Flashcards · CompTIA Security+ · Free
CompTIA Security+ flashcards, generated for you.
Example CompTIA Security+ study cards to learn from right now — then generate a full set from your own notes (plus a practice quiz) and export to Quizlet or Anki. Free, no account needed.
Example CompTIA Security+ flashcards
What is the primary purpose of the CIA triad in information security?
The CIA triad (Confidentiality, Integrity, Availability) provides a framework for evaluating and implementing security controls to protect information assets and ensure they are kept secret, accurate, and accessible.
Define confidentiality in the context of security controls.
Confidentiality ensures that information is accessible only to authorized individuals and is protected from unauthorized disclosure or access through encryption, access controls, and classification.
What is the difference between authentication and authorization?
Authentication verifies the identity of a user or device (who you are), while authorization determines what resources and actions an authenticated user is permitted to access (what you can do).
What are the three main types of access control models?
Discretionary Access Control (DAC) allows owners to set permissions, Mandatory Access Control (MAC) enforces security labels and classifications, and Role-Based Access Control (RBAC) grants permissions based on assigned roles.
Explain the principle of least privilege in access management.
Least privilege restricts users and systems to only the minimum permissions necessary to perform their job functions, reducing the attack surface and limiting damage from compromised accounts.
What is the purpose of a Digital Rights Management (DRM) system?
DRM protects intellectual property by controlling access to copyrighted digital content, preventing unauthorized copying, distribution, and use through encryption and license enforcement.
What distinguishes a vulnerability from an exploit?
A vulnerability is a weakness in hardware, software, or processes that could be exploited, while an exploit is actual code or technique that takes advantage of a vulnerability to cause harm.
Describe the NIST Cybersecurity Framework's five core functions.
Identify (understand assets and risks), Protect (implement safeguards), Detect (identify security events), Respond (contain and eliminate threats), and Recover (restore operations after incidents).
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses a single shared key to encrypt and decrypt data (fast but key distribution is difficult), while asymmetric encryption uses a public key to encrypt and a private key to decrypt (slower but solves key distribution).
What is a zero-day vulnerability and why is it critical?
A zero-day is a previously unknown software vulnerability with no available patch; it is critical because attackers can exploit it before vendors are aware and have released a fix, making systems defenseless.
Make your own CompTIA Security+ study set
Flashcards for related topics
Studying CompTIA Security+ to build with AI? MindloomHQ turns it into real skills — structured courses, agent projects, and certificates.
Explore MindloomHQ →