains acquisition, operation, staffing, resilience, and recovery options across the system's life.
Karte 524
Frage
What does EAP provide with 802.1X?
Antwort
A framework for carrying an authentication method between the supplicant and authentication infrastructure.
Karte 525
Frage
What should operational-security training help users protect?
Antwort
Sensitive routines, capabilities, locations, relationships, and small details that an observer could combine into useful intelligence.
Karte 526
Frage
What does a time-of-day access rule do?
Antwort
Allows or denies a requested action according to an approved schedule.
Karte 527
Frage
What should cloud infrastructure hardening establish?
Antwort
Secure identities, network boundaries, logging, encryption, approved configurations, and continuous checks for drift.
Karte 528
Frage
What should an asset owner ensure during offboarding?
Antwort
Assigned assets, access, data, and custody records are returned, transferred, or disposed of under the approved process.
Karte 529
Frage
Why encrypt backups?
Antwort
Backup media and transfers can expose the same sensitive data as production systems.
Karte 530
Frage
What is steganography?
Antwort
Hiding the existence of data inside another medium rather than merely encrypting its contents.
Karte 531
Frage
Which human vector uses a fabricated authority role to justify a sensitive request?
Antwort
Pretexting; the attacker invents a credible role and situation to make the request seem legitimate.
Karte 532
Frage
Why does risk transfer not remove accountability?
Antwort
The organization can retain legal, reputational, operational, and oversight consequences.
Karte 533
Frage
Why validate a change after deployment?
Antwort
To confirm the intended result occurred without introducing unacceptable side effects.
Karte 534
Frage
What makes end-of-life hardware a security vulnerability?
Antwort
The vendor no longer supplies fixes or support, so known weaknesses can persist without a reliable remediation path.
Karte 535
Frage
What does an audit add to remediation validation?
Antwort
Independent evidence that the approved fix, process, and documentation were completed and remain effective.
Karte 536
Frage
Why can SPF pass while a message still impersonates a brand?
Antwort
SPF checks the envelope domain, which may differ from the visible From domain.
Karte 537
Frage
What role can a government entity have in security governance?
Antwort
It can establish, enforce, or oversee legal and regulatory requirements within its authority.
Karte 538
Frage
How do data inventory and retention support privacy governance?
Antwort
The inventory records what data is processed and where; retention rules define how long it is kept and when it is deleted or anonymized.
Karte 539
Frage
What can concurrent sessions from distant regions indicate?
Antwort
A stolen account or shared credential, subject to VPN and proxy context.
Karte 540
Frage
What does supply-chain analysis examine?
Antwort
Upstream providers, components, dependencies, concentration, and compromise paths that can affect the purchased service.
Karte 541
Frage
What is the purpose of facility lighting as a control?
Antwort
Deter covert activity and improve observation of people and areas.
Karte 542
Frage
What architecture quality keeps a service usable during component failure?
Antwort
Availability.
Karte 543
Frage
When is fail-open behavior preferable to fail-closed behavior?
Antwort
When preserving availability during control failure is more important than blocking uninspected traffic, based on the system's risk decision.
Karte 544
Frage
Which control function does a login-failure alert provide?
Antwort
Detection; it reveals suspicious authentication activity.
Karte 545
Frage
What does a biometric MFA implementation verify?
Antwort
A measured physical or behavioral characteristic presented by the user, matched against an enrolled template.
Karte 546
Frage
How can automation enforce a security baseline?
Antwort
It compares realized settings with the approved state and reports or corrects unauthorized drift.
Karte 547
Frage
How do wireless cryptographic protocols protect network traffic?
Antwort
They encrypt frames over the air and add integrity protection, reducing eavesdropping and tampering when a secure protocol and configuration are used.
Karte 548
Frage
Why segment sensitive data stores?
Antwort
It limits reachable paths and separates them from lower-trust workloads.
Karte 549
Frage
What must remain secret in an asymmetric key pair?
Antwort
The private key; disclosure lets another party impersonate the owner or decrypt data intended for that key, depending on its use.
Karte 550
Frage
How can a supplier become a supply-chain attack vector?
Antwort
A compromised material, component, credential, or delivery process can weaken products before they reach the organization.
Karte 551
Frage
What is e-discovery?
Antwort
Identifying, preserving, collecting, reviewing, and producing electronically stored information for a legal matter.
