Risk & Compliance Flashcards

(5 cards)

1
Q

Vulnerability Assessment vs Pen Testing

A

Vulnerability Assessment = Scan for known issues
Penetration Testing = Simulate real attacks to find new issues
Example:
VA: Nessus scan
Pen Test: Try to break login with SQL injection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

GDPR Basics

A

What it is: Law protecting EU personal data
3 Principles:
Consent
Right to access/delete
Transparency
Example: User can request deletion of account data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Privacy & Data Protection

A

What it is: Keeping user data safe and private
Consequences: Data breach → legal fines + loss of trust
Example: App leaks location data → violates privacy law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Secure Software & Work Transformation

A

Definition: Software built with security from the ground up
Impacts:
Remote work tools = secure access to company systems
New job roles (e.g., cybersecurity analyst)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Intellectual Property in Software

A

Forms of IP Protection:
Copyright — code
Trademark — logos/UI
Patent — unique algorithms
Trade secrets — internal tools
Example: Google’s PageRank = patented algorithm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly