ISC S1 Flashcards

1
Q

What is the definition of Control 1: Inventory and Control of Enterprise Assets?

A

Infrastructure enterprise asset monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the definition of Control 2: Inventory and control of Software assets?

A

Allow authorized software.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the definition of Control 3: Data Protection?

A

Data disposal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the definition of Control 4: Secure Configuration of Assets and Software?

A

Secure configuation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the definition of Control 5: Account Management?

A

Authorization for credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the definition of Control 6: Access Control Management?.

A

Manage access credentials.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the definition of Control 7: Continuous Vulnerability Management?

A

Identify & track vulnerabilities/weak points.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the definition of Control 8: Audit Log Management?

A

Recover from attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the definition of Control 9: Email and Web Browser Protection?

A

Protect & detect from Email and Web.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the definition of Control 10: Malware Defense?

A

Prevent or control bad software.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the definition of Control 11: Data Recovery?

A

Restore data pre-incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the definition of Control 12: Network Infrastructure Management?

A

Prevent attacks in vulnerable points.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the definition of Control 13: Network Monitoring and Defense?

A

Establish defense as security measure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the definition of Control 14: Security Awareness and Skill Training?

A

Security mindset.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the definition of Control 15: Service Provider Management?

A

Competency in service providers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the definition of Control 16: Software Security?

A

Implement before it’s needed.

17
Q

What is the definition of Control 17: Incident Response Management?

A

Detect and response to attacks.

18
Q

What is the definition of Control 18: Penetration Testing?

A

Simulate attacker to exploit vulnerabilities.

19
Q

What are the objectives of the COBIT core model Evaluate, Direct and Monitor (EDM)?

A

Ensure:
1. Governance framework
2. Benefit delivery
3. Risk optimization
4. Resource optimizations
4. Stakeholder engagement

20
Q

What are some of the 14 objectives of the COBIT core model Align, Plan, and Organize (APO)

A

Manage:
1. Strategy
2. Innovation
3. Portfolio
4. Risk
5. Data

21
Q

What are the objectives of the COBIT core model Build, Acquire, and Implement (BAI)?

A
22
Q

What are the objectives of the COBIT core model Deliver, Service, Support (DSS)?

A

Manage:
1. Operations
2. Service and incidents
3. Problems
4. Continuity
5. Security services
6. Business controls

23
Q

What are the objectives of the COBIT core model Monitor, Evaluate, and Assess (MEA)?

A