Core IT Security Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Core IT Security flashcards as text
A CISO is implementing a defense-in-depth strategy. Which concept best describes layering multiple security controls so that if one fails, others still provide protection?
Answer: Defense-in-depth
Defense-in-depth uses multiple overlapping security layers so no single control failure results in a complete breach.
During a risk assessment, an organization determines that a threat has a 25% annual probability of occurring and would cause $400,000 in damages. What is the Annual Loss Expectancy (ALE)?
Answer: $160,000
ALE = ARO × SLE = 0.25 × $400,000 = $100,000; however here ALE = 0.25 × $400,000 = $100,000... wait: ALE = 0.25 × $400,000 = $100,000.
Which access control model assigns permissions based on a subject's clearance level and an object's classification label, enforcing mandatory access policies?
Answer: Mandatory Access Control (MAC)
MAC enforces access based on security labels and clearances, with the system—not the owner—making access decisions.
A security analyst discovers that an attacker modified audit logs to hide intrusion evidence. Which security principle was violated?
Answer: Integrity
Integrity ensures data is accurate and unaltered; tampering with audit logs directly violates this principle.
Which cryptographic protocol provides forward secrecy by generating unique session keys for each session, so compromising one key does not expose past sessions?
Answer: Diffie-Hellman Ephemeral (DHE)
DHE generates ephemeral keys per session, ensuring past session keys cannot be derived even if the long-term private key is later compromised.
An organization wants to ensure that no single employee can both initiate and approve a financial transaction. Which principle does this implement?
Answer: Separation of duties
Separation of duties divides critical tasks among multiple people to prevent fraud and errors by one individual.
A CISO reviews the organization's vulnerability management program. Which metric best indicates the effectiveness of the patching process?
Answer: Mean Time to Patch (MTTP)
MTTP measures how quickly vulnerabilities are remediated after discovery, directly reflecting patching process effectiveness.