(ISC)2 Certified in Cybersecurity Final Exam (QUESTIONS WITH 100% CORRECT ANSWERS
6 views 0 purchase
Course
Cyber security
Institution
Cyber Security
(ISC)2 Certified in Cybersecurity Final Exam (QUESTIONS WITH 100% CORRECT ANSWERS
Document specific requirements that a customer has about any aspect of a vendor's service performance.
A) DLR
B) Contract
C) SLR
D) NDA
C) SLR (Service-Level Requirements)
_________ identifies and triage...
(ISC)2 Certified in Cybersecurity Final Exam
(QUESTIONS WITH 100% CORRECT ANSWERS
Document specific requirements that a customer has about any aspect of a vendor's service
performance.
A) DLR
B) Contract
C) SLR
D) NDA
C) SLR (Service-Level Requirements)
_________ identifies and triages risks.
Risk Assessment
_________ are external forces that jeopardize security.
Threats
_________ are methods used by attackers.
Threat Vectors
_________ are the combination of a threat and a vulnerability.
Risks
We rank risks by _________ and _________.
Likelihood and impact
_________ use subjective ratings to evaluate risk likelihood and impact.
Qualitative Risk Assessment
_________ use objective numeric ratings to evaluate risk likelihood and impact.
Quantitative Risk Assessment
_________ analyzes and implements possible responses to control risk.
Risk Treatment
_________ changes business practices to make a risk irrelevant.
Risk Avoidance
_________ reduces the likelihood or impact of a risk.
Risk Mitigation
An organization's _________ is the set of risks that it faces.
Risk Profile
,_________ Initial Risk of an organization.
Inherent Risk
_________ Risk that remains in an organization after controls.
Residual Risk
_________ is the level of risk an organization is willing to accept.
Risk Tolerance
_________ reduce the likelihood or impact of a risk and help identify issues.
Security Controls
_________ stop a security issue from occurring.
Preventive Control
_________ identify security issues requiring investigation.
Detective Control
_________ remediate security issues that have occurred.
Recovery Control
Hardening == Preventative
Virus == Detective
Backups == Recovery
For exam (Local and Technical Controls are the same)
_________ use technology to achieve control objectives.
Technical Controls
_________ use processes to achieve control objectives.
Administrative Controls
_________ impact the physical world.
Physical Controls
_________ tracks specific device settings.
Configuration Management
_________ provide a configuration snapshot.
Baselines (track changes)
_________ assigns numbers to each version.
,Versioning
_________ serve as important configuration artifacts.
Diagrams
_________ and _________ help ensure a stable operating environment.
Change and Configuration Management
Purchasing an insurance policy is an example of which risk management strategy?
Risk Transference
What two factors are used to evaluate a risk?
Likelihood and Impact
What term best describes making a snapshot of a system or application at a point in time for later
comparison?
Baselining
What type of security control is designed to stop a security issue from occurring in the first place?
Preventive
What term describes risks that originate inside the organization?
Internal
What four items belong to the security policy framework?
Policies, Standards, Guidelines, Procedures
_________ describe an organization's security expectations.
Policies (mandatory and approved at the highest level of an organization)
_________ describe specific security controls and are often derived from policies.
Standards (mandatory)
_________ describe best practices.
Guidelines (recommendations/advice and compliance is not mandatory)
_________ cover use of personal devices with company information.
Bring Your Own Device (BYOD) Policies
_________ cover the use of personally identifiable information.
Privacy Policies
_________ cover the documentation, approval, and rollback of technology changes.
Change Management Policies
Which element of the security policy framework includes suggestions that are not mandatory?
Guidelines
What law applies to the use of personal information belonging to European Union residents?
GDPR
What type of security policy normally describes how users may access business information with their
own devices?
BYOD Policy
_________ the set of controls designed to keep a business running in the face of adversity, whether
natural or man-made.
Business Continuity Planning (BCP)
BCP is also known as _________.
Continuity of Operations Planning (COOP)
Defining the BCP Scope:
What business activities will the plan cover? What systems will it cover? What controls will it
consider?
_________ identifies and prioritizes risks.
Business Impact Assessment
BCP in the cloud requires _________ between providers and customers.
Collaboration
_________ protects against the failure of a single component.
Redundancy
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller LectAziim. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $16.49. You're not tied to anything after your purchase.