Karte 552
Frage
What characterizes a neutral risk appetite?
Antwort
A balanced willingness to accept uncertainty when expected value and controls justify the exposure.
Karte 553
Frage
What is passive reconnaissance?
Antwort
Gathering information without directly interacting with the target's systems.
Karte 554
Frage
What does a philosophical motive mean for a threat actor?
Antwort
The actor acts to advance a belief or moral position rather than primarily for money.
Karte 555
Frage
What does unexpected resource consumption indicate?
Antwort
Possible malware, denial of service, cryptomining, or a malfunction that needs investigation.
Karte 556
Frage
What does a host-based intrusion prevention system do?
Antwort
It monitors activity on one host and can block behavior that matches exploit or attack rules.
Karte 557
Frage
How does agent-based monitoring differ from agentless monitoring?
Antwort
An agent collects local detail on the host; agentless monitoring uses remote interfaces and may have less visibility.
Karte 558
Frage
What can network logs contribute to an investigation?
Antwort
Connection timing, endpoints, protocols, routing, name resolution, and other evidence of communication across the environment.
Karte 559
Frage
What is the purpose of a backup restore test?
Antwort
Demonstrate under tested conditions that required data and systems can be recovered within expectations.
Karte 560
Frage
Why can obsolete hardware become a security risk?
Antwort
It may lack supported firmware, modern protections, or replacement parts.
Karte 561
Frage
What does rescanning confirm after remediation?
Antwort
Whether the scanner can still detect the original finding on the affected asset.
Karte 562
Frage
What should a secure transport method provide?
Antwort
Authenticated endpoints where required, confidentiality, integrity, replay resistance, and supported cryptography for the traffic.
Karte 563
Frage
How can law affect security governance?
Antwort
It can impose mandatory duties based on jurisdiction, data, industry, or activity.
Karte 564
Frage
What does resilience mean for a security architecture?
Antwort
The ability to withstand disruption, adapt, and recover while preserving essential functions.
Karte 565
Frage
Why minimize an infrastructure's attack surface?
Antwort
Fewer exposed services and paths leave fewer opportunities for exploitation.
Karte 566
Frage
What does executing a security-awareness program require?
Antwort
Delivering the approved content to the intended audiences, tracking participation, handling exceptions, and measuring outcomes.
Karte 567
Frage
What does an infrared security sensor detect?
Antwort
A change in infrared energy, often the heat pattern created by a person moving through its field of view.
Karte 568
Frage
What is a knowledge factor?
Antwort
Something the claimant knows, such as a password.
Karte 569
Frage
Why review allow-list and deny-list impact before a change?
Antwort
Adding or removing an entry can unexpectedly grant access, block users, or interrupt dependencies.
Karte 570
Frage
What does partition-level encryption protect?
Antwort
One selected disk partition, leaving other partitions outside that encryption boundary.
Karte 571
Frage
How can instant messaging deliver a security attack?
Antwort
It can deliver a malicious link, file, request, or impersonated conversation through a fast, trusted-looking channel.
Karte 572
Frage
What can repeated blocked-content events indicate?
Antwort
Malware, policy bypass, a misconfigured application, or a user repeatedly reaching prohibited resources.
Karte 573
Frage
What should a server-hardening baseline reduce?
Antwort
Unnecessary services, exposed administration, weak identity controls, insecure defaults, and unmonitored configuration change.
Karte 574
Frage
When is physical media destruction appropriate?
Antwort
When reuse is unnecessary or sanitization cannot provide adequate assurance.
Karte 575
Frage
What is mean time to repair?
Antwort
The average time required to restore a failed component or service.
Karte 576
Frage
Why disclose conflicts of interest during vendor selection?
Antwort
A personal or financial relationship can bias evaluation away from the organization's requirements.
Karte 577
Frage
What is a fine for noncompliance?
Antwort
A monetary penalty imposed for failing to meet a legal, regulatory, or contractual requirement.
Karte 578
Frage
What does a public data classification authorize?
Antwort
Approved disclosure without confidentiality restrictions, while integrity and availability requirements may still apply.
Karte 579
Frage
What security benefit comes from standard infrastructure configurations?
Antwort
They reduce variation, make review repeatable, and let the same approved controls be applied across resources.
Karte 580
Frage
How does horizontal scaling increase capacity?
Antwort
It adds more service instances and distributes work among them.
Karte 581
Frage
Why can added connectivity weaken segmentation?
Antwort
Each allowed path can become a route for lateral movement or data escape.
Karte 582
Frage
What coding practice is central to preventing SQL injection?
Antwort
Use parameterized queries so untrusted values remain data rather than executable query syntax.
Karte 583
Frage
When is a compensating control appropriate for a vulnerability?
Antwort
When timely removal or patching is infeasible and another control can reduce the risk.
Karte 584
Frage
How does agent-based web filtering enforce policy?
Antwort
Software on the endpoint evaluates or redirects web traffic, including traffic that does not pass through a central network proxy.
Karte 585
Frage
How can regulation differ from an internal policy?
Antwort
Regulation is externally enforceable; internal policy is an organizational rule that may implement external duties.
Karte 586
Frage
What is a storage snapshot?
Antwort
A point-in-time representation of data or system state, whose independence depends on how it is stored.
Karte 587
Frage
What does password age measure?
Antwort
How long the current password has existed, which policy may use to prevent immediate reuse or trigger a risk-based change.
Karte 588
Frage
What does an ethical motive mean in vulnerability research?
Antwort
The researcher intends to improve security, typically through authorized testing and responsible disclosure.
Karte 589
Frage
What can missing security logs indicate?
Antwort
Logging failure, tampering, retention misconfiguration, or an inactive source.
Karte 590
Frage
Why disable unused ports and protocols?
Antwort
They expose unnecessary communication paths and code that attackers can reach.
Karte 591
Frage
What does antivirus contribute to monitoring?
Antwort
It scans files, memory, or behavior and reports suspected malicious code.
Karte 592
Frage
What is a honeypot?
Antwort
A decoy system or service designed to attract and observe malicious activity.
Karte 593
Frage
What does file-level encryption protect?
Antwort
Selected files independently of whether the rest of the disk or volume is encrypted.
Karte 594
Frage
How can SMS deliver a security attack?
Antwort
A text message can carry a malicious link or urgent request that exploits the recipient's trust in the phone channel.
Karte 595
Frage
What happens during incident analysis?
Antwort
Responders validate the event, determine scope and impact, build a timeline, and identify the systems, accounts, and data involved.
Karte 596
Frage
What is mean time between failures?
Antwort
The average operating time between repairable failures.
Karte 597
Frage
What is active reconnaissance?
Antwort
Probing or interacting with target systems to discover services and behavior.
Karte 598
Frage
What constraint should guide ICS or SCADA hardening?
Antwort
Safety and process availability must be preserved while access, services, network paths, and changes are tightly controlled.
Karte 599
Frage
Which control function does restoring a clean system image provide?
Antwort
Correction; it returns the system to a known-good state.
Karte 600
Frage
What does responsiveness mean in an architecture decision?
Antwort
How quickly the system and its operators can adapt to demand, failure, or attack.
Karte 601
Frage
How does out-of-band access strengthen remote administration?
Antwort
It uses a management path separate from production traffic, preserving controlled access during an outage or compromise.
Karte 602
Frage
What makes user behavior unexpected?
Antwort
It differs materially from the person's normal role, timing, location, resource use, or established work pattern.
Karte 603
Frage
What is a work order?
Antwort
A document authorizing a defined unit of work under an existing agreement.
Karte 604
Frage
What can out-of-cycle logging indicate?
Antwort
Unexpected activity outside a system's normal schedule, including misuse, compromise, or an unplanned job.
Karte 605
Frage
Why update a standard operating procedure after a change?
Antwort
It keeps routine work aligned with the new approved state and reduces inconsistent or unsafe execution.
Karte 606
Frage
What coding practice limits cross-site scripting?
Antwort
Context-appropriate output encoding, supported by safe templating and input handling.
Karte 607
Frage
What does a restricted data classification indicate?
Antwort
Access is tightly limited because unauthorized disclosure, alteration, or loss would create serious harm.
Karte 608
Frage
How does a bug bounty support responsible disclosure?
Antwort
It defines eligible systems, rules, reporting, and possible rewards for external researchers.
Karte 609
Frage
What does web-filter content categorization provide?
Antwort
A policy label for a site or page based on its subject, function, or risk so access rules can treat categories consistently.
Karte 610
Frage
How do hard and soft authentication tokens differ?
