Compliance & Operational Security Flashcards

1
Q

What are things to consider if performing an major update?

A
Test
Backup
Time frame (downtime)
Back-out plan
Test & Monitor post change
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you mitigate privilege creep?

A

User rights and permission levels based on least privelege

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is PII?

A

Personally Identifiable Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is DLP?

A

Data Loss Prevention

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What information is stored in RAM?

A

Reigisters, Cache (i.e ARP,RAID,CPU) , Process Tables, System Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are computer mechanisms ranked by volatility?

A

RAM
SWAP file (retained only if gracefully shutdown)
HD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is chain of custody?

A

Details regarding where the evidence was stored, who had access, integrity of evidence (hashes)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does a first responder do at an incident?

A

Triage (decide priority of incident)
Investigation
Contain/Quarantine

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Mandatory Access Control?

A

Data labeling and clearance levels for users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What process uses a magnet to erase a hard drive?

A

Degaussing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a compensating control measure?

A

An additional system to compensate for the incapability of another system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is an administrative control measure?

A

Written security policy
Job rotation
Mandatory vacation
Auditing etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the first step in creating a BCP?

A

Business Impact Analysis

critical systems, assets and dependencies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a hot site?

A

Full redundant copy (including storage and networking) of a primary site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a warm site?

A

Equipment available without data replicated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a cold site?

A

Facility without equipment (location only)

17
Q

Where is the DRP specified?

A

BCP may list a number of DRPs against different events

18
Q

What is IT contingency planning?

A

Specified within DRP, focuses on one system

i.e RAID 5 on computer

19
Q

What is a tabletop excercise?

A

Structured walk through of BCP including all parties

20
Q

What is stegonography?

A

Hiding documents in other files

i.e openpuff

21
Q

What is repudiation?

A

Denying responsibility for something

digital signatures provide non-reupdiation