WGU D320 EVALUATION TEST ALL QUESTIONS
AND ANSWERS SURE A+
✔✔Risk Management Framework (RMF) - ✔✔is a set of standards and guidelines to
develop a risk-based approach to Information Security. It helps and organization
prepare for risk management, categorize systems and information based on impact
studies, select appropriate controls based on risk assessments, implement and
document the controls, assess how well the controls work, authorize the system to
operate, and monitor controls and changes to the risks to the system.
✔✔RPO Recovery Point Objective - ✔✔refers to how much data can be lost before that
loss causes significant harm to the business. This often drives backup and real-time
duplication requirements.
✔✔RTO - ✔✔is the maximum time after an outage of a computer or other resource to
resume normal business operations.
✔✔SABSA - ✔✔stands for Sherwood Applied Business Security Architecture, which is a
framework for enterprise security architecture and service management.
✔✔SEC - ✔✔is the US Securities and Exchange Commission whose primary purpose is
to combat market manipulation. It also enforces the Sarbanes-Oxley Act.
✔✔SOC 1 Report - ✔✔This report focuses on controls associated with financial
services.
✔✔SOC 2 Type 2 Report - ✔✔the SOC 2 reports are composed of five principles:
confidentiality, processing integrity, availability, privacy, and security.
✔✔SOC 3 Report - ✔✔is an attestation report or can be called a seal of approval. It
lacks financial or security data but only attests that an audit was performed.
,✔✔Storage area networks (SAN) - ✔✔is a dedicated, high-speed network that connects
shared pools of storage to multiple servers.
✔✔STRIDE Model - ✔✔STRIDE is a threat model while DREAD is a risk assessment
model. STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of service, Elevation of privilege.
✔✔System and Organization Controls (SOC) reports - ✔✔help companies establish
trust and confidence in service delivery and controls. The reports are produced by third
party certified public accountants.
✔✔US Office of Management and Budget (OMB) - ✔✔is a component of the Executive
branch. Of import to us, they manage FedRAMP and direct it's used for the Federal
Governments use of the Cloud.
✔✔Uptime Institute - ✔✔has created and promoted the Tier Standard which guides the
design, construction, and operation of sites world-wide. A data center can be rated from
Tier 1, the lowest to Tier 4 based on built-in redundancy, distribution paths, concurrent
maintenance, fault tolerance, compartmentalization, and cooling.
✔✔USPTO - ✔✔is the US Patent and Trademark Office which registers both.
✔✔Business Impact Analysis (BIA) - ✔✔- Determine the value of the assets that are
protected to know how much time, money, and effort to expend to protect them.
✔✔SPOF - ✔✔- Single Point of Failure
✔✔Quantitative - ✔✔- Risk assessment that uses specific numerical values
✔✔Qualitative - ✔✔- Risk assessment that uses nonnumerical categories that are
relative in nature, such as high, medium, and low.
✔✔Risk appetite - ✔✔- level, amount, or type of risk that the organization finds
acceptable
✔✔Residual risk - ✔✔- The leftover risk left after applying countermeasures and
controls
✔✔IAAS - ✔✔- Cloud customer has the most responsibility and authority. Cloud
provider is only liable for the underlying hardware.
✔✔PAAS - ✔✔- Cloud customer still loses more control because the cloud provider is
responsible for installing, maintaining, and administering the OS as well as underlying
hardware.
, ✔✔SAAS - ✔✔- Cloud customer loses all control of the environment. Cloud provider is
responsible for all of the underlying hardware and software.
✔✔Homomorphic encryption - ✔✔- The process of processing data in the cloud while
it's encrypted (without having to decrypt), never exposing it temporarily other than
authorized users
✔✔Defense in depth - ✔✔- practice of having multiple overlapping means of securing
an environment with a variety of methods. Includes a blend of administrative, logical,
technical, and physical controls.
✔✔Data owner - ✔✔- organization that has collected or created the data
✔✔Data custodian - ✔✔- person or entity that is tasked with the daily maintenance and
administration of the data
✔✔Data processor - ✔✔- Anything that can be done to data: copying it, printing it,
destroying it, utilizing it
✔✔Data discovery - ✔✔- term that can be used to refer to several kinds of tasks; it
might mean the organization is attempting to create an initial inventory of data or that
the organization is involved in electronic discovery (e-discovery, legal terms of collecting
electronic data as part of a lawsuit or investigation)
✔✔Label-based discovery - ✔✔- labels created by the data owner greatly aid any
discovery
✔✔Metadata-based discovery - ✔✔- data about data, metadata is a listing of traits and
characteristics about specific data elements and sets.
✔✔Content-based discovery - ✔✔- discovery tools can be used to discover data by
delving into the content of datasets without labels or metadata assigned.
✔✔Structured data - ✔✔- data that is sorted according to meaningful, discrete types
and attributes.
