Domain 2: Asset Security Flashcards

1
Q

Sensitive Data

A

any info that isn’t public or unclassified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

PII

A

Personal Identifiable Information - any info that can be used to distinguish or trace an individuals identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PHI

A

Protected Health Information - any health info that can be related to a specific person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Proprietary Data

A

any data that helps an org maintain a competitive edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

DLP Server

A

Data Loss Prevention Server, emails pass through, detects labels on data or applies necessary security measurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data at Rest

A

data stored on media

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data in Transit

A

data in motion, data transmitted over a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data in use

A

data in temporary storage buffers while an application is using it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Handling

A

secure transportation of media through its lifetime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data Remanence

A

The data that remains on a hard drive as a residual magnetic flux

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to remove data remanence

A

degausser for magnetic media, not SSDs. Use destruction to a size of 2 mm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Erasing

A

deleting files, remains on the drive until space runs out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Clearing

A

prepare media for reuse and assure the cleared data cannot be recovered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Purging

A

more intense form of clearing, repeat clearing or combine with another process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Declassification

A

any process that purges media or a system in preparation for reuse in an unclass environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Sanitization

A

combination of processes that removes data from a system of from media ensuring it cannot be recovered by any means

17
Q

Degaussing

A

create a strong magnetic field that erases data on magnetic media

18
Q

Which protocol do most HTTPS transmissions use?

A

TLS - Transport Layer Security

19
Q

What was the predecessor to TLS?

A

SSL - Secure Sockets Layer but it is susceptible to the POODLE attack

20
Q

What does a VPN use?

A

IPsec combined with L2TP

21
Q

Which protocols would be used to protect data in transit on internal networks?

A

IPsec and SSH (Secure Shell)

22
Q

What are secure protocols used to transfer encrypted files over a network?

A

SCP (Secure Copy) and SFTP (Secure File Transfer Protocol)

23
Q

This person has the ultimate org responsibility for the data

A

data owner - typically CEO

24
Q

This person owns the system that processes sensitive data

A

System Owner

25
This person is usually the PM
Business/Mission Owner
26
Data processor
a natural or legal person which processes personal data solely on behalf of the data controller
27
This person is responsible for granting appropriate access to personnel
Admins
28
This person handles day to day tasks usually assigned by data owner
custodian