Domain 3 Flashcards

1
Q

IRM

A

Information Risk Management. Risks and threats identified. Vulnerabilities reduced and controls implemented.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Exposure factor

A

Estimated percentage of loss should a threat exploit the vulnerability in an asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SLE Calculation

A

SLE= Asset Value x EF (%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Threat action/Threat agent

A

Actual threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Threat vector

A

Path a threat takes to cause an action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO 27005

A

Information Risk Management framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

NIST 800-37 rev 1

A

Risk management framework for federal info systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ALE calc

A

ALE=SLE x ARO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ARO expressed as…

A

Percentage betwen 0.0 and 1.0

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Analysis vs. Assessment

A

Perform an analysis. Results of analysis enable you to make an assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

NIST 800-30

A

Guide for conducting risk assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk treatment plan

A

Determine who is responsible for controls with time frame and budget

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

MIB

A

SNMP Management information Base. Resides on the device and contains info about it. Responds to SNMP agent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SNMP Agent

A

SNMP responder on the device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Passive monitoring

A

Capture traffic on a device using span/mirror port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Active monitoring

A

Special packets introduced to network to monitor perf.

17
Q

Real time monitoring

A

Devices like IPS.