CISSP Domains Flashcards

1
Q

Which CISSP domain?
-suggest control testing
-Conducts audits

A

Domain 6: security assessment and testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which CISSP domain- separation of duties

A

Domain 3: architecture and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which CISSP domain- adding security input at each step of software development

A

Domain 8: software development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which CISSP domain- intrusion detection and prevention

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which CISSP domain- designs network security controls

A

Domain 4: communication and network security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which CISSP domain- zero trust

A

Domain 3: architecture and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which CISSP domain-threat modeling

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which CISSP domain?
-Threat modeling
-Least privilege
-defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the two responsibilities of the identity and access management domain?

A

-Overseeing access based on position
-deciding when and who has access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which CISSP domain- play Books

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the four responsibilities of the asset security domain?

A

-tracking assets
-Destruction and disposal of assets
-Establishing recovery plans
-Managing data exposure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the two responsibilities of the software development domain?

A

-adding security input at each step of software develop
-Conducting penetration testing by hiring pros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which CISSP domain?
-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security

A

InfoSec in domain 1: security risk, and management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which CISSP domain- tracking assets

A

Domain 2: asset security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which CISSP domain- conducting penetration testing (by hiring professionals)

A

Domain 8: software development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which CISSP domain- suggests control testing

A

Domain 6: security assessment and testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which CISSP domain- training and awareness

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which CISSP domain- vulnerability management

A

InfoSec (under domain 1: security risk, and management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What domain is focused on defining security, goals and objectives risk medication, compliance, business, continuity, and legal regulations?

A

Security and risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the 8 CISSP domains?

A
  1. Security risk and management.
  2. Asset security.
  3. Security architecture and engineering.
  4. Communication and network security.
  5. Identity and access management.
  6. Security assessment and testing.
  7. Security operations.
  8. Software development.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which CISSP domain- reflecting on lessons learned

A

Domain 7: security operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which CISSP domain- defense in depth

A

Domain 3: security architecture, and engineering

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which CISSP domain- incident response

A

InfoSec (under domain 1: security risk, and management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which CISSP domain?
-Adding security input at each step of software development
-Conducting penetration testing (by hiring pros)

A

Domain 8: software development

25
Q

Which CISSP domain-
-training and awareness
-Reporting and documentation
-Intrusion detection and prevention
-SIEM tools
-Log management
-play Books
-Post breach forensics
-Reflecting on lessons learned

A

Domain 7: security operations

26
Q

Which CISSP domain- trust but verify

A

Domain 3: security architecture, and engineering

27
Q

Which CISSP domain- compliance

A

Domain 1: security and risk management

28
Q

Which CISSP domain?
-Designing network security controls
-Overseeing communication guidelines and controls

A

Domain 4: communication and network security

29
Q

Which CISSP domain- security goals and objectives

A

Domain 1: security and risk management

30
Q

Which CISSP domain- SIEM TOOLS

A

Domain 7: security operations

31
Q

Which CISSP domain- incident management

A

Domain 7: security operations

32
Q

Which CISSP domain?
-Security goals, and objectives
-risk mitigation
-Compliance
-business continuity plans
-Local regulations
-Professional and organizational ethics

A

Domain 1: security and risk management

33
Q

Which CISSP domain is InfoSec a part of?

A

domain 1: security risk, and management

34
Q

Which CISSP domain- managing data exposure

A

Domain 2: asset security

35
Q

Which CISSP domain- least privilege

A

Domain 3: security architecture, and engineering

36
Q

Which CISSP domain- establishing recovery plans

A

Domain 2: asset security

37
Q

Which CISSP domain- legal regulations

A

Domain 1: security and risk management

38
Q

Which CISSP domain- professional and organizational ethics

A

Domain 1: security and risk management

39
Q

Which CISSP domain- post breach forensics

A

Domain 7: security operations

40
Q

Which CISSP domain?
-Overseas access based on position
-decides when and who has access

A

Domain 5: identity and access management

41
Q

Which CISSP domain- business continuity plans

A

Domain 1: security and risk management

42
Q

Which CISSP domain- reporting and documentation

A

Domain 7: security operations

43
Q

Which CISSP domain?
-tracking assets
-Asset destruction, and disposal
-Establishing recovery plans
-Managing data exposure

A

Domain 2: asset security

44
Q

Which CISSP domain- overseas access based on position

A

Domain 5: access management

45
Q

Which CISSP domain- risk mitigation processes

A

Domain 1: security and risk management

46
Q

Which CISSP domain- application security

A

InfoSec (under domain 1: security risk, and management)

47
Q

Which CISSP domain- decides when and who has access

A

Domain 5: access management

48
Q

What are the eight responsibilities of the security architecture and engineering domain?

A

-threat modeling
-Least privilege
-Defense in depth
-Fail securely
-Separation of duties
-Keep it simple
-zero trust
-Trust but verify

49
Q

What are the nine responsibilities of the security operations domain?

A

-training and awareness
-Reporting and document
-And children, detection and prevention
-SIEM tools
-Log management
-Incident management
-play Books
-Post breach forensics
-Reflecting on lessons learned

50
Q

Which CISSP domain- cloud security

A

InfoSec (under domain 1: security risk, and management)

51
Q

Which CISSP domain- log management

A

Domain 7: security operations

52
Q

Which CISSP domain- overseas communication guidelines and controls

A

Domain 4: communication and network security

53
Q

Which CISSP domain- infrastructure security

A

InfoSec (under domain 1: security risk, and management)

54
Q

Which CISSP domain- Fail Securely

A

Domain 3: security architecture, and engineering

55
Q

Which CISSP domain- audits

A

Domain 6: security assessment and testing

56
Q

What are the two responsibilities of the security assessment and testing domain?

A

-suggesting control testing
-Conducting audits

57
Q

What are the two responsibilities of the communication and network security domain?

A

-Designing network security controls
-Oversee communication guidelines and controls

58
Q

What are the responsibilities of InfoSec part of the first domain?

A

-incident response
-Vulnerability management
-Application security
-Cloud security
-Infrastructure security

59
Q

What are the six responsibilities of the security and risk management domain?

A

-Security goals, and objectives
-risk mitigation
-Compliance
-business continuity plans
-Legal regulations
-Professional and organizational ethics