Security Controls Flashcards

Security+

1
Q

What are detective controls used for?

A

To identify and log intrusion attempts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Give an example of a detective control.

A

Collecting and reviewing system logs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the types of assets that security controls protect?

A

Data, physical property, computer systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of preventive controls?

A

To block access to resources and prevent security events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are corrective controls used for?

A

To apply controls after an event has been detected and reverse its impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What type of controls are firewalls and anti-virus systems?

A

Technical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an example of an operational control?

A

Security guards or awareness programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are physical controls designed to do?

A

Limit physical access to assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a compensating control?

A

A control used when existing controls aren’t sufficient.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can ransomware impact be mitigated?

A

By restoring from backups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do directive controls aim to do?

A

Direct subjects towards security compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of deterrent controls?

A

To discourage intrusion attempts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Provide an example of a directive control.

A

Guard shack checks all identification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an example of a preventive control?

A

Implementing firewall rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What can a well-placed warning sign act as?

A

A deterrent control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How do administrative controls contribute to security?

A

Through policies and procedures for security design and implementation.

17
Q

What are security controls?

A

Measures implemented to protect systems and data from threats.

18
Q

Why are security controls categorized?

A

To better manage and implement them based on specific needs and risks.

19
Q

Name one category of security controls.

A

Technical controls.

20
Q

What is an example of a technical control?

A

Firewalls.

21
Q

Can a security control exist in multiple categories?

A

Yes, some controls may fit multiple categories.

22
Q

Why might an organization combine types of security controls?

A

To create a more integrated security approach tailored to their needs.

23
Q

What drives the creation of new security controls?

A

The evolution of systems and processes.

24
Q

Why is it important to regularly update security controls?

A

To address emerging threats and vulnerabilities.

25
What is the difference between administrative and technical controls?
Administrative controls focus on policies and procedures, while technical controls use technology to protect systems.
26
How can an organization's security controls vary?
Based on their specific environment, risks, and regulatory requirements.