CISSP Domains Flashcards

1
Q

Which CISSP domain?
-suggest control testing
-Conducts audits

A

Domain 6: security assessment and testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which CISSP domain- separation of duties

A

Domain 3: architecture and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which CISSP domain- adding security input at each step of software development

A

Domain 8: software development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which CISSP domain- intrusion detection and prevention

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which CISSP domain- designs network security controls

A

Domain 4: communication and network security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which CISSP domain- zero trust

A

Domain 3: architecture and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which CISSP domain-threat modeling

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which CISSP domain?
-Threat modeling
-Least privilege
-defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the two responsibilities of the identity and access management domain?

A

-Overseeing access based on position
-deciding when and who has access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which CISSP domain- play Books

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the four responsibilities of the asset security domain?

A

-tracking assets
-Destruction and disposal of assets
-Establishing recovery plans
-Managing data exposure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the two responsibilities of the software development domain?

A

-adding security input at each step of software develop
-Conducting penetration testing by hiring pros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which CISSP domain?
-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security

A

InfoSec in domain 1: security risk, and management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which CISSP domain- tracking assets

A

Domain 2: asset security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which CISSP domain- conducting penetration testing (by hiring professionals)

A

Domain 8: software development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which CISSP domain- suggests control testing

A

Domain 6: security assessment and testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which CISSP domain- training and awareness

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which CISSP domain- vulnerability management

A

InfoSec (under domain 1: security risk, and management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What domain is focused on defining security, goals and objectives risk medication, compliance, business, continuity, and legal regulations?

A

Security and risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the 8 CISSP domains?

A
  1. Security risk and management.
  2. Asset security.
  3. Security architecture and engineering.
  4. Communication and network security.
  5. Identity and access management.
  6. Security assessment and testing.
  7. Security operations.
  8. Software development.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which CISSP domain- reflecting on lessons learned

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which CISSP domain- defense in depth

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which CISSP domain- incident response

A

InfoSec (under domain 1: security risk, and management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which CISSP domain?
-Adding security input at each step of software development
-Conducting penetration testing (by hiring pros)

A

Domain 8: software development

25
Which CISSP domain- -training and awareness -Reporting and documentation -Intrusion detection and prevention -SIEM tools -Log management -play Books -Post breach forensics -Reflecting on lessons learned
Domain 7: security operations
26
Which CISSP domain- trust but verify
Domain 3: security architecture, and engineering
27
Which CISSP domain- compliance
Domain 1: security and risk management
28
Which CISSP domain? -Designing network security controls -Overseeing communication guidelines and controls
Domain 4: communication and network security
29
Which CISSP domain- security goals and objectives
Domain 1: security and risk management
30
Which CISSP domain- SIEM TOOLS
Domain 7: security operations
31
Which CISSP domain- incident management
Domain 7: security operations
32
Which CISSP domain? -Security goals, and objectives -risk mitigation -Compliance -business continuity plans -Local regulations -Professional and organizational ethics
Domain 1: security and risk management
33
Which CISSP domain is InfoSec a part of?
domain 1: security risk, and management
34
Which CISSP domain- managing data exposure
Domain 2: asset security
35
Which CISSP domain- least privilege
Domain 3: security architecture, and engineering
36
Which CISSP domain- establishing recovery plans
Domain 2: asset security
37
Which CISSP domain- legal regulations
Domain 1: security and risk management
38
Which CISSP domain- professional and organizational ethics
Domain 1: security and risk management
39
Which CISSP domain- post breach forensics
Domain 7: security operations
40
Which CISSP domain? -Overseas access based on position -decides when and who has access
Domain 5: identity and access management
41
Which CISSP domain- business continuity plans
Domain 1: security and risk management
42
Which CISSP domain- reporting and documentation
Domain 7: security operations
43
Which CISSP domain? -tracking assets -Asset destruction, and disposal -Establishing recovery plans -Managing data exposure
Domain 2: asset security
44
Which CISSP domain- overseas access based on position
Domain 5: access management
45
Which CISSP domain- risk mitigation processes
Domain 1: security and risk management
46
Which CISSP domain- application security
InfoSec (under domain 1: security risk, and management)
47
Which CISSP domain- decides when and who has access
Domain 5: access management
48
What are the eight responsibilities of the security architecture and engineering domain?
-threat modeling -Least privilege -Defense in depth -Fail securely -Separation of duties -Keep it simple -zero trust -Trust but verify
49
What are the nine responsibilities of the security operations domain?
-training and awareness -Reporting and document -And children, detection and prevention -SIEM tools -Log management -Incident management -play Books -Post breach forensics -Reflecting on lessons learned
50
Which CISSP domain- cloud security
InfoSec (under domain 1: security risk, and management)
51
Which CISSP domain- log management
Domain 7: security operations
52
Which CISSP domain- overseas communication guidelines and controls
Domain 4: communication and network security
53
Which CISSP domain- infrastructure security
InfoSec (under domain 1: security risk, and management)
54
Which CISSP domain- Fail Securely
Domain 3: security architecture, and engineering
55
Which CISSP domain- audits
Domain 6: security assessment and testing
56
What are the two responsibilities of the security assessment and testing domain?
-suggesting control testing -Conducting audits
57
What are the two responsibilities of the communication and network security domain?
-Designing network security controls -Oversee communication guidelines and controls
58
What are the responsibilities of InfoSec part of the first domain?
-incident response -Vulnerability management -Application security -Cloud security -Infrastructure security
59
What are the six responsibilities of the security and risk management domain?
-Security goals, and objectives -risk mitigation -Compliance -business continuity plans -Legal regulations -Professional and organizational ethics