ISC2 CERTIFIED IN CYBERSECURITY (CC) EXAM:
DOMAIN 1 - SECURITY PRINCIPLES
Information Security - Answers :Security that focuses on all of our information. This
includes paper documents, voice information, data, knowledge.
IT security - Answers :Security that focuses on the hardware and software. THis
includes Computers, servers, networks, hardware, software, and data being
communicated.
Cybersecurity - Answers :Everything from IT security that is accessible on the web.
Confidentiality - Answers :the act of holding information in confidence, not to be
released to unauthorized individuals
Integrity - Answers :How we protect modifications of the data and the systems to ensure
data has not been altered.
Availability - Answers :Ensure authorized people can access the data they need when
they need ti
Applications for Confidentiality - Answers :- Encryption for Data at rest, full disk
encyption
- Secure transport encryption protocols for data-in-motion (SSL, TLS or IPSEC)
Best practices for data-in-use - Answers :- Clean Desk
- No shoulder surfin
- Screen view angle protector
- PC Locking
Other factors of confidentiality - Answers :- Strong Passwords
- MFA
- Masking
- Access Control
- Need-to-know
- Least Privilege
Threats to Confidentiality - Answers :- Attacks on encryption (cryptoanalysis)
- Social Engineering
- Key Loggers
- Cameras
- Steganography
- Internet of Things (IOT) devices
, Applications for Integrity - Answers :- Cryptography
- Check Sums
- Message Digests
- Digital Signatures
- Non Repudiation
- Access Control
Threats to Integrity - Answers :- Alternations of data
- Code Injections
- Cryptoanalysis
Applications for Availability - Answers :- IPS / IDS
- Patch Management
- Redunancy on hardware power
- Disks (RAID)
- Traffic Paths
- Service Level Agreement (SLA)
Threats to Availability - Answers :- Malicious attacks (DDOS, physical, system,
compromise, staff)
- Application failures
- Component failure
The DAD Triad - Answers :Disclosure;
Alteration; and,
Destruction.
Disclosure - Answers :Someone not authorized to access certain information
Alteration - Answers :Data has been changed
Destruction - Answers :Data or systems have been destroyed or have become
inaccessible
IAAA - Answers :Identification, authentication, authorization, accountability
Identification - Answers :Using a piece of information to identify who you are
Examples include name, username, ID, number, employe number, SSN
Authentication - Answers :Proving that a user is genuine, and not an imposter.
Type 1 Authentication - Answers :A type of authentication that requires the user to
provide something that they know, such as a password or PIN.
This is the weakest form of authentication.
DOMAIN 1 - SECURITY PRINCIPLES
Information Security - Answers :Security that focuses on all of our information. This
includes paper documents, voice information, data, knowledge.
IT security - Answers :Security that focuses on the hardware and software. THis
includes Computers, servers, networks, hardware, software, and data being
communicated.
Cybersecurity - Answers :Everything from IT security that is accessible on the web.
Confidentiality - Answers :the act of holding information in confidence, not to be
released to unauthorized individuals
Integrity - Answers :How we protect modifications of the data and the systems to ensure
data has not been altered.
Availability - Answers :Ensure authorized people can access the data they need when
they need ti
Applications for Confidentiality - Answers :- Encryption for Data at rest, full disk
encyption
- Secure transport encryption protocols for data-in-motion (SSL, TLS or IPSEC)
Best practices for data-in-use - Answers :- Clean Desk
- No shoulder surfin
- Screen view angle protector
- PC Locking
Other factors of confidentiality - Answers :- Strong Passwords
- MFA
- Masking
- Access Control
- Need-to-know
- Least Privilege
Threats to Confidentiality - Answers :- Attacks on encryption (cryptoanalysis)
- Social Engineering
- Key Loggers
- Cameras
- Steganography
- Internet of Things (IOT) devices
, Applications for Integrity - Answers :- Cryptography
- Check Sums
- Message Digests
- Digital Signatures
- Non Repudiation
- Access Control
Threats to Integrity - Answers :- Alternations of data
- Code Injections
- Cryptoanalysis
Applications for Availability - Answers :- IPS / IDS
- Patch Management
- Redunancy on hardware power
- Disks (RAID)
- Traffic Paths
- Service Level Agreement (SLA)
Threats to Availability - Answers :- Malicious attacks (DDOS, physical, system,
compromise, staff)
- Application failures
- Component failure
The DAD Triad - Answers :Disclosure;
Alteration; and,
Destruction.
Disclosure - Answers :Someone not authorized to access certain information
Alteration - Answers :Data has been changed
Destruction - Answers :Data or systems have been destroyed or have become
inaccessible
IAAA - Answers :Identification, authentication, authorization, accountability
Identification - Answers :Using a piece of information to identify who you are
Examples include name, username, ID, number, employe number, SSN
Authentication - Answers :Proving that a user is genuine, and not an imposter.
Type 1 Authentication - Answers :A type of authentication that requires the user to
provide something that they know, such as a password or PIN.
This is the weakest form of authentication.