CISSP Domains Flashcards
Which CISSP domain?
-suggest control testing
-Conducts audits
Domain 6: security assessment and testing
Which CISSP domain- separation of duties
Domain 3: architecture and engineering
Which CISSP domain- adding security input at each step of software development
Domain 8: software development
Which CISSP domain- intrusion detection and prevention
Domain 7: security operations
Which CISSP domain- designs network security controls
Domain 4: communication and network security
Which CISSP domain- zero trust
Domain 3: architecture and engineering
Which CISSP domain-threat modeling
Domain 3: security architecture, and engineering
Which CISSP domain?
-Threat modeling
-Least privilege
-defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify
Domain 3: security architecture, and engineering
What are the two responsibilities of the identity and access management domain?
-Overseeing access based on position
-deciding when and who has access
Which CISSP domain- play Books
Domain 7: security operations
What are the four responsibilities of the asset security domain?
-tracking assets
-Destruction and disposal of assets
-Establishing recovery plans
-Managing data exposure
What are the two responsibilities of the software development domain?
-adding security input at each step of software develop
-Conducting penetration testing by hiring pros
Which CISSP domain?
-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security
InfoSec in domain 1: security risk, and management
Which CISSP domain- tracking assets
Domain 2: asset security
Which CISSP domain- conducting penetration testing (by hiring professionals)
Domain 8: software development
Which CISSP domain- suggests control testing
Domain 6: security assessment and testing
Which CISSP domain- training and awareness
Domain 7: security operations
Which CISSP domain- vulnerability management
InfoSec (under domain 1: security risk, and management)
What domain is focused on defining security, goals and objectives risk medication, compliance, business, continuity, and legal regulations?
Security and risk management
What are the 8 CISSP domains?
- Security risk and management.
- Asset security.
- Security architecture and engineering.
- Communication and network security.
- Identity and access management.
- Security assessment and testing.
- Security operations.
- Software development.
Which CISSP domain- reflecting on lessons learned
Domain 7: security operations
Which CISSP domain- defense in depth
Domain 3: security architecture, and engineering
Which CISSP domain- incident response
InfoSec (under domain 1: security risk, and management)