Skip to content
L
LearnCoachAssist
Topics
AI
AI Agents (500 Questions)
AI Math (500 Questions)
AI Math Beginner
AI Search Results
Claude Code Prompts
Art & Design
Art History
Color Theory
Graphic Design Principles
Knitting And Crochet
Photography Exposure Triangle And Composition
Business
Accounting Basics
Customer Research
Economics
Excel Formulas For Financial Analysts
Go To Market Strategy
Browse all topics →
Packs
Featured Packs
Python Programming Essentials
Prompt Engineering
Prompting Claude Code
AI Agents and Autonomous Systems
SQL and Database Fundamentals
JavaScript Fundamentals
Algorithms and Data Structures
Git and Version Control
Browse all packs →
Learn
Learning Paths
AI Deck Generator
How it works
Quiz
Blog
Cheat Sheets
Pricing
Resources
Pricing
Compare
FAQ
About
Contact
Effective Studying Guide
Free Anki Decks
Log in
Start Free
Topics
AI
AI Agents (500 Questions)
AI Math (500 Questions)
AI Math Beginner
AI Search Results
Claude Code Prompts
Art & Design
Art History
Color Theory
Graphic Design Principles
Knitting And Crochet
Photography Exposure Triangle And Composition
Business
Accounting Basics
Customer Research
Economics
Excel Formulas For Financial Analysts
Go To Market Strategy
Browse all topics →
Packs
Python Programming Essentials
Prompt Engineering
Prompting Claude Code
AI Agents and Autonomous Systems
SQL and Database Fundamentals
JavaScript Fundamentals
Algorithms and Data Structures
Git and Version Control
Browse all packs →
Learn
Learning Paths
AI Deck Generator
How it works
Quiz
Blog
Cheat Sheets
Pricing
Resources
Pricing
Compare
FAQ
About
Contact
Effective Studying Guide
Free Anki Decks
Start Free
Log in
← Quit
Cybersecurity Fundamentals (200 Cards) Practice Exam
Question
1
of
50
60:00
Question 1
Cybersecurity Fundamentals (200 Cards)
What is session fixation?
Forcing a user to use an attacker-known session ID.
Universal 2nd Factor — hardware-based second factor authentication.
Malware that operates in memory without writing files to disk.
Intrusion Prevention System — detects AND blocks malicious activity.
Question 2
Cybersecurity Fundamentals (200 Cards)
What is social engineering?
US law protecting health information.
Broken access control, cryptographic failures, injection.
Manipulating people into divulging information or performing actions.
Software that displays unwanted advertisements.
Question 3
Cybersecurity Fundamentals (200 Cards)
What is tailgating?
Sending fake ARP messages to associate attacker's MAC with target's IP.
Following an authorized person into a restricted area.
Checking that user input conforms to expectations before processing.
Cloud Workload Protection Platform — secures workloads in cloud.
Question 4
Cybersecurity Fundamentals (200 Cards)
What is Kubernetes security?
Public Key Infrastructure — the framework for managing digital certificates.
Securing container orchestration including pods, secrets, network policies.
Assessment identifies vulnerabilities; pen test exploits them to demonstrate impact.
Malicious code triggered by a specific condition or event.
Question 5
Cybersecurity Fundamentals (200 Cards)
What is just-in-time access?
3 copies, 2 different media, 1 offsite.
A network of compromised devices controlled by an attacker.
Educating employees about security threats and best practices.
Granting elevated access only when needed and for limited time.
Question 6
Cybersecurity Fundamentals (200 Cards)
What is the 3-2-1 backup rule?
Granting permission to access specific resources or perform specific actions.
Compromising a trusted vendor to attack their customers.
3 copies, 2 different media, 1 offsite.
Acceptable Use Policy — rules for using organizational resources.
Question 7
Cybersecurity Fundamentals (200 Cards)
What is CIS Benchmarks?
A weakness that can be exploited by a threat to compromise security.
Chief Information Security Officer — senior executive responsible for security.
Confidentiality, Integrity, and Availability — the three core security principles.
Configuration baselines for hardening systems.
Question 8
Cybersecurity Fundamentals (200 Cards)
What is spyware?
Infrastructure as a Service — virtualized compute, storage, network.
