← All CSC Flashcard Decks

Security Controls & Compliance Implementation Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security Controls & Compliance Implementation flashcards as text
  1. An organization wants to implement compensating controls because a required technical control is not feasible. What must the compensating control demonstrate?

    Answer: It must provide equivalent protection to the original required control

    Compensating controls must provide equivalent or greater protection than the original required control they replace.

  2. Which NIST SP 800-53 control family specifically addresses audit and accountability requirements?

    Answer: AU (Audit and Accountability)

    The AU (Audit and Accountability) control family in NIST SP 800-53 addresses logging, audit record content, protection, and review requirements.

  3. A company undergoes a SOC 2 Type II audit. What distinguishes a Type II audit from a Type I audit?

    Answer: Type II evaluates controls over a period of time rather than at a single point in time

    SOC 2 Type II audits assess the operational effectiveness of controls over an examination period (typically 6–12 months), while Type I assesses design at a point in time.

  4. Under PCI DSS Requirement 6, what is the primary focus for protecting cardholder data environments?

    Answer: Developing and maintaining secure systems and software

    PCI DSS Requirement 6 focuses on developing and maintaining secure systems and software, including patch management and secure development practices.

  5. What is the purpose of a System Security Plan (SSP) in the federal compliance context?

    Answer: It documents the security requirements and controls implemented for an information system

    An SSP describes the security requirements of a system and documents how controls are implemented to satisfy those requirements, typically required by FISMA.

  6. An organization applies the principle of least privilege. Which scenario BEST illustrates this principle?

    Answer: A developer is granted only read access to production database records needed for debugging

    Least privilege means granting users only the minimum access rights needed to perform their job functions, as illustrated by read-only access scoped to necessary records.

  7. Which control type is BEST described as deterring a threat actor from attempting an attack?

    Answer: Deterrent control

    Deterrent controls discourage threat actors from attempting attacks, such as warning banners, security cameras, or security guard presence.