/
AI Flashcards
Save to my account
Sign up
AI Flashcards
Network and Endpoint Security Essentials
Study
1
Question
What is the main risk described in Threat 1 (RAT)?
Answer
Unauthorized remote control of the system
2
Question
Which protection measure involves verifying user identity before remote access?
Answer
Multi-Factor Authentication (MFA)
3
Question
How can NFC card cloning be mitigated according to Threat 2?
Answer
Encrypted NFC cards
4
Question
What additional safeguard helps monitor access attempts for NFC-based entry?
Answer
Access logging
5
Question
What is a misconfigured firewall likely to expose?
Answer
Critical ports and unfiltered traffic
6
Question
Which technology enables automatic detection and blocking of suspicious traffic?
Answer
Intrusion Prevention System (IPS)
7
Question
What is the purpose of logging and alerts in network protection?
Answer
Detect unauthorized access attempts
8
Question
What vulnerability exists in Threat 4 (Unauthorised Network Access)?
Answer
Lack of access controls and segmentation
9
Question
What wireless protocol should be used to secure wifi access in Threat 4?
Answer
WPA3 encryption
10
Question
What is the primary risk described in Threat 5 (Data Interception)?
Answer
Data being intercepted in transit without encryption
11
Question
What additional security is recommended for remote access in Threat 5?
Answer
Use of a secure VPN for remote workers
12
Question
What is the main source of risk in Threat 6 (Phishing)?
Answer
Users clicking malicious links leading to credential compromise
13
Question
What is one anti-phishing defensive measure?
Answer
Anti-phishing software
14
Question
What does encrypting data in transit and at rest achieve for a business?
Answer
Protects data confidentiality and integrity, reducing risk of unauthorized access.
15
Question
Q1: What should happen if data is intercepted during transmission according to the test description?
Answer
Data should be unreadable or protected during transmission.
16
Question
Name one protection measure against phishing described in the text.
Answer
Multi Factor Authentication (MFA).
17
Question
What does ‘Zero Trust Infrastructure’ aim to achieve in internal threats?
Answer
Continuously validating identity and behavior of users accessing resources.
18
Question
What does VPN Enforcement require for mobile devices?
Answer
Use of a VPN when accessing the business network.
19
Question
What is the principal risk of an outdated operating system?
Answer
Lack of security patches leading to exploitable vulnerabilities.
20
Question
What is the purpose of network segmentation?
Answer
Limit lateral movement by isolating sensitive systems using VLANs.
21
Question
What is a primary protection measure to reduce attack surface related to open ports?
Answer
Close unused ports and disable unnecessary services
22
Question
What tool is commonly used to identify open ports in a network scan?
Answer
Nmap (or Nessus)
23
Question
What firewall configuration strategy minimizes exposure of services?
Answer
Block access to all but essential ports
24
Question
What is a recommended test to verify network segmentation effectiveness?
Answer
Attempt to access a sensitive system from a general user network and verify blocking
25
Question
What is the effect of properly implemented WPA3 on wireless security?
Answer
Enhances encryption and resists brute-force attacks
26
Question
What is the recommended action if outdated Wi-Fi protocols are detected on a network?
Answer
Disable WEP/WPA; enable WPA2 (AES) or WPA3
27
Question
What is a primary security measure for protecting storage devices containing sensitive data?
Answer
Encrypt data (e.g., AES-256) and enforce access controls
28
Question
What additional step complements encryption to protect external storage devices?
Answer
Implement strict access controls and MFA; consider disabling USB ports where feasible
29
Question
Why should external media devices be restricted in secure environments like hotels?
Answer
To prevent malware infections and unauthorized access through connected devices
30
Question
What is a key difference between file encryption and full disk encryption?
Answer
File encryption protects specific files; full disk encryption protects the entire drive