Domain 1 Flashcards

1
Q

Any potential danger to an organization

A

threat

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is STRIDE

A

Identifies threats based off of major categories:

Spoofing
Tampering
Repudiation
Information disclosure
Denial of service
Elevation of privileges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A 7 step risk centric methodology that starts by identifying business objectives and technical requirements and takes into account compliance issues and business specific

A

PASTA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Total cost an organization can expect to occur from a given risk in a year

A

ALE (annual loss expectancy)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

AV x EF = ?

A

SLE (single loss expectancy)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Controls that are proactive or preventative

A

safeguard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Reactive controls put in place when risks have occurred

A

countermeasure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Protects important business information. They do not need to be disclosed and are infinite

A

Trade Secrets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

meant to protect some innovative or novel idea they do need to be disclosed and they only provide protection for a set period

A

Patent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

protects the expression of an idea in some sort of fixed medium like books movies or songs disclosure is required and the protection is again only for a set period of time

A

copyright

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

protect some sort of unique color, sound, symbol used to distinguish one product or company

A

trademarks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

the maximum tolerable data loss that an
organization can accept

A

RPO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

the time from when the incident occurs to the point at which the business is back

A

RTO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

the maximum time required to verify the integrity of a systems and data as they return the normal operation

A

work recovery time (WRT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

maximum amount of time in total that a process can be disrupted before the
business is no longer in business

A

MTD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly