🃏 SecurityX Flashcards

Test your advanced security knowledge.

About This Flashcard Deck

This flashcard deck contains 10 cards covering key SecurityX concepts for the SECX exam. Test your advanced security knowledge. Use active recall by attempting to answer each question before revealing the answer.

Card 1 of 10

Question

What is NIST RMF?

Click to reveal answer

Answer

Risk Management Framework: Categorize → Select → Implement → Assess → Authorize → Monitor. Applied to federal systems.

Click to flip back

All SecurityX Flashcards

1

Q: What is NIST RMF?

A: Risk Management Framework: Categorize → Select → Implement → Assess → Authorize → Monitor. Applied to federal systems.

2

Q: What is ephemeral key exchange?

A: Generates new key pairs per session (e.g., DHE, ECDHE). Provides perfect forward secrecy — past sessions stay secure if long-term key is compromised.

3

Q: What is HSM?

A: Hardware Security Module — dedicated hardware for secure cryptographic key storage and operations. Tamper-resistant.

4

Q: What is SCAP?

A: Security Content Automation Protocol — suite of specifications for automating vulnerability management and compliance checking.

5

Q: What is BCP vs DRP?

A: BCP (Business Continuity Plan): keep operations running during disruption. DRP (Disaster Recovery Plan): restore IT systems after a disaster.

6

Q: What is data sovereignty?

A: Data is subject to the laws of the country where it is stored. Affects cloud provider selection and data residency decisions.

7

Q: What is CASB?

A: Cloud Access Security Broker — enforces security policies between users and cloud services (visibility, compliance, threat protection, DLP).

8

Q: What is TPM?

A: Trusted Platform Module — hardware chip for secure key storage, platform integrity measurement, and hardware-based encryption.

9

Q: What is a WAF?

A: Web Application Firewall — inspects HTTP traffic to block application attacks (SQLi, XSS, CSRF). Layer 7 protection.

10

Q: What is DevSecOps?

A: Integrating security into every phase of the DevOps pipeline: code analysis, container scanning, infrastructure as code validation, automated testing.

CompTIA Flashcard Study Technique

CompTIA exams cover broad domains with hundreds of concepts. Use these flashcards in short, focused sessions of 15–20 minutes rather than marathon study sessions. Group cards by domain and track which domains have the lowest recall rates — allocate extra study time to those areas. CompTIA exams weight domains differently, so match your flashcard focus to the domain percentages listed in the exam objectives.

More SECX Flashcard Decks