1.0 General Security Concepts Flashcards
Which type of control would a firewall be classified as?
a) Technical
Security awareness training for employees is an example of which control type?
b) Managerial
Which control type is most likely to be automated?
a) Technical
Which control type is most focused on day-to-day security activities?
c) Operational
A company’s disaster recovery plan would be considered what type of control?
b) Managerial
Biometric access systems are an example of which control type?
d) Physical
Which control type is most likely to be implemented through written policies and procedures?
b) Managerial
Log review and monitoring would typically be classified as what type of control?
c) Operational
Which control type is most focused on overall security strategy and governance?
b) Managerial
A security guard conducting patrols is an example of which control type?
c) Operational
Which control type is most likely to require regular software updates or patches?
a) Technical
Risk assessments are typically considered what type of control?
b) Managerial
Which control type is most prone to human error or inconsistency?
c) Operational
Encryption of data at rest is an example of which control type?
a) Technical
Which control type is most likely to be visible to employees and visitors?
d) Physical
Which type of control is designed to discourage potential attackers from attempting a security breach?
b) Deterrent
An intrusion detection system (IDS) is an example of which type of control?
c) Detective
When a primary control cannot be implemented due to technical limitations, what type of control would be most appropriate?
a) Compensating
Which control type is most closely associated with security policies and procedures?
c) Directive
A firewall is primarily an example of which type of control?
c) Preventive
Incident response plans are best categorized as which type of control?
c) Corrective
Which control type aims to limit damage and restore systems to normal after a security incident?
c) Corrective
Security awareness training programs are primarily examples of which two types of controls?
a) Preventive and Directive
Which control type is most likely to involve psychological elements to influence potential attackers?
b) Deterrent
A SIEM system that alerts security personnel to potential threats is an example of which control type?
c) Detective
Which control type is most closely associated with providing alternative security measures?
b) Compensating
Encryption is primarily an example of which type of control?
a) Preventive
Which control type is most likely to be implemented after a security incident has occurred?
d) Corrective
Access control systems are primarily examples of which type of control?
a) Preventive
Which control type is most closely associated with ensuring compliance with security policies?
c) Directive
What are the three components of the CIA triad?
Confidentiality, Integrity, Availability
Which principle ensures that data remains unaltered and trustworthy throughout its lifecycle?
Integrity
What is the primary purpose of non-repudiation in information security?
To ensure that a user cannot deny performing a specific action
In the AAA framework, what does the first “A” stand for?
Authentication
Which authentication method might use fingerprints or retinal scans?
Biometrics
What is the main difference between authentication and authorization?
Authentication verifies identity, while authorization determines access rights
Which authorization model assigns permissions based on a user’s job function or title?
Role-Based Access Control (RBAC)
In ABAC, what are four types of attributes that might be considered for access decisions?
User
Resource
Action
Environmental Attributes
Who typically controls access rights in a Discretionary Access Control (DAC) model?
The resource owner
Which access control model is most commonly used in high-security government environments?
Mandatory Access Control (MAC)