/
Fundamentals of Cybersecurity Controls and IAM
Save to my account
Sign up
Fundamentals of Cybersecurity Controls and IAM
Fundamentals of Cybersecurity Controls and IAM
Study
1
Question
What are the four pillars of the CIA triad usually listed in order?
Answer
Confidentiality, Integrity, Availability (CIA)
2
Question
What is the primary security goal of confidentiality?
Answer
Keep information private and protected from unauthorized access
3
Question
What is the primary security goal of integrity?
Answer
Keep information accurate and unmodified by unauthorized actions
4
Question
What is the primary security goal of availability?
Answer
Ensure systems operate continuously and data is accessible to authorized users
5
Question
What does non-repudiation ensure in data and transmissions?
Answer
Sender/creator cannot deny sending or creating data
6
Question
Which organization develops standards used by US federal agencies and publishes best practices?
Answer
NIST (National Institute of Standards and Technology)
7
Question
What are cybersecurity frameworks (CSF) used for?
Answer
Standards, best practices, guidelines for security risk management
8
Question
What are security controls?
Answer
Technologies or procedures to mitigate vulnerabilities and ensure CIA
9
Question
What is a gap analysis used for?
Answer
Measure difference between current and desired states to scope work
10
Question
What does IAM stand for and what does it provide?
Answer
Identity and Access Management; identification, authentication, authorization for assets
11
Question
What is Identification in IAM?
Answer
Process of issuing a user account and credentials to the correct person
12
Question
What is Authentication in IAM?
Answer
Validating a entity’s or individual’s credentials
13
Question
What is Authorization in IAM?
Answer
Determining rights and privileges of an entity
14
Question
What is Accounting in IAM?
Answer
Tracking usage and alerting on unauthorized use
15
Question
What does AAA stand for in security contexts?
Answer
Authentication, Authorization, and Accounting
16
Question
What is a security control?
Answer
A technology or procedure to protect CIA of information
17
Question
What is managerial security control focused on?
Answer
Oversight, risk identification, and evaluation of controls
18
Question
What is operational security control?
Answer
Controls implemented by people (processes) rather than tech alone
19
Question
What is a technical security control?
Answer
Controls implemented as hardware/software/firmware (e.g., firewall)
20
Question
What are physical security controls?
Answer
Alarms, locks, cameras; deter and detect access to premises/hardware
21
Question
What is preventive security control?
Answer
Act before an incident to reduce likelihood of attack
22
Question
What is an access control list (ACL)?
Answer
Collection of ACEs determining access rights to an object
23
Question
What does an ACE in an ACL specify?
Answer
Whether an subject is allowed or denied access and with which privileges
24
Question
What does authentication validate?
Answer
A entity's or individual's credentials
25
Question
What is authorization in security terms?
Answer
Determining rights and privileges of an entity
26
Question
Define accounting in security context.
Answer
Tracking authorized usage and detecting unauthorized use
27
Question
What does AAA stand for in IAM?
Answer
Authentication, Authorization, and Accounting
28
Question
What is a security control?
Answer
A technology/procedure to mitigate risk and protect CIA triad
29
Question
What is a managerial security control?
Answer
Oversight activities like risk identification and control evaluation
30
Question
What is an operational security control?
Answer
Controls implemented by people (procedures, processes)