UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS
A NON-REGULATORY agency of the United States Department of COMMERCE that offers an
incredible variety of standards - CORRECT ANSWER A non-regulatory agency of the United
States Department of Commerce that offers an incredible variety of standards
Internet Engineering Task Force (IETF) - CORRECT ANSWER Develops and promotes
INTERNET standards that may be voluntarily adopted throughout the industry.
At one time supported by the federal government, it now performs a standards development function
under the Internet Society
Institute of Electrical and Electronics Engineers (IEEE) - CORRECT ANSWER Professional
organization for the advancement of computer engineering and computer science, among other
aspects of electronics and communications. As one of the leading standards organizations, it is
responsible for the 802 group of standards
American National Standards Institute (ANSI) - CORRECT ANSWER A NONPROFIT
ORGANIZATION that oversees the development of STANDARDS that are approved by consensus
and are applied on a voluntary basis across a given industry.
Manages and maintains the ASCII standard
World Wide Web Consortium (W3C) - CORRECT ANSWER Standards organization in which
members, staff, and the public collaborate to develop web standards. The web technologies include
the recommended implementation of Cascading Style Sheets and XHTML, among many other
recommendations
International Organization for Standardization (ISO) - CORRECT ANSWER A true standards
organization. It tests various products and provides its seal of approval once they pass rigorous tests.
The organization administers over 13,000 standards across many industries.
,Telecommunications Industry Association (TIA) - CORRECT ANSWER Accredited by the
American National Standards Institute (ANSI) to develop voluntary, consensus-based industry
standards for a wide variety of information and communication technologies (ICT) products and
currently represents nearly 400 companies
SANS Institute - CORRECT ANSWER A private company formed in 1989 that provides
training to the cyber security industry
Security Triad - CORRECT ANSWER Confidentiality
Availability
Integrity
The Primary Security Categories - CORRECT ANSWER Prevention
Detection
Recovery
Access Control Steps - CORRECT ANSWER Identification
Authentication
Authorization
Accounting
Auditing
Risk - CORRECT ANSWER A chance of damage or loss based upon the exposure to a
potential hazard or threat.
Threat Vector - CORRECT ANSWER A path that an attacker might take to take advantage of a
vulnerability and do harm
Prudent Man Concept - CORRECT ANSWER Refers to actions that may be REASONABLY
TAKEN (or are obvious) to safeguard corporate assets and data
Components of Risk - CORRECT ANSWER Threat
,Vulnerability
Controls
Threat - CORRECT ANSWER Any incident or action that, if carried out, could cause harm or
loss of data or an asset.
Vulnerabilities - CORRECT ANSWER Weaknesses that may be penetrated or exploited by an
attacker
Controls - CORRECT ANSWER Used to reduce the possibility that a threat will exploit a
vulnerability
Types of Access Controls - CORRECT ANSWER Physical
Administrative
Logical
Due Diligence - CORRECT ANSWER ENSURING that the CONTROLS put into place are
functioning ADEQUATELY.
May also be referred to as ASSUREDNESS.
Due Care - CORRECT ANSWER The actions that a PRUDENT and REASONABLE person
would make to protect an organization's assets
Categories of Assets - CORRECT ANSWER Physical Resources
Data
Data - CORRECT ANSWER Contents placed on the company network and storage devices
Concept of Least Privilege - CORRECT ANSWER Refers to granting the least amount of
access rights and permissions required to perform a task.
, The Three As of Accounting - CORRECT ANSWER Authentication
Authorization
Accounting
Mandatory Vacation - CORRECT ANSWER A security technique that allows for the review of
employee activities.
Separation of Duties - CORRECT ANSWER Ensures that no one person has too much power
or ¬control
M of N Requirement - CORRECT ANSWER Requires a certain number of individuals to agree
prior to action being taken. M represents the minimum number of individuals that must agree on a
course of action. N represents the total number individuals involved.
Two-Man Rule - CORRECT ANSWER A procedure popular in very high-security locations
and situations. It features two individuals who must agree upon action yet are physically separated
and must therefore take action independent of the other
Types of Security Awareness Education Programs - CORRECT ANSWER New Hire
Orientation
Mandatory Security Training
Corporate-Wide Security Training
Specialty Security Training
Mitigation - CORRECT ANSWER The act of limiting risk
Physical Controls - CORRECT ANSWER Restrict or prohibit access to the physical
components of the infrastructure; usually independent of computer hardware, software, and
communication systems
Usually the first line of defense
Include doors, locks, and fences.