Detecting threats based on actions they perform.
Trusted Platform Module — hardware chip for cryptographic operations.
Malware that secretly monitors user activity and exfiltrates information.
Question 9
Cybersecurity Fundamentals (200 Cards)
What is a rootkit?
Malware that hides itself and provides persistent privileged access.
Protecting cloud-based systems, data, and infrastructure.
A hidden method of bypassing normal authentication.
Categorizing data by sensitivity (e.g., public, internal, confidential, secret).
Question 10
Cybersecurity Fundamentals (200 Cards)
What is a stateful firewall?
A firewall that tracks the state of network connections.
Cloud Workload Protection Platform — secures workloads in cloud.
A one-way function that converts data to a fixed-size string.
A framework cataloging adversary tactics, techniques, and procedures.
Question 11
Cybersecurity Fundamentals (200 Cards)
What is session hijacking?
Splitting critical functions across multiple people to prevent fraud.
Stealing a user's session token to impersonate them.
A vulnerability unknown to the vendor with no patch available.
Header preventing clickjacking by controlling iframe embedding.
Question 12
Cybersecurity Fundamentals (200 Cards)
What is a signature-based detection?
A device or software that filters network traffic based on rules.
Granting elevated access only when needed and for limited time.
Phishing conducted via voice calls.
Matching known patterns of malicious code.
Question 13
Cybersecurity Fundamentals (200 Cards)
What is input validation?
Often used for ransom payments due to perceived anonymity.
Data stored on a device or medium.
Checking that user input conforms to expectations before processing.
Assessment identifies vulnerabilities; pen test exploits them to demonstrate impact.
Question 14
Cybersecurity Fundamentals (200 Cards)
What is a security policy?
Maliciously rerouting Internet traffic via BGP manipulation.
A document defining security requirements and acceptable behavior.
HTTP Strict Transport Security — forces HTTPS connections.
Information about threats used to inform defensive actions.
Question 15
Cybersecurity Fundamentals (200 Cards)
What is OSINT in recon?
Physical USB/NFC device used for authentication.
Reporting vulnerabilities to vendors before public disclosure.
High severity vulnerability.
Using public information for reconnaissance.
Question 16
Cybersecurity Fundamentals (200 Cards)
What is output encoding?
Compromising a trusted vendor to attack their customers.
3 copies, 2 different media, 1 offsite.
An isolated environment to safely run suspicious code.
Encoding data before output to prevent injection attacks.
Question 17
Cybersecurity Fundamentals (200 Cards)
What is IaaS?
Compromising sites a target frequents.
Self-replicating malware that spreads across networks without user interaction.
Infrastructure as a Service — virtualized compute, storage, network.
The malicious code delivered by an attack.
Question 18
Cybersecurity Fundamentals (200 Cards)
What is MTTD?
Trying all possible password combinations until success.
A hidden method of bypassing normal authentication.
Mean Time To Detect a security incident.
National Institute of Standards and Technology — publishes cybersecurity frameworks.
Question 19
Cybersecurity Fundamentals (200 Cards)
What is accounting (AAA)?
Tracking and logging user actions for audit and forensic purposes.
Writing code with security in mind to prevent vulnerabilities.
Cloud provider secures the cloud; customer secures their data in the cloud.
The malicious code delivered by an attack.
Question 20
Cybersecurity Fundamentals (200 Cards)
What is parameterized query?
Malware whose purpose is to install other malware.
Mean Time To Respond/Recover from a security incident.
Converting plaintext to ciphertext to protect confidentiality.
Database query with placeholders, preventing SQL injection.
Question 21
Cybersecurity Fundamentals (200 Cards)
What is baiting?
Leaving infected media (e.g., USB sticks) to lure victims.
Platform as a Service — managed runtime for application deployment.
An open authentication standard for passwordless login.
Certified Information Systems Security Professional — senior security certification.
Question 22
Cybersecurity Fundamentals (200 Cards)
What is rainbow table attack?
Using precomputed hash tables to crack passwords.
Payment Card Industry Data Security Standard for cardholder data.
Running suspicious files in a sandbox to observe behavior.
A hidden method of bypassing normal authentication.
Question 23
Cybersecurity Fundamentals (200 Cards)
What is data in use?
