1.0 General Security Concepts Flashcards
(100 cards)
Which type of control would a firewall be classified as?
a) Technical
Security awareness training for employees is an example of which control type?
b) Managerial
Which control type is most likely to be automated?
a) Technical
Which control type is most focused on day-to-day security activities?
c) Operational
A company’s disaster recovery plan would be considered what type of control?
b) Managerial
Biometric access systems are an example of which control type?
d) Physical
Which control type is most likely to be implemented through written policies and procedures?
b) Managerial
Log review and monitoring would typically be classified as what type of control?
c) Operational
Which control type is most focused on overall security strategy and governance?
b) Managerial
A security guard conducting patrols is an example of which control type?
c) Operational
Which control type is most likely to require regular software updates or patches?
a) Technical
Risk assessments are typically considered what type of control?
b) Managerial
Which control type is most prone to human error or inconsistency?
c) Operational
Encryption of data at rest is an example of which control type?
a) Technical
Which control type is most likely to be visible to employees and visitors?
d) Physical
Which type of control is designed to discourage potential attackers from attempting a security breach?
b) Deterrent
An intrusion detection system (IDS) is an example of which type of control?
c) Detective
When a primary control cannot be implemented due to technical limitations, what type of control would be most appropriate?
a) Compensating
Which control type is most closely associated with security policies and procedures?
c) Directive
A firewall is primarily an example of which type of control?
c) Preventive
Incident response plans are best categorized as which type of control?
c) Corrective
Which control type aims to limit damage and restore systems to normal after a security incident?
c) Corrective
Security awareness training programs are primarily examples of which two types of controls?
a) Preventive and Directive
Which control type is most likely to involve psychological elements to influence potential attackers?
b) Deterrent