Font size
WorksheetsSecurity Principles Module 1-5
Total questions: 142
Worksheet time: 2hrs 21mins
Protect society and infrastructure
Canon 1
Canon 2
Canon 3
Canon 4
ISC2 members are required to report breaches of the Code of Ethics to ISC2 for investigation
True
False
Advance the information security profession
Canon 1
Canon 2
Canon 3
Canon 4
Serve principals diligently and competently
Canon 1
Canon 2
Canon 3
Canon 4
Act honorably
Canon 1
Canon 2
Canon 3
Canon 4
You must have (a) to file a complaint.
(a) may file a complaint under Canon 1 and 2
Employers or (a) may file a complaint under Canon 3
(a) may file a complaint under Canon 4
Protects information from unauthorized changes
Integrity
Confidentiality
Availability
Protects information from unauthorized disclosure
Integrity
Confidentiality
Availability
Protects authorized access to systems and data
Integrity
Confidentiality
Availability
Confidentiality Concern:
Snooping
Dumpster Diving
Eavesdropping
Wiretapping Social
Social Engineering
Unauthorized modifications
Impersonation
Man-in-the-middle (MITM)
Replay
Denial of Service (DoS)
Power outages
Hardware failures
Destruction
Service outages
Protecting our own data
Educating our users
Protecting data collected by our organization
Involves gathering information that is left out in the open
Snooping
Dumpster Diving
Eavesdropping
Wiretapping
Social Engineering
Shredding protects against (a)
Rules about sensitive conversations prevent...
Snooping
Dumpster Diving
Eavesdropping
Wiretapping
Social Engineering
Encryption protects against (a)
Education protects against (a)
Integrity Concerns:
Unauthorized modifications
Impersonation
Man-in-the-middle (MITM)
Replay
Snooping
Dumpster Diving
Eavesdropping
Wiretapping
Social Engineering
Denial of Service (DoS)
Power outages
Hardware failures
Destruction
Service outages
Protecting our own data
Educating our users
Protecting data collected by our organizations
What attack make without permission
Unauthorized modification
Attack
Impersonation Attack
Man-in-the-middle Attack
Replay Attack
What attack pretend to be someone else
Impersonation Attack
Unauthorized modification Attack
Man-in-the-middle Attack
Replay Attack
What attack place the attacker in the middle of a communications
Man-in-the-middle Attack
Replay Attack
Impersonation Attack
Unauthorized modification Attack
What attack eavesdrop on logins and reuse the captured credentials
Replay Attack
Man-in-the-middle Attack
Impersonation Attack
Unauthorized modification
Attack
Least privileged protects against (a)
User education protects against (a) attacks
Encryption protects against ____ and ____
(a)
Protects authorized access to systems and data
Availability
Integrity
Confidentiality
Availability Concerns:
Denial of Service (DoS)
Power outages
Hardware failures
Destruction
Service outages
Protecting our own data
Educating our users
Protecting data collected by our organizations
Dumpster Diving
Eavesdropping
Wiretapping
Social Engineering
Unauthorized modifications
Impersonation
Man-in-the-middle (MITM)
Replay
Both unauthorized connections to protect against (a) attacks
Redundant power and generators protect against (a) outages
Redundant components protect against (a) failure
Backup data centers protect against (a)
Resilient systems protect against (a) outage
Involves making a claim of identity
Identification
Authentication
Authorization
Accounting
Electronic identification commonly uses (a)
Requires providing a claim identity
Authentication
Authorization
Accounting
Identification
Ensures that an action is allowed
Authorization
Accounting
Authentication
Identification
Electronic authentication commonly uses (a)
Electronic authorization commonly uses access (a) lists
Maintains logs of users activity
Accounting
Authorization
Authentication
Identification
(a) includes authentication, authorization, and accounting
Requirements set a minimum number of characters
Password length
Password complexity
Password expiration
Password history
Password managers
Requirements describe the types of characters that must be included
Password complexity
Password expiration
Password length
Password history
Password managers
Requirements force password changes
Password expiration
Password complexity
Password length
Password history
Password managers
Requirements prevent password reuse
Password history
Password managers
Password expiration
Password complexity
Password length
Facilitate the use of strong, unique passwords
Password managers
Password history
Password expiration
Password length
Password length
Make it easy for users to change their (a)
What are 3 Authentication factors:
Something you know
Something you are
Something you have
Control applied
Residual risk
Control risk
Preventive control
Detective control
Recovery control
Policies
Standards
Guidelines
"Something you know"
Passwords, PINs, and security questions
Biometric security mechanisms
Software and hardware tokens
"Something you are"
Biometric security mechanism
Password, PINs, and security questions
Software and hardware tokens
"Something you have"
Software and hardware tokens
Biometric security mechanisms
Passwords, PINs, and security questions
(a) can steal passwords
(a) might lose smart cards
(a) authentication combines two different authentication factors
