Security Awareness Flashcards

(27 cards)

1
Q

What is the goal of Security Awareness?

A

Equip individuals to recognize and respond to threats for data protection

Focuses on common threats, potential risks, and best practices for secure digital interactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who can be a source of Insider Threats?

A
  • Employees
  • Former employees
  • Contractors
  • Business partners

Insider threats involve security risks from individuals within an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the goal of Password Management?

A

Ensure strong, unique passwords; securely stored; reduces unauthorized access risk

Involves practices and tools for creating, storing, and managing passwords.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name two techniques to prevent Social Engineering Attacks.

A
  • Maintaining situational awareness
  • Avoiding shoulder surfing

Prevention includes recognizing phone scams and maintaining operational security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the difference between Remote Work and Hybrid Work?

A
  • Remote Work: Performing job functions outside the office
  • Hybrid Work: Combining in-office and remote work for flexibility

Both models have unique security challenges.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or false: Creating a Culture of Security involves integrating cybersecurity into the organization’s ethos.

A

TRUE

It requires organizational change management, strategic planning, execution, monitoring, and reporting.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are some Behavior Indicators of Insider Threats?

A
  • Altered State or Substance Abuse
  • Emotional Distress
  • Lifestyle Incongruences
  • Financial Struggles

Training employees to recognize these behaviors is essential.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Password Manager?

A

Specialized tool, plugin, or extension used with web browsers to securely store and manage usernames and passwords

Helps prevent password reuse and enhances security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Operational Security (OPSEC)?

A

Protects critical information from being used by adversaries

Safeguards sensitive data, daily routines, and internal procedures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What should organizations do to address Security Challenges in remote work?

A
  • Establish comprehensive policies
  • Use secure connections like VPN
  • Implement multi-factor authentication
  • Provide cybersecurity training

Regular security audits and feedback sessions are also important.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the importance of Policies and Handbooks in an organization?

A

Guide decisions, ensuring compliance with legal and ethical standards

They shape behavior and decision-making in organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Fill in the blank: Policies and handbooks should be reviewed at least _______.

A

annually

Updates reflect the changing cybersecurity landscape.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the five domains of CompTIA Security+ (SY0-701)?

A
  • Domain 1: General Security Concepts
  • Domain 2: Threats, Vulnerabilities, and Mitigations
  • Domain 3: Security Architecture
  • Domain 4: Security Operations
  • Domain 5: Security Program Management and Oversight

Each domain has a specific percentage weight in the exam.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the purpose of training employees in a security culture?

A

Recognizing phishing attempts, data privacy, and safe online behavior

Encourages reporting of suspicious activities and includes practical exercises.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is Dumpster Diving in the context of security threats?

A

Attackers sift through garbage for discarded information

Employees with situational awareness can spot such activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the characteristics of a culture of security?

A
  • Continuous education
  • Proactive risk mitigation
  • Collective responsibility

Essential for safeguarding an organization.

17
Q

What is the goal of establishing an insider threat program?

A

Create a security culture

Encourages employees to report suspicious activities and provides training.

18
Q

How many countries around the world are mentioned?

A

50

The organization is continually adding countries.

19
Q

What is the benefit of being a CompTIA Platinum Partner?

A

Special discounted rate on exam vouchers

These savings are passed onto students when ordering exam vouchers.

20
Q

List the top five tips for increasing your score on the exam.

A
  • Use a cheat sheet
  • Skip any questions that are giving you trouble
  • Take a guess
  • Pick the best time for your exam
  • Be confident

These strategies can help improve exam performance.

21
Q

What should you do with a cheat sheet during the exam?

A

Write down important things you may forget

You can use a whiteboard or dry erase sheet provided at the testing center.

22
Q

True or false: You should try to answer every question, even if you’re struggling.

A

FALSE

Mark questions for review and skip them if they are too difficult.

23
Q

What is the penalty for guessing incorrectly on the exam?

A

There is no penalty

Guessing is encouraged if you are in doubt.

24
Q

What should you consider when choosing the best time for your exam?

A

Pick a time that works best for you

Avoid scheduling after a long workday.

25
What should you do if you are not **confident** before the exam?
Wait a few days to schedule your exam ## Footnote Build confidence by taking practice exams.
26
When taking a practice exam, what is the goal?
Understand why the right answer was right and the wrong answers are wrong ## Footnote Memorizing the answer key is not the objective.
27
What certifications are mentioned as steps to continue climbing the **CompTIA certification ladder**?
* CySA+ * PenTest+ * CASP+ ## Footnote These certifications represent advanced levels in cybersecurity.