Prof Messer CompTIA SY0-701 Security+ 1.1

0.0(0)
studied byStudied by 0 people
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
Card Sorting

1/12

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

13 Terms

1
New cards

control categories

technical controls

managerial controls

operational controls

physical controls

2
New cards

technical controls

controls implemented using systems/tech

OS controls

firewalls, antivirus, etc

3
New cards

managerial controls

administrative controls associated with security design and implementation

security policies, standard operating procedures, etc

4
New cards

operational controls

controls implemented by people

security guards, etc

5
New cards

physical controls

limit physical access

fences, locks, badge readers, etc

6
New cards

control types

preventive

deterrent

detective

corrective

compensating

directive

7
New cards

preventive control types

block access to a resource

ex: firewall rules, door locks, guards checking ID, etc

8
New cards

deterrent control types

discourage intrusion

threat of demotion, posted warning signs, application splash screens, etc

9
New cards

detective control types

identify and log an intrusion attempt

find issue

- collect and review system logs

- review login reports

- regularly patrol property

- motion detectors

10
New cards

corrective control types

apply a control after event has been detected

reverse impact of event

continue operating with minimal downtime

ex: restoring from backups to mitigate an infection, create policies for reporting security issues, use fire extinguisher

11
New cards

compensating control types

control using other means; current controls arent enough

prevent the exploitation of a weakness

ex:

firewalls block an application while devs work on a patch, generator used after power outage

12
New cards

directive control types

direct a subject towards a security compliance

relatively weak security control

"do this please"

ex: store all sensitive files in a protected folder, post a sign saying "authorized personnel only" etc

13
New cards

control categories and types

knowt flashcard image