Domain 1 (General Security Concepts) Flashcards
Practice Questions unofficial sources (160 cards)
CIA C
Confidentiality
CIA I
Integrity
CIA A
Availability
This protects information and systems from unauthorized access
Confidentiality defintion
This protects information and systems from unauthorized modification
Integrity definition
____ attacks seek to undermine confidentiality
Disclosure
____ attacks seek to undermine integrity
Alteration
This ensures that information and systems are available for authorized users when needed
Availability definition
____ attacks seek to undermine availibility
Denial
Steps of the access control process
Identification, authentication, authorization
When an individual makes a claim about their identity (this could be a true or false claim)
Identification defintion
When an individual proves their identity to the satisfaction of the access control system
Authentication definition
These are procedures and mechanisms that an organization puts in place to manage security risks
Security Controls definition
When multiple controls are used for one objective, the same control objective
Defense in Depth definition
____ controls stops a security issue from occurring in the first place
Preventive
____ controls identifies that a potential security issue has taken place
Detective
____ controls remediates security issues that have already occurred
Corrective
____ controls prevents an attacker from seeking to violate security policies
Deterrent
____ controls informs employees and others what they must do to achieve security objectives
Directive
____ controls fills a known gap in a security environment
Compensating
____ controls use technology to achieve security control objectives
Technical
____ controls use human-driven processes to manage technology in a secure manner
Operational
____ controls improve the security of the risk management process itself
Managerial
____ controls that impact the physical world
Physical