| |

LFCA 127 🐧 LFCA Practice Questions — Domain 4

Domain 4, Security Fundamentals, is 14% of the LFCA exam—roughly 8 questions. It covers the concepts that underpin security in modern IT: the CIA triad, authentication and authorization, encryption, firewalls, compliance, and common threats. These are conceptual questions. There are no commands to memorize, no configurations to build. The exam tests whether you understand the vocabulary and the distinctions—authentication versus authorization, symmetric versus asymmetric encryption, encryption at rest versus in transit, and the categories of threats that security controls are designed to address.

This chapter is a set of practice questions in the style of the LFCA exam. Each question presents a scenario and asks for the best answer among four choices. The answers are explained, and the distractors are identified so you can see why the wrong answers are wrong. The questions cover the specific competencies in Domain 4: the CIA triad, authentication and authorization, sensitive data and encryption, compliance, firewalls, and common security threats.

Key point: Domain 4 is about concepts, not tools. It tests whether you can distinguish authentication from authorization, symmetric from asymmetric encryption, and a firewall from an antivirus. The correct answer is the one that matches the definition, not the one that sounds most technical.


Why Domain 4 matters

The universal problem. Security is not a specialty. Every system administrator, every developer, every IT professional needs to understand the basic concepts. The LFCA treats security fundamentals as a core competency because security is everyone’s responsibility. A system that is deployed without security controls is a system that will be compromised.

The vocabulary problem. Security terminology is precise. Authentication is not authorization. Encryption is not hashing. A firewall is not an antivirus. A vulnerability is not a threat. The exam tests whether you can keep these categories distinct. Confusing them leads to controls that do not address the risk they were intended to address.

The CIA problem. The CIA triad—Confidentiality, Integrity, Availability—is the foundation of security thinking. Every control exists to protect one or more of these properties. Confidentiality ensures that data is not disclosed to unauthorized parties. Integrity ensures that data is not modified without detection. Availability ensures that data and systems are accessible when needed. The exam tests whether you can identify which property a control protects.

The threat problem. Security threats are categorized: phishing, malware, ransomware, DDoS, social engineering, insider threats. Each has a characteristic pattern and a characteristic defense. The exam tests whether you can identify the category from a scenario.

The shared responsibility problem. Security is not absolute. It is a trade-off between protection, usability, and cost. The exam tests whether you understand that security controls must be appropriate to the risk, and that no single control is sufficient on its own.


a. The CIA triad, authentication, and authorization

Question 1. A hospital encrypts patient records so that only authorized staff can read them. Which property of the CIA triad does this protect?

A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation

Answer: A. Encryption protects confidentiality by ensuring that data is not disclosed to unauthorized parties. Only staff with the decryption key can read the records. Option B, integrity, protects against unauthorized modification. Option C, availability, ensures the data is accessible when needed. Option D, non-repudiation, prevents a party from denying an action.


Question 2. A system uses checksums to detect whether a file has been modified. Which property of the CIA triad does this protect?

A. Confidentiality
B. Integrity
C. Availability
D. Authentication

Answer: B. Checksums protect integrity by detecting unauthorized modification. If the file changes, the checksum no longer matches, and the system can alert or reject the file. Option A, confidentiality, protects against disclosure. Option C, availability, ensures access. Option D, authentication, verifies identity.


Question 3. A company implements redundant servers and failover so that its website remains accessible during hardware failures. Which property of the CIA triad does this protect?

A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation

Answer: C. Redundancy and failover protect availability by ensuring the system remains accessible even when components fail. Option A protects against disclosure. Option B protects against modification. Option D prevents denial of actions.


Question 4. What is the difference between authentication and authorization?

A. Authentication verifies identity; authorization determines access
B. Authorization verifies identity; authentication determines access
C. Both verify identity
D. Both determine access

Answer: A. Authentication is the process of verifying that a user is who they claim to be—typically through a password, a token, or a biometric. Authorization is the process of determining what that authenticated user is allowed to do. Option B is the reverse. Option C is incorrect—only authentication verifies identity. Option D is incorrect—only authorization determines access.


Question 5. A user logs in with a username and password, and then is prompted for a code from their phone. What is this called?

A. Single sign-on
B. Multi-factor authentication
C. Role-based access control
D. Least privilege

Answer: B. Multi-factor authentication (MFA) requires two or more factors from different categories: something you know (password), something you have (phone), something you are (biometric). The password and the phone code are two different factors. Option A, single sign-on, allows one login to access multiple systems. Option C, role-based access control, assigns permissions based on roles. Option D, least privilege, grants only the access needed to perform a task.


