Certified in Cyber security ISC CC
Questions Answers
Adequate nSecurity n- nCorrect n nAnswer n- nSecurity ncommensurate nwith nthe nrisk nand nthe
nmagnitude nof nharm nresulting nfrom nthe nloss, nmisuse, nor nunauthorized naccess nto nor
nmodification nof ninformation.
Administrative nControls n- nCorrect n nAnswer n- nControls nimplemented nthrough npolicy nand
nprocedures. nExamples ninclude naccess ncontrol nprocesses nand nrequiring nmultiple npersonnel
nto nconduct na nspecific noperation. nAdministrative ncontrols nin nmodern nenvironments nare
noften nenforced nin nconjunction nwith nphysical nand/or ntechnical ncontrols, nsuch nas nan
naccess-granting npolicy nfor nnew nusers nthat nrequires nlogin nand napproval nby nthe nhiring
nmanager.
Artificial nIntelligence n- nCorrect n nAnswer n- nThe nability nof ncomputers nand nrobots nto
nsimulate nhuman nintelligence nand nbehavior.
Asset n- nCorrect n nAnswer n- nAnything nof nvalue nthat nis nowned nby nan norganization. nAssets
ninclude nboth ntangible nitems nsuch nas ninformation nsystems nand nphysical nproperty nand
nintangible nassets nsuch nas nintellectual nproperty.
Authentication n- nCorrect n nAnswer n- nAccess ncontrol nprocess nvalidating nthat nthe nidentity
nbeing nclaimed nby na nuser nor nentity nis nknown nto nthe nsystem, nby ncomparing none n(single
nfactor nor nSFA) nor nmore n(multi-factor nauthentication nor nMFA) nfactors nof nidentification.
Authorization n- nCorrect n nAnswer n- nThe nright nor na npermission nthat nis ngranted nto na
nsystem nentity nto naccess na nsystem nresource. nNIST n800-82 nRev.2
Token n- nCorrect n nAnswer n- nA nphysical nobject na nuser npossesses nand ncontrols nthat nis
nused nto nauthenticate nthe nuser's nidentity. nSource: nNISTIR n7711
Vulnerability n- nCorrect n nAnswer n- nWeakness nin nan ninformation nsystem, nsystem nsecurity
nprocedures, ninternal ncontrols nor nimplementation nthat ncould nbe nexploited nby na nthreat
nsource. nSource: nNIST nSP n800-30 nRev n1
Threat n- nCorrect n nAnswer n- nAny ncircumstance nor nevent nwith nthe npotential nto nadversely
nimpact norganizational noperations n(including nmission, nfunctions, nimage nor nreputation),
norganizational nassets, nindividuals, nother norganizations nor nthe nnation nthrough nan
,ninformation nsystem nvia nunauthorized naccess, ndestruction, ndisclosure, nmodification nof
ninformation nand/or ndenial nof nservice. nSource: nNIST nSP n800-30 nRev n1
Threat nVector n- nCorrect n nAnswer n- nAn nindividual nor na ngroup nthat nattempts nto nexploit
nvulnerabilities nto ncause nor nforce na nthreat nto noccur.
Technical nControls n- nCorrect n nAnswer n- nSecurity ncontrols n(i.e., nsafeguards nor
ncountermeasures) nfor nan ninformation nsystem nthat nare nprimarily nimplemented nand
nexecuted nby nthe ninformation nsystem nthrough nmechanisms ncontained nin nthe nhardware,
nsoftware nor nfirmware ncomponents nof nthe nsystem.
System nIntegrity n- nCorrect n nAnswer n- nThe nquality nthat na nsystem nhas nwhen nit nperforms
nits nintended nfunction nin nan nunimpaired nmanner, nfree nfrom nunauthorized nmanipulation nof
nthe nsystem, nwhether nintentional nor naccidental. nSource: nNIST nSP n800-27 nRev. nA
Availability n- nCorrect n nAnswer n- nEnsuring ntimely nand nreliable naccess nto nand nuse nof
ninformation nby nauthorized nusers.
Single-Factor nAuthentication n- nCorrect n nAnswer n- nUse nof njust none nof nthe nthree navailable
nfactors n(something nyou nknow, nsomething nyou nhave, nsomething nyou nare) nto ncarry nout
nthe nauthentication nprocess nbeing nrequested.
Baseline n- nCorrect n nAnswer n- nA ndocumented, nlowest nlevel nof nsecurity nconfiguration
nallowed nby na nstandard nor norganization.
State n- nCorrect n nAnswer n- nThe ncondition nan nentity nis nin nat na npoint nin ntime.
Bot n- nCorrect n nAnswer n- nMalicious ncode nthat nacts nlike na nremotely ncontrolled n"robot" nfor
nan nattacker, nwith nother nTrojan nand nworm ncapabilities.