✔✔Unstructured data - ✔✔- content of various emails in a user's sent folder
✔✔IRM (Information Rights Management) - ✔✔- the use of specific controls that act in
concert with or in addition to the organization's other access control mechanisms to
protect certain types of assets, usually at the file level
AND ANSWERS SURE A+
✔✔Risk Management Framework (RMF) - ✔✔is a set of standards and guidelines to
develop a risk-based approach to Information Security. It helps and organization
prepare for risk management, categorize systems and information based on impact
studies, select appropriate controls based on risk assessments, implement and
document the controls, assess how well the controls work, authorize the system to
operate, and monitor controls and changes to the risks to the system.
✔✔RPO Recovery Point Objective - ✔✔refers to how much data can be lost before that
loss causes significant harm to the business. This often drives backup and real-time
duplication requirements.
✔✔RTO - ✔✔is the maximum time after an outage of a computer or other resource to
resume normal business operations.
✔✔SABSA - ✔✔stands for Sherwood Applied Business Security Architecture, which is a
framework for enterprise security architecture and service management.
✔✔SEC - ✔✔is the US Securities and Exchange Commission whose primary purpose is
to combat market manipulation. It also enforces the Sarbanes-Oxley Act.
✔✔SOC 1 Report - ✔✔This report focuses on controls associated with financial
services.
✔✔SOC 2 Type 2 Report - ✔✔the SOC 2 reports are composed of five principles:
confidentiality, processing integrity, availability, privacy, and security.
✔✔SOC 3 Report - ✔✔is an attestation report or can be called a seal of approval. It
lacks financial or security data but only attests that an audit was performed.
,✔✔Storage area networks (SAN) - ✔✔is a dedicated, high-speed network that connects
shared pools of storage to multiple servers.
✔✔STRIDE Model - ✔✔STRIDE is a threat model while DREAD is a risk assessment
model. STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of service, Elevation of privilege.
✔✔System and Organization Controls (SOC) reports - ✔✔help companies establish
trust and confidence in service delivery and controls. The reports are produced by third
party certified public accountants.
✔✔US Office of Management and Budget (OMB) - ✔✔is a component of the Executive
branch. Of import to us, they manage FedRAMP and direct it's used for the Federal
Governments use of the Cloud.
✔✔Uptime Institute - ✔✔has created and promoted the Tier Standard which guides the
design, construction, and operation of sites world-wide. A data center can be rated from
Tier 1, the lowest to Tier 4 based on built-in redundancy, distribution paths, concurrent
maintenance, fault tolerance, compartmentalization, and cooling.
✔✔USPTO - ✔✔is the US Patent and Trademark Office which registers both.
✔✔Business Impact Analysis (BIA) - ✔✔- Determine the value of the assets that are
protected to know how much time, money, and effort to expend to protect them.
✔✔SPOF - ✔✔- Single Point of Failure
✔✔Quantitative - ✔✔- Risk assessment that uses specific numerical values
✔✔Qualitative - ✔✔- Risk assessment that uses nonnumerical categories that are
relative in nature, such as high, medium, and low.
✔✔Risk appetite - ✔✔- level, amount, or type of risk that the organization finds
acceptable
✔✔Residual risk - ✔✔- The leftover risk left after applying countermeasures and
controls
✔✔IAAS - ✔✔- Cloud customer has the most responsibility and authority. Cloud
provider is only liable for the underlying hardware.
✔✔PAAS - ✔✔- Cloud customer still loses more control because the cloud provider is
responsible for installing, maintaining, and administering the OS as well as underlying
hardware.
, ✔✔SAAS - ✔✔- Cloud customer loses all control of the environment. Cloud provider is
responsible for all of the underlying hardware and software.
✔✔Homomorphic encryption - ✔✔- The process of processing data in the cloud while
it's encrypted (without having to decrypt), never exposing it temporarily other than
authorized users
✔✔Defense in depth - ✔✔- practice of having multiple overlapping means of securing
an environment with a variety of methods. Includes a blend of administrative, logical,
technical, and physical controls.
✔✔Data owner - ✔✔- organization that has collected or created the data
✔✔Data custodian - ✔✔- person or entity that is tasked with the daily maintenance and
administration of the data
✔✔Data processor - ✔✔- Anything that can be done to data: copying it, printing it,
destroying it, utilizing it
✔✔Data discovery - ✔✔- term that can be used to refer to several kinds of tasks; it
might mean the organization is attempting to create an initial inventory of data or that
the organization is involved in electronic discovery (e-discovery, legal terms of collecting
electronic data as part of a lawsuit or investigation)
✔✔Label-based discovery - ✔✔- labels created by the data owner greatly aid any
discovery
✔✔Metadata-based discovery - ✔✔- data about data, metadata is a listing of traits and
characteristics about specific data elements and sets.
✔✔Content-based discovery - ✔✔- discovery tools can be used to discover data by
delving into the content of datasets without labels or metadata assigned.
✔✔Structured data - ✔✔- data that is sorted according to meaningful, discrete types
and attributes.
✔✔Unstructured data - ✔✔- content of various emails in a user's sent folder
✔✔IRM (Information Rights Management) - ✔✔- the use of specific controls that act in
concert with or in addition to the organization's other access control mechanisms to
protect certain types of assets, usually at the file level