Question 6. An administrator grants a user only the permissions needed to perform their job, and no more. What principle is this?

A. Separation of duties
B. Least privilege
C. Defense in depth
D. Zero trust

Answer: B. The principle of least privilege states that a user should have only the minimum access required to perform their function. Option A, separation of duties, divides critical tasks among multiple people so that no single person can complete a sensitive operation alone. Option C, defense in depth, uses multiple layers of controls. Option D, zero trust, assumes no implicit trust and verifies every access request.


b. Encryption, hashing, and sensitive data

Question 7. Which type of encryption uses the same key for both encryption and decryption?

A. Asymmetric encryption
B. Symmetric encryption
C. Hashing
D. Digital signatures

Answer: B. Symmetric encryption uses a single shared key for both encryption and decryption. It is fast and efficient but requires a secure way to share the key. Option A, asymmetric encryption, uses a public key for encryption and a private key for decryption. Option C, hashing, is a one-way transformation that cannot be reversed. Option D, digital signatures, use asymmetric encryption to verify authenticity.


Question 8. Which type of encryption uses a public key and a private key?

A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Encoding

Answer: B. Asymmetric encryption uses a key pair: a public key that can be shared and a private key that is kept secret. Data encrypted with the public key can only be decrypted with the private key. Option A, symmetric encryption, uses a single shared key. Option C, hashing, is one-way. Option D, encoding, is not encryption—it transforms data for compatibility, not for security.


Question 9. What is the primary purpose of hashing a password before storing it?

A. To encrypt the password so it can be decrypted later
B. To verify the password without storing the original
C. To compress the password to save space
D. To encode the password for transmission

Answer: B. Hashing is a one-way transformation. When a user sets a password, the system stores the hash. When the user logs in, the system hashes the entered password and compares it to the stored hash. The original password is never stored and cannot be recovered from the hash. Option A is incorrect—hashing is not reversible. Option C is incorrect—hashing does not compress. Option D is incorrect—hashing is not encoding.


Question 10. A company encrypts data on its database servers and also encrypts data transmitted over the network. What are these two practices called?

A. Encryption at rest and encryption in transit
B. Symmetric and asymmetric encryption
C. Hashing and salting
D. Authentication and authorization

Answer: A. Encryption at rest protects data stored on disk. Encryption in transit protects data moving over the network. Together they protect data throughout its lifecycle. Option B describes encryption algorithms, not states. Option C describes password storage techniques. Option D describes access control.


c. Firewalls, compliance, and common threats

Question 11. What is the primary function of a firewall?

A. Detect and remove malware
B. Control network traffic based on rules
C. Encrypt data at rest
D. Manage user passwords

Answer: B. A firewall controls network traffic by allowing or blocking packets based on rules. It is a network-layer control. Option A describes antivirus software. Option C describes disk encryption. Option D describes an identity management system.


Question 12. An employee receives an email that appears to be from the IT department, asking them to click a link and enter their password. What type of attack is this?

A. DDoS
B. Phishing
C. Ransomware
D. SQL injection

Answer: B. Phishing is a social engineering attack that impersonates a trusted entity to trick the recipient into revealing credentials or clicking a malicious link. Option A, DDoS, overwhelms a service with traffic. Option C, ransomware, encrypts files and demands payment. Option D, SQL injection, exploits unvalidated input in database queries.


Question 13. A website is overwhelmed with traffic from thousands of compromised devices, making it unavailable to legitimate users. What type of attack is this?

A. Phishing
B. Ransomware
C. DDoS
D. Man-in-the-middle

Answer: C. A Distributed Denial of Service (DDoS) attack uses many sources to flood a target with traffic, exhausting its resources and making it unavailable. Option A, phishing, tricks users into revealing information. Option B, ransomware, encrypts data. Option D, man-in-the-middle, intercepts communications.


Question 14. What does compliance mean in the context of security?

A. Adhering to laws, regulations, and standards
B. Encrypting all data
C. Blocking all network traffic
D. Backing up all systems

Answer: A. Compliance means adhering to external requirements—laws, regulations, industry standards, and contractual obligations. Examples include GDPR for data privacy, HIPAA for health information, and PCI DSS for payment card data. Option B, C, and D are controls that may support compliance but are not compliance itself.


