Fundamental Security Flashcards

1
Q

What is Information Security?

A

Protecting data and information from unauthorized access, modification, disruption, disclosure, and destruction.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the Information Systems Security

A

Protecting the systems (ex. computers, servers, network devices) that hold and process critical data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does CIA stand for?

A

Confidentiality, Integrity, Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Confidentiality

A

Ensures information is accessible only to authorized personnel (ex. encryption)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Integrity

A

Ensures data remains accurate and unaltered (ex. checksums)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Availablity

A

Ensures information and resources are accessible when needed (Ex. redundancy measures)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Non-Repudiation

A

Guarantees that an action or event cannot be denied by the involved parties (ex. digital signatures)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

CIANA Pentagon

A

Extension of CIA triad, but with non-repudation and authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Triple A’s of Security

A

Authentication, Authorization, Accounting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security Control Categories

A

Technical, Managerial, Operational, and Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Security Control Types

A

Preventative, Deterrent, Detective, Corrective, Compensating, Directive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Zero Trust Model

A

Operates on the principle that no one should be trusted by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do we achieve zero trust?

A

Through the Control Plane & the Data Plane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Data Plane

A

Subject/system, policy engine, policy administrator, and establishing policy enforcement points

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Control Plane

A

Adaptative Identity, threat scope reduction, policy-driven access control, and secured zone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly