ISC2 Domain 5: Security Operations

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/20

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:13 PM on 8/31/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

21 Terms

1
New cards

What are the 6 stages to the data life cycle?

  1. Create

  2. Store

  3. Use

  4. Share

  5. Archive

  6. Destroy


2
New cards

What is something which every security policy should have?

Consequences for non-compliance

3
New cards

What type of phishing attacks target highly placed officials or private individuals with sizable assets?

Whaling attacks

4
New cards

Why is asymmetric encryption considered more secure?

it involves a unique code for the sender and receiver

5
New cards

What is meant by the term rollback?

Restoring the system to its previous state before change

6
New cards

What are the 3 steps in the change management process?

  1. Request for Change (RFC)

  2. Approval

  3. Rollback


7
New cards

What is ingress monitoring?

survelliance and assesment of all inbound communications traffic and access attempts

8
New cards

What is egress monitoring?

regulate data leaving the organization’s IT environment

9
New cards

What does DLP stand for?

Data loss prevention

10
New cards

What is symmetric encryption?

both decryption and encryption use the same key

11
New cards

What is a mode of encryption which ensures confidentiality efficiently, with a minimum amount of processing overhead?

Symmetric

12
New cards

True/False Logs should always be stored separately from he system they’re logging

True

13
New cards

What is asymmetric encryption?

different keys for encryption and decryption

14
New cards

What is a process and discipline used to ensure that the only changes made to a system are those that have been authorized and validated?

Configuration Management

15
New cards

What does AUP stand for?

Acceptable Use Policy

16
New cards

The organization’s privacy policy should stipulate which information is considered ________?

PII/ePHI

17
New cards

______ ______ are part of implementing controls to protect classified information.

Security Labels

18
New cards

Information and data should be kept only for as long as it is beneficial, no more and no less

Retention

19
New cards

What is Data that might be left on media after deleting?

Remanence

20
New cards

Clearing the device or system, which usually involves writing multiple patterns of random values throughout all storage media such as main memory, registers and fixed disks.

overwriting/zeroizing

21
New cards