Question 15. What is the purpose of the principle of defense in depth?

A. To use a single strong control
B. To use multiple layers of controls so that no single failure compromises security
C. To eliminate all risk
D. To reduce the cost of security

Answer: B. Defense in depth uses multiple overlapping controls—network security, host security, application security, data security—so that if one control fails, others still protect the system. Option A is the opposite—a single control is a single point of failure. Option C is impossible—risk cannot be eliminated entirely. Option D is not the purpose—defense in depth may increase cost, not reduce it.


Question 16. Which of the following is an example of a social engineering attack?

A. Exploiting a software vulnerability
B. Tricking an employee into revealing a password
C. Flooding a network with traffic
D. Intercepting network communications

Answer: B. Social engineering manipulates people rather than systems. Tricking an employee into revealing a password is a classic example. Option A is a technical attack. Option C is a DDoS attack. Option D is a man-in-the-middle attack.


Question 17. Why is encryption important for data in transit?

A. It prevents data from being modified
B. It prevents data from being read if intercepted
C. It prevents data from being deleted
D. It prevents data from being copied

Answer: B. Encryption in transit protects confidentiality by making the data unreadable to anyone who intercepts it. Option A describes integrity, which is a separate property. Option C describes availability. Option D is not prevented by encryption—data can still be copied, but the copy is unreadable.


Question 18. What is the primary difference between a vulnerability and a threat?

A. A vulnerability is a weakness; a threat is something that can exploit it
B. A threat is a weakness; a vulnerability is something that can exploit it
C. Both are the same thing
D. A vulnerability is external; a threat is internal

Answer: A. A vulnerability is a weakness in a system—an unpatched software bug, a misconfiguration, a weak password. A threat is something that can exploit that weakness—a malicious actor, a piece of malware, a natural disaster. Option B is the reverse. Option C is incorrect. Option D is incorrect—both vulnerabilities and threats can be internal or external.


Complete Example Session

# ============================================
# PART 1: CIA TRIAD
# ============================================
Confidentiality  → encryption, access control
Integrity        → checksums, digital signatures
Availability     → redundancy, failover, backups

# ============================================
# PART 2: AUTHENTICATION AND AUTHORIZATION
# ============================================
Authentication   → verifies identity (password, MFA)
Authorization    → determines access (RBAC, least privilege)

# ============================================
# PART 3: ENCRYPTION
# ============================================
Symmetric        → one shared key
Asymmetric       → public/private key pair
Hashing          → one-way, for passwords
At rest          → data on disk
In transit       → data on network

# ============================================
# PART 4: THREATS
# ============================================
Phishing         → impersonation via email
Ransomware       → encrypts files, demands payment
DDoS             → overwhelms with traffic
Social engineering → manipulates people

The four parts summarized the concepts tested in Domain 4: the CIA triad, authentication and authorization, encryption, and common threats.


Quick Reference

CIA Triad

PropertyDefinitionControls
ConfidentialityData not disclosed to unauthorized partiesEncryption, access control
IntegrityData not modified without detectionChecksums, signatures
AvailabilityData and systems accessible when neededRedundancy, backups

Authentication vs Authorization

AspectAuthenticationAuthorization
QuestionWho are you?What can you do?
HappensFirstAfter authentication
MethodsPassword, MFA, biometricRBAC, ACL, least privilege

Encryption Types

TypeKeysUse Case
SymmetricOne shared keyBulk data encryption
AsymmetricPublic/private pairKey exchange, signatures
HashingNone (one-way)Password storage, integrity

Encryption States

StateProtectsExample
At restData on diskDatabase encryption
In transitData on networkTLS

Common Threats

ThreatDescription
PhishingImpersonation to steal credentials
RansomwareEncrypts files, demands payment
DDoSOverwhelms with traffic
Social engineeringManipulates people
Man-in-the-middleIntercepts communications
SQL injectionExploits unvalidated input

Compliance Frameworks

FrameworkDomain
GDPRData privacy (EU)
HIPAAHealth information (US)
PCI DSSPayment card data
SOC 2Service organization controls

Best Practices

✅ Do This:

# Match the control to the CIA property
Confidentiality → encryption                            # ✅
Integrity       → checksums                             # ✅
Availability    → redundancy                            # ✅

