Chapter 5: Security Controls Flashcards
Understand Security Controls
{Blank} are procedures and mechanisms that an organization puts in place to address security risks in some manner.
Security controls
Applying multiple overlapping controls to achieve the same objective.
Defense in Depth
{Blank} are designed to stop a security issue from occuring in the first place,
Preventive controls
{Blank} identify potential security breaches that require further investigation.
Detective controls
{Blank} remediate security issues that have already occured.
Recovery controls
Technical controls use technology to achieve security objectives. What other terms describes the same type of control.
Logical controls
{Blank} include the processes that you put in place to manage technology in a secure manner. These include many of the tasks that security professionals carry out each day, such as user access reviews, log monitoring, background checks, and security awarness training.
Administrative controls
{Blank} are those that impact the physical world. Locks are used to keep people out of buildings, cameras to detect unauthorized intrustions, and security guards to monitor activity in out facilities .
Physical controls
What can security controls be classified by?
- Purpose
- Mechanism of action
Tonya is concerned about the risk that an attacker will attempt to gain access to her organizations’s database server. She is searching for a control that would blockthe attacker’s attempt to gain access. Which type of security control is she seeking to implement?
A. Technical
B. Detective
C. Recovery
D. Preventive
Technical
Tonya evaluated all of the options available to her for protecting her database and decided to implement strong encrytion to protect the contents of the data in her database. Which mechanism of action is she using?
A. Technical
B. Administrative
C. Preventive
D. Physical
Technical
What are the three purpose categories for security controls?
- Preventive controls
- Detective controls
- Recovery controls
What are the three mechanism of action categories for security controls?
- Technical controls
- Administrative controls
- Physical controls