Domain 2: Asset Security Flashcards

1
Q

Sensitive Data

A

any info that isn’t public or unclassified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

PII

A

Personal Identifiable Information - any info that can be used to distinguish or trace an individuals identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PHI

A

Protected Health Information - any health info that can be related to a specific person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Proprietary Data

A

any data that helps an org maintain a competitive edge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

DLP Server

A

Data Loss Prevention Server, emails pass through, detects labels on data or applies necessary security measurs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Data at Rest

A

data stored on media

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data in Transit

A

data in motion, data transmitted over a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Data in use

A

data in temporary storage buffers while an application is using it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Handling

A

secure transportation of media through its lifetime

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Data Remanence

A

The data that remains on a hard drive as a residual magnetic flux

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How to remove data remanence

A

degausser for magnetic media, not SSDs. Use destruction to a size of 2 mm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Erasing

A

deleting files, remains on the drive until space runs out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Clearing

A

prepare media for reuse and assure the cleared data cannot be recovered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Purging

A

more intense form of clearing, repeat clearing or combine with another process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Declassification

A

any process that purges media or a system in preparation for reuse in an unclass environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Sanitization

A

combination of processes that removes data from a system of from media ensuring it cannot be recovered by any means

17
Q

Degaussing

A

create a strong magnetic field that erases data on magnetic media

18
Q

Which protocol do most HTTPS transmissions use?

A

TLS - Transport Layer Security

19
Q

What was the predecessor to TLS?

A

SSL - Secure Sockets Layer but it is susceptible to the POODLE attack

20
Q

What does a VPN use?

A

IPsec combined with L2TP

21
Q

Which protocols would be used to protect data in transit on internal networks?

A

IPsec and SSH (Secure Shell)

22
Q

What are secure protocols used to transfer encrypted files over a network?

A

SCP (Secure Copy) and SFTP (Secure File Transfer Protocol)

23
Q

This person has the ultimate org responsibility for the data

A

data owner - typically CEO

24
Q

This person owns the system that processes sensitive data

A

System Owner

25
Q

This person is usually the PM

A

Business/Mission Owner

26
Q

Data processor

A

a natural or legal person which processes personal data solely on behalf of the data controller

27
Q

This person is responsible for granting appropriate access to personnel

A

Admins

28
Q

This person handles day to day tasks usually assigned by data owner

A

custodian