# Distinguish authentication from authorization
Authentication = identity, authorization = access       # ✅

# Distinguish symmetric from asymmetric
Symmetric = one key, asymmetric = key pair              # ✅

# Distinguish encryption from hashing
Encryption = reversible, hashing = one-way              # ✅

# Identify threats by their pattern
Email impersonation → phishing                          # ✅
Traffic flood → DDoS                                    # ✅

❌ Don’t Do This:

# Don't confuse authentication and authorization
Authentication ≠ authorization                          # ❌

# Don't confuse encryption and hashing
Encryption can be reversed; hashing cannot               # ❌

# Don't confuse a vulnerability and a threat
Vulnerability = weakness; threat = exploiter             # ❌

# Don't assume one control is sufficient
Defense in depth is the principle                        # ❌

# Don't confuse at rest and in transit
At rest = disk; in transit = network                     # ❌

Common Pitfalls

PitfallWhy It HappensFix
Confusing auth and authzBoth start with “auth”Auth = identity, authz = access
Confusing encryption and hashingBoth transform dataEncryption = reversible
Confusing vulnerability and threatBoth are security termsVulnerability = weakness
Confusing at rest and in transitBoth are encryptionAt rest = disk, in transit = network
Assuming MFA is two passwordsBoth are “factors”Factors must be different types

Real-World Examples

1. Confidentiality

Encrypting patient records
Only authorized staff can decrypt

2. Integrity

SHA-256 checksum of downloaded file
Compare to published checksum

3. Availability

Load balancer across three web servers
One fails, others continue

4. Authentication

Username + password + TOTP code

5. Authorization

Role: developer
Permissions: read code, write code, no deploy

6. Symmetric Encryption

AES-256 for database encryption

7. Asymmetric Encryption

RSA key pair for TLS handshake

8. Hashing

bcrypt for password storage

9. Phishing

Email pretending to be from IT
Link to fake login page

10. DDoS

Botnet floods web server
Legitimate users cannot connect

Visual

CIA Triad

┌─────────────────────────────────────────────────────────────┐
│  CIA TRIAD                                                  │
│                                                             │
│                    ┌───────────────┐                        │
│                    │Confidentiality│                        │
│                    │               │                        │
│                    │  Encryption   │                        │
│                    │ Access control│                        │
│                    └───────┬───────┘                        │
│                            │                                │
│              ┌─────────────┼─────────────┐                  │
│              │             │             │                  │
│              ▼             ▼             ▼                  │
│      ┌───────────┐  ┌───────────┐  ┌───────────┐            │
│      │ Integrity │  │           │  │Availability│           │
│      │           │  │           │  │            │           │
│      │ Checksums │  │           │  │ Redundancy │           │
│      │ Signatures│  │           │  │ Failover   │           │
│      └───────────┘  └───────────┘  └───────────┘            │
│                                                             │
│  Every security control protects one or more of these.      │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Authentication vs Authorization

┌─────────────────────────────────────────────────────────────┐
│  AUTHENTICATION                                             │
│                                                             │
│  "Who are you?"                                             │
│                                                             │
│  ┌─────────────────────────────────────────────────────┐    │
│  │  Username + password                                │    │
│  │  + TOTP code                                        │    │
│  │  → Verified: this is jsmith                         │    │
│  └─────────────────────────────────────────────────────┘    │
│                                                             │
│  Happens first.                                             │
│                                                             │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  AUTHORIZATION                                              │
│                                                             │
│  "What can jsmith do?"                                      │
│                                                             │
│  ┌─────────────────────────────────────────────────────┐    │
│  │  Role: developer                                    │    │
│  │  Permissions: read code, write code                 │    │
│  │  Denied: deploy, access production                  │    │
│  └─────────────────────────────────────────────────────┘    │
│                                                             │
│  Happens after authentication.                              │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Encryption Types