Software Composition Analysis — checks dependencies for known vulnerabilities.
Advanced Persistent Threat — sophisticated, sustained attacker, often nation-state.
Data being actively processed in memory.
Tools and processes to prevent unauthorized data exfiltration.
Question 24
Cybersecurity Fundamentals (200 Cards)
What is a DMZ?
Demilitarized Zone — a buffer network between the internal network and the internet.
Secure Sockets Layer — an older encryption protocol now deprecated in favor of TLS.
Endpoint Detection and Response — monitors and responds to threats on endpoints.
Proactively searching for threats not detected by automated systems.
Question 25
Cybersecurity Fundamentals (200 Cards)
What is SameSite cookie?
A web application security testing platform.
Cookie attribute controlling cross-site requests, mitigating CSRF.
A cryptographic method to verify message authenticity and integrity.
Collaboration between red and blue teams.
Question 26
Cybersecurity Fundamentals (200 Cards)
What is the principle of separation of duties?
Splitting critical functions across multiple people to prevent fraud.
A property where session keys can't be compromised even if the long-term key is.
Ensuring information is accessible only to authorized parties.
Independent review of security controls and practices.
Question 27
Cybersecurity Fundamentals (200 Cards)
What is RPO?
Mean Time To Respond/Recover from a security incident.
Trying passwords from a curated list of likely candidates.
Forcing a user to use an attacker-known session ID.
Recovery Point Objective — maximum acceptable data loss.
Question 28
Cybersecurity Fundamentals (200 Cards)
What is XDR?
A traditional security stance, largely supplanted by zero trust.
Using artificial intelligence to detect threats and automate response.
A popular hardware security key.
Extended Detection and Response — unified threat detection across endpoints, network, cloud.
Question 29
Cybersecurity Fundamentals (200 Cards)
What is SSL?
User and Entity Behavior Analytics — detecting anomalies in behavior.
A potential cause of unwanted incident that may harm a system.
US law protecting health information.
Secure Sockets Layer — an older encryption protocol now deprecated in favor of TLS.
Question 30
Cybersecurity Fundamentals (200 Cards)
What is the difference between authentication and authorization?
Physically isolating a system from networks for high security.
Linux Unified Key Setup — standard for Linux disk encryption.
Authentication confirms who you are; authorization defines what you can do.
Malware that operates in memory without writing files to disk.
Question 31
Cybersecurity Fundamentals (200 Cards)
What is IDS?
Intrusion Detection System — monitors for malicious activity.
Single Sign-On — one login grants access to multiple systems.
Checking that user input conforms to expectations before processing.
Phishing conducted via SMS text messages.
Question 32
Cybersecurity Fundamentals (200 Cards)
What is cross-site scripting (XSS)?
Mandatory Access Control — system enforces policies regardless of user choice.
Database query with placeholders, preventing SQL injection.
Injecting client-side scripts into web pages viewed by other users.
Security Orchestration, Automation, and Response — automating security workflows.
Question 33
Cybersecurity Fundamentals (200 Cards)
What is a worm?
Targeted phishing aimed at specific individuals or organizations.
A Linux distribution loaded with security and penetration testing tools.
Authentication using two or more independent factors.
Self-replicating malware that spreads across networks without user interaction.
Question 34
Cybersecurity Fundamentals (200 Cards)
What is a CVE?
Common Vulnerabilities and Exposures — a public list of known security flaws.
Acceptable Use Policy — rules for using organizational resources.
Granting elevated access only when needed and for limited time.
An isolated environment to safely run suspicious code.
Question 35
Cybersecurity Fundamentals (200 Cards)
What is logging?
€20 million or 4% of global annual revenue, whichever is higher.
Software Bill of Materials — inventory of components in software.
Recording events for monitoring and forensics.
High severity vulnerability.
Question 36
Cybersecurity Fundamentals (200 Cards)
What is DAST?
Dynamic Application Security Testing — tests running applications.
A simplified equation showing how risk is calculated.
A potential cause of unwanted incident that may harm a system.
Hardware Security Module — dedicated cryptographic hardware.
Question 37
Cybersecurity Fundamentals (200 Cards)
What is port scanning?
