CYBERSECURITY STUDY GUIDE MIDTERM 2026: KEY CONCEPTS & EXAM TIPS
Cybersecurity Study Guide Midterm 2026: Key
Concepts & Exam Tips Howard Community
College)
🔑 1.0 Security Concepts
What is Information Security?
● Protecting information and systems from unauthorized access, use,
disclosure, disruption, modification, or destruction.
● Goal: ensure Confidentiality, Integrity, and Availability (CIA Triad).
Challenges Security Professionals Face
● Constantly evolving threats (malware, hackers, insider threats).
● Balancing usability vs. security.
● Managing human error (phishing, weak passwords).
● Keeping up with new technologies and compliance requirements.
Proactive Approach to Security
● Continuous monitoring and threat intelligence (SOC).
● Automation and DevSecOps for faster detection and response.
● Security awareness training to reduce human risk.
Integrity vs. Non-Repudiation
● Integrity: Ensures data isn’t changed or corrupted. (Verified by hashing.)
● Non-repudiation: Ensures the sender cannot deny sending data (achieved
with digital signatures).
pg. 1
, CYBERSECURITY STUDY GUIDE MIDTERM 2026: KEY CONCEPTS & EXAM TIPS
CIA Triad Goals
1. Confidentiality – Keep data private (encryption, access controls).
2. Integrity – Ensure accuracy and consistency (hashing, checksums).
3. Availability – Ensure access when needed (redundancy, backups).
Risk Management Components
● Identify assets & threats
● Assess risk (likelihood × impact)
● Mitigate (controls)
● Monitor continuously
● Respond & recover from incidents
Three Types of Threat Agents
1. Internal – Employees, contractors, or insiders.
2. External – Hackers, competitors, criminals.
3. Natural/Environmental – Disasters, power outages.
Key Terms
● SOC (Security Operations Center): Monitors & protects assets 24/7.
● DevOps: Combines software development + IT operations.
● DevSecOps: Embeds security into DevOps pipeline.
● CIRT/CSIRT/CERT: Incident response teams for managing cyber events.
Control Categories
Category Examples
pg. 2
Cybersecurity Study Guide Midterm 2026: Key
Concepts & Exam Tips Howard Community
College)
🔑 1.0 Security Concepts
What is Information Security?
● Protecting information and systems from unauthorized access, use,
disclosure, disruption, modification, or destruction.
● Goal: ensure Confidentiality, Integrity, and Availability (CIA Triad).
Challenges Security Professionals Face
● Constantly evolving threats (malware, hackers, insider threats).
● Balancing usability vs. security.
● Managing human error (phishing, weak passwords).
● Keeping up with new technologies and compliance requirements.
Proactive Approach to Security
● Continuous monitoring and threat intelligence (SOC).
● Automation and DevSecOps for faster detection and response.
● Security awareness training to reduce human risk.
Integrity vs. Non-Repudiation
● Integrity: Ensures data isn’t changed or corrupted. (Verified by hashing.)
● Non-repudiation: Ensures the sender cannot deny sending data (achieved
with digital signatures).
pg. 1
, CYBERSECURITY STUDY GUIDE MIDTERM 2026: KEY CONCEPTS & EXAM TIPS
CIA Triad Goals
1. Confidentiality – Keep data private (encryption, access controls).
2. Integrity – Ensure accuracy and consistency (hashing, checksums).
3. Availability – Ensure access when needed (redundancy, backups).
Risk Management Components
● Identify assets & threats
● Assess risk (likelihood × impact)
● Mitigate (controls)
● Monitor continuously
● Respond & recover from incidents
Three Types of Threat Agents
1. Internal – Employees, contractors, or insiders.
2. External – Hackers, competitors, criminals.
3. Natural/Environmental – Disasters, power outages.
Key Terms
● SOC (Security Operations Center): Monitors & protects assets 24/7.
● DevOps: Combines software development + IT operations.
● DevSecOps: Embeds security into DevOps pipeline.
● CIRT/CSIRT/CERT: Incident response teams for managing cyber events.
Control Categories
Category Examples
pg. 2