Antwort
A hard token is a separate physical device; a soft token is implemented in software on a general-purpose device.
Karte 611
Frage
How can industry requirements affect security governance?
Antwort
Industry standards, shared practices, assurance expectations, and sector-specific risks can shape required policies and controls.
Karte 612
Frage
How can noncompliance cause loss of a license?
Antwort
An authority may suspend or revoke the permission needed to operate, sell, or perform regulated work.
Karte 613
Frage
What does volume-level encryption protect?
Antwort
All data within a selected logical storage volume.
Karte 614
Frage
How can impersonation exploit familiarity?
Antwort
The attacker imitates a known person or routine communication style so the request receives less scrutiny.
Karte 615
Frage
How does RTO guide recovery design?
Antwort
It sets the target maximum time to restore the function, driving recovery automation, staffing, capacity, and site choices.
Karte 616
Frage
What is a honeynet?
Antwort
A network of decoy systems used to study or divert attackers.
Karte 617
Frage
What does backup replication provide?
Antwort
Additional synchronized or copied recovery data in another system or location.
Karte 618
Frage
What lets automation scale securely?
Antwort
Bounded permissions, validated inputs, rate controls, audit records, and consistent policy at every new resource.
Karte 619
Frage
Why monitor a hardened computing resource continuously?
Antwort
New drift, failures, attacks, and unsupported changes can appear after a secure baseline is deployed.
Karte 620
Frage
Why keep a certificate of destruction?
Antwort
It documents that a disposal provider handled specified media under the agreed process.
Karte 621
Frage
Why consider patch availability before selecting a platform?
Antwort
Unsupported or difficult-to-update components accumulate known exposure.
Karte 622
Frage
Why should remote administration use an encrypted, authenticated protocol?
Antwort
It keeps credentials and commands confidential in transit. When correctly configured with integrity protection, the protocol also detects tampering and authenticates the intended endpoint.
Karte 623
Frage
How can revenge motivate an insider incident?
Antwort
A disgruntled person may damage systems or disclose data to punish the organization.
Karte 624
Frage
What is a published or documented indicator of malicious activity?
Antwort
A malicious observable or behavior—such as a hash, domain, IP address, or TTP—shared through threat intelligence, an advisory, or an incident report to help identify related malicious activity.
Karte 625
Frage
Why monitor a system more closely when a mitigation exception is accepted?
Antwort
Monitoring can reveal exploitation or control failure while the documented exception remains open.
Karte 626
Frage
What is an SNMP trap?
Antwort
An unsolicited device notification sent to a management system when a configured event occurs.
Karte 627
Frage
How can an automated report support an investigation?
Antwort
It assembles repeatable findings, trends, or control results that investigators can correlate with the incident timeline.
Karte 628
Frage
What is a security key?
Antwort
A hardware authenticator that uses cryptographic proof, often bound to the legitimate service origin.
Karte 629
Frage
What does database-level encryption protect?
Antwort
A database or selected database structures through controls managed at the database layer.
Karte 630
Frage
How does brand impersonation exploit trust?
Antwort
It copies a familiar organization's identity so a fraudulent message, site, or account appears legitimate.
Karte 631
Frage
What browser-side impact can a cross-site scripting vulnerability create?
Antwort
It can run attacker-controlled script in a trusted site's origin and access data or actions available to the victim's session.
Karte 632
Frage
How can a system or process audit identify vulnerabilities?
Antwort
It compares evidence with required configuration and procedure to reveal control gaps.
Karte 633
Frage
What security role can Group Policy provide?
Antwort
Centralized Windows configuration of account, application, audit, and system security settings.
Karte 634
Frage
What should incident-response training prepare people to do?
Antwort
Recognize their role, use the communication and escalation paths, preserve evidence, and perform approved response actions.
Karte 635
Frage
Why must governance track local or regional requirements?
Antwort
They may impose location-specific duties that differ from national, global, industry, or contractual rules.
Karte 636
Frage
How can a dependency become a useful key risk indicator?
Antwort
A measurable change in its availability, capacity, control state, or concentration can warn that exposure is increasing.
Karte 637
Frage
What is a business partners agreement?
Antwort
An agreement defining how business partners will work together, including responsibilities and security or data-handling terms.
Karte 638
Frage
What makes an audit regulatory?
Antwort
It evaluates compliance with requirements established or enforced by a government or delegated authority.