Password combined with (a) ARE multi-factor
Fingerprints combined with (a) ARE multi-factor
Passwords combined with (a) are NOT multi-factor
Shares authenticated sessions across systems
Single Sign-Out (SSO)
Multi-Factor authentication
Passwords
Fingerprints
Prevents someone from denying the truth
Non-repudiation
Privacy
Internal risk
Multiparty risk
Signatures provide non-repudiation for (a) documents
Digital signatures provide non-repudiation for (a) documents
Privacy Concerns:
Protecting our own data
Educating our users
Protecting data collected by our organization
Risk avoidance
Risk transference
Risk mitigation
Risk acceptance
Threat vectors
Vulnerabilities
Risk assessment
Internal risk
Likelihood
Threats
Impact
Risk
Relates to a specific individual
Personally Identifiable Information (PII)
Protected Health Information (PHI)
Includes health care records
Protected Health Information (PHI)
Personally Identification Information (PII)
You do not have a reasonable expectation of privacy in social media
True
False
You have some expectation of privacy for private electronic communications
True
False
You have a reasonable expectation of privacy when sharing PII with an organization
True
False
You have no expectation of privacy when using employer reasources
True
False
Arise from within the organizations
Internal risk
External risk
Multiparty risks
Internal controls address (a) risks
Arise from outside the organization
External risk
Multiparty risks
Internal risk
Affect more than one organization
Multiparty risks
Internal risk
External risk
Any organization using ___, consider replacing ___
(a)
Poses a risk to knowledge-based organizations
Intellectual Property Theft
Software license compliance
Risk Assessment
Vulnerabilities
Issues risk fines and legal action
Software license compliance
Intellectual property theft
Risk assessment
Vulnerabilities
(a) professionals must prioritize risks
The process of identifying, analysing and evaluating risk.
“Identifies and triages risks”
Risk assessment
Threats
Vulnerabilities
Controls
External forces that jeopardize security
Threats
Risk
Vulnerabilities
Risk assessment
(a) vectors are methods used by attackers
Weakness in your security controls
Vulnerabilities
Risks
Threats
Risk assessment
The combination of a threat and vulnerability
Risks
Risk assessment
Likelihood
Impact
We rank risks by ___ and ___
(a)
The probability a risk will occur
Likelihood
Impact
Qualitative Risk Assessment
Quantitative Risk Assessment
The amount of damage a risk will cause
Impact
Likelihood
Qualitative Risk Assessment
Quantitative Risk Assessment
Uses subjective ratings to evaluate risk likelihood and impact
Qualitative Risk Assessment
Quantitative Risk Assessment
Likelihood
Impact
Uses objective numeric ratings to evaluate risk likelihood and impact
Quantitative Risk Assessment
Qualitative Risk Assessment
Risk
Vulnerabilities
Include avoiding, optimizing, transferring or retaining risk.
“Analyzes and implements possible responses control risk”
Risk treatment
Risk avoidance
Risk mitigation
Risk acceptance
Risk transference
Changes business practices to make a risk irrelevant
Risk avoidance
Risk mitigation
Risk acceptance
Risk treatment
Risk transference
Insurance is a common way to (a) risk
Reduces the likelihood or impact of a risk
Risk mitigation
Risk acceptance
Risk avoidance
Risk treatment
The choice to continue operations in the face of a risk
Risk acceptance
Risk mitigation
Risk avoidance
Risk treatment
Risk transference
An organization's (a) profile is the set of risk that it faces
The initial level of risk that exists in an organization before any controls are put in place
Inherent risk
Risk transference
Risk mitigation
Risk acceptance
Restricts or blocks applications from operating in a way that puts your data at risk.
“To reduce that risk”
Application control
Residual risk
Control risk
Risk tolerance
The amount of risk left over after actions have already been taken to address threats
“Reduced by controls”
Residual risk
Control risk
Application control
Risk tolerance
Introduce new risk
Control risk
Risk tolerance
Residual risk
Application control
The level of risk an organization is willing
Risk tolerance
Application control
Control risk
Residual risk
The goal of risk management: is to make sure that the combination of the residual risk and the control risk is below the organization's risk tolerance.
True
False
Reduce the likelihood or impact of a risk and help identify issues
Security controls
Defense in depth
Risk tolerance
Risk assessment
Uses layered defensive mechanisms to protect systems and data.
"Uses overlapping security controls"
Examples: Anti-virus software, Firewalls, Intrusion detection systems, Multi-factor authentication, Data encryption, Network segmentation, Zero Trust
Defense in depth
Risk tolerance
Control risk
Control applied
Stop a security issue from occurring
Preventive control
Detective control
Recovery control
Identify security issues requiring investigation
Detective control
Recovery control
Preventive control
Remediate security issues that have occurred
Recovery controls
Detective controls
Preventive controls
A measures taken to repair damage or restore resources and capabilities to their prior state following an unauthorized or unwanted activity.
