Chapter 16 Managing Security Operations Flashcards
What policy creates a checks-and-balances system where two or more users verify each other’s actions and must work in concert to accomplish necessary work
separation of duties
What policy grant specific processes only the privileges necessary to perform certain
functions,
Separation of privilege
What policy applies to all public companies that have registered equity or debt securities with the Securities and Exchange Commission (SEC) ?
Sarbanes-Oxley Act of 2002 (SOX)
The goal of Sarbanes-Oxley Act of 2002 (SOX) is :
a) Separation of privilege
b) Segregation of duties
c) Separation of duties
Segregation of Duties
What is The need to know principle ?
The need to know principle imposes the requirement to grant users access only to data or
resources they need to perform assigned work tasks.
What is aggregation ?
aggregation refers to the amount of privileges
that users collect over time.
What is the goal of Segregation of duties ?
to ensure that individuals do not have
excessive system access that may result in a confl ict of interest.
What policy states that personnel responsible for auditing, monitoring, and reviewing security do not have other operational duties related to what they are auditing, monitoring, and reviewing.
segregation of duties
________ ensures that no single person
has sufficient privileges to compromise the security of the environment.
Split knowledge
What does the control plane do ?
The control plane uses protocols to decide where to send traffic,
What does the data plane do ?
data plane includes rules that decide whether traffi c will be forwarded.
The _______ manages the VMs, virtual data storage, and virtual network components.
hypervisor
On-demand access to computing resources available from almost anywhere is called what ?
Cloud computing
What models provide fully functional applications typically accessible via a web browser ?
a) Platform as a Service (PaaS)
b) Infrastructure as a Service (IaaS)
c) Software as a Service (SaaS)
Software as a Service (SaaS)
CSP provide consumers with hardware, an operating system, and applications.
a) Platform as a Service (PaaS)
b) Infrastructure as a Service (IaaS)
c) Software as a Service (SaaS)
Platform as a Service (PaaS)