Karte 639
Frage
What is a honeyfile?
Antwort
A decoy file whose access can reveal unauthorized activity.
Karte 640
Frage
Why does legal information require explicit protection?
Antwort
It may contain privileged advice, case strategy, evidence, or regulated records whose disclosure or alteration creates legal risk.
Karte 641
Frage
Which indicator can mass file renaming and encryption produce?
Antwort
Resource inaccessibility; users may be unable to open files after an attacker encrypts or renames them.
Karte 642
Frage
What remains with an organization after transferring architecture risk?
Antwort
Oversight and residual risk remain, even when a provider or insurer accepts defined responsibility or financial consequences.
Karte 643
Frage
When does local console placement provide useful administrative access?
Antwort
When network management is unavailable or unsafe, a physically controlled console offers a direct recovery path.
Karte 644
Frage
What makes a harmful user action unintentional?
Antwort
The user causes exposure or policy violation through error or misunderstanding rather than deliberate misuse.
Karte 645
Frage
How should an organization harden workstations?
Antwort
Apply a managed secure baseline: patch the OS and applications, remove unnecessary software and services, enforce least privilege, and enable endpoint protection and a host firewall.
Karte 646
Frage
What is journaling in recovery?
Antwort
Recording ordered changes so data can be replayed or restored to a consistent point.
Karte 647
Frage
What downtime must a change plan account for?
Antwort
The period when the affected service will be unavailable or degraded, including the impact on users and dependent systems.
Karte 648
Frage
Why must a privacy program map local or regional law to data flows?
Antwort
The applicable duties can change with the location of the person, organization, processing, or stored data.
Karte 649
Frage
Why combine independent preventive controls at different layers?
Antwort
A failure at one layer does not automatically let the same attack succeed at the next layer.
Karte 650
Frage
What is passwordless authentication?
Antwort
A flow that does not require the user to enter a memorized password, often using public-key credentials.
Karte 651
Frage
How can automation improve security reaction time?
Antwort
It can collect context and perform preapproved containment or routing as soon as a reliable trigger occurs.
Karte 652
Frage
What does record-level encryption protect?
Antwort
Individual records or fields, allowing finer protection than encrypting the entire database.
Karte 653
Frage
How can business email compromise misuse urgency?
Antwort
It pressures an employee to bypass normal verification for a payment, credential, or data request.
Karte 654
Frage
What does impact measure in risk analysis?
Antwort
The consequence to objectives, such as financial, operational, safety, legal, or reputational harm.
Karte 655
Frage
What makes cyber activity part of warfare?
Antwort
It supports military or state conflict objectives such as disruption, intelligence, or influence.
Karte 656
Frage
Which indicator can a newly created privileged account produce outside the normal change window?
Antwort
Out-of-cycle logging; the account event appears at a time when no authorized administrative change was scheduled.
Karte 657
Frage
How can configuration enforcement validate a deployed mitigation?
Antwort
It compares the realized settings with the approved state and corrects or reports drift.
Karte 658
Frage
How does validating an alert improve alert tuning?
Antwort
The analyst can identify which conditions, thresholds, or context caused noise or missed important evidence.
Karte 659
Frage
What data-layer impact can a SQL injection vulnerability create?
Antwort
It can let untrusted input alter a database query, exposing or changing data and sometimes executing administrative operations.
Karte 660
Frage
What environmental variables can change vulnerability priority?
Antwort
Local exposure, configuration, existing controls, asset importance, and the effect on the organization's actual environment.
Karte 661
Frage
What security role does SELinux provide?
Antwort
Mandatory access controls that confine processes according to centrally defined policy.
Karte 662
Frage
Why review governance documents periodically?
Antwort
Business, technology, threats, and external obligations change.
Karte 663
Frage
Why evaluate power requirements for a system design?
Antwort
Power capacity and redundancy constrain availability and recovery.
Karte 664
Frage
When is IPsec a better tunnel choice than TLS?
Antwort
Choose IPsec when policy must protect IP traffic broadly below individual applications—for example, across a site-to-site gateway tunnel. Choose TLS for a specific service connection.
Karte 665
Frage
What is a honeytoken?
Antwort
A fake credential or data element that generates a high-confidence alert when used.
Karte 666
Frage
What should embedded-system hardening prioritize?
