Security and Risk Management
1. What does CISSP stand for?
Answer: Certified Information Systems Security Professional.
2. Which organization administers the CISSP certification?
Answer: ISC2.
3. What is information security primarily concerned with?
Answer: Protecting the confidentiality, integrity, and availability of information.
4. What does the CIA Triad stand for?
Answer: Confidentiality, Integrity, and Availability.
5. What is confidentiality?
Answer: Preventing unauthorized disclosure of information.
6. What is integrity?
Answer: Ensuring information remains accurate and unaltered.
7. What is availability?
Answer: Ensuring information is accessible when needed.
8. What is risk?
Answer: The likelihood and impact of a threat exploiting a vulnerability.
9. What is a threat?
Answer: Any circumstance that can cause harm to an asset.
10. What is a vulnerability?
Answer: A weakness that can be exploited by a threat.
, 11. What is risk management?
Answer: The process of identifying, assessing, and mitigating risks.
12. What are the four primary risk responses?
Answer: Avoid, Transfer, Mitigate, and Accept.
13. What is due care?
Answer: Acting responsibly to protect organizational assets.
14. What is due diligence?
Answer: Continuously reviewing and maintaining security controls.
15. What is governance?
Answer: The framework used to direct and control an organization.
Asset Security
16. What is an asset?
Answer: Anything of value to an organization.
17. What is data classification?
Answer: Categorizing data based on sensitivity and value.
18. Why is data classification important?
Answer: It helps determine appropriate protection measures.
19. What is data ownership?
Answer: Responsibility for determining data classification and protection requirements.
20. What is data retention?
Answer: The period data is kept before disposal.
21. What is data sanitization?