WGU D430 FUNDAMENTALS OF INFORMATION
SECURITY TEST 6 EXAM REVIEW SOLVED
QUESTIONS WITH ACCURATE ANSWERS
◉ Technical/ logical controls.
Answer: Controls are devices and software that protect assets. Think
of firewalls, av, ids, and ips
◉ Administrative controls.
Answer: Controls are the policies that organizations create for
governance. Ex: email policies
◉ risk mamagement.
Answer: A constant process as assets are purchased, used and
retired. The general steps are 1- identify assets
2- identify threats
3- assess vulnerabilities
4- assess risk
5- mitigating risks
◉ Identify assets.
,Answer: First and most important part or risk management.
Identifying and categorizing the assets we are protecting
◉ Identify threats.
Answer: Once we have our critical assets we can identify the threats
that might effect them
◉ Assess Vulnerabilities.
Answer: Look at potential threats. any given asset may have
thousand or millions of threats that could impact it, but only a small
fraction of the threats will be relevant
◉ Assess risks.
Answer: Once we have identified the threats and vulnerabilities for a
given asset we can access the overall risk
◉ Mitigating risks.
Answer: Putting measures in place to help ensure that a given type
of threat is accounted for
◉ Incident response.
Answer: Response to when risk management practices have failed
and have cause an inconvenience to a disastrous event
,◉ Incident response cycle.
Answer: 1 preparation
2- detection and analysis
3- containment
4- eradication
5- recovery
6- post incident activity
◉ Preparation phase.
Answer: The preparation phase consists of all of the activities that
we can preform in advance of the incident itself in order to better
enable us to handle it
◉ Detection and analysis phase.
Answer: Where the action begins to happen. We will detect the
occurrence of an issue and decide whether or not it is actually an
incident so that we can respond
◉ Containment phase.
Answer: Taking steps to ensure that the situation does not cause any
more damage than it already has, or to at least lessen any ongoing
harm.
, ◉ Eradication phase.
Answer: We will attempt to remove the effects of the issue from our
environment
◉ Recovery phase.
Answer: Recover to a better state that we were prior to the incident
or perhaps prior to when the issue started if we did not detect it
immediately
◉ Post incident activity phase.
Answer: We attempt to determine specifically what happened, why
it happened, and what we can do to keep it from happening again.
◉ Defense in depth.
Answer: Layering of security controls is more effective and secure
than relying on a single control
◉ Identity.
Answer: Who or what we claim to be ( username)
◉ Authentication.
Answer: The act of proving who or what we claim to be (password)
SECURITY TEST 6 EXAM REVIEW SOLVED
QUESTIONS WITH ACCURATE ANSWERS
◉ Technical/ logical controls.
Answer: Controls are devices and software that protect assets. Think
of firewalls, av, ids, and ips
◉ Administrative controls.
Answer: Controls are the policies that organizations create for
governance. Ex: email policies
◉ risk mamagement.
Answer: A constant process as assets are purchased, used and
retired. The general steps are 1- identify assets
2- identify threats
3- assess vulnerabilities
4- assess risk
5- mitigating risks
◉ Identify assets.
,Answer: First and most important part or risk management.
Identifying and categorizing the assets we are protecting
◉ Identify threats.
Answer: Once we have our critical assets we can identify the threats
that might effect them
◉ Assess Vulnerabilities.
Answer: Look at potential threats. any given asset may have
thousand or millions of threats that could impact it, but only a small
fraction of the threats will be relevant
◉ Assess risks.
Answer: Once we have identified the threats and vulnerabilities for a
given asset we can access the overall risk
◉ Mitigating risks.
Answer: Putting measures in place to help ensure that a given type
of threat is accounted for
◉ Incident response.
Answer: Response to when risk management practices have failed
and have cause an inconvenience to a disastrous event
,◉ Incident response cycle.
Answer: 1 preparation
2- detection and analysis
3- containment
4- eradication
5- recovery
6- post incident activity
◉ Preparation phase.
Answer: The preparation phase consists of all of the activities that
we can preform in advance of the incident itself in order to better
enable us to handle it
◉ Detection and analysis phase.
Answer: Where the action begins to happen. We will detect the
occurrence of an issue and decide whether or not it is actually an
incident so that we can respond
◉ Containment phase.
Answer: Taking steps to ensure that the situation does not cause any
more damage than it already has, or to at least lessen any ongoing
harm.
, ◉ Eradication phase.
Answer: We will attempt to remove the effects of the issue from our
environment
◉ Recovery phase.
Answer: Recover to a better state that we were prior to the incident
or perhaps prior to when the issue started if we did not detect it
immediately
◉ Post incident activity phase.
Answer: We attempt to determine specifically what happened, why
it happened, and what we can do to keep it from happening again.
◉ Defense in depth.
Answer: Layering of security controls is more effective and secure
than relying on a single control
◉ Identity.
Answer: Who or what we claim to be ( username)
◉ Authentication.
Answer: The act of proving who or what we claim to be (password)