Antwort
Trusted firmware, restricted interfaces, secure defaults, minimal services, and a supported update path.
Karte 667
Frage
Why must sanitization address data remanence?
Antwort
Residual data may remain recoverable after ordinary deletion, so the sanitization method must make recovery infeasible for the media and risk.
Karte 668
Frage
Why require rules of engagement for vendor testing?
Antwort
Authorized scope, timing, methods, contacts, and stop conditions prevent unsafe or mistaken activity.
Karte 669
Frage
What does a private data classification indicate?
Antwort
The information concerns an individual or limited internal audience and should not be exposed publicly.
Karte 670
Frage
What does a tabletop recovery exercise test?
Antwort
Participants walk through a scenario and decisions without switching production systems, exposing plan and coordination gaps.
Karte 671
Frage
Why prevent password reuse?
Antwort
One compromised password should not unlock other accounts or services.
Karte 672
Frage
Which malicious-activity indicator is unexplained sustained CPU or memory use?
Antwort
Abnormal resource consumption, such as unusual CPU, memory, power, storage, or network-bandwidth use.
Karte 673
Frage
What does transport encryption protect?
Antwort
It protects data-in-transit confidentiality: captured or intercepted traffic is unreadable without the key. Encryption does not prevent interception or, by itself, provide integrity or authenticate endpoints.
Karte 674
Frage
How can a voice call become an attack vector?
Antwort
An attacker can use a live or synthetic voice to impersonate a trusted party and request secrets, money, or unsafe actions.
Karte 675
Frage
What should a digital-forensics report document?
Antwort
The question examined, methods, evidence sources, timeline, findings, limitations, and the basis for each conclusion.
Karte 676
Frage
What tradeoff comes with an expansionary risk appetite?
Antwort
It accepts more uncertainty and exposure to pursue growth or return, so limits and monitoring must remain explicit.
Karte 677
Frage
What does a known penetration-test environment provide?
Antwort
The tester receives substantial internal knowledge or access so the exercise can focus on deeper control and attack-path testing.
Karte 678
Frage
Why evaluate compute requirements before deployment?
Antwort
Insufficient resources can cause failure, while excessive resources increase cost and attack surface.
Karte 679
Frage
Why place sensors at network choke points?
Antwort
They can observe traffic crossing important trust boundaries.
Karte 680
Frage
What should hybrid or remote-work security training emphasize?
Antwort
Trusted networks and devices, physical privacy, secure communication, reporting, data handling, and separation of work from shared environments.
Karte 681
Frage
Why plan an application restart separately from a service restart?
Antwort
The application may need its own state handling, user coordination, health checks, and rollback point.
Karte 682
Frage
What is a cryptographic vulnerability?
Antwort
A weakness in algorithm choice, key handling, implementation, or protocol use that defeats the intended protection.
Karte 683
Frage
Why report findings by asset owner?
Antwort
Owners need clear accountability and a prioritized remediation queue.
Karte 684
Frage
What should guide selection of a secure protocol?
Antwort
The protocol must protect the required data flow, authenticate the right endpoints, use supported cryptography, and fit operational constraints.
Karte 685
Frage
How do centralized and decentralized governance structures differ?
Antwort
Centralized governance sets decisions from one authority; decentralized governance delegates them and needs strong coordination for consistency.
Karte 686
Frage
How does privacy-aware design limit data retention?
Antwort
It records a justified retention period and makes deletion or anonymization part of the normal data lifecycle.
Karte 687
Frage
What does a pressure security sensor detect?
Antwort
Force or weight applied to a protected surface, such as a floor mat or fence line.
Karte 688
Frage
What automation costs should a security team plan for?
Antwort
Development, licensing, infrastructure, monitoring, maintenance, failure recovery, and the staff needed to own the workflow.
Karte 689
Frage
What should RTOS hardening preserve while reducing attack surface?
Antwort
Deterministic timing and safety requirements, with only necessary services, privileges, interfaces, and validated updates enabled.
Karte 690
Frage
What is the goal of disruption-for-chaos activity?
Antwort
Create instability or damage itself rather than pursue a clear financial or intelligence return.
Karte 691
Frage
Which indicator can repeated password guessing produce?
Antwort
Unexpected account lockout; repeated failed attempts can trigger the account's lockout policy.
Karte 692
Frage
How does removing unnecessary software harden a system?
