Security+ Test Study Flashcards
What are the four security control categories?
Technical, Managerial, Operational, and Physical.
What are Technical controls?
Controls implemented using some type of technical system, for example, setting up policies and procedures in an OS that would allow or disallow different functions from occurring. Firewalls, anti-virus, and other similar software fall under this category.
What are Managerial controls?
A series of policies that explain to end users the best way to manage their computers, data, or other systems. A security policy document or manual is an example of this.
What are Operational controls?
Controls implemented and/or made by people . Security guards, awareness programs, and posters are all examples of this.
What are Physical controls?
Controls that limit physical access to a building, room or device. Locks, fences, and badge readers are examples of this.
What are the six security control types?
Preventive, Deterrent, Detective, Corrective, Compensating, and Directive.
What is a Preventive control type?
A control type that block access to a resource.
What is a Deterrent control type?
A control type that discourages an intrusion, but does not directly prevent access.
What is a Detective control type?
A control type that identifies and logs an intrusion attempt.
What is a Corrective control type?
A control type that applies a control after an event has been detected.
What is a Compensating control type?
A control type that uses other means instead to compensate for what was originally intended (Plan B).
What is a Directive control type?
A control type that directs a subject towards security compliance.
A firewall is an example of what control category and type?
Technical Preventive
Being informed you may receive a demotion for not following policy is an example of what control category and type?
Managerial Deterrent
Guards patrolling a property is an example of what control category and type?
Operational Detective
A fire extinguisher is an example of what control category and type?
Physical Corrective
Requiring multiple security staff is an example of what control category and type?
Operational Compensating
Compliance policies is an example of what control category and type?
Managerial Directive
An on-boarding policy that states what you can and can’t do with company equipment is an example of what control category and type?
Managerial Preventive
A splash screen issuing a warning is an example of what control category and type?
Technical Deterrent
Reviewing printed out login reports is an example of what control category and type?
Managerial Detective
Contacting the authorities after an incident has occurred is an example of what control category and type?
Operational Corrective
Utilizing a power generator is an example of what control category and type?
Physical Compensating
Having staff undergo security policy training is an example of what control category and type?
Operational Directive