NEW
Font size
WorksheetsCNET151 - Chapt 15 -Cybersecurity Engineering
Total questions: 15
Worksheet time: 8mins
The traditional engineering disciplines include mechanical, electrical, civil, and __________.
Computer
Aerospace
Chemical
Nuclear
In the SMART acronym that defines what makes a good requirement for a cybersecurity project, the “A” stands for __________.
Accessible
Applicable
Available
Achievable
__________ is a set of diagrams used to model software.
UML
WBS
SecML
MATLAB
There are __________ categories in the NIST 800-53 Security Control Families.
15
18
20
22
Which domain in the ISO 27001 standard includes controls that protect the network infrastructure and services, as well as the information that travels through them?
A.8: Asset Management
A.10: Cryptography
A.13: Communications Security
A.18: Compliance
Which domain in the ISO 27001 standard includes controls that ensure that the IT systems, including operating systems and software, are secure and protected against data loss?
A.5: Information Security Policies
A.9: Access Control
A.12: Operations Security
A.16: Information Security Incident Management
The ISO 27004 standard is all about __________.
Compliance
Metrics
Continuity
Modeling
The NIST SP 800-63B standard provides guidance for __________.
Authentication
Maintenance
Accountability
Planning
Which standard lists 114 security controls and is one of the most widely accepted cybersecurity standards?
ISO 27001
RMF
ISO 27004
NIST SP 800-63B
__________ is the primary modeling tool used in systems engineering.
MCD
INCOSE
DID
SysML
In the traditional use-case diagram, activities appear as __________.
Stick figures
Lines
Labeled ovals
<
In SysML, a __________ diagram shows how objects interact over time.
Data interface
Sequence
Use-case
Security block
In SecML, the __________ diagram models the flow of data into and out of any system.
Data interface
Sequence
Use-case
Security block
__________ created the acronym STRIDE for identifying security threats in six separate categories: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privileges.
NIST
Microsoft
IEEE
ISO
Which of the following is the first stage of the Process for Attack Simulation and Threat Analysis (PASTA)?
Application decomposition
Threat analysis
Define objectives
Attack modeling
