CYSA Key Terms Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
Security Operations Center (SOC) The location where security professionals
monitor
and protect critical information assets in an
organization.
Security Control Mitigates vulnerabilities and risk to ensure
the
confidentiality, integrity, availability,
nonrepudiation, and authentication of data
ISO 27001 An international standard that details
requirements
for establishing, implementing, maintaining
and
continually improving an information
security
management system (ISMS)
Technical (Logical) Controls (NIST A category of security control that is
800-53 Ver3 Older) implemented
as a system (hardware, software, or
firmware)
Operational Controls (NIST 800-53 A category of security control that is
Ver3 Older) implemented
primarily by people rather than systems
,Managerial Controls (NIST 800-53 A category of security control that provides
Ver3 Older) oversight of the information system
Preventative Control A control that acts to eliminate or reduce
the
likelihood that an attack can succeed
Detective Control A control that may not prevent or deter
access, but
will identify and record any attempted or
successful intrusion
Corrective Control A control that acts to eliminate or reduce
the
impact of an intrusion event.
Physical Control A type of security control that acts against
in-
person intrusion attempts.
Deterrent Control A type of security control that discourages
intrusion attempts
Computer Security Incident An IR team composed of technical IT,
Response Team (CSIRT) managerial
IT, and InfoSec professionals who are
prepared to
detect, react to, and recover from an
incident. May
include members of the IRPT.
, Risk Assessment Evaluation of the short-term and long-term
risks
associated with a particular activity or
hazard
Penetration Test An authorized attempt to break into the
organization's information system
Responsive Control System that actively monitors for potential
vulnerabilities or attacks, and then takes
action to
mitigate them before they can cause
damage.
Security Intelligence The process where data is generated and
is then
collected, processed, analyzed, and
disseminated
to provide insights into the security status
of
information systems
Cyber Threat Intelligence Investigation, collection, analysis, and
dissemination of information about
emerging
threats and threat sources to provide data
about
the external threat landscape
Requirements Planning & Sets out the goals for the intelligence
Direction gathering
(Intelligence Cycle) effort
Answers with Verified Solutions | Latest
Updated 2026
Security Operations Center (SOC) The location where security professionals
monitor
and protect critical information assets in an
organization.
Security Control Mitigates vulnerabilities and risk to ensure
the
confidentiality, integrity, availability,
nonrepudiation, and authentication of data
ISO 27001 An international standard that details
requirements
for establishing, implementing, maintaining
and
continually improving an information
security
management system (ISMS)
Technical (Logical) Controls (NIST A category of security control that is
800-53 Ver3 Older) implemented
as a system (hardware, software, or
firmware)
Operational Controls (NIST 800-53 A category of security control that is
Ver3 Older) implemented
primarily by people rather than systems
,Managerial Controls (NIST 800-53 A category of security control that provides
Ver3 Older) oversight of the information system
Preventative Control A control that acts to eliminate or reduce
the
likelihood that an attack can succeed
Detective Control A control that may not prevent or deter
access, but
will identify and record any attempted or
successful intrusion
Corrective Control A control that acts to eliminate or reduce
the
impact of an intrusion event.
Physical Control A type of security control that acts against
in-
person intrusion attempts.
Deterrent Control A type of security control that discourages
intrusion attempts
Computer Security Incident An IR team composed of technical IT,
Response Team (CSIRT) managerial
IT, and InfoSec professionals who are
prepared to
detect, react to, and recover from an
incident. May
include members of the IRPT.
, Risk Assessment Evaluation of the short-term and long-term
risks
associated with a particular activity or
hazard
Penetration Test An authorized attempt to break into the
organization's information system
Responsive Control System that actively monitors for potential
vulnerabilities or attacks, and then takes
action to
mitigate them before they can cause
damage.
Security Intelligence The process where data is generated and
is then
collected, processed, analyzed, and
disseminated
to provide insights into the security status
of
information systems
Cyber Threat Intelligence Investigation, collection, analysis, and
dissemination of information about
emerging
threats and threat sources to provide data
about
the external threat landscape
Requirements Planning & Sets out the goals for the intelligence
Direction gathering
(Intelligence Cycle) effort