Security & Compliance Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Compliance flashcards as text
Which type of access control model assigns permissions based on predefined roles within an organization?
Answer: Role-Based Access Control (RBAC)
RBAC grants permissions based on a user's role within the organization, simplifying access management by grouping users with similar responsibilities.
A system integrator discovers that an integrated subsystem is communicating on an unexpected port. What is the FIRST step to take?
Answer: Document and investigate to determine if the traffic is legitimate or malicious
Before taking action, the integrator must document the finding and investigate to determine whether the unexpected communication is a misconfiguration, a known behavior, or an indicator of compromise.
What is the primary purpose of an intrusion detection system (IDS) compared to an intrusion prevention system (IPS)?
Answer: IDS monitors and alerts on suspicious activity; IPS actively blocks detected threats
An IDS passively monitors traffic and generates alerts, while an IPS sits inline and can actively block or drop malicious traffic in real time.
Which HIPAA rule specifically addresses the technical safeguards required to protect electronic protected health information (ePHI)?
Answer: HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.
In cryptography, what is a 'salt' used for in password hashing?
Answer: To add a random value to each password before hashing, preventing rainbow table attacks
A salt is a random value added to a password before hashing, ensuring that identical passwords produce different hash values and defeating precomputed rainbow table attacks.
A CSI is asked to perform a Business Impact Analysis (BIA) for an integrated control system. What does the BIA primarily determine?
Answer: The criticality of systems and the impact of their downtime on business operations
A BIA identifies critical business functions, the systems supporting them, and the financial and operational impact of system downtime, informing recovery priorities.
Which security concept describes the practice of dividing a network into smaller segments to limit the spread of a security breach?
Answer: Network segmentation
Network segmentation divides a network into isolated zones so that a compromise in one segment cannot easily propagate to others, limiting the blast radius of an attack.