Antwort
It eliminates code, services, dependencies, and privileges that an attacker could otherwise target.
Karte 693
Frage
What does NetFlow provide?
Antwort
Metadata summarizing network conversations, such as endpoints, ports, timing, protocol, and byte counts.
Karte 694
Frage
How can a dashboard support an investigation?
Antwort
It brings selected current and historical signals together so investigators can spot changes, patterns, and affected scope.
Karte 695
Frage
When should a password be expired?
Antwort
When compromise is suspected, policy or risk requires a change, or the credential no longer meets the approved authentication standard.
Karte 696
Frage
Why does cryptographic key length matter?
Antwort
It affects the work required to search the key space, although security also depends on the algorithm and implementation.
Karte 697
Frage
How can an unsecure Bluetooth connection become an attack vector?
Antwort
Weak pairing, discoverability, or vulnerable services can let a nearby attacker connect, intercept data, or issue commands.
Karte 698
Frage
What is a key risk indicator?
Antwort
A metric that signals changing exposure or increasing likelihood of an adverse outcome.
Karte 699
Frage
What should vendor monitoring verify when a contract ends?
Antwort
Vendor accounts, credentials, connections, data access, and retained assets are removed or transferred as approved.
Karte 700
Frage
What does a sensitive data classification indicate?
Antwort
The information needs safeguards because unauthorized access, change, or loss could cause harm.
Karte 701
Frage
What does software-defined networking separate?
Antwort
The control plane that decides traffic behavior from the data plane that forwards traffic.
Karte 702
Frage
Where should a web application firewall be placed?
Antwort
In the path of web requests before they reach the protected application.
Karte 703
Frage
What does a simulated recovery exercise test?
Antwort
Participants perform realistic response actions in a controlled environment without disrupting production.
Karte 704
Frage
How can a team verify that a detective control is effective?
Antwort
Trigger a known test event and confirm that the control records it, alerts the right responder, and supplies useful evidence.
Karte 705
Frage
How should defenders apply a published or documented indicator to telemetry and validate it before escalating?
Antwort
Search relevant telemetry for matches, then confirm the indicator's relevance, context, and freshness before escalating.
Karte 706
Frage
What makes a vulnerability cloud-specific?
Antwort
It arises from cloud service configuration, shared responsibility, control-plane exposure, tenancy, or provider-specific behavior.
Karte 707
Frage
How can insurance respond to vulnerability risk?
Antwort
It may transfer defined financial consequences, but it does not remove the weakness or the organization's duties.
Karte 708
Frage
How does reputation improve web filtering?
Antwort
It uses prior observations about a domain, address, certificate, or hosting pattern to identify destinations with elevated risk.
Karte 709
Frage
What does an encryption policy establish?
Antwort
Which data and communications require encryption, approved methods, key responsibilities, exceptions, and review duties.
Karte 710
Frage
How does a microwave security sensor detect movement?
Antwort
It emits microwave energy and detects changes in the reflected signal caused by motion.
Karte 711
Frage
What should IoT-device hardening change before deployment?
Antwort
Default credentials, unnecessary services, insecure communication, unmanaged updates, and unrestricted network access.
Karte 712
Frage
Why track software licenses as assets?
Antwort
License ownership, permitted use, updates, and end-of-support status affect compliance and risk.
Karte 713
Frage
What does a password manager improve?
Antwort
It can generate and store unique long passwords so users do not memorize or reuse them.
Karte 714
Frage
What makes a ledger open and public?
Antwort
Anyone can inspect its recorded entries, while its consensus and integrity controls determine who can add valid entries.
Karte 715
Frage
What should a payment-change request trigger?
Antwort
Independent verification through a known channel before any account or payment detail is changed.
Karte 716
Frage
What does preserving digital evidence require?
Antwort
Protecting its integrity, context, access history, and availability from collection through final disposition.
Karte 717
Frage
What should a risk report tell decision-makers?
Antwort
The risk, uncertainty, business impact, owner, treatment, trend, and decision required.
Karte 718
Frage
What should an external assessment report provide?
Antwort
Its scope, criteria, evidence, findings, limitations, conclusions, and responsible follow-up actions.
Karte 719
Frage
What is a centralized design's main resilience risk?
Antwort
A central dependency can become a bottleneck or single point of failure.
Karte 720
Frage
What does mutual TLS add to a TLS-protected service connection?
