LFCA 127 🐧 LFCA Practice Questions — Domain 4
Domain 4, Security Fundamentals, is 14% of the LFCA exam—roughly 8 questions. It covers the concepts that underpin security in modern IT: the CIA triad, authentication and authorization, encryption, firewalls, compliance, and common threats. These are conceptual questions. There are no commands to memorize, no configurations to build. The exam tests whether you understand the vocabulary and the distinctions—authentication versus authorization, symmetric versus asymmetric encryption, encryption at rest versus in transit, and the categories of threats that security controls are designed to address.
This chapter is a set of practice questions in the style of the LFCA exam. Each question presents a scenario and asks for the best answer among four choices. The answers are explained, and the distractors are identified so you can see why the wrong answers are wrong. The questions cover the specific competencies in Domain 4: the CIA triad, authentication and authorization, sensitive data and encryption, compliance, firewalls, and common security threats.
Key point: Domain 4 is about concepts, not tools. It tests whether you can distinguish authentication from authorization, symmetric from asymmetric encryption, and a firewall from an antivirus. The correct answer is the one that matches the definition, not the one that sounds most technical.
Why Domain 4 matters
The universal problem. Security is not a specialty. Every system administrator, every developer, every IT professional needs to understand the basic concepts. The LFCA treats security fundamentals as a core competency because security is everyone’s responsibility. A system that is deployed without security controls is a system that will be compromised.
The vocabulary problem. Security terminology is precise. Authentication is not authorization. Encryption is not hashing. A firewall is not an antivirus. A vulnerability is not a threat. The exam tests whether you can keep these categories distinct. Confusing them leads to controls that do not address the risk they were intended to address.
The CIA problem. The CIA triad—Confidentiality, Integrity, Availability—is the foundation of security thinking. Every control exists to protect one or more of these properties. Confidentiality ensures that data is not disclosed to unauthorized parties. Integrity ensures that data is not modified without detection. Availability ensures that data and systems are accessible when needed. The exam tests whether you can identify which property a control protects.
The threat problem. Security threats are categorized: phishing, malware, ransomware, DDoS, social engineering, insider threats. Each has a characteristic pattern and a characteristic defense. The exam tests whether you can identify the category from a scenario.
The shared responsibility problem. Security is not absolute. It is a trade-off between protection, usability, and cost. The exam tests whether you understand that security controls must be appropriate to the risk, and that no single control is sufficient on its own.
a. The CIA triad, authentication, and authorization
Question 1. A hospital encrypts patient records so that only authorized staff can read them. Which property of the CIA triad does this protect?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: A. Encryption protects confidentiality by ensuring that data is not disclosed to unauthorized parties. Only staff with the decryption key can read the records. Option B, integrity, protects against unauthorized modification. Option C, availability, ensures the data is accessible when needed. Option D, non-repudiation, prevents a party from denying an action.
Question 2. A system uses checksums to detect whether a file has been modified. Which property of the CIA triad does this protect?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication
Answer: B. Checksums protect integrity by detecting unauthorized modification. If the file changes, the checksum no longer matches, and the system can alert or reject the file. Option A, confidentiality, protects against disclosure. Option C, availability, ensures access. Option D, authentication, verifies identity.
Question 3. A company implements redundant servers and failover so that its website remains accessible during hardware failures. Which property of the CIA triad does this protect?
A. Confidentiality
B. Integrity
C. Availability
D. Non-repudiation
Answer: C. Redundancy and failover protect availability by ensuring the system remains accessible even when components fail. Option A protects against disclosure. Option B protects against modification. Option D prevents denial of actions.
Question 4. What is the difference between authentication and authorization?
A. Authentication verifies identity; authorization determines access
B. Authorization verifies identity; authentication determines access
C. Both verify identity
D. Both determine access
Answer: A. Authentication is the process of verifying that a user is who they claim to be—typically through a password, a token, or a biometric. Authorization is the process of determining what that authenticated user is allowed to do. Option B is the reverse. Option C is incorrect—only authentication verifies identity. Option D is incorrect—only authorization determines access.
Question 5. A user logs in with a username and password, and then is prompted for a code from their phone. What is this called?
A. Single sign-on
B. Multi-factor authentication
C. Role-based access control
D. Least privilege
Answer: B. Multi-factor authentication (MFA) requires two or more factors from different categories: something you know (password), something you have (phone), something you are (biometric). The password and the phone code are two different factors. Option A, single sign-on, allows one login to access multiple systems. Option C, role-based access control, assigns permissions based on roles. Option D, least privilege, grants only the access needed to perform a task.
