GCGA Ch. 1 Understanding Security Controls Flashcards

(11 cards)

1
Q

Four security control categories

A

managerial, operational, technical, and physical.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Managerial controls

A

primarily administrative and include items such as risk and vulnerability assessments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Operational controls

A

focused on the day-to-day operations of an organization. They help ensure an organization is complying with its overall security plan. Some examples include security awareness and training, configuration management, and change management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Technical controls

A

use technology to reduce vulnerabilities. Encryption, antivirus software, IDSs, firewalls, and the principle of least privilege are technical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Physical controls

A

any controls that you can physically touch. Some examples are bollards and other barricades, access control vestibules (sometimes called mantraps), lighting, fences, and signs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Six control types

A

preventive, deterrent, detective, corrective, compensating, and directive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Preventive controls

A

attempt to prevent security incidents. Examples include system hardening, user training, guards, change management, and account disablement processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Detective controls

A

attempt to detect when a vulnerability has been exploited. Examples include log monitoring, security information and event management (SIEM) systems, trend analysis, video surveillance systems, and motion detection systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Deterrent controls

A

attempt to prevent incidents by discouraging threats. Examples include locks and guards. Note that these can also be described as preventive controls. The primary difference is that they try to discourage people from trying to exploit a weakness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Corrective controls

A

attempt to reverse the impact of an incident or problem after it has occurred. Examples include backups, system recovery plans, and incident handling processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Compensating controls

A

alternative controls used when it isn’t feasible or possible to use the primary control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly