Lesson 1 - Security Roles and Controls Flashcards

1
Q

What is the CIA triad?

A

Confidentiality, Integrity, and Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the NIST Cybersecurity Framework?

A

Identify, Protect, Detect, Respond, Recover

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of the Security Operations Center (SOC)?

A

This is where security professionals monitor and protect critical information assets across other business functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which security related phrase relates to the integrity of data?

A

Modification - Any modification is authorized and is stored and transferred as intended when referring to the integrity of data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How might the goals of basic network management not align with the goals of security?

A

Management focuses on availability over confidentiality.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Any external responsibility for an organization’s security lies mainly with which individuals?

A

The senior executives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The NIST provides a framework that classifies security-related functions. Which description aligns with the “respond” function?

A

Identify, analyze, and eradicate threats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The ________ requires federal agencies to develop security policies for computer systems that process confidential information.

A

Computer Security Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

After a poorly handled security breach, a company updates its security policy to include an improved incident response plan. Which of the following security controls does this update address?

A

Corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which of the following has a cyber security framework (CSF) that focuses exclusively on IT security rather than IT service provisioning?

A

National Institute of Standards and Technology (NIST)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly