Lesson 1 Flashcards

Compare/Contrast Various types of Security Controls

1
Q

Threat

A

Potential Danger

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Vulnerability

A

A weakness

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat actor

A

adversary with malicious intent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Exploit

A

When a threat actor successfully takes advantage of a vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Controls

A

Tactics or mechanisms or strategies to proactively minimize risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

3 ways controls minimize risks

A

Reduce or eliminate
1) vulnerability
2) likelyhood a threat actor will be able to exploit a vulnerability
3) impact of an exploit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Countermeasures

A

controls implemented to adress a specific threat. Reactive and more effective, but less broadly efficient (example: block specific IP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Functionality

A

what a control does

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

effectiveness

A

how well control works

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Assurance

A

measure of confidence measured controls are effective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

control objective

A

statement of desired result/purpose to be achieved by implementing a control or set of controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Defense-in-Depth
(layered security)

A

design and implementation of multiple overlapping layers of diverse controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

security control baseline

A

minimum standards for a given environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

scoping

A

elimining unnecessary baseline recommendations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

tailoring

A

customizing baseline recs to align with organizational requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Compensating

A

substituting a recommended base control with a similar control

17
Q

supplementing

A

augmenting to base recommendations

18
Q

Cost-benefit analysis

A

process of comparing estimates costs & benefits

19
Q
A