Security Controls 1.1 Flashcards

1
Q

What are the 4 categories of Security Controls

A

Technical
Managerial
Operational
Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

[…] are implemented with some type of technical system
- Firewalls
- Anti Virus
- OS system controls

A

Technical Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

[…] controls are policies dictating security design/implementation
- Security Policies
- Standard Operating Procedures

A

Managerial Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

[…] controls are implemented by people instead of systems
- Security Guards
- Awareness Programs

A

Operational Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

[…] controls limit physical access
- Fences
- Locks
- Badge Readers

A

Physical Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

[…] Control type limits access to a particular resource
- Firewall Rules
- Door Locks
- Guard Shack checking all ID
- On boarding policy

A

Preventive Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

[…] control type discourages an intrusion attempt and
makes an attacker think twice
- Threat of demotion
- Front reception desk
- Posted warning signs
- Splash screen

A

Deterrent Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

[…] control type identifies and logs an intrusion attempt
- Collect / Review of system logs
- Review login reports
- Regularly patrol the property
- Motion Detectors

A

Detective Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

[…] control type applies a control after an event has been detected in an effort to reverse the impact
- Restoring from backups
- Fire extinguishers
- Contact law enforcement to manage criminal activity

A

Corrective Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

[…] control type is used while a plan is put together to solve the incident
- Firewall blocks an application while waiting for a patch
- Generator
- Separation of duties
- Simultaneous guard duties

A

Compensating Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

[…] control type is directing users towards security compliance and has relatively weak security control
- Store sensitive files in a protected folders
- Create compliance policies and procedures
- Train users on security policy
- Post a sign for “Authorized Personnel Only”

A

Directive Control Type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly