F1 Flashcards
Difference between Public and Community?
Public does not allow for redundancy and data sharing with industry peers.
Who would not be part of the intended audience for NIST SP 800-53?
Individuals with marketing and advertising responsibilities
What is NIST SP 800-53?
Protects information systems against sophisticated threats.
When would independence be needed by an auditor for a subservice.
When the organizations management used the inclusive method.
When do service auditors report on subsequent events.
Auditors don’t have to perform any procedures after the date of service but must appropriately respond to any subsequently discovered event.
What is an SQL injection attack?
Application based attack in which an attacker injects malicious SQL code into existing SQL code on a company’s website to gain unauthorized access to a company’s data.
What is a Network based attach>
Target the infrastructure of a network including switches, routers, servers, and cabling with the intent to gain unauthorized access or disrupt operations for users.
Supply chain attack?
Target the production and distribution of goods within a supply chain so that there are larger disruptions in the normal operations of a company, government, or other entity.
Host based attack?
Target a single host such as a laptop, mobile device, or a server to disrupt functionality or obtain unauthorized access. SQL injections do not target a single host but rather the website’s database.
What cycle do these fall into voucher, production schedule, receipt, earnings statement?
Purchasing and disbursement cycle.
Production cycle.
Revenue cycle.
payroll cycle.
What is not a disadvantage of outsourcing?
Risk Mitigation.
SOC 1 enagemnt would not focus on?
Applicable trust SOC 2 and 3 would.
Also only SOC 2 focuses on effective operations of controls.
SQL?
Is the most likely used when running queries to retrieve specific subsets within a data when performing data extraction.
JavaScript is more focused on Web programming and a host of other applications.
What is a Software-defined wide-area network (SD-WAN) devices?
Networks that are optimized using software that is integrated into the hardware, rather than solely physical connections.
What is application network gateway?
Resource-intensive devices that inspect packets but do not assign IP addresses to other devices on the same network as their primary function.