Audits and Assessments Flashcards

1
Q

Internal Audit

A

evaluation of the effectiveneness of internal (controls, complicance, integrity) of systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Internal Audit Focuses (Dp Ns Ac Ir)

A

Data Protection, Network Security, Access Controls, and Incident Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does it mean to be compliant

A

the checkee met standards, regulations, and laws

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Audit Commitee

A

the group responsible for supervising the org’s audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Internal Assessment

A

In-depth analysis to identify/access potential risks and vulnerabilities internally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Self Assessment

A

internal review conducted by an org to gauge adherance to specific standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Minnesota Counties Intergovernmental Trust (MCIT)

A

checklist to help aid/guidline the interal assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

External Audit

A

systematic evaluation carried out by external entities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

External Assessment

A

analysis conducted by independent entities to identify vulnerabilities and risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Regulatory Compliance

A

the objective that orginzations aim to reach in adherance to (laws, policies, and regulations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

System Examination

A

comprehensive security infrastructure inspections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Internal Third-Party Audit

A

offers validation of security pratices and helps give trust to an org (Has to be reputable themselves first)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Physical Penetration Testing

A

testing an org’s physical security such as locks, access cards, security cameras, and other protective measures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Offensive Penetration Testing

A

proactive approach using attack techniques of real cyber threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Defensive Penetration Testing

A

reactive approach that entails fortifying systems, identifying attack space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Integrated Pen Testing

A

Both offensive and defensive pen testing in one

17
Q

Reconnaissance

A

An initial phase where critical information about a target system is gathered to enhance an attack success rate

18
Q

Active Reconnaissance

A

Direct engagement with the target system to pull information

19
Q

Passive Reconnaissance

A

Doesn’t interact with the target system to get information

20
Q

Reconnaissance Environment

A

The targeted infrastructure information known prior to the test

21
Q

Metasploit

A

Computer security and pen-testing frameworks that help evaluate pen testing

22
Q

Reconnaissance Environment Types

A

Known, partially known, and unknown

23
Q

Software Attestation

A

Validating the integrity of software by checking that it hasn’t been tampered with

24
Q

Hardware Attestation

A

Validating the integrity of hardware components

25
System Attestation
Validating the security posture of a system