CISSP Domains Flashcards
Which CISSP domain?
-suggest control testing
-Conducts audits
Domain 6: security assessment and testing
Which CISSP domain- separation of duties
Domain 3: architecture and engineering
Which CISSP domain- adding security input at each step of software development
Domain 8: software development
Which CISSP domain- intrusion detection and prevention
Domain 7: security operations
Which CISSP domain- designs network security controls
Domain 4: communication and network security
Which CISSP domain- zero trust
Domain 3: architecture and engineering
Which CISSP domain-threat modeling
Domain 3: security architecture, and engineering
Which CISSP domain?
-Threat modeling
-Least privilege
-defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify
Domain 3: security architecture, and engineering
What are the two responsibilities of the identity and access management domain?
-Overseeing access based on position
-deciding when and who has access
Which CISSP domain- play Books
Domain 7: security operations
What are the four responsibilities of the asset security domain?
-tracking assets
-Destruction and disposal of assets
-Establishing recovery plans
-Managing data exposure
What are the two responsibilities of the software development domain?
-adding security input at each step of software develop
-Conducting penetration testing by hiring pros
Which CISSP domain?
-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security
InfoSec in domain 1: security risk, and management
Which CISSP domain- tracking assets
Domain 2: asset security
Which CISSP domain- conducting penetration testing (by hiring professionals)
Domain 8: software development
Which CISSP domain- suggests control testing
Domain 6: security assessment and testing
Which CISSP domain- training and awareness
Domain 7: security operations
Which CISSP domain- vulnerability management
InfoSec (under domain 1: security risk, and management)
What domain is focused on defining security, goals and objectives risk medication, compliance, business, continuity, and legal regulations?
Security and risk management
What are the 8 CISSP domains?
- Security risk and management.
- Asset security.
- Security architecture and engineering.
- Communication and network security.
- Identity and access management.
- Security assessment and testing.
- Security operations.
- Software development.
Which CISSP domain- reflecting on lessons learned
Domain 7: security operations
Which CISSP domain- defense in depth
Domain 3: security architecture, and engineering
Which CISSP domain- incident response
InfoSec (under domain 1: security risk, and management)
Which CISSP domain?
-Adding security input at each step of software development
-Conducting penetration testing (by hiring pros)
Domain 8: software development
Which CISSP domain-
-training and awareness
-Reporting and documentation
-Intrusion detection and prevention
-SIEM tools
-Log management
-play Books
-Post breach forensics
-Reflecting on lessons learned
Domain 7: security operations
Which CISSP domain- trust but verify
Domain 3: security architecture, and engineering
Which CISSP domain- compliance
Domain 1: security and risk management
Which CISSP domain?
-Designing network security controls
-Overseeing communication guidelines and controls
Domain 4: communication and network security
Which CISSP domain- security goals and objectives
Domain 1: security and risk management
Which CISSP domain- SIEM TOOLS
Domain 7: security operations
Which CISSP domain- incident management
Domain 7: security operations
Which CISSP domain?
-Security goals, and objectives
-risk mitigation
-Compliance
-business continuity plans
-Local regulations
-Professional and organizational ethics
Domain 1: security and risk management
Which CISSP domain is InfoSec a part of?
domain 1: security risk, and management
Which CISSP domain- managing data exposure
Domain 2: asset security
Which CISSP domain- least privilege
Domain 3: security architecture, and engineering
Which CISSP domain- establishing recovery plans
Domain 2: asset security
Which CISSP domain- legal regulations
Domain 1: security and risk management
Which CISSP domain- professional and organizational ethics
Domain 1: security and risk management
Which CISSP domain- post breach forensics
Domain 7: security operations
Which CISSP domain?
-Overseas access based on position
-decides when and who has access
Domain 5: identity and access management
Which CISSP domain- business continuity plans
Domain 1: security and risk management
Which CISSP domain- reporting and documentation
Domain 7: security operations
Which CISSP domain?
-tracking assets
-Asset destruction, and disposal
-Establishing recovery plans
-Managing data exposure
Domain 2: asset security
Which CISSP domain- overseas access based on position
Domain 5: access management
Which CISSP domain- risk mitigation processes
Domain 1: security and risk management
Which CISSP domain- application security
InfoSec (under domain 1: security risk, and management)
Which CISSP domain- decides when and who has access
Domain 5: access management
What are the eight responsibilities of the security architecture and engineering domain?
-threat modeling
-Least privilege
-Defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify
What are the nine responsibilities of the security operations domain?
-training and awareness
-Reporting and document
-And children, detection and prevention
-SIEM tools
-Log management
-Incident management
-play Books
-Post breach forensics
-Reflecting on lessons learned
Which CISSP domain- cloud security
InfoSec (under domain 1: security risk, and management)
Which CISSP domain- log management
Domain 7: security operations
Which CISSP domain- overseas communication guidelines and controls
Domain 4: communication and network security
Which CISSP domain- infrastructure security
InfoSec (under domain 1: security risk, and management)
Which CISSP domain- Fail Securely
Domain 3: security architecture, and engineering
Which CISSP domain- audits
Domain 6: security assessment and testing
What are the two responsibilities of the security assessment and testing domain?
-suggesting control testing
-Conducting audits
What are the two responsibilities of the communication and network security domain?
-Designing network security controls
-Oversee communication guidelines and controls
What are the responsibilities of InfoSec part of the first domain?
-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security
What are the six responsibilities of the security and risk management domain?
-Security goals, and objectives
-risk mitigation
-Compliance
-business continuity plans
-Legal regulations
-Professional and organizational ethics