Cybersecurity CompTIA 1.1 - Security Controls

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/23

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:56 PM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

24 Terms

1
New cards

Technical Controls (Logical Controls)

Security controls implemented with technology or technical mechanisms. (Examples: firewalls, encryption, MFA, IDS/IPS)

2
New cards

Firewalls

Monitors and filters incoming and outgoing network traffic based on security rules. (Blocks unauthorized network connections, Allows approved traffic, Protects networks from hackers)

3
New cards

Firewall Logs

Records of attempted or established connections for incoming traffic from the internet. It also includes outbound requests to the internet from within the network. (Source IP, Destination IP, Port numbers, Protocol, Allowed or blocked, Date and time)

4
New cards

Multi-Factor Authentication (MFA)

Requires users to provide two or more forms of authentication before accessing an account. Makes stolen passwords much less useful. (Something you know (password), Something you have (phone/security key), Something you are (fingerprint))

5
New cards

Intrusion Detection System (IDS)

Monitors network traffic and alerts administrators about suspicious activity. (Detects attacks, Sends alerts, Does not stop attacks)

6
New cards

Intrusion Prevention System (IPS)

Monitors network traffic and automatically blocks malicious activity. (Detects attacks, Stops attacks automatically)

7
New cards

Antivirus/Anti-malware

Software that detects, blocks, and removes malicious software. (Scans files, Removes viruses, Stops malware infections)

8
New cards

Encryption

Converts readable data (plaintext) into unreadable data (ciphertext). Protects data even if it is stolen.

9
New cards

Access Control Lists (ACLs)

Rules that determine which users or devices can access resources.

10
New cards

VPN (Virtual Private Network)

Creates an encrypted connection between a device and a network.

11
New cards

Managerial Controls (Administrative Controls)

Policies, procedures, planning, and decision-making processes created by management. These tell employees what they are supposed to do.

12
New cards

Security Policies

Written rules that explain security expectations.

13
New cards

Risk Assessments

Identifying and evaluating risks to an organization.

14
New cards

Security Awareness Training

Teaching employees how to recognize cyber threats.

15
New cards

Incident Response Plan

A documented plan explaining how to respond to cybersecurity incidents.

16
New cards

Operational Controls

Day-to-day procedures carried out by people to maintain security. Operational controls involve performing the work. (Example: Security Guards, Backups, Account reviews, Incident response, change management)

17
New cards

Physical Controls

Protect buildings, equipment, and people from unauthorized physical access.(Example: Locks, CCTV, Badge Readers, Fences, Biometric scanners)

18
New cards

Mantraps

A small secured room with two locking doors that only allows one person through after identity verification.

19
New cards

Preventive Controls

Stop security incidents before they happen. (Firewall, MFA, Encryption, Door locks, Antivirus, ACLs, Strong passwords)

20
New cards

Deterrent Controls

Discourage attackers or users from attempting malicious actions. (Security cameras, Warning signs, Security guards, Login banners, Bright lighting, Visible fences)

21
New cards

Detective Controls

Identify or discover security incidents after or while they occur. (IDS, Security cameras, SIEM, Log monitoring, Motion sensors, Security audits)

22
New cards

Corrective Controls

Reduce damage and restore systems after an incident. (Backups, Patching, Antivirus removing malware, Disaster recovery, Incident response, Reinstalling infected systems)

23
New cards

Compensating Controls

Provide an alternative security measure when the preferred control cannot be implemented. (Increased monitoring, Additional MFA, Manual approval process, VPN instead of upgrading an insecure application, Physical security when technical controls aren't possible)

24
New cards

Directive Controls

Guide people by telling them what they should or should not do. (Security policies, Procedures, Employee handbook, Acceptable Use Policy (AUP), Security training, Password policy)