Chapter 2: Asset Security Flashcards

1
Q

What is UBA ?

A

User Behavior Analytics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is UEBA ?

A

User and Entity Behavior Analytics

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What’s a VMS ?

A

Vendor Management System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Compliance ?

A

The act of confirming to or adhering to rules, policies, regulations, standards or requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is PCI DSS ?

A

Payment Card Industry Data Security Standard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is HIPAA ?

A

Health Insurance Portability and Accountability Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does SOX stands for?

A

Sarbanes-Oxley Act of 2002

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does GDPR stand for?

A

General Data Protection Regulation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the goal of Risk Management?

A

Reduce Risk to an acceptable level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define Asset

A

Anything used in a business process or task.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is AV ?

A

Asset Value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Threat

A

Any potential occurrence that may cause an undesirable or unwanted outcome for an organization or specific asset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is EF ?

A

Exposure Factor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Formula - - Risk = ??

A

Threat * Vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is covered by NIST 800-30r1 Appendices D & E ?

A

Threat Sources & Threat Events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What kind of risk analysis assigns intangible values to the loss of an asset?

A

Qualitative Risk Analysis

17
Q

Name some techniques for Qualitative Risk Analysis.

A

Brainstorming, Storyboarding, Focus Group, Survey, Checklist, Questionnaire, Interviews, Mtgs, Scenarios, Delphi Technique

18
Q

What is the Delphi Technique ?

A

Using a series of rounds of questionnaires to gather data from experts.

19
Q

What are the formulae to calculate before examining counter-measures in Quantitative Risk Analysis?

A

AV * EF = SLE
SLE * ARO = ALE