Sensitivity n- nCorrect n nAnswer n- nA nmeasure nof nthe nimportance nassigned nto ninformation nby
nits nowner, nfor nthe npurpose nof ndenoting nits nneed nfor nprotection. nSource: nNIST nSP n800-
60 nVol n1 nRev n1
Classified nor nSensitive nInformation n- nCorrect n nAnswer n- nInformation nthat nhas nbeen
ndetermined nto nrequire nprotection nagainst nunauthorized ndisclosure nand nis nmarked nto
nindicate nits nclassified nstatus nand nclassification nlevel nwhen nin ndocumentary nform.
Risk nTreatment n- nCorrect n nAnswer n- nThe ndetermination nof nthe nbest nway nto naddress nan
nidentified nrisk.
Confidentiality n- nCorrect n nAnswer n- nThe ncharacteristic nof ndata nor ninformation nwhen nit nis
nnot nmade navailable nor ndisclosed nto nunauthorized npersons nor nprocesses. nNIST n800-66
Security nControls n- nCorrect n nAnswer n- nThe nmanagement, noperational nand ntechnical
ncontrols n(i.e., nsafeguards nor ncountermeasures) nprescribed nfor nan ninformation nsystem nto
, nprotect nthe nconfidentiality, nintegrity nand navailability nof nthe nsystem nand nits ninformation.
nSource: nFIPS nPUB n199
Criticality n- nCorrect n nAnswer n- nA nmeasure nof nthe ndegree nto nwhich nan norganization
ndepends non nthe ninformation nor ninformation nsystem nfor nthe nsuccess nof na nmission nor nof
na nbusiness nfunction. nNIST nSP n800-60 nVol. n1, nRev. n1
Risk nTolerance n- nCorrect n nAnswer n- nThe nlevel nof nrisk nan nentity nis nwilling nto nassume nin
norder nto nachieve na npotential ndesired nresult. nSource: nNIST nSP n800-32. nRisk nthreshold, nrisk
nappetite nand nacceptable nrisk nare nalso nterms nused nsynonymously nwith nrisk ntolerance.
Data nIntegrity n- nCorrect n nAnswer n- nThe nproperty nthat ndata nhas nnot nbeen naltered nin nan
nunauthorized nmanner. nData nintegrity ncovers ndata nin nstorage, nduring nprocessing nand nwhile
nin ntransit. nSource: nNIST nSP n800-27 nRev nA
Risk nTransference n- nCorrect n nAnswer n- nPaying nan nexternal nparty nto naccept nthe nfinancial
nimpact nof na ngiven nrisk.
General nData nProtection nRegulation n(GDPR) n- nCorrect n nAnswer n- nIn n2016, nthe nEuropean
nUnion npassed ncomprehensive nlegislation nthat naddresses npersonal nprivacy, ndeeming nit nan
nindividual nhuman nright.
Risk nMitigation n- nCorrect n nAnswer n- nThe nprocess nof nidentifying nand nanalyzing nrisks nto
norganizational noperations n(including nmission, nfunctions, nimage, nor nreputation), norganizational
nassets, nindividuals nand nother norganizations. nThe nanalysis nperformed nas npart nof nrisk
nmanagement nwhich nincorporates nthreat nand nvulnerability nanalyses nand nconsiders
nmitigations nprovided nby nsecurity ncontrols nplanned nor nin nplace.
Risk nAcceptance n- nCorrect n nAnswer n- nDetermining nthat nthe npotential nbenefits nof na
nbusiness nfunction noutweigh nthe npossible nrisk nimpact/likelihood nand nperforming nthat
nbusiness nfunction nwith nno nother naction.
Governance n- nCorrect n nAnswer n- nThe nprocess nof nhow nan norganization nis nmanaged;
nusually nincludes nall naspects nof nhow ndecisions nare nmade nfor nthat norganization, nsuch nas
npolicies, nroles, nand nprocedures nthe norganization nuses nto nmake nthose ndecisions.
Quantitative nRisk nAnalysis n- nCorrect n nAnswer n- nA nmethod nfor nrisk nanalysis nwhere
nnumerical nvalues nare nassigned nto nboth nimpact nand nlikelihood nbased non nstatistical
nprobabilities nand nmonetarized nvaluation nof nloss nor ngain. nSource: nNISTIR n8286
Health nInsurance nPortability nand nAccountability nAct n(HIPAA) n- nCorrect n nAnswer n- nThis nU.S.
nfederal nlaw nis nthe nmost nimportant nhealthcare ninformation nregulation nin nthe nUnited
nStates. nIt ndirects nthe nadoption nof nnational nstandards nfor nelectronic nhealthcare
ntransactions nwhile nprotecting nthe nprivacy nof nindividual's nhealth ninformation. nOther
Questions Answers
Adequate nSecurity n- nCorrect n nAnswer n- nSecurity ncommensurate nwith nthe nrisk nand nthe
nmagnitude nof nharm nresulting nfrom nthe nloss, nmisuse, nor nunauthorized naccess nto nor
nmodification nof ninformation.
Administrative nControls n- nCorrect n nAnswer n- nControls nimplemented nthrough npolicy nand
nprocedures. nExamples ninclude naccess ncontrol nprocesses nand nrequiring nmultiple npersonnel
nto nconduct na nspecific noperation. nAdministrative ncontrols nin nmodern nenvironments nare
noften nenforced nin nconjunction nwith nphysical nand/or ntechnical ncontrols, nsuch nas nan
naccess-granting npolicy nfor nnew nusers nthat nrequires nlogin nand napproval nby nthe nhiring
nmanager.
Artificial nIntelligence n- nCorrect n nAnswer n- nThe nability nof ncomputers nand nrobots nto
nsimulate nhuman nintelligence nand nbehavior.
Asset n- nCorrect n nAnswer n- nAnything nof nvalue nthat nis nowned nby nan norganization. nAssets
ninclude nboth ntangible nitems nsuch nas ninformation nsystems nand nphysical nproperty nand
nintangible nassets nsuch nas nintellectual nproperty.
Authentication n- nCorrect n nAnswer n- nAccess ncontrol nprocess nvalidating nthat nthe nidentity
nbeing nclaimed nby na nuser nor nentity nis nknown nto nthe nsystem, nby ncomparing none n(single
nfactor nor nSFA) nor nmore n(multi-factor nauthentication nor nMFA) nfactors nof nidentification.
Authorization n- nCorrect n nAnswer n- nThe nright nor na npermission nthat nis ngranted nto na
nsystem nentity nto naccess na nsystem nresource. nNIST n800-82 nRev.2
Token n- nCorrect n nAnswer n- nA nphysical nobject na nuser npossesses nand ncontrols nthat nis
nused nto nauthenticate nthe nuser's nidentity. nSource: nNISTIR n7711
Vulnerability n- nCorrect n nAnswer n- nWeakness nin nan ninformation nsystem, nsystem nsecurity
nprocedures, ninternal ncontrols nor nimplementation nthat ncould nbe nexploited nby na nthreat
nsource. nSource: nNIST nSP n800-30 nRev n1
Threat n- nCorrect n nAnswer n- nAny ncircumstance nor nevent nwith nthe npotential nto nadversely
nimpact norganizational noperations n(including nmission, nfunctions, nimage nor nreputation),
norganizational nassets, nindividuals, nother norganizations nor nthe nnation nthrough nan
,ninformation nsystem nvia nunauthorized naccess, ndestruction, ndisclosure, nmodification nof
ninformation nand/or ndenial nof nservice. nSource: nNIST nSP n800-30 nRev n1
Threat nVector n- nCorrect n nAnswer n- nAn nindividual nor na ngroup nthat nattempts nto nexploit
nvulnerabilities nto ncause nor nforce na nthreat nto noccur.
Technical nControls n- nCorrect n nAnswer n- nSecurity ncontrols n(i.e., nsafeguards nor
ncountermeasures) nfor nan ninformation nsystem nthat nare nprimarily nimplemented nand
nexecuted nby nthe ninformation nsystem nthrough nmechanisms ncontained nin nthe nhardware,
nsoftware nor nfirmware ncomponents nof nthe nsystem.
System nIntegrity n- nCorrect n nAnswer n- nThe nquality nthat na nsystem nhas nwhen nit nperforms
nits nintended nfunction nin nan nunimpaired nmanner, nfree nfrom nunauthorized nmanipulation nof
nthe nsystem, nwhether nintentional nor naccidental. nSource: nNIST nSP n800-27 nRev. nA
Availability n- nCorrect n nAnswer n- nEnsuring ntimely nand nreliable naccess nto nand nuse nof
ninformation nby nauthorized nusers.
Single-Factor nAuthentication n- nCorrect n nAnswer n- nUse nof njust none nof nthe nthree navailable
nfactors n(something nyou nknow, nsomething nyou nhave, nsomething nyou nare) nto ncarry nout
nthe nauthentication nprocess nbeing nrequested.
Baseline n- nCorrect n nAnswer n- nA ndocumented, nlowest nlevel nof nsecurity nconfiguration
nallowed nby na nstandard nor norganization.
State n- nCorrect n nAnswer n- nThe ncondition nan nentity nis nin nat na npoint nin ntime.
Bot n- nCorrect n nAnswer n- nMalicious ncode nthat nacts nlike na nremotely ncontrolled n"robot" nfor
nan nattacker, nwith nother nTrojan nand nworm ncapabilities.