Antwort
It adds client authentication, commonly with a client certificate, so the client and server authenticate each other.
Karte 721
Frage
What should recurring security-awareness reporting show?
Antwort
Changes in participation, knowledge, behavior, reporting, and incidents, with gaps assigned to owners and follow-up actions.
Karte 722
Frage
Why do legacy applications require extra change planning?
Antwort
They may depend on undocumented behavior, unsupported components, or fragile integrations that make failure and rollback more likely.
Karte 723
Frage
How do a data controller and a data processor differ?
Antwort
A controller decides why and how personal data is processed. A processor handles that data on the controller’s behalf.
Karte 724
Frage
How can orchestration become a single point of failure?
Antwort
Many security workflows may depend on one engine, credential path, or integration hub whose outage stops all of them.
Karte 725
Frage
Why should defenses account for a threat actor's sophistication and capability?
Antwort
Those attributes indicate which techniques the actor can sustain and which controls are likely to slow or expose them.
Karte 726
Frage
How does an injection attack make an application execute unintended instructions?
Antwort
It sends crafted input that an interpreter treats as code or commands instead of data.
Karte 727
Frage
What does a host-based firewall control?
Antwort
Inbound and outbound network traffic for one endpoint according to local rules.
Karte 728
Frage
Why revise alerting after an incident?
Antwort
The incident can reveal missing telemetry, logic, thresholds, or response paths that should produce a better future alert.
Karte 729
Frage
Why include security duties in procurement criteria?
Antwort
Security is easier to require before selection than to retrofit after dependency and data transfer begin.
Karte 730
Frage
What does a critical data classification indicate?
Antwort
The information is essential to vital operations, safety, or mission outcomes and needs the strongest availability and recovery controls.
Karte 731
Frage
What infrastructure capacity must support failover?
Antwort
The alternate site, network, power, cooling, and facility resources needed to carry the transferred load.
Karte 732
Frage
Why does shared cloud context matter when evaluating a cloud-specific vulnerability?
Antwort
The affected service model and responsibility boundary determine who can observe, patch, configure, or compensate for the weakness.
Karte 733
Frage
How does a remediation exemption differ from an exception?
Antwort
Terminology follows the governing policy. A common convention is that an exemption removes a requirement for an approved scope, while an exception permits a time-bounded deviation.
Karte 734
Frage
Why should automated EDR or XDR blocking have an exception and rollback path?
Antwort
A false positive can isolate a critical endpoint or stop a legitimate process, so operators need controlled recovery without disabling protection broadly.
Karte 735
Frage
What does a security playbook provide?
Antwort
A repeatable set of roles, decisions, and actions for handling a defined operational scenario.
Karte 736
Frage
How does an ultrasonic security sensor detect movement?
Antwort
It emits high-frequency sound and detects changes in the returning sound pattern caused by motion.
Karte 737
Frage
What should a managed mobile device require for Bluetooth connections?
Antwort
Intentional pairing, non-discoverable operation when unused, trusted peers, current software, and only necessary Bluetooth profiles.
Karte 738
Frage
How do password complexity rules differ from password length?
Antwort
Complexity rules require selected character types; length measures total characters. Current policy should prioritize sufficient length and block weak or compromised choices instead of relying on composition alone.
Karte 739
Frage
What makes a certificate third-party trusted?
Antwort
A certificate authority outside the subject organization signs it and chains it to a root trusted by relying systems.
Karte 740
Frage
Why is an out-of-band check effective against impersonation?
Antwort
It verifies the request through a separate, previously trusted communication path.
Karte 741
Frage
What does a risk exception authorize?
Antwort
A documented deviation from a requirement for a defined scope, rationale, controls, owner, review, and expiration.
Karte 742
Frage
What security challenge grows in a decentralized design?
Antwort
Consistent policy, inventory, monitoring, and patching become harder.
Karte 743
Frage
How should controls be selected for an unused network path?
Antwort
Choose controls that block it by default, expose only approved connectivity, and make exceptions explicit and reviewable.
Karte 744
Frage
How can a buffer-overflow attack affect an application?
Antwort
It writes past a buffer boundary to corrupt memory, which can crash the application or redirect execution.
744 Karten
CompTIA Security+ SY0-701 Flashcards: Complete Objective Review
Flashcards wird geöffnet, damit du mit dem Lernen beginnen kannst.