┌─────────────────────────────────────────────────────────────┐
│  SYMMETRIC ENCRYPTION                                       │
│                                                             │
│  ┌─────────┐                  ┌─────────┐                   │
│  │ Plain   │ ──[key]──▶       │ Cipher  │                   │
│  │ text    │                  │ text    │                   │
│  └─────────┘                  └─────────┘                   │
│                                                             │
│  Same key encrypts and decrypts.                            │
│  Fast. Requires secure key sharing.                         │
│  Example: AES                                               │
│                                                             │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  ASYMMETRIC ENCRYPTION                                      │
│                                                             │
│  ┌─────────┐                  ┌─────────┐                   │
│  │ Plain   │ ──[public]──▶    │ Cipher  │                   │
│  │ text    │                  │ text    │                   │
│  └─────────┘                  └─────────┘                   │
│                                                             │
│  ┌─────────┐                  ┌─────────┐                   │
│  │ Cipher  │ ──[private]──▶   │ Plain   │                   │
│  │ text    │                  │ text    │                   │
│  └─────────┘                  └─────────┘                   │
│                                                             │
│  Public key encrypts; private key decrypts.                 │
│  Slower. Solves key distribution.                           │
│  Example: RSA                                               │
│                                                             │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  HASHING                                                    │
│                                                             │
│  ┌─────────┐                  ┌─────────┐                   │
│  │ Input   │ ──[hash]──▶      │ Digest  │                   │
│  └─────────┘                  └─────────┘                   │
│                                                             │
│  One-way. Cannot be reversed.                               │
│  Used for password storage and integrity.                   │
│  Example: SHA-256, bcrypt                                   │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Threat Categories

┌─────────────────────────────────────────────────────────────┐
│  THREAT CATEGORIES                                          │
│                                                             │
│  SOCIAL ENGINEERING                                         │
│  ├── Phishing: email impersonation                          │
│  ├── Vishing: voice call impersonation                      │
│  └── Pretexting: fabricated scenario                        │
│                                                             │
│  MALWARE                                                    │
│  ├── Ransomware: encrypts files, demands payment            │
│  ├── Trojan: disguised as legitimate software               │
│  ├── Worm: self-replicating                                 │
│  └── Spyware: collects information                          │
│                                                             │
│  NETWORK ATTACKS                                            │
│  ├── DDoS: overwhelms with traffic                          │
│  ├── Man-in-the-middle: intercepts communications           │
│  └── DNS spoofing: redirects to malicious site              │
│                                                             │
│  APPLICATION ATTACKS                                        │
│  ├── SQL injection: exploits unvalidated input              │
│  ├── XSS: injects script into web pages                     │
│  └── Buffer overflow: overwrites memory                     │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Summary

TopicKey Distinction
ConfidentialityEncryption, access control
IntegrityChecksums, signatures
AvailabilityRedundancy, failover
AuthenticationVerifies identity
AuthorizationDetermines access
MFATwo or more factor types
Least privilegeMinimum access
SymmetricOne shared key
AsymmetricPublic/private key pair
HashingOne-way transformation
At restData on disk
In transitData on network
FirewallControls network traffic
PhishingEmail impersonation
DDoSTraffic flood
RansomwareEncrypts files

Key takeaways:

  • The CIA triad is the foundation. Confidentiality protects against disclosure. Integrity protects against modification. Availability protects against disruption. Every control exists to protect one or more of these properties.
  • Authentication and authorization are different. Authentication verifies identity. Authorization determines access. Authentication happens first; authorization happens after.
  • MFA requires different factor types. Something you know, something you have, something you are. Two passwords are not MFA. A password and a phone code are.
  • Symmetric encryption uses one key; asymmetric uses a pair. Symmetric is fast and used for bulk data. Asymmetric is slower and used for key exchange and signatures.
  • Hashing is one-way. It cannot be reversed. It is used for password storage and integrity checking, not for encryption.
  • Encryption at rest protects data on disk; encryption in transit protects data on the network. Both are necessary for comprehensive data protection.
  • A firewall controls network traffic; an antivirus detects malware. They are different controls addressing different threats.
  • Threats have patterns. Phishing impersonates. DDoS floods. Ransomware encrypts. Social engineering manipulates. Identifying the pattern identifies the threat.

Remember: Domain 4 is conceptual. It tests whether you understand the vocabulary of security and can apply it to scenarios. The questions ask you to identify which CIA property a control protects, whether a scenario describes authentication or authorization, which type of encryption is being used, or what category of threat is being described. If you know the definitions and can distinguish the categories, the domain is straightforward. Security is not about memorizing tools; it is about understanding the principles that tools implement.



Stop using slow, ad-bloated tool sites! 🤮

🔎 Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
✅ Finance (Mortgage, Interest, Inflation)
✅ Tech (Base64, JSON, Dev Suite, IP)
✅ Health (BMI, BMR, TDEE)
✅ Productivity (Timer, Workspace, QR)

⚡️ Fast & Private
🔒 No data leaves your device
💎 100% Free

🔗 Use it now: https://tools.kandz.me
🔖 Bookmark it—you’ll need it later!