Core IT Security Flashcards
7 cards from real CCISO practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Core IT Security flashcards as text
A CISO must develop a Business Continuity Plan (BCP). Which metric defines the maximum acceptable amount of time a system can be offline before causing unacceptable business impact?
Answer: Recovery Time Objective (RTO)
RTO specifies the target time within which a system must be restored after a disruption to avoid unacceptable consequences.
During a forensic investigation, which principle ensures that evidence is collected and handled in a manner that preserves its admissibility in court?
Answer: Chain of custody
Chain of custody documents every person who handled evidence and every action taken, ensuring its integrity and legal admissibility.
An organization's security policy requires that employees use multi-factor authentication. An employee uses a password and a hardware token. These represent which two authentication factor types?
Answer: Something you know and something you have
A password is 'something you know' and a hardware token is 'something you have,' satisfying two distinct MFA factor categories.
A CISO is evaluating cloud security controls. Which framework specifically addresses cloud security best practices and provides a Cloud Controls Matrix (CCM)?
Answer: Cloud Security Alliance (CSA)
The CSA publishes the Cloud Controls Matrix, a framework of security controls specifically mapped to cloud service delivery models.
Which type of social engineering attack involves sending fraudulent emails to a small, highly targeted group of individuals within a specific organization?
Answer: Spear phishing
Spear phishing targets a specific individual or small group with personalized messages, unlike broad phishing campaigns.
An organization implements encryption for data at rest in its database. Which threat does this control primarily mitigate?
Answer: Unauthorized access to stolen storage media
Encrypting data at rest protects data stored on disk from being read if physical storage media is stolen or improperly disposed of.
A CISO is reviewing a third-party vendor's security posture as part of supply chain risk management. Which document should the vendor provide to demonstrate its security controls?
Answer: SOC 2 Type II report
A SOC 2 Type II report provides an independent auditor's assessment of a vendor's security, availability, and confidentiality controls over a period of time.