CIS Security & Compliance Flashcards
6 cards from real CIS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CIS Security & Compliance flashcards as text
What is a security risk assessment in the context of a CIS implementation?
Answer: A structured process to identify, analyze, and evaluate security risks to the system
A security risk assessment systematically identifies threats, evaluates vulnerabilities, and determines the potential impact of security incidents to guide mitigation planning.
Which principle ensures that critical tasks in a CIS implementation require involvement of more than one person to prevent fraud or error?
Answer: Separation of duties
Separation of duties requires that no single person has control over all steps of a critical process, reducing the risk of fraud or undetected errors.
During CIS go-live, which security action is MOST important before deploying to production?
Answer: Changing all default system passwords and credentials
Changing default passwords before go-live is critical because default credentials are publicly known and are among the first things attackers attempt.
A Business Continuity Plan (BCP) in a CIS implementation context is designed to:
Answer: Ensure critical business operations can continue during and after a major disruption
A BCP defines how an organization will maintain or restore critical functions during disruptive events such as system outages, natural disasters, or cyberattacks.
What is the purpose of classifying data (e.g., Public, Internal, Confidential, Restricted) in a CIS implementation?
Answer: To apply appropriate security controls based on sensitivity level
Data classification assigns sensitivity labels to data so that appropriate security controls—such as encryption, access restrictions, or handling procedures—can be applied to each level.
Which US federal law requires organizations to notify affected individuals when a security breach exposes their personal data?
Answer: State breach notification laws and federal sector-specific laws
All 50 US states have enacted breach notification laws, and federal laws like HIPAA impose breach notification requirements for covered sectors, collectively mandating timely disclosure to affected individuals.