WGU D320 UPDATED COMPREHENSIVE ALL
QUESTIONS AND ANSWERS SURE A+
✔✔Federal Information Systems Management Act (FISMA) - ✔✔is a US law that makes
mandatory requirements for federal agencies to develop, document, and implement
management cyber security. NIST plays a major role in implementing FISMA and has
promulgated numerous security standards and guidelines. One key guideline is the Risk
Management Framework (RMF). Office of Management and Budget (OMB) monitors
compliance with NIST programs.
✔✔Fiber Channel - ✔✔is a data transfer protocol used to connect servers to Storage
Area Networks (SAN) in data centers. It typically runs on fiber optic cables but can also
run on copper. Data rates range from 1 to 128 gigabit/sec.
✔✔FIPS 140-2 - ✔✔Used for protecting sensitive but unclassified information by the
federal government. The standard provides four increasing, qualitative levels of security:
Level 1, Level 2, Level 3, and Level 4. The Cryptographic Module Validation Program
(CMVP) validates cryptographic modules to Federal Information Processing Standard
(FIPS) 140-2 and other cryptography-based standards such as CMVP. The CMVP is a
joint effort between NIST and the Communications Security Establishment (CSE) of the
Government of Canada. Products validated as conforming to FIPS 140-2 are accepted
by the Federal agencies of both countries.
✔✔GDPR - General Data Protection Regulation - ✔✔gives individuals control over their
personal data. It also simplified regulation by forcing all member states to comply with a
single regulation. GDPR specifies rights of the data subject, including access
rectification, erasure, object to use of PII. It poses requirements on data controllers and
data processors.
✔✔Generally Accepted Privacy Principles described by the AICPA (GAPP) - ✔✔The
generally accepted principles and practices (GAPP), were agreed upon by 23 countries
in response to investors and regulators concerned about transparency, independence,
,and governance of the accounting industry. It was based on 24 principles in the areas of
legal, institutional, and investment and risk.
✔✔Gramm-Leach-Bliley Act (GLBA) - ✔✔requires companies that offer financial
products or services to safeguard sensitive data about customers and inform the
customers of those requirements.
✔✔Health Insurance Portability and Accountability Act (HIPAA) - ✔✔modernized
healthcare information and stipulated how PII kept by healthcare and healthcare
insurance industries should be protected. The act was vague
✔✔HITECH - ✔✔act motivated the implementation of electronic health records (HER)
and the supporting technology. Some penalties for non-compliance of HIPAA were
increased under HITEC, as well as establishing breach notification to impacted patients.
✔✔International Standards Organization (ISO) - ✔✔is an international standards body
composed of representatives from various standards organizations.
✔✔Internet Small Computer System Interface (iSCSI) - ✔✔is a storage networking
standard used to link data storage to systems using the Internet Protocol (IP).
✔✔ISO/IEC 27001 - ✔✔Standard on managing Information Security. It includes
requirements for establishing , implementing, maintaining, and continually improving
information management.
✔✔ISO/IEC 27002 - ✔✔provides best practices on information security controls for
those attempting to be ISO/IEC 27001.
✔✔ISO/IEC 27017 - ✔✔created to supplement ISO/IEC 27002 to provide additional
security controls for the cloud.
✔✔ISO/IEC 28000 - ✔✔2007: is a standard for ensuring security assurance in the
supply chain.
✔✔ISO/IEC 31000 - ✔✔2009: is a standard providing industry independent principles
and guidelines on risk management. It does not intend or attempt to achieve uniformity
but rather the most appropriate risk management for each organization for its
objectives, context, structure, operations, processes, functions, services, or assets
employed.
✔✔(ISC)2 Cloud Secure Data Life Cycle - ✔✔Based on CSA Guidance. 1. Create; 2.
Store; 3. Use; 4. Share; 5. Archive; 6. Destroy.
✔✔Key risk indicators (KRI) - ✔✔critical predictors of risks or adverse events that can
impact and organization.
, ✔✔Lightweight Directory Access Protocol (LDAP) - ✔✔environment, each entry in a
directory server is identified by a Distinguished name (DN)
✔✔Mean time between failure (MTBF) - ✔✔is the predicted time between failures of a
system during normal system operation. It applies only to unplanned maintenance and
excludes scheduled maintenance, inspection, recalibration, or prevent parts
replacement.
✔✔Mean time to repair (MTTR) - ✔✔is the mean time it takes to repair a system. It
includes both the repair time and testing time.
✔✔NIST National Institute of Standards and Technology - ✔✔is an agency of the
Department of Commerce whose mission is to promote innovation and industrial
competitiveness. It also creates numerous standard and requirements for the DoD,
Federal Government, and government contractors relating to Cyber security.
✔✔NIST SP 800-37 - ✔✔establishes the Risk Management Framework using a life
cycle approach for security and privacy. "The RMF provides a disciplined, structured,
and flexible process for managing security and privacy risk that includes information
security categorization; control selection, implementation, and assessment; system and
common control authorizations; and continuous monitoring. The RMF includes activities
to prepare organizations to execute the framework at appropriate risk management
levels. The RMF also promotes near real-time risk management and ongoing
information system and common control authorization through the implementation of
continuous monitoring processes; provides senior leaders and executives with the
necessary information to make efficient, cost-effective, risk management decisions
about the systems supporting their missions and business functions; and incorporates
security and privacy into the system development life cycle."
✔✔NIST SP 800-53 - ✔✔provides security and privacy controls for information systems
and organizations.
✔✔NIST SP 800-92 - ✔✔Guide to Computer Security Log Management "seeks to assist
organizations in understanding the need for sound computer security log management.
It provides practical, real-world guidance on developing, implementing, and maintaining
effective log management practices throughout an enterprise. The guidance in this
publication covers several topics, including establishing log management
infrastructures, and developing and performing robust log management processes
throughout an organization. The publication presents logging technologies from a high-
level viewpoint."
✔✔Open Web Application Security Project (OWASP) - ✔✔is a nonprofit organization
working to improve the security of software. They are known for their top 10 most critical
QUESTIONS AND ANSWERS SURE A+
✔✔Federal Information Systems Management Act (FISMA) - ✔✔is a US law that makes
mandatory requirements for federal agencies to develop, document, and implement
management cyber security. NIST plays a major role in implementing FISMA and has
promulgated numerous security standards and guidelines. One key guideline is the Risk
Management Framework (RMF). Office of Management and Budget (OMB) monitors
compliance with NIST programs.
✔✔Fiber Channel - ✔✔is a data transfer protocol used to connect servers to Storage
Area Networks (SAN) in data centers. It typically runs on fiber optic cables but can also
run on copper. Data rates range from 1 to 128 gigabit/sec.
✔✔FIPS 140-2 - ✔✔Used for protecting sensitive but unclassified information by the
federal government. The standard provides four increasing, qualitative levels of security:
Level 1, Level 2, Level 3, and Level 4. The Cryptographic Module Validation Program
(CMVP) validates cryptographic modules to Federal Information Processing Standard
(FIPS) 140-2 and other cryptography-based standards such as CMVP. The CMVP is a
joint effort between NIST and the Communications Security Establishment (CSE) of the
Government of Canada. Products validated as conforming to FIPS 140-2 are accepted
by the Federal agencies of both countries.
✔✔GDPR - General Data Protection Regulation - ✔✔gives individuals control over their
personal data. It also simplified regulation by forcing all member states to comply with a
single regulation. GDPR specifies rights of the data subject, including access
rectification, erasure, object to use of PII. It poses requirements on data controllers and
data processors.
✔✔Generally Accepted Privacy Principles described by the AICPA (GAPP) - ✔✔The
generally accepted principles and practices (GAPP), were agreed upon by 23 countries
in response to investors and regulators concerned about transparency, independence,
,and governance of the accounting industry. It was based on 24 principles in the areas of
legal, institutional, and investment and risk.
✔✔Gramm-Leach-Bliley Act (GLBA) - ✔✔requires companies that offer financial
products or services to safeguard sensitive data about customers and inform the
customers of those requirements.
