Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: 5.2A - CFUs

star
star
star
star
star
Last updated about 3 hours ago
18 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A company stores customer names, credit card numbers, and addresses. Employees who work with this data must complete annual training on how to handle and protect it. What managerial control is the company using?

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

A company allows employees to access customer data but never trains them on privacy laws or how to handle sensitive data. Which risk is the company MOST likely to face?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

A hospital trains employees on how to protect patient records and explains that medical data must remain private and secure. Why is this training important?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

Which of the following is an example of an operational security practice?

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

An employee emails a spreadsheet with customer Social Security numbers using a personal email account because it was more convenient. What type of problem does this represent?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

A company creates a document that lists which encryption algorithms employees are allowed to use and the minimum key length required. What is this document called?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

Why do organizations require minimum key lengths for encryption?

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

A company encrypts its customer data but stores the encryption key in a text file on the same server as the encrypted data. What is the main security problem?

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

Why is secure key generation important?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

A company launches a new website that stores customer information but never tests the website for security vulnerabilities. What policy is missing?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

When should a web application be tested for security vulnerabilities?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

A company discovers a serious vulnerability that allows attackers to access customer data but decides to fix it “eventually” because fixing it is expensive. What is the main problem with this decision?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

Why do companies fix vulnerabilities based on risk level?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

A company gives all employees full access to payroll records, customer data, and company financial information, even though most employees do not need that access. Which security principle is being violated?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

Why is the principle of least privilege important?

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

An attacker gains access to a low-level employee account, but the attacker cannot access financial data or customer databases because the employee did not have permission to access those systems. What security principle helped limit the damage?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A company does not train employees on how to recognize phishing emails. An employee clicks a fake login link and enters their password, allowing an attacker into the system. What managerial control could have prevented this?

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

A company has a policy that requires security testing every time an application is updated and requires high-risk vulnerabilities to be fixed within 48 hours. What type of policy is this?