MOD 2 QUIZ Flashcards
What is Separation of Duties?
Critical, significant, and sensitive work tasks are divided among several individual administrators or high-level operators
What is Job rotation?
Consists of rotating employees among multiple job positions
What is SLA?
Service-Level Agreement
What is Security Governance?
The collection of practices related to supporting, defining, and directing the security efforts of an organization
What is the, “detailed process of identifying factors that could damage or disclose data, evaluating those factors in light of data value and countermeasure cost, and implementing cost-effective solutions for mitigating or reducing risk”?
Risk Management
What is Vulnerability?
A weakness in an asset or the absence or the weakness of a safeguard or countermeasure
What are the two types of Risk Analysis?
Qualitative and Quantitative
What are the six major elements of Quantitative Risk Analysis?
Annualized Rate of Occurrence
Single Loss Expectancy
Asset Value
Exposure Factor
Annualized Loss Expectancy
What are the valid Risk Responses?
Transfer
Accept
Mitigate
What are the three Control Categories used in Defense in Depth?
What is Exposure?
Being susceptible to asset loss because of a threat (doesn’t mean a threat will be realized)
What is Asset Valuation
?
What is Phishing?
Stealing credentials or identity information from any potential target
What is Shoulder Surfing?
Whens someone is able to watch a user’s keyboard or view their display
What is Typo Squatting?
A practice employed to capture and redirect traffic when a user mistypes the domain name or IP address of an intended resource