LO6 Flashcards

(7 cards)

1
Q

What are the different sides of the McCumber Cube?

A

Safeguards
CIA
Asset State

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is CIA?

A

Confidentiality, Integrity and Availability.

Confidentiality - Keeps users data private

Integrity - Assurance the system preserves data

Availability - Assurance users can access resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are safeguards?

A

Policy and Practices - The controls an organisation puts in to ensure people mitigate risks

Human Factors - The training provided by an organisation to avoid risks such as viruses and social engineering tactics

Technology - The software and hardware solutions used to protect systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Asset State?

A

Storage - Most valuable but easiest to protect as is in a hard drive, memory or an external device

Transmission - Data being moved between systems

Processing - The data is currently being used so considered vulnerable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is an attack vector?

A

A path an attacker takes to access an asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Provide an example of an attack vector?

A

Phishing
Code injection
Malware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does STRIDE stand for and what does each letter mean?

A

Spoofing - Pretending to be someone else

Tampering - Changing data in some manner

Repudiation - Hiding your tracks

Information Disclosure - Exposure of users data

Denial of Service - Target service availability i.e setting off a fire alarm to stop an exam

Elevation of Privilege - Finding a method of performing tasks that the user isn’t authorised to do so.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly