A ___________ is a potential danger which occurs when a ___________ exploits a
vulnerability. - ANSWER threat, threat agent
Which of the following is NOT a category of control types? - ANSWER protects or
assures the accuracy and reliability of information and systems.
Integrity is the principle that _________________. - ANSWER
An exposure occurs when a vulnerability _____________. - ANSWER creates the
possibility of incurring a loss or experiencing harm.
Which of the following controls would protect confidentiality? ANSWER Digital signing
software to authenticate recipients.
Data hiding and data obscuring techniques.
Encrypting data at rest and in transit.
Clustering and load balancing are controls that ________ ANSWER map to the Availability
component of the AIC triad.
Balanced security refers to _____________ ANSWER a process of weighing choices in
controls against the magnitude of risk presented by a variety of threats.
Availability, integrity, and confidentiality controls along with addressing threats.
, understand concepts of the AIC triad.
Which of the following does best describes a security program? - ANSWER A group of
standards, regulations, and best practices.
An organization within an enterprise that houses business activities associated with
providing security.
A framework made up of many entities working together to provide protection for an
organization.
Which of the following is used to reduce the risk of vulnerabilities in purchased or
acquired hardware and software products? - ANSWER Supply Chain Risk Management
Hashing is a control that _______ - ANSWER maps to the Integrity component of the AIC
triad.
Which category of control types is referred to as "soft controls?" - ANSWER
Administrative
Risk can be reduced by _____________. - ANSWER applying countermeasures to
eliminate vulnerabilities.
Which of the following is true? - ANSWER PCI-DSS is a federal law that protects the
confidentiality of credit card transactions.
USA Patriot Act extends privacy protection for federal law enforcement agents and for
immigration officials.
FISMA pertains to federal agencies and their contractors.
Which of the following guidance documents specifically addresses security controls
required for information systems owned by or operated for the U.S. Federal
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Braxton. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $9.99. You're not tied to anything after your purchase.