CYBR 7300 Exam 1 Questions with Correct
Answers
Assets
Organizational resource that is being protected. Can be logical, such as a website, software,
etc; or an asset can be physical such as a person, computer system, etc. assets are the focus of
what security efforts are aiming to protect
Information assets
Any collection, set, or database of information or any asset that collects, stores, processes, or
transmits information of value to the organization.
Security
A state of being free from danger or harm. Also, the actions taken to make someone or
something secure
Information security
Focuses on the protection of info and the characteristics that give it value, such as
confidentiality, integrity and availability
McCumber Cube
A graphical representation of the architectural approach widely used in computer and
information security. Adaptation of the NSTISSI model, serves as the standard for
understanding many aspects of InfoSec
CIA Triad
,The industry standard for computer security since the development of the mainframe. The
standard is based on three characteristics that describe the utility of information:
confidentiality, integrity, and availability.
Confidentiality
An attribute of information that describes how data is protected from disclosure or exposure
to unauthorized individuals or systems.
Disclosure
The intentional or unintentional exposure of an information asset to unauthorized parties
Integrity
An attribute of information that describes how data is whole, complete, and uncorrupted; I.e.
how usable is the data
Availability
An attribute of information that describes how data is accessible and correctly formatted for
use without interference or obstruction.
Privacy
The right of individuals or groups to protect themselves and their information from
unauthorized access, providing confidentiality
Information aggregation
The collection and combination of pieces of nonprivate data, which could result in
information that violates privacy. Not to be confused with aggregate information.
Identification
, The access control mechanism whereby unverified entities who seek access to a resource
provide a label by which they are first known the the system
Authentication
The access control mechanism that requires the validation and verification of an
unauthenticated entity's purported identity.
Authorization
The access control mechanism that represents the matching of an authenticated entity to a list
of information assets and corresponding access levels.
Accountability
Access control mechanism that ensures all actions on a system- authorized or otherwise- can
be attributed to an authenticated identity
Types of Access Controls
Identification, Authentication, Authorization, accountability
Threat
Any event or circumstance that has the potential to adversely affect operations and assets.
Attack
An intentional or unintentional act that can damage or otherwise compromise information and
the systems that support it.
Threat agent
the specific instance or a component of a threat
Exploit
Answers
Assets
Organizational resource that is being protected. Can be logical, such as a website, software,
etc; or an asset can be physical such as a person, computer system, etc. assets are the focus of
what security efforts are aiming to protect
Information assets
Any collection, set, or database of information or any asset that collects, stores, processes, or
transmits information of value to the organization.
Security
A state of being free from danger or harm. Also, the actions taken to make someone or
something secure
Information security
Focuses on the protection of info and the characteristics that give it value, such as
confidentiality, integrity and availability
McCumber Cube
A graphical representation of the architectural approach widely used in computer and
information security. Adaptation of the NSTISSI model, serves as the standard for
understanding many aspects of InfoSec
CIA Triad
,The industry standard for computer security since the development of the mainframe. The
standard is based on three characteristics that describe the utility of information:
confidentiality, integrity, and availability.
Confidentiality
An attribute of information that describes how data is protected from disclosure or exposure
to unauthorized individuals or systems.
Disclosure
The intentional or unintentional exposure of an information asset to unauthorized parties
Integrity
An attribute of information that describes how data is whole, complete, and uncorrupted; I.e.
how usable is the data
Availability
An attribute of information that describes how data is accessible and correctly formatted for
use without interference or obstruction.
Privacy
The right of individuals or groups to protect themselves and their information from
unauthorized access, providing confidentiality
Information aggregation
The collection and combination of pieces of nonprivate data, which could result in
information that violates privacy. Not to be confused with aggregate information.
Identification
, The access control mechanism whereby unverified entities who seek access to a resource
provide a label by which they are first known the the system
Authentication
The access control mechanism that requires the validation and verification of an
unauthenticated entity's purported identity.
Authorization
The access control mechanism that represents the matching of an authenticated entity to a list
of information assets and corresponding access levels.
Accountability
Access control mechanism that ensures all actions on a system- authorized or otherwise- can
be attributed to an authenticated identity
Types of Access Controls
Identification, Authentication, Authorization, accountability
Threat
Any event or circumstance that has the potential to adversely affect operations and assets.
Attack
An intentional or unintentional act that can damage or otherwise compromise information and
the systems that support it.
Threat agent
the specific instance or a component of a threat
Exploit