Security Controls Flashcards

Security+

1
Q

What are detective controls used for?

A

To identify and log intrusion attempts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Give an example of a detective control.

A

Collecting and reviewing system logs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the types of assets that security controls protect?

A

Data, physical property, computer systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of preventive controls?

A

To block access to resources and prevent security events.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are corrective controls used for?

A

To apply controls after an event has been detected and reverse its impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What type of controls are firewalls and anti-virus systems?

A

Technical controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an example of an operational control?

A

Security guards or awareness programs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are physical controls designed to do?

A

Limit physical access to assets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a compensating control?

A

A control used when existing controls aren’t sufficient.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can ransomware impact be mitigated?

A

By restoring from backups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What do directive controls aim to do?

A

Direct subjects towards security compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of deterrent controls?

A

To discourage intrusion attempts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Provide an example of a directive control.

A

Guard shack checks all identification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an example of a preventive control?

A

Implementing firewall rules.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What can a well-placed warning sign act as?

A

A deterrent control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How do administrative controls contribute to security?

A

Through policies and procedures for security design and implementation.

17
Q

What are security controls?

A

Measures implemented to protect systems and data from threats.

18
Q

Why are security controls categorized?

A

To better manage and implement them based on specific needs and risks.

19
Q

Name one category of security controls.

A

Technical controls.

20
Q

What is an example of a technical control?

A

Firewalls.

21
Q

Can a security control exist in multiple categories?

A

Yes, some controls may fit multiple categories.

22
Q

Why might an organization combine types of security controls?

A

To create a more integrated security approach tailored to their needs.

23
Q

What drives the creation of new security controls?

A

The evolution of systems and processes.

24
Q

Why is it important to regularly update security controls?

A

To address emerging threats and vulnerabilities.

25
Q

What is the difference between administrative and technical controls?

A

Administrative controls focus on policies and procedures, while technical controls use technology to protect systems.

26
Q

How can an organization’s security controls vary?

A

Based on their specific environment, risks, and regulatory requirements.