Security Basics Flashcards

1
Q

What is the CIA Triade?

A

Confidentiality, Integrity, Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Confidentiality?

A

The ability to keep data secret usually utilizing the principle of “least privilege”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Integrity?

A

The ability to keep data accurate and making sure it is trusted and is protected from intentional, unauthorized, or accidental changes while the object is in storage, in transit, or in process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Avalibility?

A

Availability is the security principle that provides a high level of assurance that authorized subjects have timely and uninterrupted access to data, objects, and resources when needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the IAAA (I Triple A)?

A

The process of holding users accountable within a system

Identification, Authentication, Authorization, Accountability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Identification?

A

The process of declaring who you are (usually username)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Authentication?

A

Proves who you are (password, pin, biometric, ect…) to a system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is Authorization?

A

the amount of access users have within a system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Auditing?

A

It is the ability to collect data on what is happening within a system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is accountability?

A

Acting on data gathered from from Auditing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Nonrepudiation?

A

A subject cannot deny an event has taken place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What basic Security Controls should every organization implement?

A

User Training, Endpoint Protection Software, Encryption, and Access Controls (Software and Physical)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly