CIA Triad Flashcards

1
Q

What does CIA stand for in information security?

A

Confidentiality, Integrity, Availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is confidentiality?

A

Ensuring people cannot access information they are not authorized to see.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does high confidentiality mean?

A

Data is encrypted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is low confidentiality?

A

Data is open on the web.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is integrity in the CIA triad?

A

Ensuring information is not modified or corrupted by unauthorized parties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is availability?

A

Ensuring information is accessible when needed by authorized users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are access control elements?

A

Identification, Authentication, Authorization, Accountability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are administrative access controls?

A

Institutional policies and procedures such as hiring and supervision.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are physical controls?

A

Methods to prevent/detect physical access, e.g., guards, locked doors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are logical/technical controls?

A

Hardware/software security mechanisms like firewalls and encryption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the principle of least privilege?

A

Users should only have access needed for their job.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is separation of duties?

A

Dividing sensitive tasks among individuals to reduce risk of fraud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is discretionary access control?

A

Access based on user identity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is rule-based access control?

A

Access based on predefined rules (e.g., firewalls).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is lattice-based access control?

A

Access determined by security labels and user clearance levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is centralized access control?

A

One entity manages all access decisions.

17
Q

What is decentralized access control?

A

Multiple entities manage access, suitable for large systems.