Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 18 pages
Exam (elaborations)

CERTIFIED IN CYBERSECURITY ISC CC EXAM QUESTIONS AND CORRECT ANSWERS ALREADY GRADED A+

Document preview thumbnail
Preview 3 out of 18 pages

CERTIFIED IN CYBERSECURITY ISC CC EXAM QUESTIONS AND CORRECT ANSWERS ALREADY GRADED A+ CERTIFIED IN CYBERSECURITY ISC CC EXAM QUESTIONS AND CORRECT ANSWERS ALREADY GRADED A+

Content preview

CERTIFIED IN CYBERSECURITY ISC CC EXAM QUESTIONS AND CORRECT
ANSWERS ALREADY GRADED A+
Adequate Security - answer-Security commensurate with the risk and the magnitude of harm resulting
from the loss, misuse, or unauthorized access to or modification of information.



Administrative Controls - answer-Controls implemented through policy and procedures. Examples
include access control processes and requiring multiple personnel to conduct a specific operation.
Administrative controls in modern environments are often enforced in conjunction with physical and/or
technical controls, such as an access-granting policy for new users that requires login and approval by
the hiring manager.



Artificial Intelligence - answer-The ability of computers and robots to simulate human intelligence and
behavior.



Asset - answer-Anything of value that is owned by an organization. Assets include both tangible items
such as information systems and physical property and intangible assets such as intellectual property.



Authentication - answer-Access control process validating that the identity being claimed by a user or
entity is known to the system, by comparing one (single factor or SFA) or more (multi-factor
authentication or MFA) factors of identification.



Authorization - answer-The right or a permission that is granted to a system entity to access a system
resource. NIST 800-82 Rev.2



Token - answer-A physical object a user possesses and controls that is used to authenticate the user's
identity. Source: NISTIR 7711



Vulnerability - answer-Weakness in an information system, system security procedures, internal controls
or implementation that could be exploited by a threat source. Source: NIST SP 800-30 Rev 1



Threat - answer-Any circumstance or event with the potential to adversely impact organizational
operations (including mission, functions, image or reputation), organizational assets, individuals, other
organizations or the nation through an information system via unauthorized access, destruction,
disclosure, modification of information and/or denial of service. Source: NIST SP 800-30 Rev 1

,Threat Vector - answer-An individual or a group that attempts to exploit vulnerabilities to cause or force
a threat to occur.



Technical Controls - answer-Security controls (i.e., safeguards or countermeasures) for an information
system that are primarily implemented and executed by the information system through mechanisms
contained in the hardware, software or firmware components of the system.



System Integrity - answer-The quality that a system has when it performs its intended function in an
unimpaired manner, free from unauthorized manipulation of the system, whether intentional or
accidental. Source: NIST SP 800-27 Rev. A



Availability - answer-Ensuring timely and reliable access to and use of information by authorized users.



Single-Factor Authentication - answer-Use of just one of the three available factors (something you
know, something you have, something you are) to carry out the authentication process being requested.



Baseline - answer-A documented, lowest level of security configuration allowed by a standard or
organization.



State - answer-The condition an entity is in at a point in time.



Bot - answer-Malicious code that acts like a remotely controlled "robot" for an attacker, with other
Trojan and worm capabilities.



Sensitivity - answer-A measure of the importance assigned to information by its owner, for the purpose
of denoting its need for protection. Source: NIST SP 800-60 Vol 1 Rev 1



Classified or Sensitive Information - answer-Information that has been determined to require protection
against unauthorized disclosure and is marked to indicate its classified status and classification level
when in documentary form.



Risk Treatment - answer-The determination of the best way to address an identified risk.

, Confidentiality - answer-The characteristic of data or information when it is not made available or
disclosed to unauthorized persons or processes. NIST 800-66



Security Controls - answer-The management, operational and technical controls (i.e., safeguards or
countermeasures) prescribed for an information system to protect the confidentiality, integrity and
availability of the system and its information. Source: FIPS PUB 199



Criticality - answer-A measure of the degree to which an organization depends on the information or
information system for the success of a mission or of a business function. NIST SP 800-60 Vol. 1, Rev. 1



Risk Tolerance - answer-The level of risk an entity is willing to assume in order to achieve a potential
desired result. Source: NIST SP 800-32. Risk threshold, risk appetite and acceptable risk are also terms
used synonymously with risk tolerance.



Data Integrity - answer-The property that data has not been altered in an unauthorized manner. Data
integrity covers data in storage, during processing and while in transit. Source: NIST SP 800-27 Rev A



Risk Transference - answer-Paying an external party to accept the financial impact of a given risk.



General Data Protection Regulation (GDPR) - answer-In 2016, the European Union passed
comprehensive legislation that addresses personal privacy, deeming it an individual human right.



Risk Mitigation - answer-The process of identifying and analyzing risks to organizational operations
(including mission, functions, image, or reputation), organizational assets, individuals and other
organizations. The analysis performed as part of risk management which incorporates threat and
vulnerability analyses and considers mitigations provided by security controls planned or in place.



Risk Acceptance - answer-Determining that the potential benefits of a business function outweigh the
possible risk impact/likelihood and performing that business function with no other action.



Governance - answer-The process of how an organization is managed; usually includes all aspects of
how decisions are made for that organization, such as policies, roles, and procedures the organization
uses to make those decisions.

Document information

Uploaded on
March 15, 2025
Number of pages
18
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
JAYDEN254
5.0
(4223)
Sold
326
Followers
21
Items
3011
Last sold
1 day ago

Reviews from verified buyers




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions