CORRECT ANSWERS
Chief Information Security Officer (CISO) - CORRECT ANSWER Responsible for
assessing, managing, and implementing security
Security Manager - CORRECT ANSWER Supervises technicians, administrators, and
security staff
Requires and understanding of configuration and operation but not technical mastery
Security Administrator - CORRECT ANSWER Has both technical knowledge and
managerial skills,
Manages daily operations of security technology,
May analyze and design security solutions
Security Technician - CORRECT ANSWER Entry Level, Provides technical support to
configure security hardware, implement security software, and diagnose and troubleshoot
problems
The CompTIA Security+ Certification - CORRECT ANSWER Identifies knowledge
and skills required to identify risk and participate in risk mitigation
CIA Triangle - CORRECT ANSWER Confidentiality, Integrity, Availablity
Confidentiality - CORRECT ANSWER Security actions that ensure that only
authorized parties can view the information
Integrity - CORRECT ANSWER Security actions that ensure that the information is
correct and no unauthorized person or malicious software has altered the data
, Availability - CORRECT ANSWER Security actions that ensure that data is accessible
to authorized users
Defining Information Security - CORRECT ANSWER protecting the integrity,
confidentiality, and availability of information on the devices that store, manipulate, and
transmit the information through products, people, and procedures.
Information Security threat agent - CORRECT ANSWER A person or element that has
the power to carry out a threat
Preventing data theft - CORRECT ANSWER the primary objective of information
security
Health Insurance Portability and Accountability (HIPPA) - CORRECT
ANSWER Health care enterprises must guard protected healthcare information
$50,000 each violation up to $1.5 Million or 10 years in prison
Sarbanes-Oxley (SARBOX) - CORRECT ANSWER Set specific requirements and
internal controls on electronic financial reporting systems
$5 million or 20 years in prison
The Gramm-Leach-Bliley Act (GLBA) - CORRECT ANSWER Requires banks and
financial institutions to alert customers of the policies and practices for disclosing customer
information
$500,000
Payment Card Industry Data Security Standard (PCI DSS) - CORRECT ANSWER Set
of security standards all companies that process, store, or transmit credit card info must
follow.
$100,000 per month