EPISODE · Jan 21, 2025 · 17 MIN
ISC2 CC Domain 1: Security Principles Study Exam Questions by Edward Henriquez
from Decoded: The Cybersecurity Podcast · host Edward Henriquez
Domain 1: Security Principles1. Which part of the CIA triad ensures data is accessible when needed?A. ConfidentialityB. IntegrityC. AvailabilityD. AuthenticationAnswer: C. Availability2. What is the main purpose of confidentiality in information security?A. To ensure data is free from errorsB. To ensure only authorized parties can access dataC. To ensure data is accessible when neededD. To enforce accountabilityAnswer: B. To ensure only authorized parties can access data3. Which security principle ensures data has not been altered during transmission?A. IntegrityB. ConfidentialityC. AvailabilityD. AccountabilityAnswer: A. Integrity4. Which of the following is considered a preventive control?A. FirewallB. Audit logC. Incident response planD. BackupAnswer: A. Firewall5. What does the principle of least privilege entail?A. Users should have the maximum access possible.B. Users should only have access necessary for their role.C. All access should be denied by default.D. Users should share accounts.Answer: B. Users should only have access necessary for their role.6. A policy requiring two people to approve a critical action is an example of:A. Separation of dutiesB. Job rotationC. Least privilegeD. Defense in depthAnswer: A. Separation of duties7. Encryption is primarily used to achieve:A. AvailabilityB. ConfidentialityC. IntegrityD. AccountabilityAnswer: B. Confidentiality8. Which of the following describes a threat?A. A weakness in a systemB. A potential danger to a systemC. A measure taken to reduce riskD. A way to detect vulnerabilitiesAnswer: B. A potential danger to a system9. What is a vulnerability?A. A measure to counteract a threatB. A weakness in a system that can be exploitedC. A probability of a threat occurringD. A risk to the systemAnswer: B. A weakness in a system that can be exploited10. What type of risk cannot be fully eliminated but must be accepted?A. Avoidable riskB. Residual riskC. Inherent riskD. Mitigated riskAnswer: B. Residual risk11. Which of the following is an example of a physical control?A. Firewall rulesB. Biometric scannersC. Encryption algorithmsD. Password policiesAnswer: B. Biometric scanners12. What is an example of a deterrent control?A. Security guardsB. Data backupC. Antivirus softwareD. Incident responseAnswer: A. Security guards13. What is the purpose of defense in depth?A. To focus all efforts on a single strong controlB. To layer multiple security measuresC. To ensure faster access to dataD. To eliminate risks completelyAnswer: B. To layer multiple security measures14. Social engineering attacks primarily target:A. Software vulnerabilitiesB. Network protocolsC. Human behaviorD. Encryption mechanismsAnswer: C. Human behavior15. Which of the following is an example of social engineering?A. Sending a phishing emailB. Exploiting a software bugC. Performing a man-in-the-middle attackD. Cracking a password hashAnswer: A. Sending a phishing email16. What is the primary goal of risk assessment?A. To eliminate all risksB. To identify and prioritize risksC. To design security controlsD. To monitor security incidentsAnswer: B. To identify and prioritize risks17. Which type of attack involves overwhelming a network with traffic?A. PhishingB. RansomwareC. Denial of Service (DoS)D. KeyloggingAnswer: C. Denial of Service (DoS)18. What is the primary purpose of policies in cybersecurity?A. To replace technical controlsB. To provide guidelines and expectationsC. To replace monitoring systemsD. To enforce complianceAnswer: B. To provide guidelines and expectations19. A brute-force attack targets:A. The user’s personal detailsB. Guessing passwords systematicallyC. Exploiting a software vulnerabilityD. Social manipulationAnswer: B. Guessing passwords systematically20. What type of malware encrypts files and demands payment for their release?A. SpywareB. RansomwareC. WormD. TrojanAnswer: B. Ransomware
Embed this episode
NOW PLAYING
ISC2 CC Domain 1: Security Principles Study Exam Questions by Edward Henriquez
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.