Sec+ 601 Flashcards

1
Q

A CSO is interested in determining the security posture of a cloud provider
who may provide service to their organization in the future. Which of the
following would the CSO want to review?

PCI DSS standards

SOC 2 report

CSF framework

SLA contract

A

SOC 2 report
A service organization controls (SOC) report (not to be confused with the other SOC acronym,
security operations center) is a way to verify that an organization is following some specific best practices before you outsource a business function to that organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of control would make an organization aware of an intrusion or
compromise?

Detective

Corrective

Protective

Preventive

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What control type resolves a previously discovered issue and mitigates a
risk going forward?

Corrective

Detective

Preventative

Finalized

A

Corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which ISO standard is specifically designed for certifying privacy?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
A
16
Q
A
17
Q
A
18
Q
A
19
Q
A
20
Q
A
21
Q
A
22
Q
A
23
Q
A
24
Q
A
25
Q
A
26
Q
A
27
Q
A
28
Q
A
29
Q
A
30
Q
A