Question 6. An administrator grants a user only the permissions needed to perform their job, and no more. What principle is this?
A. Separation of duties
B. Least privilege
C. Defense in depth
D. Zero trust
Answer: B. The principle of least privilege states that a user should have only the minimum access required to perform their function. Option A, separation of duties, divides critical tasks among multiple people so that no single person can complete a sensitive operation alone. Option C, defense in depth, uses multiple layers of controls. Option D, zero trust, assumes no implicit trust and verifies every access request.
b. Encryption, hashing, and sensitive data
Question 7. Which type of encryption uses the same key for both encryption and decryption?
A. Asymmetric encryption
B. Symmetric encryption
C. Hashing
D. Digital signatures
Answer: B. Symmetric encryption uses a single shared key for both encryption and decryption. It is fast and efficient but requires a secure way to share the key. Option A, asymmetric encryption, uses a public key for encryption and a private key for decryption. Option C, hashing, is a one-way transformation that cannot be reversed. Option D, digital signatures, use asymmetric encryption to verify authenticity.
Question 8. Which type of encryption uses a public key and a private key?
A. Symmetric encryption
B. Asymmetric encryption
C. Hashing
D. Encoding
Answer: B. Asymmetric encryption uses a key pair: a public key that can be shared and a private key that is kept secret. Data encrypted with the public key can only be decrypted with the private key. Option A, symmetric encryption, uses a single shared key. Option C, hashing, is one-way. Option D, encoding, is not encryption—it transforms data for compatibility, not for security.
Question 9. What is the primary purpose of hashing a password before storing it?
A. To encrypt the password so it can be decrypted later
B. To verify the password without storing the original
C. To compress the password to save space
D. To encode the password for transmission
Answer: B. Hashing is a one-way transformation. When a user sets a password, the system stores the hash. When the user logs in, the system hashes the entered password and compares it to the stored hash. The original password is never stored and cannot be recovered from the hash. Option A is incorrect—hashing is not reversible. Option C is incorrect—hashing does not compress. Option D is incorrect—hashing is not encoding.
Question 10. A company encrypts data on its database servers and also encrypts data transmitted over the network. What are these two practices called?
A. Encryption at rest and encryption in transit
B. Symmetric and asymmetric encryption
C. Hashing and salting
D. Authentication and authorization
Answer: A. Encryption at rest protects data stored on disk. Encryption in transit protects data moving over the network. Together they protect data throughout its lifecycle. Option B describes encryption algorithms, not states. Option C describes password storage techniques. Option D describes access control.
c. Firewalls, compliance, and common threats
Question 11. What is the primary function of a firewall?
A. Detect and remove malware
B. Control network traffic based on rules
C. Encrypt data at rest
D. Manage user passwords
Answer: B. A firewall controls network traffic by allowing or blocking packets based on rules. It is a network-layer control. Option A describes antivirus software. Option C describes disk encryption. Option D describes an identity management system.
Question 12. An employee receives an email that appears to be from the IT department, asking them to click a link and enter their password. What type of attack is this?
A. DDoS
B. Phishing
C. Ransomware
D. SQL injection
Answer: B. Phishing is a social engineering attack that impersonates a trusted entity to trick the recipient into revealing credentials or clicking a malicious link. Option A, DDoS, overwhelms a service with traffic. Option C, ransomware, encrypts files and demands payment. Option D, SQL injection, exploits unvalidated input in database queries.
Question 13. A website is overwhelmed with traffic from thousands of compromised devices, making it unavailable to legitimate users. What type of attack is this?
A. Phishing
B. Ransomware
C. DDoS
D. Man-in-the-middle
Answer: C. A Distributed Denial of Service (DDoS) attack uses many sources to flood a target with traffic, exhausting its resources and making it unavailable. Option A, phishing, tricks users into revealing information. Option B, ransomware, encrypts data. Option D, man-in-the-middle, intercepts communications.
Question 14. What does compliance mean in the context of security?
A. Adhering to laws, regulations, and standards
B. Encrypting all data
C. Blocking all network traffic
D. Backing up all systems
Answer: A. Compliance means adhering to external requirements—laws, regulations, industry standards, and contractual obligations. Examples include GDPR for data privacy, HIPAA for health information, and PCI DSS for payment card data. Option B, C, and D are controls that may support compliance but are not compliance itself.
Question 15. What is the purpose of the principle of defense in depth?
A. To use a single strong control
B. To use multiple layers of controls so that no single failure compromises security
C. To eliminate all risk
D. To reduce the cost of security
Answer: B. Defense in depth uses multiple overlapping controls—network security, host security, application security, data security—so that if one control fails, others still protect the system. Option A is the opposite—a single control is a single point of failure. Option C is impossible—risk cannot be eliminated entirely. Option D is not the purpose—defense in depth may increase cost, not reduce it.
Question 16. Which of the following is an example of a social engineering attack?
A. Exploiting a software vulnerability
B. Tricking an employee into revealing a password
C. Flooding a network with traffic
D. Intercepting network communications
Answer: B. Social engineering manipulates people rather than systems. Tricking an employee into revealing a password is a classic example. Option A is a technical attack. Option C is a DDoS attack. Option D is a man-in-the-middle attack.
Question 17. Why is encryption important for data in transit?
A. It prevents data from being modified
B. It prevents data from being read if intercepted
C. It prevents data from being deleted
D. It prevents data from being copied
Answer: B. Encryption in transit protects confidentiality by making the data unreadable to anyone who intercepts it. Option A describes integrity, which is a separate property. Option C describes availability. Option D is not prevented by encryption—data can still be copied, but the copy is unreadable.
Question 18. What is the primary difference between a vulnerability and a threat?
A. A vulnerability is a weakness; a threat is something that can exploit it
B. A threat is a weakness; a vulnerability is something that can exploit it
C. Both are the same thing
D. A vulnerability is external; a threat is internal
Answer: A. A vulnerability is a weakness in a system—an unpatched software bug, a misconfiguration, a weak password. A threat is something that can exploit that weakness—a malicious actor, a piece of malware, a natural disaster. Option B is the reverse. Option C is incorrect. Option D is incorrect—both vulnerabilities and threats can be internal or external.
Complete Example Session
# ============================================
# PART 1: CIA TRIAD
# ============================================
Confidentiality → encryption, access control
Integrity → checksums, digital signatures
Availability → redundancy, failover, backups
# ============================================
# PART 2: AUTHENTICATION AND AUTHORIZATION
# ============================================
Authentication → verifies identity (password, MFA)
Authorization → determines access (RBAC, least privilege)
# ============================================
# PART 3: ENCRYPTION
# ============================================
Symmetric → one shared key
Asymmetric → public/private key pair
Hashing → one-way, for passwords
At rest → data on disk
In transit → data on network
# ============================================
# PART 4: THREATS
# ============================================
Phishing → impersonation via email
Ransomware → encrypts files, demands payment
DDoS → overwhelms with traffic
Social engineering → manipulates people
The four parts summarized the concepts tested in Domain 4: the CIA triad, authentication and authorization, encryption, and common threats.
Quick Reference
CIA Triad
| Property | Definition | Controls |
|---|---|---|
| Confidentiality | Data not disclosed to unauthorized parties | Encryption, access control |
| Integrity | Data not modified without detection | Checksums, signatures |
| Availability | Data and systems accessible when needed | Redundancy, backups |
Authentication vs Authorization
| Aspect | Authentication | Authorization |
|---|---|---|
| Question | Who are you? | What can you do? |
| Happens | First | After authentication |
| Methods | Password, MFA, biometric | RBAC, ACL, least privilege |
Encryption Types
| Type | Keys | Use Case |
|---|---|---|
| Symmetric | One shared key | Bulk data encryption |
| Asymmetric | Public/private pair | Key exchange, signatures |
| Hashing | None (one-way) | Password storage, integrity |
Encryption States
| State | Protects | Example |
|---|---|---|
| At rest | Data on disk | Database encryption |