Popular open-source network scanning tool.
Hiding data within other data (e.g., text in images).
Identifying open ports on a target system.
A network protocol analyzer used for traffic inspection.
Question 38
Cybersecurity Fundamentals (200 Cards)
What is Secure cookie flag?
Granting users only the minimum permissions needed for their tasks.
Cookie sent only over HTTPS.
Traffic between internal systems and external networks.
A model describing stages of a cyberattack (e.g., reconnaissance to actions).
Question 39
Cybersecurity Fundamentals (200 Cards)
What is end-to-end encryption?
Encryption where only the communicating parties can read messages.
A network protocol analyzer used for traffic inspection.
Code or technique that takes advantage of a vulnerability.
Compromising a trusted vendor to attack their customers.
Question 40
Cybersecurity Fundamentals (200 Cards)
What is SBOM?
Software Bill of Materials — inventory of components in software.
A Linux distribution loaded with security and penetration testing tools.
Security Assertion Markup Language — XML-based standard for SSO.
Splitting critical functions across multiple people to prevent fraud.
Question 41
Cybersecurity Fundamentals (200 Cards)
What is "verify and never trust"?
The zero-trust principle replacing the legacy "trust but verify."
Matching known patterns of malicious code.
A traditional security stance, largely supplanted by zero trust.
Protecting API keys, credentials, and other sensitive configuration.
Question 42
Cybersecurity Fundamentals (200 Cards)
What is fileless malware?
Malware that operates in memory without writing files to disk.
Malware that encrypts data and demands payment for decryption.
Intrusion Prevention System — detects AND blocks malicious activity.
JSON Web Token — a compact, signed token format for authentication.
Question 43
Cybersecurity Fundamentals (200 Cards)
What is CVSS?
A device or software that filters network traffic based on rules.
Common Vulnerabilities and Exposures — a public list of known security flaws.
Common Vulnerability Scoring System — measures severity of vulnerabilities.
Use of IT systems without organizational approval.
Question 44
Cybersecurity Fundamentals (200 Cards)
What is spear phishing?
Targeted phishing aimed at specific individuals or organizations.
Static Application Security Testing — analyzes source code for vulnerabilities.
Fraudulent attempts to obtain sensitive information by impersonating trusted entities.
Software Bill of Materials — inventory of components in software.
Question 45
Cybersecurity Fundamentals (200 Cards)
What is IPS?
Intrusion Prevention System — detects AND blocks malicious activity.
Preparation, identification, containment, eradication, recovery, lessons learned.
Database query with placeholders, preventing SQL injection.
Acceptable Use Policy — rules for using organizational resources.
Question 46
Cybersecurity Fundamentals (200 Cards)
What is browser isolation?
Using stolen credentials from one breach to access other accounts.
Malware that secretly monitors user activity and exfiltrates information.
The duration an attacker remains undetected in a network.
Running web sessions in remote sandboxes to protect endpoints.
Question 47
Cybersecurity Fundamentals (200 Cards)
What is HTTPS?
Code or technique that takes advantage of a vulnerability.
Sending fake ARP messages to associate attacker's MAC with target's IP.
HTTP over TLS, providing encrypted web traffic.
Attribute-Based Access Control — using attributes (user, resource, environment) for policy.
Question 48
Cybersecurity Fundamentals (200 Cards)
What is hardening?
A security model assuming no implicit trust; verify every request.
Reducing a system's attack surface through configuration.
Account with elevated permissions, requiring stronger controls.
HTTP header restricting which resources a page can load.
Question 49
Cybersecurity Fundamentals (200 Cards)
What is a firewall?
A device or software that filters network traffic based on rules.
Role-Based Access Control — assigning permissions based on roles.
Software Composition Analysis — checks dependencies for known vulnerabilities.
A voluntary framework with five functions: Identify, Protect, Detect, Respond, Recover.
Question 50
Cybersecurity Fundamentals (200 Cards)
What is PaaS?
Hardware Security Module — dedicated cryptographic hardware.
Platform as a Service — managed runtime for application deployment.
Recovery Point Objective — maximum acceptable data loss.
Writing code with security in mind to prevent vulnerabilities.
Question navigator
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
← Previous
Next →
✅ Submit Exam