P1L1 Security Mindset Flashcards

1
Q

What is of value that you are trying to protect from attackers?

A

data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 2 kinds of companies?

A
  1. Companies that have been hacked and know it

2. Companies that have been hacked and DON’T know it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Threat sources

A

Cyber criminals
Hacktivists
Nation States

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Vulnerabilities and attacks

A

compromises

security breach

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

where are the vulnerabilities

A

software
networks
humans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CIA

A

Confidentiality
Integrity
Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Cyber attacks can have ________ consequences

A

physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What should the good guys do?

A
Prevention
Detection
Response
Recovery and remediation
policy vs mechanism
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Reduce vulnerabilities

A

Economy of mechanism–keep systems small and simple
Fail-safe defaults–means default access is denied
Complete mediation–no one should be able to bypass security measures
open design–no secrecy
Least privilege–minimum level of access needed
Psychological acceptability–don’t expect people to do what is inconvenient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly