Font size
WorksheetsSecurity+ Lesson1
Total questions: 12
Worksheet time: 8mins
Your company is developing an application in which a private US-based hospital will allow patients to access their medical records online. Regardless of what other data the application handles, what kind of compliance do you already know you need to research?
FISMA
FERPA
PCI DSS
HIPAA
The US government agency plans to migrate some of its internally hosted data to a cloud-based service. You need to make sure the proposed vendor can meet the same security requirements as the current solution. What are you currently practicing?
Each correct answer represents a complete solution. Choose all that apply.
GDPR compliance
FISMA compliance
Due diligence
Due care
EGLBA compliance
Joe is tuning her organization's firewall rules to prevent IP spoofing. What type of control is Joe implementing?
Technical
Operational
Managerial
Physical
Which of the following controls primarily protect data availability?
Hashing
Patch management
Digital signatures
Version control
Which one of the following statements is not true about compensating controls under PCI DSS?
Use and regularly update antivirus software or programs.
Do not use vendor-supplied defaults for system passwords and other security parameters.
Allow physical access to cardholder data.
Encrypt transmission of cardholder data across open public networks.
A new privacy law demands more robust protection for your customer database. First, you researched database security products to find which would reliably meet your needs. Now that you’ve selected and installed one, you’re currently training administrators to perform integrity checks, update the software, and review logs for suspicious activities. What are you practicing?
Availability
Negligence
Regulatory compliance
Due care
A third-party team is going to formally examine your organization’s overall security practices to make sure they meet regulatory compliance goals. Your organization may be fined if it fails. What would this verification process be called?
Evaluation
Certification
Audit
Assessment
Someone stole thousands of customer records from your organization's database. What aspect of security was primarily attacked?
Availability
Integrity
Confidentiality
Portability
Your internal network is protected from Internet attacks by a Cisco firewall. To improve security, your supervisor suggests installing a Fortinet firewall between the Cisco firewall and the trusted LAN, then using the space between as a perimeter network. Which security principles does this promote?
Each correct answer represents a complete solution. Choose all that apply.
Defense-in-depth
Availability
Vendor diversity
Security by obscurity
Security by design
Which of the following is a US government agency charged with developing and supporting standards used by other government organizations?
W3C
NIST
ISOC
OWASP
Which of the following statements is correct regarding threat vector?
A threat vector refers to the pathway that organization takes to find the attackers.
Malware is a common example of a threat vector.
The mechanism of minimizing vulnerabilities is called a threat vector.
A threat vector is an unintentional threat.
Assuming that all four roles exist separately at your company, who oversees strategic security needs, with a focus on organizational risk management?
CPO
CIO
CCO
CSO
