WGU D430 fundamentals of
information security
exam(246 questions and
answers)
Information security - answer protecting data,
software, and hardware secure against
unauthorized access, use, disclosure, disruption,
modification, or destruction.
Compliance - answer The requirements that are set
forth by laws and industry regulations.
IE: HIPPA/ HITECH- healthcare, PCI/DSS- payment
card industry, FISMA- federal government agencies
DAD Triad - answer Disclosure, alteration, and
denial
CIA Triad - answer The core model of all
information security concepts. Confidential,
integrity and availability
,Confidential - answer Ability to protect our data
from those who are not authorized to view it.
What ways can confidentiality be compromised? -
answer - lose a personal laptop with data
- Person can view your password you are entering
in
- Send an email attachment to the wrong person.
- Attacker can penetrate your systems....etc.
integrity - answer Keeping data unaltered by
accidental or malicious intent
How to maintain integrity? - answer Prevent
unauthorized changes to the data and the ability to
reverse unwanted authorized changes.
Via system/file permissions or Undo/Roll back
undesirable changes.
Availability - answer The ability to access data
when needed
Ways Availability can be compromised - answer -
Power loss
,- Application issues
- Network attacks
- System compromised (DoS)
Denial of Service (DoS) - answer Security problem
in which users are not able to access an
information system; can be caused by human
errors, natural disaster, or malicious activity.
Parkerian hexad model - answer A model that adds
three more principles to the CIA triad:
Possession/Control
Utility
Authenticity
Possession/ control - answer Refers to the physical
disposition of the media on which the data is
stored; This allows you to discuss loss of data via
its physical medium.
Principle of Possession example - answer Lost
package (encrypted USB's and unencrypted USB's)
, possession is an issue because the tapes are
physically lost.
(Unencrypted is compromised via confidentiality
and possession; encrypted is compromised only via
possession).
Principle of Authenticity - answer Allows you to say
whether you've attributed the data in question to
the proper owner/creator.
Ways authenticity can be compromised - answer
Sending an email but altering the message to look
like it came from someone else, than the original
one that was sent.
Utility - answer How useful the data is to you.
Ex. Unencrypted (a lot of utility) Encrypted (little
utility).
Security Attacks - answer Broken down from the
type of attack, risk the attack represents, and
controls you might use to mitigate it.
Types of attacks - answer 1- interception
Voordelen van het kopen van samenvattingen bij Stuvia op een rij:
√ Verzekerd van kwaliteit door reviews
Stuvia-klanten hebben meer dan 700.000 samenvattingen beoordeeld. Zo weet je zeker dat je de beste documenten koopt!
Snel en makkelijk kopen
Je betaalt supersnel en eenmalig met iDeal, Bancontact of creditcard voor de samenvatting. Zonder lidmaatschap.
Focus op de essentie
Samenvattingen worden geschreven voor en door anderen. Daarom zijn de samenvattingen altijd betrouwbaar en actueel. Zo kom je snel tot de kern!
Veelgestelde vragen
Wat krijg ik als ik dit document koop?
Je krijgt een PDF, die direct beschikbaar is na je aankoop. Het gekochte document is altijd, overal en oneindig toegankelijk via je profiel.
Tevredenheidsgarantie: hoe werkt dat?
Onze tevredenheidsgarantie zorgt ervoor dat je altijd een studiedocument vindt dat goed bij je past. Je vult een formulier in en onze klantenservice regelt de rest.
Van wie koop ik deze samenvatting?
Stuvia is een marktplaats, je koop dit document dus niet van ons, maar van verkoper BRAINBOOSTERS. Stuvia faciliteert de betaling aan de verkoper.
Zit ik meteen vast aan een abonnement?
Nee, je koopt alleen deze samenvatting voor $14.99. Je zit daarna nergens aan vast.