Fundamentals Of Information Security – Q&A – Pass!!
Protects information and information systems from unauthorized access, use,
disclosure, disruption, modification, or destruction ✔️Ans -Information
Security
Companies that process credit card payments must comply with this set of
standards ✔️Ans -Payment Card Industry Data Security Standard (PCI DSS)
Used to keep something private or minimally known ✔️Ans -Confidentially
Refers to the ability to prevent our data from being changed in an
unauthorized or undesirable manner. ✔️Ans -Integrity
Refers to the ability to access our data when we need it ✔️Ans -Availability
A type of attack, primarily against confidentiality ✔️Ans -Interception
Something that has the potential to cause harm to our assets ✔️Ans -Threat
A weakness that can be used to harm us ✔️Ans -Vulnerability
The likelihood that something bad will happen ✔️Ans -Risk
An attack that causes our assets to become unusable or unavailable for our
use, on a temporary or permanent basis ✔️Ans -interuption attack
An attack that involves tampering with our assets ✔️Ans -Modification
attack
A model that adds three more principles to the CIA triad: possession or
control, utility, and authenticity ✔️Ans -Parkerian hexad
The physical disposition of the media on which the data is stored ✔️Ans -
possession or control
Allows for attribution as to the owner or creator of the data in question
✔️Ans -authenticity
,Refers to how useful the data is to us ✔️Ans -utility
An attack that involves generating data, processes, communications, or other
similar activities with a system ✔️Ans -fabrication attack
One of the first and most important steps of the risk management process
✔️Ans -identify assests
A multilayered defense that will allow us to achieve a successful defense
should one or more of our defensive measures fail ✔️Ans -defense in depth
Based on rules, laws, policies, procedures, guidelines, and other items that are
"paper" in nature ✔️Ans -administrative controls
Sometimes called technical controls, these protect the systems, networks, and
environments that process, transmit, and store our data ✔️Ans -logical
controls
Controls that protect the physical environment in which our systems sit, or
where our data is stored ✔️Ans -physical controls
Involves putting measures in place to help ensure that a given type of threat is
accounted for ✔️Ans -migrating risk
The risk management phase that consists of all of the activities that we can
perform in advance of the incident itself, in order to better enable us to handle
it ✔️Ans -preparation phase
The risk management phase where we detect the occurrence of an issue and
decide whether it is actually an incident so that we can respond to it
appropriately ✔️Ans -detection and analysis phase
The risk management phase where we determine specifically what happened,
why it happened, and what we can do to keep it from happening again
✔️Ans -Post-incident activity phase
To completely remove the effects of the issue from our environment ✔️Ans
-Eradication
, Taking steps to ensure that the situation does not cause any more damage
than it already has, or at the very least, lessen any ongoing harm ✔️Ans -
containment
Restore to a better state (either to the state prior to the incident, or if we did
not detect the problem immediately, prior to when the issue started) ✔️Ans
-recover
Something that supports our claim to identity, either in our personal
interactions or in computer systems, e.g. social security cards ✔️Ans -
Identity verification
Authentication requirements help prevent this crime ✔️Ans -Falsifying
identification
A set of methods we use to establish a claim of identity as being true ✔️Ans
-Authentication
A password is an example of this type of factor ✔️Ans -Something you know
An iris scan is an example of this type of factor ✔️Ans -Something you are
A swipe card is an example of this type of factor ✔️Ans -Something you
have
The time delay between your keystrokes is an example of this type of factor
✔️Ans -Something you do
Being at a specific terminal is an example of this type of factor ✔️Ans -
where you are
Uses one or more authentication methods for access ✔️Ans -multi-factor
authentication
An authentication mechanism in which both parties authenticate each other
✔️Ans -mutual authentication
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Studycafe. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $17.99. You're not tied to anything after your purchase.