โ† All CSC Flashcard Decks

Security Controls & Compliance Implementation Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Controls & Compliance Implementation flashcards as text
  1. An organization implements network segmentation to isolate its cardholder data environment (CDE). What is the primary compliance benefit of this segmentation under PCI DSS?

    Answer: It reduces the scope of the PCI DSS assessment by limiting systems subject to requirements

    Network segmentation limits the cardholder data environment scope, reducing the number of systems subject to PCI DSS requirements and simplifying compliance assessment.

  2. What does the term 'control effectiveness' measure in a compliance program?

    Answer: Whether a control is operating as intended and achieving its security objective

    Control effectiveness measures whether an implemented control is functioning as designed and actually reducing risk to an acceptable level.

  3. A security analyst is reviewing logs and finds evidence of a privilege escalation attack that bypassed detective controls. Which control category would have PREVENTED this attack?

    Answer: Preventive controls

    Preventive controls are designed to stop attacks from succeeding in the first place, whereas detective controls only identify attacks that have already occurred.

  4. Under FISMA, which organization is responsible for developing and issuing standards and guidelines for federal information systems security?

    Answer: National Institute of Standards and Technology (NIST)

    FISMA designates NIST as responsible for developing security standards and guidelines for federal information systems, including the FIPS and SP 800-series publications.

  5. Which HIPAA safeguard category requires covered entities to implement policies and procedures to detect, contain, and correct security violations?

    Answer: Administrative Safeguards

    HIPAA Administrative Safeguards include requirements for security management processes, workforce training, and procedures for identifying and responding to security incidents.

  6. What is the main difference between a risk assessment and a vulnerability assessment in a compliance context?

    Answer: Vulnerability assessments identify technical weaknesses, while risk assessments evaluate likelihood and impact to prioritize responses

    Vulnerability assessments identify specific technical weaknesses, while risk assessments evaluate the probability and potential business impact of threats exploiting those weaknesses.

  7. An organization must comply with CIS Controls. Which implementation group (IG) is recommended as the starting point for organizations with limited cybersecurity expertise and resources?

    Answer: IG1

    CIS Controls IG1 represents the essential cyber hygiene baseline and is designed for organizations with limited security expertise, covering the most critical foundational controls.