✔✔Health Insurance Portability and Accountability Act (HIPAA) - ✔✔modernized
healthcare information and stipulated how PII kept by healthcare and healthcare
insurance industries should be protected. The act was vague
✔✔HITECH - ✔✔act motivated the implementation of electronic health records (HER)
and the supporting technology. Some penalties for non-compliance of HIPAA were
increased under HITEC, as well as establishing breach notification to impacted patients.
✔✔International Standards Organization (ISO) - ✔✔is an international standards body
composed of representatives from various standards organizations.
✔✔Internet Small Computer System Interface (iSCSI) - ✔✔is a storage networking
standard used to link data storage to systems using the Internet Protocol (IP).
✔✔ISO/IEC 27001 - ✔✔Standard on managing Information Security. It includes
requirements for establishing , implementing, maintaining, and continually improving
information management.
✔✔ISO/IEC 27002 - ✔✔provides best practices on information security controls for
those attempting to be ISO/IEC 27001.
✔✔ISO/IEC 27017 - ✔✔created to supplement ISO/IEC 27002 to provide additional
security controls for the cloud.
✔✔ISO/IEC 28000 - ✔✔2007: is a standard for ensuring security assurance in the
supply chain.
✔✔ISO/IEC 31000 - ✔✔2009: is a standard providing industry independent principles
and guidelines on risk management. It does not intend or attempt to achieve uniformity
but rather the most appropriate risk management for each organization for its
objectives, context, structure, operations, processes, functions, services, or assets
employed.
✔✔(ISC)2 Cloud Secure Data Life Cycle - ✔✔Based on CSA Guidance. 1. Create; 2.
Store; 3. Use; 4. Share; 5. Archive; 6. Destroy.
✔✔Key risk indicators (KRI) - ✔✔critical predictors of risks or adverse events that can
impact and organization.
, ✔✔Lightweight Directory Access Protocol (LDAP) - ✔✔environment, each entry in a
directory server is identified by a Distinguished name (DN)
✔✔Mean time between failure (MTBF) - ✔✔is the predicted time between failures of a
system during normal system operation. It applies only to unplanned maintenance and
excludes scheduled maintenance, inspection, recalibration, or prevent parts
replacement.
✔✔Mean time to repair (MTTR) - ✔✔is the mean time it takes to repair a system. It
includes both the repair time and testing time.
✔✔NIST National Institute of Standards and Technology - ✔✔is an agency of the
Department of Commerce whose mission is to promote innovation and industrial
competitiveness. It also creates numerous standard and requirements for the DoD,
Federal Government, and government contractors relating to Cyber security.
✔✔NIST SP 800-37 - ✔✔establishes the Risk Management Framework using a life
cycle approach for security and privacy. "The RMF provides a disciplined, structured,
and flexible process for managing security and privacy risk that includes information
security categorization; control selection, implementation, and assessment; system and
common control authorizations; and continuous monitoring. The RMF includes activities
to prepare organizations to execute the framework at appropriate risk management
levels. The RMF also promotes near real-time risk management and ongoing
information system and common control authorization through the implementation of
continuous monitoring processes; provides senior leaders and executives with the
necessary information to make efficient, cost-effective, risk management decisions
about the systems supporting their missions and business functions; and incorporates
security and privacy into the system development life cycle."
✔✔NIST SP 800-53 - ✔✔provides security and privacy controls for information systems
and organizations.
✔✔NIST SP 800-92 - ✔✔Guide to Computer Security Log Management "seeks to assist
organizations in understanding the need for sound computer security log management.
It provides practical, real-world guidance on developing, implementing, and maintaining
effective log management practices throughout an enterprise. The guidance in this
publication covers several topics, including establishing log management
infrastructures, and developing and performing robust log management processes
throughout an organization. The publication presents logging technologies from a high-
level viewpoint."
✔✔Open Web Application Security Project (OWASP) - ✔✔is a nonprofit organization
working to improve the security of software. They are known for their top 10 most critical