| In transit | Data on network | TLS |
Common Threats
| Threat | Description |
|---|---|
| Phishing | Impersonation to steal credentials |
| Ransomware | Encrypts files, demands payment |
| DDoS | Overwhelms with traffic |
| Social engineering | Manipulates people |
| Man-in-the-middle | Intercepts communications |
| SQL injection | Exploits unvalidated input |
Compliance Frameworks
| Framework | Domain |
|---|---|
| GDPR | Data privacy (EU) |
| HIPAA | Health information (US) |
| PCI DSS | Payment card data |
| SOC 2 | Service organization controls |
Best Practices
✅ Do This:
# Match the control to the CIA property
Confidentiality → encryption # ✅
Integrity → checksums # ✅
Availability → redundancy # ✅
# Distinguish authentication from authorization
Authentication = identity, authorization = access # ✅
# Distinguish symmetric from asymmetric
Symmetric = one key, asymmetric = key pair # ✅
# Distinguish encryption from hashing
Encryption = reversible, hashing = one-way # ✅
# Identify threats by their pattern
Email impersonation → phishing # ✅
Traffic flood → DDoS # ✅
❌ Don’t Do This:
# Don't confuse authentication and authorization
Authentication ≠ authorization # ❌
# Don't confuse encryption and hashing
Encryption can be reversed; hashing cannot # ❌
# Don't confuse a vulnerability and a threat
Vulnerability = weakness; threat = exploiter # ❌
# Don't assume one control is sufficient
Defense in depth is the principle # ❌
# Don't confuse at rest and in transit
At rest = disk; in transit = network # ❌
Common Pitfalls
| Pitfall | Why It Happens | Fix |
|---|---|---|
| Confusing auth and authz | Both start with “auth” | Auth = identity, authz = access |
| Confusing encryption and hashing | Both transform data | Encryption = reversible |
| Confusing vulnerability and threat | Both are security terms | Vulnerability = weakness |
| Confusing at rest and in transit | Both are encryption | At rest = disk, in transit = network |
| Assuming MFA is two passwords | Both are “factors” | Factors must be different types |
Real-World Examples
1. Confidentiality
Encrypting patient records
Only authorized staff can decrypt
2. Integrity
SHA-256 checksum of downloaded file
Compare to published checksum
3. Availability
Load balancer across three web servers
One fails, others continue
4. Authentication
Username + password + TOTP code
5. Authorization
Role: developer
Permissions: read code, write code, no deploy
6. Symmetric Encryption
AES-256 for database encryption
7. Asymmetric Encryption
RSA key pair for TLS handshake
8. Hashing
bcrypt for password storage
9. Phishing
Email pretending to be from IT
Link to fake login page
10. DDoS
Botnet floods web server
Legitimate users cannot connect
Visual
CIA Triad
┌─────────────────────────────────────────────────────────────┐
│ CIA TRIAD │
│ │
│ ┌───────────────┐ │
│ │Confidentiality│ │
│ │ │ │
│ │ Encryption │ │
│ │ Access control│ │
│ └───────┬───────┘ │
│ │ │
│ ┌─────────────┼─────────────┐ │
│ │ │ │ │
│ ▼ ▼ ▼ │
│ ┌───────────┐ ┌───────────┐ ┌───────────┐ │
│ │ Integrity │ │ │ │Availability│ │
│ │ │ │ │ │ │ │
│ │ Checksums │ │ │ │ Redundancy │ │
│ │ Signatures│ │ │ │ Failover │ │
│ └───────────┘ └───────────┘ └───────────┘ │
│ │
│ Every security control protects one or more of these. │
│ │
└─────────────────────────────────────────────────────────────┘
Authentication vs Authorization
┌─────────────────────────────────────────────────────────────┐
│ AUTHENTICATION │
│ │
│ "Who are you?" │
│ │
│ ┌─────────────────────────────────────────────────────┐ │
│ │ Username + password │ │
│ │ + TOTP code │ │
│ │ → Verified: this is jsmith │ │
│ └─────────────────────────────────────────────────────┘ │
│ │
│ Happens first. │
│ │
├─────────────────────────────────────────────────────────────┤
│ │
│ AUTHORIZATION │
│ │
│ "What can jsmith do?" │
│ │
│ ┌─────────────────────────────────────────────────────┐ │
│ │ Role: developer │ │
│ │ Permissions: read code, write code │ │
│ │ Denied: deploy, access production │ │
│ └─────────────────────────────────────────────────────┘ │
│ │
│ Happens after authentication. │
│ │
└─────────────────────────────────────────────────────────────┘
Encryption Types
┌─────────────────────────────────────────────────────────────┐
│ SYMMETRIC ENCRYPTION │
│ │
│ ┌─────────┐ ┌─────────┐ │
│ │ Plain │ ──[key]──▶ │ Cipher │ │
│ │ text │ │ text │ │
│ └─────────┘ └─────────┘ │
│ │
│ Same key encrypts and decrypts. │
│ Fast. Requires secure key sharing. │
│ Example: AES │
│ │