Sensitivity n- nCorrect n nAnswer n- nA nmeasure nof nthe nimportance nassigned nto ninformation nby
nits nowner, nfor nthe npurpose nof ndenoting nits nneed nfor nprotection. nSource: nNIST nSP n800-
60 nVol n1 nRev n1
Classified nor nSensitive nInformation n- nCorrect n nAnswer n- nInformation nthat nhas nbeen
ndetermined nto nrequire nprotection nagainst nunauthorized ndisclosure nand nis nmarked nto
nindicate nits nclassified nstatus nand nclassification nlevel nwhen nin ndocumentary nform.
Risk nTreatment n- nCorrect n nAnswer n- nThe ndetermination nof nthe nbest nway nto naddress nan
nidentified nrisk.
Confidentiality n- nCorrect n nAnswer n- nThe ncharacteristic nof ndata nor ninformation nwhen nit nis
nnot nmade navailable nor ndisclosed nto nunauthorized npersons nor nprocesses. nNIST n800-66
Security nControls n- nCorrect n nAnswer n- nThe nmanagement, noperational nand ntechnical
ncontrols n(i.e., nsafeguards nor ncountermeasures) nprescribed nfor nan ninformation nsystem nto
, nprotect nthe nconfidentiality, nintegrity nand navailability nof nthe nsystem nand nits ninformation.
nSource: nFIPS nPUB n199
Criticality n- nCorrect n nAnswer n- nA nmeasure nof nthe ndegree nto nwhich nan norganization
ndepends non nthe ninformation nor ninformation nsystem nfor nthe nsuccess nof na nmission nor nof
na nbusiness nfunction. nNIST nSP n800-60 nVol. n1, nRev. n1
Risk nTolerance n- nCorrect n nAnswer n- nThe nlevel nof nrisk nan nentity nis nwilling nto nassume nin
norder nto nachieve na npotential ndesired nresult. nSource: nNIST nSP n800-32. nRisk nthreshold, nrisk
nappetite nand nacceptable nrisk nare nalso nterms nused nsynonymously nwith nrisk ntolerance.
Data nIntegrity n- nCorrect n nAnswer n- nThe nproperty nthat ndata nhas nnot nbeen naltered nin nan
nunauthorized nmanner. nData nintegrity ncovers ndata nin nstorage, nduring nprocessing nand nwhile
nin ntransit. nSource: nNIST nSP n800-27 nRev nA
Risk nTransference n- nCorrect n nAnswer n- nPaying nan nexternal nparty nto naccept nthe nfinancial
nimpact nof na ngiven nrisk.
General nData nProtection nRegulation n(GDPR) n- nCorrect n nAnswer n- nIn n2016, nthe nEuropean
nUnion npassed ncomprehensive nlegislation nthat naddresses npersonal nprivacy, ndeeming nit nan
nindividual nhuman nright.
Risk nMitigation n- nCorrect n nAnswer n- nThe nprocess nof nidentifying nand nanalyzing nrisks nto
norganizational noperations n(including nmission, nfunctions, nimage, nor nreputation), norganizational
nassets, nindividuals nand nother norganizations. nThe nanalysis nperformed nas npart nof nrisk
nmanagement nwhich nincorporates nthreat nand nvulnerability nanalyses nand nconsiders
nmitigations nprovided nby nsecurity ncontrols nplanned nor nin nplace.
Risk nAcceptance n- nCorrect n nAnswer n- nDetermining nthat nthe npotential nbenefits nof na
nbusiness nfunction noutweigh nthe npossible nrisk nimpact/likelihood nand nperforming nthat
nbusiness nfunction nwith nno nother naction.
Governance n- nCorrect n nAnswer n- nThe nprocess nof nhow nan norganization nis nmanaged;
nusually nincludes nall naspects nof nhow ndecisions nare nmade nfor nthat norganization, nsuch nas
npolicies, nroles, nand nprocedures nthe norganization nuses nto nmake nthose ndecisions.
Quantitative nRisk nAnalysis n- nCorrect n nAnswer n- nA nmethod nfor nrisk nanalysis nwhere
nnumerical nvalues nare nassigned nto nboth nimpact nand nlikelihood nbased non nstatistical
nprobabilities nand nmonetarized nvaluation nof nloss nor ngain. nSource: nNISTIR n8286
Health nInsurance nPortability nand nAccountability nAct n(HIPAA) n- nCorrect n nAnswer n- nThis nU.S.
nfederal nlaw nis nthe nmost nimportant nhealthcare ninformation nregulation nin nthe nUnited
nStates. nIt ndirects nthe nadoption nof nnational nstandards nfor nelectronic nhealthcare
ntransactions nwhile nprotecting nthe nprivacy nof nindividual's nhealth ninformation. nOther