GRADED A+ (QUESTIONS AND
ANSWERS)
True positive - A problem occurred, and the analysis recognized it. This is a good result: even if the
problem itself is bad, it was recognized and can be addressed.
True negative - The event was benign and triggered no alerts. This is a good result since everything is
quietly working correctly.
False positive - The event was benign, but the analysis mistook it for a problem. This is bad: frequent
false alarms can disrupt routine functions, cost administrators time, or just make people less alert
when a real attack happens.
False negative - A problem occurred, and the analysis mistook it for benign behaviour. This is
potentially disastrous since any resulting security compromise will go unnoticed.
Integrity - Ensuring that information remains accurate and complete over its entire lifetime. In
particular, this means ensuring that data in storage or transit can't be modified in an undetected
manner, but it can encompass all methods for preventing data loss.
Confidentiality - Ensures that only authorized parties can view the information
Availability - Ensuring timely and reliable access to and use of information by authorized users.
Managerial/Administrative Controls - Organizational policies and training regarding security.
Common management controls include password policies, employee screening, training procedures,
and compliance with legal regulations.
Technical/Logical controls - Technological solutions used to enforce security. Includes firewalls,
authentication systems, and encryption protocols.
Operational Controls - Day-to-day employee activities which are used to achieve security goals.
Include backup management, security assessments, and incident response.