CIS Security & Compliance Flashcards
6 cards from real CIS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CIS Security & Compliance flashcards as text
In a CIS implementation, Role-Based Access Control (RBAC) is used to:
Answer: Grant system access based on a user's job function rather than individual identity
RBAC assigns permissions to roles (e.g., Admin, Editor, Viewer) and then assigns users to those roles, simplifying access management at scale.
What is the principle of least privilege in CIS security design?
Answer: Users and systems are granted only the minimum access rights needed to perform their job
The principle of least privilege limits user and system access to the minimum required, reducing the attack surface and potential damage from compromised accounts.
Which US regulation governs the privacy and security of protected health information (PHI) that a CIS specialist must consider for healthcare implementations?
Answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets US federal standards for the privacy and security of protected health information in healthcare contexts.
During a CIS implementation, a penetration test is conducted to:
Answer: Simulate attacks to identify exploitable security vulnerabilities before go-live
Penetration testing involves authorized simulated attacks against the system to discover and fix security vulnerabilities before malicious actors can exploit them.
What is multi-factor authentication (MFA) and why is it important in a CIS implementation?
Answer: An authentication process requiring two or more verification factors, increasing security beyond passwords alone
MFA requires users to provide multiple forms of verification (e.g., password + SMS code), significantly reducing the risk of unauthorized access from stolen credentials.
PCI DSS compliance is required for CIS implementations that involve:
Answer: Storage, processing, or transmission of payment card data
PCI DSS (Payment Card Industry Data Security Standard) mandates security controls for any system that stores, processes, or transmits cardholder data.