"Action planned or taken to stop something from recurring."
Corrective controls
Preventive controls
Detective controls
Recovery controls
Control Function Examples; Repair physical damage, Re-issue access cards, Patch a system, Terminate a process, Reboot a system, Quarantine a virus, Implement a business continuity plan or Incident response plan.
(a)
Control Function Examples; Fences, Gates, Locks, Firewall, Intrusion Prevention System (IPS), MFA solution, Antivirus Software, Hiring and Termination policies, Separation of duties, Data classification.
(a)
Control Function Examples; Closed-Circuit Television (CCTV) and Surveillance camera logs, Intrusion detection systems, Intrusion Detection System (IDS), Honeypots, Review access rights, Audit logs and Unauthorized changes.
(a)
Hardware or software mechanisms used to protect assets. "Use technology to achieve control objectives"
Technical controls
Administrative Controls
Physical controls
"Use processes to achieve control objectives"
Policies, procedures, or guidelines that define personnel or business practice with organization's security goals.
Administrative controls
Technical controls
Physical controls
Use to prevent or detect unauthorized access to physical areas, systems, or assets. "Impact the physical world"
Physical controls
Administrative control
Technical controls
Control Type Examples; Fences, Gates, Guards, Security badges and Access cards, Biometric access controls, Security lighting, CCTVs, Surveillance cameras, Motion sensors, Fire suppression, HVAC and Humidity Controls.
(a)
Control Type Examples; Employee hiring and Termination, Equipment and Internet usage, Physical access to facilities, Separation of duties, Security awareness training, Data classification and Auditing
(a)
Control Type Examples; Authentication solutions, Firewalls, Antivirus software, IDS, IPS, Constrained interfaces, Access Control Lists (ACL) and Encryption measures.
(a)
Tracks specific device settings
Configuration Management
Baseline
Versioning
Configuration Artifacts
Configuration Management can track both operating system settings and the inventory of software installed on a device.
True
False
Provide a configuration snapshot at a given point in time
Baselines
Versioning
Configuration Management
Configuration Artifacts
Assigns numbers to each version
Versioning
Baseline
Configuration Management
Configuration Artifacts
Diagrams serve as important (a) artifacts
Standardize Device Configurations:
Naming conventions
IP addressing schemes
Regulations and laws
Preventive controls
Detective controls
Change and configuration management help ensure a stable operating environment
True
False
We must identify the (a) and regulations that apply to us
Many different jurisdictions may govern our operations
True
False
Applies to EU resident information worldwide
General Data Protection Regulation (GDRP)
PCI DSS
Security professionals should be aware of the different national, territory, and state laws that apply to their operations
True
False
A private regulation governing credit card information
PCI DSS
General Data Protection Regulation (GDPR)
The security policy framework includes four types of documents:
Policies
Standards
Guidelines
Procedures
Risk avoidance
Risk transference
Risk mitigation
Risk acceptance
Canon 1
Canon 2
Canon 3
Canon 4
Describe an organization's security expectations
Policies
Standards
Guidelines
Procedures
What are TWO weak policy statements: (select two answers)
"All sensitive information must be encrypted with AES-256 encryption."
"Store all employee records in Room 225."
"Sensitive information must be encrypted using approved technology."
"Store all employee records in a location approved by Human Resources."
What are TWO good policy statements: (select two answers)
"Sensitive information must be encrypted using approved technology."
"Store all employee records in a location approved by Human Resources."
"All sensitive information must be encrypted with AES-256 encryption."
"Store all employee records in Room 225."
Describe specific security controls
Standards
Guidelines
Procedures
Policy
Describe best practices
Guidelines
Procedures
Standards
Policy
Step-by-step instructions
Procedures
Guidelines
Standards
Policy
Compliance with policies and standards is ALWAYS (a)
Compliance with guidelines is ALWAYS (a)
Compliance with procedures can go (a) , depending upon the organization and the specific procedure that's in question
Describe authorized uses of technology
Acceptable User Policies (AUP)
Data handling policies
Password policies
Bring You Own Device (BYOD) policies
Describe how to protect sensitive information
Data handling policies
Password policies
Privacy policies
Change management policies
Cover password security practices
Password policies
Privacy policies
Change management policies
Data handling policies
Cover use of personal devices with company information
Bring Your Own Device (BYOD) policies
Privacy policies
Acceptable Use Policies (AUP)
Change management policies
Explanation of how you plan to use any personal information that you collect through your mobile app or website.
“The use of personally identifiable information”
Privacy policies
Change management policies
Password policies
Data handling policies
Cover the documentation, approval, and rollback of technology changes.
Change management policies
Privacy policies
Password policies
Acceptable Use Policies (AUP)
Customize policies to your (a)
