Security Controls Flashcards

1
Q

Security Controls

Solutions that mitigate threats

A

Security Controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security Controls

example of security controls

A

Malware scanner mitigates malware infections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Security Controls

implemented differently based on platform/vendor/user

A

N/W infrastructure devices
- switches
- routers
- firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security Control Categories

What should be done?
- employee background checks

A

Managerial/administrative

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Security Control Categories

how often we must do it
periodic review of security policies and include policy reviews

A

Operational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Security Control Categories

How exactly will we do it.
Firewall rule config

A

Technical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Security Control Categories

Technical Control category

A

specific to IT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security Control Types

Access control vestibule (mantraps)

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security Control Types

Log Analysis

A

Detective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Security Control Types

patching known vulnerabilities

A

Corrective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Security Control Types

Device logon warning banners

A

Deterrent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Security Control Types

Network isolation for Internet of Things (IoT) devices
https://www.shodan.io/

A

Compensating

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Security Control Types

Cloud Security Alliance (CSA)
cloud Controls Matrix (CCM)

A

Cloud Security Control Documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Security Control Types

Security controls must be in place to be compliant - example

A

Payment Card Industry Data Security Standard (PCIDSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Security Control Types

Risk Example

Theft of online banking creds

A

Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Security Control Types

Risk Example

spoofed e-mail message with link to spoofed web site tricking an end user

A

Attack vector

17
Q

Security Control Types

Risk Example

User security awareness

antivirus software

spam filters

A

Mitigation through security controls