1602 final guide

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/48

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:30 PM on 12/2/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

49 Terms

1
New cards

What is the purpose of making IT security policies available on an internal intranet?

To ensure easy employee access and improve policy adherence.

2
New cards

What does a baseline standard specify in IT security?

Technical configurations and security settings required for devices and systems.

3
New cards

How does automating the documentation process benefit IT security?

Increases efficiency, consistency, and accuracy while reducing manual errors.

4
New cards

What does RPO stand for in IT disaster recovery?

Recovery Point Objective, which indicates how much data loss is acceptable during an incident.

5
New cards

Who is typically seen as the first line of defense in IT security management?

Operational management and control owners.

6
New cards

What level of access do system administrators have?

They hold the highest level of access to perform maintenance, configuration, and troubleshooting.

7
New cards

What is the purpose of a PAA (Privilege Access Agreement)?

To outline expectations and responsibilities of users with elevated system access.

8
New cards

What does the scope of a security policy define?

Resources, systems, people, and environments subject to the policy.

9
New cards

What does an Operational Risk Committee do?

Manages day-to-day IT risks and aligns them with business processes.

10
New cards

What does the Proportionality Principle in IT security state?

Security controls should match the value and sensitivity of data.

11
New cards

What is risk transference in terms of IT security?

Shifting the financial burden of risk to another party, such as insurance or outsourcing.

12
New cards

Why is spear phishing considered more dangerous than general phishing?

Because it is targeted and tailored, increasing the chance of success.

13
New cards

What is Defense-in-Depth in IT security?

Deploying multiple, overlapping layers of security controls.

14
New cards

What is critical data in the context of IT security?

Information that must be recovered quickly to avoid major disruption.

15
New cards

What does the Remote Access Domain cover?

Policies for secure authentication of remote users and endpoint protection.

16
New cards

What is the purpose of Separation of Duties in IT security?

To prevent fraud, error, and misuse by dividing responsibilities.

17
New cards

In the U.S. military system, what does 'Confidential' data refer to?

Data that, if disclosed, could cause damage to national security.

18
New cards

What is a Business Impact Analysis (BIA)?

It identifies critical business processes and potential impacts of disruptions.

19
New cards

What should a secure data handling policy include?

Controlled encryption key access and a retrievable but protected key management process.

20
New cards

What does a Security Awareness Policy aim to achieve?

It educates users on identifying and reporting suspicious activity.

21
New cards

What are strategic risks in a business context?

High-level risks that can influence long-term business direction or operations.

22
New cards

What is the role of an Incident Response Team (IRT)?

To contain threats, perform forensic analysis, and restore normal operations.

23
New cards

How can insider threats be mitigated?

By implementing layered security, access monitoring, and policy enforcement.

24
New cards

What does an Intrusion Detection System (IDS) do?

Monitors network traffic to detect potential threats.

25
New cards

What is the principle of least privilege?

It limits access rights to only what's necessary for users to perform their duties.

26
New cards

What is the first step in responding to a security incident?

To contain the incident to limit its spread or damage.

27
New cards

What is the purpose of a DMZ in network security?

To house public-facing services while minimizing the risk of internal exposure.

28
New cards

How should encryption keys be stored for security?

They should be stored separately from the data they protect.

29
New cards

What does COBIT stand for in IT governance?

Control Objectives for Information and Related Technologies.

30
New cards

Who typically signs off on major security policies in an organization?

The CEO or Board of Directors.

31
New cards

What is the role of the Executive Committee in security management?

To eliminate organizational roadblocks and set high-level security priorities.

32
New cards

What type of control do Access Control Lists (ACL) represent?

Preventive controls that restrict access to systems.

33
New cards

What is the purpose of classification policies in data security?

To identify, label, and protect data based on its sensitivity.

34
New cards

What distinguishes an Intrusion Prevention System (IPS) from an IDS?

An IPS can actively block threats in real-time.

35
New cards

What are firewall rules for public web servers categorized as?

They fall under server or network domain policies.

36
New cards

What is the function of Nessus in network security?

It is used for automated vulnerability scans.

37
New cards

What do Privileged Access Agreements (PAAs) ensure?

That users acknowledge responsibilities and risks associated with elevated privileges.

38
New cards

What type of document provides step-by-step instructions for configuring an IDS?

A procedure document.

39
New cards

What does the least privilege principle restrict?

Users to only the access needed to perform their role.

40
New cards

What standard is created for handling credit card data securely?

PCI DSS.

41
New cards

Why should vendors and contractors have controlled access?

To reduce risks due to limited oversight or turnover.

42
New cards

What does risk avoidance mean in the context of IT security?

Eliminating exposure by not engaging in the risky activity.

43
New cards

How does separation of duties help in IT security?

By dividing responsibilities to prevent fraud and error.

44
New cards

What should BYOD policies enforce?

Access controls like network segmentation and device registration.

45
New cards

What is the purpose of Risk and Control Self-Assessment?

To evaluate operational risks and process weaknesses in risk management.

46
New cards

What is the aim of an Acceptable Use Policy (AUP)?

To define appropriate behaviors and restrictions regarding technology use.

47
New cards

What is the basis of social engineering attacks?

Manipulating people into giving up confidential information.

48
New cards

Which departments should collaborate in effective security policy development?

HR, Legal, Compliance, and IT.

49
New cards

What should an Incident Response Team (IRT) include?

A diverse team from IT, Legal, Public Relations, and Business Continuity.