Security X Flashcards

(24 cards)

1
Q

What does GRC stand for?

A

Governance, Risk, and Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of GRC?

A

To align IT and business objectives, manage risk, and ensure regulatory compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the three lines of defense in GRC?

A

Governance, Risk, and Compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Who responds to risks with policy?

A

Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who verifies that rules are being followed?

A

Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the RACI model used for?

A

Defining roles and responsibilities across processes and teams.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In the RACI model, who owns the result of the task?

A

Accountable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Name two awareness and training topics in security program management.

A

Phishing, Social engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is COBIT used for?

A

IT governance and management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is ITIL focused on?

A

Service delivery and continual improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does NIST CSF provide?

A

Guidance for building resilient cybersecurity programs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the main purpose of GRC tools?

A

To map, automate, track compliance, and manage documentation and monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why is data governance important in dev/test environments?

A

Regulated data must be protected at all stages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the difference between explainable and non-explainable AI?

A

Explainable AI helps humans understand decisions; non-explainable does not.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What regulation applies to healthcare organizations in the U.S.?

A

HIPAA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which regulation governs financial reporting transparency?

17
Q

Name one privacy regulation from the EU.

18
Q

What is PCI DSS?

A

A standard for securing payment card transactions

19
Q

What are DoD STIGs used for?

A

Hardening and securing government systems

20
Q

Why are third-party certifications important?

A

They validate compliance and build credibility

21
Q

Which service provides an external attacker’s view of your system?

A

Penetration Testing

22
Q

What framework should a CISO use for global flexibility and monitoring?

A

NIST Cybersecurity Framework

23
Q

What are three activities in the reconnaissance phase of the kill chain?

A

Discover servers, harvest emails, identify employees on social media

24
Q

Can continuous monitoring replace audits?

A

No, periodic audits are still needed