โ† All CSI Flashcard Decks

Security & Compliance Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Compliance flashcards as text
  1. When integrating cloud services into an on-premises environment, which model defines the shared security responsibilities between the cloud provider and the customer?

    Answer: Shared responsibility model

    The shared responsibility model delineates which security obligations belong to the cloud provider versus the customer, varying by service type (IaaS, PaaS, SaaS).

  2. What is the purpose of a DMZ (Demilitarized Zone) in network security architecture?

    Answer: To create a subnet that exposes external-facing services while protecting the internal network

    A DMZ is a perimeter network segment that hosts external-facing services (like web servers) while keeping the internal network protected behind an additional firewall layer.

  3. An integrator is deploying BACnet for a building automation system. What is the primary security concern with default BACnet implementations?

    Answer: BACnet lacks native authentication and encryption

    Standard BACnet protocol does not include built-in authentication or encryption, making it vulnerable to unauthorized access and eavesdropping without additional security layers.

  4. Which NIST Special Publication provides the Risk Management Framework (RMF) used by federal agencies and contractors?

    Answer: NIST SP 800-37

    NIST SP 800-37 defines the Risk Management Framework, providing a structured process for integrating security and risk management into system development life cycles.

  5. A CSI must segment an OT network from the corporate IT network. What device is most appropriate for this task?

    Answer: Industrial firewall or data diode

    An industrial firewall or data diode provides controlled, policy-based separation between OT and IT networks, preventing unauthorized lateral movement while allowing necessary data flows.

  6. What is 'security by obscurity' and why is it considered insufficient as a standalone security measure?

    Answer: Hiding system details to deter attackers; it fails when the secret is discovered

    Security by obscurity relies on keeping implementation details secret, but once the secret is revealed, the system has no remaining defenses, making it an unreliable sole security strategy.

  7. During a system integration project, which activity ensures that security controls are functioning as intended before go-live?

    Answer: Security control assessment or penetration testing

    A security control assessment or penetration test validates that implemented security controls are effective and properly configured before the system goes live.