Security Controls & Compliance Implementation Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Controls & Compliance Implementation flashcards as text
A compliance officer is mapping controls to multiple frameworks simultaneously. What is the PRIMARY advantage of using a unified control framework or crosswalk?
Answer: It reduces duplication by identifying controls that satisfy requirements across multiple frameworks at once
Control crosswalks map overlapping requirements across frameworks, allowing a single control implementation to satisfy multiple compliance obligations and reducing redundant effort.
Under the NIST Cybersecurity Framework (CSF), which function focuses on developing and implementing appropriate activities to detect the occurrence of a cybersecurity event?
Answer: Detect
The Detect function in the NIST CSF encompasses activities for continuous monitoring, anomaly detection, and timely discovery of cybersecurity events.
What is 'data minimization' as required under GDPR, and why is it a security control?
Answer: Collecting and retaining only the personal data that is adequate, relevant, and necessary for the specified purpose
Data minimization reduces risk by limiting what personal data is collected and retained, thereby reducing the potential harm and compliance exposure if a breach occurs.
A penetration tester is performing a compliance-driven test under a 'black box' methodology. What characterizes this approach?
Answer: The tester has no prior knowledge of the target environment, simulating an external attacker
Black box penetration testing simulates an external attacker with no prior knowledge of the target, testing defenses without insider information.
Which of the following BEST describes the purpose of a Plan of Action and Milestones (POA&M)?
Answer: A structured document tracking identified weaknesses, remediation tasks, resources, and scheduled completion dates
A POA&M documents security weaknesses, the corrective actions planned or underway, responsible parties, and target completion dates, commonly required under FISMA and FedRAMP.
An organization implements separation of duties (SoD) for its financial processing system. Which threat does SoD PRIMARILY mitigate?
Answer: Insider fraud or errors caused by a single individual having end-to-end control over a sensitive process
SoD divides critical tasks among multiple individuals so that no single person can commit fraud or make errors without detection, directly mitigating insider threat risk.
When implementing encryption for data at rest in compliance with NIST guidelines, which algorithm and key length is currently recommended for symmetric encryption?
Answer: AES with 128-bit or 256-bit keys
NIST recommends AES (Advanced Encryption Standard) with 128-bit or 256-bit keys as the approved symmetric encryption algorithm for protecting sensitive data at rest.