Mastering Security Basics Flashcards
What is CIA triad?
CIA triad stands for Confidentiality, Integrity, and Availability. It’s a fundamental concept in information security.
Define Confidentiality
Confidentiality ensures that information is only accessible to those who are authorized to view it.
Define Integrity.
Integrity ensures that data remains accurate, complete, and unaltered.
Define Availability.
Availability ensures that information and resources are accessible and usable when needed.
What is Risk Management?
Risk Management is the process of identifying, assessing, and prioritizing risks followed by the coordinated application of resources to minimize, monitor, and control the probability and/or impact of unfortunate events.
What is Vulnerability?
A vulnerability is a weakness that could be exploited by a threat to breach security.
What is Threat?
A threat is any potential danger to information or systems.
Define Exploit.
An exploit is a piece of software, a chunk of data, or a sequence of commands that take advantage of a bug, glitch, or vulnerability to cause unintended or unanticipated behavior to occur on computer software, hardware, or something electronic (usually computerized).
What are the four security Categories?
Technical, Managerial, Operational, Physical.
Describe technical controls
Use of technology such as hardware, software, and firmware to reduce vulnerabilities.
Describe Managerial controls.
Administrative documents or policies to enforce security protocols.
Provide some examples of technical controls.
Encryption, Antivirus software, intrusion detection system (IDSs) and intrusion prevention systems (IPSs), Firewalls, Least privilege.
What are some examples of Managerial controls
Risk assessment, vulnerability assessments,
Describe Operational security controls.
Ensure daily operations and compliance of an organizations security plan.
Provide some examples of operational security controls
Patrols, personnel security, awareness and training, configuration management