← All CSI Flashcard Decks

Mixed Deck — All CSI Topics Flashcards

100 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CSI Topics flashcards as text
  1. Why is patch management crucial for system security?

    Answer: To ensure that known vulnerabilities are fixed and prevent exploits

    Patch management is critical for system security because it involves regularly applying updates and fixes to software and operating systems. These patches often address newly discovered security vulnerabilities that could otherwise be exploited by attackers to gain unauthorized access or cause damage. By keeping systems updated, organizations significantly reduce their exposure to known threats and maintain a secure environment.

  2. What is the role of firewalls in system security?

    Answer: To block unauthorized access while allowing legitimate traffic

    Firewalls are critical security devices that act as a barrier between a trusted internal network and untrusted external networks, like the internet. They analyze incoming and outgoing network traffic based on predefined security rules, effectively blocking malicious or unauthorized access attempts while permitting legitimate data flow. This selective filtering is essential for protecting systems from external threats.

  3. Which cloud architecture principle recommends designing systems to expect and handle component failures as a normal condition?

    Answer: Design for Failure

    Design for Failure assumes components will fail and builds resilience through redundancy, retries, and graceful degradation.

  4. Which change management metric measures the percentage of changes that cause unplanned outages or incidents?

    Answer: Change failure rate (also called change-induced incident rate)

    Change failure rate tracks how often changes introduce incidents, serving as a key DORA metric for deployment and change management maturity.

  5. What does a Total Cost of Ownership (TCO) analysis include when evaluating vendors?

    Answer: Purchase price, implementation, training, maintenance, and support costs over the system's lifecycle

    TCO encompasses all direct and indirect costs over the full lifecycle, not just the upfront purchase price.

  6. What is the purpose of a vendor's ISO 9001 certification in the context of vendor evaluation?

    Answer: It demonstrates the vendor has a quality management system ensuring consistent processes and continual improvement

    ISO 9001 certification verifies the vendor operates a documented quality management system (QMS) committed to process consistency and improvement.

  7. A system integrator is designing a solution where multiple source systems send orders that must be collected and processed as a batch. Which EIP pattern applies?

    Answer: Aggregator

    The Aggregator pattern collects related messages from multiple sources and combines them into a single message for batch processing.

  8. In a distributed system, which consistency model allows reads to return stale data but guarantees that all replicas eventually converge to the same value?

    Answer: Eventual consistency

    Eventual consistency guarantees that all replicas will converge to the same value over time, but reads may temporarily return stale data.

  9. During a system integration project, which activity ensures that security controls are functioning as intended before go-live?

    Answer: Security control assessment or penetration testing

    A security control assessment or penetration test validates that implemented security controls are effective and properly configured before the system goes live.

  10. Which pattern is best suited for integrating a legacy system that cannot be modified to publish events directly into a modern event-driven architecture?

    Answer: Change Data Capture (CDC) from the legacy system's database transaction log

    CDC reads the database transaction log (e.g., via Debezium) to detect changes without modifying the legacy application, converting database changes into events for the modern platform.

  11. Which NIST Special Publication provides the Risk Management Framework (RMF) used by federal agencies and contractors?

    Answer: NIST SP 800-37

    NIST SP 800-37 defines the Risk Management Framework, providing a structured process for integrating security and risk management into system development life cycles.

  12. When integrating a new industrial controller into an existing SCADA network, which step should be performed FIRST?

    Answer: Conduct a site survey and document existing network topology

    A site survey and topology documentation ensures the integrator understands existing infrastructure before making any physical or logical changes.

  13. Which role is PRIMARILY accountable for ensuring an IT project remains aligned with organizational strategy throughout its lifecycle?

    Answer: Executive sponsor

    The executive sponsor holds ultimate accountability for strategic alignment and business value realization of the project.

  14. Why is user training important during system integration?

    Answer: It prepares users to operate the system effectively

    User training is a critical component during system integration because it equips end-users with the necessary knowledge and skills to interact with the new or modified system confidently and effectively. Without proper training, users may struggle with new interfaces or processes, leading to frustration, errors, and reduced productivity. By preparing users, training ensures smooth adoption, maximizes the benefits of the integrated system, and minimizes resistance to change.

  15. Which architectural pattern separates the data modification (command) path from the data retrieval (query) path into distinct models?

    Answer: CQRS (Command Query Responsibility Segregation)

    CQRS segregates commands (writes) and queries (reads) into separate models, optimizing each independently.

  16. What is the role of encryption in system security?

    Answer: To protect sensitive data by converting it into an unreadable format

    Encryption plays a vital role in system security by transforming sensitive data into an unreadable, coded format. This process, known as ciphertext, ensures that even if unauthorized individuals gain access to the data, they cannot understand or use it without the correct decryption key. Thus, encryption is fundamental for maintaining data confidentiality and integrity.

  17. A system integrator installs a new fieldbus segment and finds that devices randomly drop off the network. Checking the physical layer, the integrator should verify:

    Answer: That the bus is properly terminated at both ends with the correct termination resistors

    Missing or incorrect termination resistors cause signal reflections on fieldbus segments, leading to random communication errors and device dropouts.

  18. In the context of security architecture & iam, what role does continuous professional development play for CSI practitioners?

    Answer: It ensures practitioners remain current with evolving standards, technologies, and best practices

    Continuous professional development is essential in security architecture & iam because it ensures CSI practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.

  19. What is the primary difference between a vendor's stated capabilities and their demonstrated capabilities during evaluation?

    Answer: Demonstrated capabilities are validated through evidence, while stated capabilities are self-reported claims

    Demonstrated capabilities backed by PoCs, case studies, and references carry more weight than self-reported claims in vendor marketing materials.

  20. What is a 'dead letter queue' (DLQ) in the context of data transformation pipelines?

    Answer: A storage destination for messages that failed transformation and could not be processed successfully

    A dead letter queue captures messages that fail transformation due to data quality errors or processing exceptions, allowing them to be reviewed, corrected, and reprocessed without data loss.