click below
click below
Normal Size Small Size show me how
Unit exam 1&2
| Term | Definition |
|---|---|
| Which CIA Triad component ensures data is only accessible to authorized users? | Confidentiality |
| Which CIA component ensures data has not been altered without authorization? | Integrity |
| Which security property ensures systems are accessible when needed? | Availability |
| Non-repudiation provides: | Proof an action occurred |
| Which NIST function focuses on asset inventories and risk assessment? | Identify |
| Which NIST function focuses on monitoring for malicious activity? | Detect |
| Gap analysis compares current security capabilities against: | Framework requirements |
| Authentication is the process of: | Proving identity |
| Authorization determines: | What a user can access |
| Accounting refers to: | Tracking actions |
| A firewall is a: | Technical control |
| Security guards are primarily which type of control? | Operational |
| Access logs are best classified as | Detective |
| Backups are commonly considered: | Corrective |
| Warning signs are examples of: | Deterrent controls |
| Who has overall responsibility for IT operations? | CIO |
| A SOC primarily performs: | Security monitoring |
| Risk is generally created when: | Threats exploit vulnerabilities |
| An employee stealing company data is a(n): | Insider threat |
| Unauthorized transfer of data is known as: | Exfiltration |
| APT stands for: | Advanced Persistent Threat |
| Shadow IT involves: | Unauthorized technology use |
| A vulnerability exploited over a network is a: | Remote exploit |
| Leaving default credentials unchanged can create: | A threat vector |
| Typosquatting relies on: | Misspelled domains |
| An employee receives an email appearing to be from Microsoft asking them to verify credentials. The email contains a suspicious link. Identify the attack and one security control that could help prevent it. | Phishing; user awareness training, email filtering, or MFA |
| A company must continue using unsupported software critical to operations. Explain the primary risk and identify an appropriate compensating control. | Primary risk: unpatched vulnerabilities; compensating control: network segmentation/isolation |
| A former contractor can still access cloud resources two weeks after leaving the organization. Identify the threat and the IAM process failure. | Insider threat; failure in access revocation/deprovisioning |
| A supplier is breached, and attacker credentials are used to access your organization. What attack surface was exploited? | Supply-chain attack surface |
| Employees begin receiving text messages directing them to a fake login page. Identify the attack type and two indicators that suggest it is malicious. | SMiShing; indicators: suspicious URL, urgency/pressure, unexpected request |
| Confidentiality | Keeping information private and accessible only to authorized users |
| Integrity | Ensuring data stays accurate and unaltered |
| Availability | Ensuring systems and data are accessible when needed |
| Non-repudiation | Preventing denial of having performed an action |
| Gap Analysis | Comparing current state to desired security state |
| Authentication | Verifying a user's claimed identity |
| Authorization | Granting permissions to access specific resources |
| Accounting | Tracking user actions and resource usage |
| Threat Vector | Path or method used to deliver an attack |
| Pretexting | Using a fabricated scenario to manipulate someone |