Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 20 pages
Exam (elaborations)

ISC2 Certified in Cybersecurity (CC) Exam Domain 1 - Security Principles.

Document preview thumbnail
Preview 3 out of 20 pages

ISC2 Certified in Cybersecurity (CC)Exam Domain 1 - SecurityPrinciples. Information Security - Correct Answer Security that focuses on all of our information. This includes paper documents, voice information, data, knowledge. IT security - Correct Answer Security that focuses on the hardware and software. THis includes Computers, servers, networks, hardware, software, and data being communicated. Cybersecurity - Correct Answer Everything from IT security that is accessible on the web. Confidentiality - Correct Answer the act of holding information in confidence, not to be released to unauthorized individuals Integrity - Correct Answer How we protect modifications of the data and the systems to ensure data has not been altered.

Content preview

ISC2 Certified in Cybersecurity (CC) Exam Domain 1 -
Security Principles.

Information Security - Correct Answer Security that focuses on all of our information. This
includes paper documents, voice information, data, knowledge.


IT security - Correct Answer Security that focuses on the hardware and software. THis
includes Computers, servers, networks, hardware, software, and data being
communicated.


Cybersecurity - Correct Answer Everything from IT security that is accessible on the web.


Confidentiality - Correct Answer the act of holding information in confidence, not to be
released to unauthorized individuals


Integrity - Correct Answer How we protect modifications of the data and the systems to
ensure data has not been altered.


Availability - Correct Answer Ensure authorized people can access the data they need
when they need ti


Applications for Confidentiality - Correct Answer - Encryption for Data at rest, full disk
encyption
- Secure transport encryption protocols for data-in-motion (SSL, TLS or IPSEC)


Best practices for data-in-use - Correct Answer - Clean Desk
- No shoulder surfin
- Screen view angle protector
- PC Locking


Other factors of confidentiality - Correct Answer - Strong Passwords
- MFA
- Masking
- Access Control

,- Need-to-know
- Least Privilege


Threats to Confidentiality - Correct Answer - Attacks on encryption (cryptoanalysis)
- Social Engineering
- Key Loggers
- Cameras
- Steganography
- Internet of Things (IOT) devices


Applications for Integrity - Correct Answer - Cryptography
- Check Sums
- Message Digests
- Digital Signatures
- Non Repudiation
- Access Control


Threats to Integrity - Correct Answer - Alternations of data
- Code Injections
- Cryptoanalysis


Applications for Availability - Correct Answer - IPS / IDS
- Patch Management
- Redunancy on hardware power
- Disks (RAID)
- Traffic Paths
- Service Level Agreement (SLA)


Threats to Availability - Correct Answer - Malicious attacks (DDOS, physical, system,
compromise, staff)
- Application failures

, - Component failure


The DAD Triad - Correct Answer Disclosure;
Alteration; and,
Destruction.

Disclosure - Correct Answer Someone not authorized to access certain information


Alteration - Correct Answer Data has been changed


Destruction - Correct Answer Data or systems have been destroyed or have become
inaccessible


IAAA - Correct Answer Identification, authentication, authorization, accountability


Identification - Correct Answer Using a piece of information to identify who you are


Examples include name, username, ID, number, employe number, SSN


Authentication - Correct Answer Proving that a user is genuine, and not an imposter.


Type 1 Authentication - Correct Answer A type of authentication that requires the user to
provide something that they know, such as a password or PIN.


This is the weakest form of authentication.


key stretching - Correct Answer A technique used to increase the strength of stored
passwords. it adds additional bits (called salts) and can help thwart brute force and
rainbow table attacks.


Brute Force Attack - Correct Answer the password cracker tries every possible
combination of characters


Clipping levels - Correct Answer Put in place to prevent administrative overhead

Document information

Uploaded on
November 15, 2024
Number of pages
20
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Josejosy
5.0
(2)
Sold
9
Followers
1
Items
1856
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions