← All CIS Flashcard Decks

CIS Security & Compliance Flashcards

6 cards from real CIS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CIS Security & Compliance flashcards as text
  1. Which security practice ensures that system access is reviewed and revoked when no longer needed during a CIS implementation?

    Answer: Access recertification or user access review

    Access recertification is a periodic review process where managers confirm that users still require their current access levels, and revoke access that is no longer needed.

  2. In CIS security planning, encryption 'at rest' means:

    Answer: Data stored on disk or in a database is encrypted to protect it from physical theft

    Encryption at rest protects stored data by encoding it so that physical access to storage media does not expose readable information.

  3. A CIS implementation specialist is reviewing a system for SOX compliance. SOX primarily relates to:

    Answer: Financial reporting controls and audit trails for publicly traded companies

    The Sarbanes-Oxley Act (SOX) requires publicly traded companies to maintain accurate financial records with strong internal controls and audit trails.

  4. What is the purpose of an audit log in a CIS implementation?

    Answer: To record a tamper-evident history of who accessed or changed what and when

    Audit logs provide a chronological, tamper-evident record of system events, user actions, and data changes used for security monitoring and compliance investigations.

  5. Which approach to vulnerability management requires assigning a severity score to discovered vulnerabilities to prioritize remediation in a CIS system?

    Answer: CVSS-based risk scoring

    The Common Vulnerability Scoring System (CVSS) provides a standardized numerical score (0–10) indicating a vulnerability's severity, helping teams prioritize which issues to fix first.

  6. In CIS implementations handling sensitive data, data masking in non-production environments is used to:

    Answer: Replace real sensitive data with realistic but fictional data for testing purposes

    Data masking substitutes real sensitive values with fictional but structurally valid data so developers and testers can work without exposure to actual PII or confidential information.