├─────────────────────────────────────────────────────────────┤
│ │
│ ASYMMETRIC ENCRYPTION │
│ │
│ ┌─────────┐ ┌─────────┐ │
│ │ Plain │ ──[public]──▶ │ Cipher │ │
│ │ text │ │ text │ │
│ └─────────┘ └─────────┘ │
│ │
│ ┌─────────┐ ┌─────────┐ │
│ │ Cipher │ ──[private]──▶ │ Plain │ │
│ │ text │ │ text │ │
│ └─────────┘ └─────────┘ │
│ │
│ Public key encrypts; private key decrypts. │
│ Slower. Solves key distribution. │
│ Example: RSA │
│ │
├─────────────────────────────────────────────────────────────┤
│ │
│ HASHING │
│ │
│ ┌─────────┐ ┌─────────┐ │
│ │ Input │ ──[hash]──▶ │ Digest │ │
│ └─────────┘ └─────────┘ │
│ │
│ One-way. Cannot be reversed. │
│ Used for password storage and integrity. │
│ Example: SHA-256, bcrypt │
│ │
└─────────────────────────────────────────────────────────────┘
Threat Categories
┌─────────────────────────────────────────────────────────────┐
│ THREAT CATEGORIES │
│ │
│ SOCIAL ENGINEERING │
│ ├── Phishing: email impersonation │
│ ├── Vishing: voice call impersonation │
│ └── Pretexting: fabricated scenario │
│ │
│ MALWARE │
│ ├── Ransomware: encrypts files, demands payment │
│ ├── Trojan: disguised as legitimate software │
│ ├── Worm: self-replicating │
│ └── Spyware: collects information │
│ │
│ NETWORK ATTACKS │
│ ├── DDoS: overwhelms with traffic │
│ ├── Man-in-the-middle: intercepts communications │
│ └── DNS spoofing: redirects to malicious site │
│ │
│ APPLICATION ATTACKS │
│ ├── SQL injection: exploits unvalidated input │
│ ├── XSS: injects script into web pages │
│ └── Buffer overflow: overwrites memory │
│ │
└─────────────────────────────────────────────────────────────┘
Summary
| Topic | Key Distinction |
|---|---|
| Confidentiality | Encryption, access control |
| Integrity | Checksums, signatures |
| Availability | Redundancy, failover |
| Authentication | Verifies identity |
| Authorization | Determines access |
| MFA | Two or more factor types |
| Least privilege | Minimum access |
| Symmetric | One shared key |
| Asymmetric | Public/private key pair |
| Hashing | One-way transformation |
| At rest | Data on disk |
| In transit | Data on network |
| Firewall | Controls network traffic |
| Phishing | Email impersonation |
| DDoS | Traffic flood |
| Ransomware | Encrypts files |
Key takeaways:
- The CIA triad is the foundation. Confidentiality protects against disclosure. Integrity protects against modification. Availability protects against disruption. Every control exists to protect one or more of these properties.
- Authentication and authorization are different. Authentication verifies identity. Authorization determines access. Authentication happens first; authorization happens after.
- MFA requires different factor types. Something you know, something you have, something you are. Two passwords are not MFA. A password and a phone code are.
- Symmetric encryption uses one key; asymmetric uses a pair. Symmetric is fast and used for bulk data. Asymmetric is slower and used for key exchange and signatures.
- Hashing is one-way. It cannot be reversed. It is used for password storage and integrity checking, not for encryption.
- Encryption at rest protects data on disk; encryption in transit protects data on the network. Both are necessary for comprehensive data protection.
- A firewall controls network traffic; an antivirus detects malware. They are different controls addressing different threats.
- Threats have patterns. Phishing impersonates. DDoS floods. Ransomware encrypts. Social engineering manipulates. Identifying the pattern identifies the threat.
Remember: Domain 4 is conceptual. It tests whether you understand the vocabulary of security and can apply it to scenarios. The questions ask you to identify which CIA property a control protects, whether a scenario describes authentication or authorization, which type of encryption is being used, or what category of threat is being described. If you know the definitions and can distinguish the categories, the domain is straightforward. Security is not about memorizing tools; it is about understanding the principles that tools implement.
Stop using slow, ad-bloated tool sites! 🤮
🔎 Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
✅ Finance (Mortgage, Interest, Inflation)
✅ Tech (Base64, JSON, Dev Suite, IP)
✅ Health (BMI, BMR, TDEE)
✅ Productivity (Timer, Workspace, QR)
⚡️ Fast & Private
🔒 No data leaves your device
💎 100% Free
🔗 Use it now: https://tools.kandz.me
🔖 Bookmark it—you’ll need it later!