100% tevredenheidsgarantie Direct beschikbaar na je betaling Lees online óf als PDF Geen vaste maandelijkse kosten 4.2 TrustPilot
logo-home
Tentamen (uitwerkingen)

iSACA Cybersecurity Fundamentals Certification Exam ALL ANSWERS 100% CORRECT

Beoordeling
-
Verkocht
-
Pagina's
18
Cijfer
A+
Geüpload op
04-01-2024
Geschreven in
2023/2024

Confidentiality Protection from unauthorized access integrity Protection from unauthorized modification Availability protection from disruptions in access Cybersecurity the protection of information assets (digital assets) by addressing threats to information processed, stored, and transported by internetworked information systems NIST Functions to Protect Digital Assets IPDRR 1) Identify 2) Protect 3) Detect 4) Respond 5) Recover Nonrepudiation Def: ensuring that a message or other piece of information is genuine Examples: digital signatures and transaction logs Risk combination of the probability of an event and its consequences, mitigated through controls Threat Anything that is capable of acting against an asset in a harmful manner Asset something of either tangible or intangible value that is worth protecting Vulnerability A weakness in the design, implementation, operation or internal control of a process that could expose the system to adverse threats from threat events Inherent risk The risk level or exposure without taking into account the actions that management has taken or might take (e.g., implementing controls) Residual risk the risk that remains after management implements internal controls or some other response to risk Likelihood A.K.A probability measure of frequency of which an event may occur, which depends on the threat and vulnerability Approaches to Cybersecurity Risk Dependent on: 1) Risk tolerance 2) Size & scope of the environment 3) Amount of data available Approaches: 1) Ad hoc 2) Compliance-based 3) Risk-based Threat Agents The actors causing the threats that might exploit a vulnerability Types: 1) Corporations - competitive advantage 2) Cybercriminals - profit 3) Cyberterrorists - critical infrastructures/government 4) Cyberwarriors - politically motivated 5) Employees - revenge 6) Hacktivists - politically motivated 7) Nation states - government/private entities 8) Online social hackers - identity theft, profit 9) Script kiddies - learning to hack Attack vector The path or route used to gain access to the target (asset) Types: 1) Ingress - intrusion 2) Egress - Data removal Attack Attributes 1) Attack Vector 2) Payload 3) Exploit 4) Vulnerability 5) Target (Asset) Threat Process 1) Perform reconnaissance (gathering information) 2) Create attack tools 3) Deliver malicious capabilities 4) Exploit and compromise 5) Conduct an attack 6) Achieve results 7) Maintain a presence or set of capabilities 8) Coordinate a campaign Malware Def: software designed to infiltrate or damage a computer system without the user's informed consent Examples: Viruses, network worms, Trojan horses Policies communicate required and prohibited activities and behaviors Standards Interpret policies in specific situations Procedures Provide details on how to comply with policies and standards Guidelines

Meer zien Lees minder
Instelling
ISACA










Oeps! We kunnen je document nu niet laden. Probeer het nog eens of neem contact op met support.

Documentinformatie

Geüpload op
4 januari 2024
Aantal pagina's
18
Geschreven in
2023/2024
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

Voorbeeld van de inhoud

iSACA Cybersecurity Fundamentals
Certification Exam ALL ANSWERS 100%
CORRECT SPRING FALL-2023/24 EDITION
GUARANTEED GRADE A+

Confidentiality

Protection from unauthorized access

integrity

Protection from unauthorized modification

Availability

protection from disruptions in access

Cybersecurity

the protection of information assets (digital assets) by addressing threats to information processed,
stored, and transported by internetworked information systems

NIST Functions to Protect Digital Assets

IPDRR

1) Identify
2) Protect
3) Detect
4) Respond
5) Recover

Nonrepudiation

Def: ensuring that a message or other piece of information is genuine

Examples: digital signatures and transaction logs

Risk

combination of the probability of an event and its consequences, mitigated through controls

,Threat

Anything that is capable of acting against an asset in a harmful manner

Asset

something of either tangible or intangible value that is worth protecting

Vulnerability

A weakness in the design, implementation, operation or internal control of a process that could expose
the system to adverse threats from threat events

Inherent risk

The risk level or exposure without taking into account the actions that management has taken or might
take (e.g., implementing controls)

Residual risk

the risk that remains after management implements internal controls or some other response to risk

Likelihood

A.K.A probability

measure of frequency of which an event may occur, which depends on the threat and vulnerability

Approaches to Cybersecurity Risk

Dependent on:
1) Risk tolerance
2) Size & scope of the environment
3) Amount of data available

Approaches:
1) Ad hoc
2) Compliance-based
3) Risk-based

Threat Agents

The actors causing the threats that might exploit a vulnerability

Types:
1) Corporations - competitive advantage
2) Cybercriminals - profit
3) Cyberterrorists - critical infrastructures/government
4) Cyberwarriors - politically motivated
5) Employees - revenge
6) Hacktivists - politically motivated

, 7) Nation states - government/private entities
8) Online social hackers - identity theft, profit
9) Script kiddies - learning to hack

Attack vector

The path or route used to gain access to the target (asset)

Types:
1) Ingress - intrusion
2) Egress - Data removal

Attack Attributes

1) Attack Vector
2) Payload
3) Exploit
4) Vulnerability
5) Target (Asset)

Threat Process

1) Perform reconnaissance (gathering information)
2) Create attack tools
3) Deliver malicious capabilities
4) Exploit and compromise
5) Conduct an attack
6) Achieve results
7) Maintain a presence or set of capabilities
8) Coordinate a campaign

Malware

Def: software designed to infiltrate or damage a computer system without the user's informed consent

Examples: Viruses, network worms, Trojan horses

Policies

communicate required and prohibited activities and behaviors

Standards

Interpret policies in specific situations

Procedures

Provide details on how to comply with policies and standards

Guidelines

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
THEEXCELLENCELIBRARY Harvard University
Bekijk profiel
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
17
Lid sinds
2 jaar
Aantal volgers
6
Documenten
2641
Laatst verkocht
1 maand geleden
THE EXCELLENCE LIBRARY

The Excellence Library Where Academic Success Begins. Welcome to The Excellence Library — your trusted marketplace for past and upcoming exam papers with verified answers, spanning all academic fields. Whether you're a med student, a future lawyer, a high schooler prepping for finals, or a researcher looking for model dissertations — we've got you covered. What We Offer Accurate & Complete Exam Papers From Medicine, Nursing, Law (Bar Exams), High School subjects, and more. Model Dissertations & Novels Top-tier academic references and full-text materials to guide your writing and study. Affordable & Fair Pricing Quality resources at a price that respects students' budgets. Why Choose Us? Thoroughly Reviewed Answers – Every paper includes clear, correct solutions. Massive Library – Thousands of documents, constantly updated. Academic Excellence, Delivered – We help you prepare smarter, not harder. Fast Delivery – Get what you need, when you need it. Our Goal To empower students and professionals by offering reliable, affordable academic materials — helping you succeed one paper at a time.

Lees meer Lees minder
2,5

2 beoordelingen

5
0
4
0
3
1
2
1
1
0

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Veelgestelde vragen