Give us your feedback!
Question:
Match the following control types to their purposes
Response:
Reducing Risk
Compensating
Correcting violations and incidents
Detective
Corrective controls also help improve existing preventative and detective controls
Discouraging violations
Preventative
Providing alternate ways of accomplishing a task
Restoring systems and information
Recovery
Match the following key terms
Availability
Reliable and timely access to data and resources
Confidentiality
Necessary level of secrecy, unauthorized disclosure is prevented
Shoulder surfing
Unauthorized viewing of information (screen peeking)
Social Engineering
Tricking someone into giving sensitive information (to gain unauthorized access)
What is a cryptographic keystream that can only be used once?
More key terms from Chapter 2
Weakness or lack of a countermeasure
Vulnerability
Entity that can exploit a vulnerability
Threat agent
The danger of having a vulnerability exploited
Exposure
The probability of a threat being realized
Presence of a vulnerability which exposes the organization
Risk
A WAN is
a Working Authentication Name
the Westinghouse Address Naming convention
a Wide Area Network
one of the Wilson-Adder Need types
a Wide Array Node
A LAN is
a Local Area Network
a Linear Applebaum Network diagram
a Local Account Name
a Least Access Notification
a Local Authentication Node