1/48
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the purpose of making IT security policies available on an internal intranet?
To ensure easy employee access and improve policy adherence.
What does a baseline standard specify in IT security?
Technical configurations and security settings required for devices and systems.
How does automating the documentation process benefit IT security?
Increases efficiency, consistency, and accuracy while reducing manual errors.
What does RPO stand for in IT disaster recovery?
Recovery Point Objective, which indicates how much data loss is acceptable during an incident.
Who is typically seen as the first line of defense in IT security management?
Operational management and control owners.
What level of access do system administrators have?
They hold the highest level of access to perform maintenance, configuration, and troubleshooting.
What is the purpose of a PAA (Privilege Access Agreement)?
To outline expectations and responsibilities of users with elevated system access.
What does the scope of a security policy define?
Resources, systems, people, and environments subject to the policy.
What does an Operational Risk Committee do?
Manages day-to-day IT risks and aligns them with business processes.
What does the Proportionality Principle in IT security state?
Security controls should match the value and sensitivity of data.
What is risk transference in terms of IT security?
Shifting the financial burden of risk to another party, such as insurance or outsourcing.
Why is spear phishing considered more dangerous than general phishing?
Because it is targeted and tailored, increasing the chance of success.
What is Defense-in-Depth in IT security?
Deploying multiple, overlapping layers of security controls.
What is critical data in the context of IT security?
Information that must be recovered quickly to avoid major disruption.
What does the Remote Access Domain cover?
Policies for secure authentication of remote users and endpoint protection.
What is the purpose of Separation of Duties in IT security?
To prevent fraud, error, and misuse by dividing responsibilities.
In the U.S. military system, what does 'Confidential' data refer to?
Data that, if disclosed, could cause damage to national security.
What is a Business Impact Analysis (BIA)?
It identifies critical business processes and potential impacts of disruptions.
What should a secure data handling policy include?
Controlled encryption key access and a retrievable but protected key management process.
What does a Security Awareness Policy aim to achieve?
It educates users on identifying and reporting suspicious activity.
What are strategic risks in a business context?
High-level risks that can influence long-term business direction or operations.
What is the role of an Incident Response Team (IRT)?
To contain threats, perform forensic analysis, and restore normal operations.
How can insider threats be mitigated?
By implementing layered security, access monitoring, and policy enforcement.
What does an Intrusion Detection System (IDS) do?
Monitors network traffic to detect potential threats.
What is the principle of least privilege?
It limits access rights to only what's necessary for users to perform their duties.
What is the first step in responding to a security incident?
To contain the incident to limit its spread or damage.
What is the purpose of a DMZ in network security?
To house public-facing services while minimizing the risk of internal exposure.
How should encryption keys be stored for security?
They should be stored separately from the data they protect.
What does COBIT stand for in IT governance?
Control Objectives for Information and Related Technologies.
Who typically signs off on major security policies in an organization?
The CEO or Board of Directors.
What is the role of the Executive Committee in security management?
To eliminate organizational roadblocks and set high-level security priorities.
What type of control do Access Control Lists (ACL) represent?
Preventive controls that restrict access to systems.
What is the purpose of classification policies in data security?
To identify, label, and protect data based on its sensitivity.
What distinguishes an Intrusion Prevention System (IPS) from an IDS?
An IPS can actively block threats in real-time.
What are firewall rules for public web servers categorized as?
They fall under server or network domain policies.
What is the function of Nessus in network security?
It is used for automated vulnerability scans.
What do Privileged Access Agreements (PAAs) ensure?
That users acknowledge responsibilities and risks associated with elevated privileges.
What type of document provides step-by-step instructions for configuring an IDS?
A procedure document.
What does the least privilege principle restrict?
Users to only the access needed to perform their role.
What standard is created for handling credit card data securely?
PCI DSS.
Why should vendors and contractors have controlled access?
To reduce risks due to limited oversight or turnover.
What does risk avoidance mean in the context of IT security?
Eliminating exposure by not engaging in the risky activity.
How does separation of duties help in IT security?
By dividing responsibilities to prevent fraud and error.
What should BYOD policies enforce?
Access controls like network segmentation and device registration.
What is the purpose of Risk and Control Self-Assessment?
To evaluate operational risks and process weaknesses in risk management.
What is the aim of an Acceptable Use Policy (AUP)?
To define appropriate behaviors and restrictions regarding technology use.
What is the basis of social engineering attacks?
Manipulating people into giving up confidential information.
Which departments should collaborate in effective security policy development?
HR, Legal, Compliance, and IT.
What should an Incident Response Team (IRT) include?
A diverse team from IT, Legal, Public Relations, and Business Continuity.