Security Principles
BC, DR & Incident Response
Access Controls
Network Security
Security Operations
100

What are the three elements of the CIA triad?

Confidentiality, Integrity, Availability

 

100

What is the correct order of the Incident Response lifecycle?

Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned

100

What does IAAA stand for?

Identification, Authentication, Authorization, Accountability

100

IDS vs IPS?

IDS = detects/alerts (passive). IPS = detects AND blocks (active, inline).

100

Three types of security controls by implementation?

Administrative (policies/training), Technical (firewalls/encryption), Physical (locks/cameras).

200

What is the difference between a vulnerability, a threat, and a risk?

Vulnerability = weakness. Threat = exploits weakness. Risk = likelihood × impact.

200

What is the difference between RTO and RPO?

RTO = max acceptable downtime. RPO = max acceptable data loss.

200

Three factors of authentication with examples?

Know (password), Have (smart card), Are (fingerprint).

200

Three cloud service models  who manages the OS?

IaaS = customer manages OS. PaaS = provider manages OS. SaaS = provider manages all

200

Differential vs incremental backup?

Differential = since last FULL (grows). Incremental = since last ANY backup (stays small).

300

What is the formula for Single Loss Expectancy (SLE)?

SLE = Asset Value (AV) × Exposure Factor (EF)

300

Difference between hot site, warm site, and cold site?

Hot = minutes (real-time mirror). Warm = hours (hardware ready). Cold = days/weeks (empty space)

300

Difference between DAC, MAC, and RBAC?

DAC = owner decides. MAC = labels/clearances. RBAC = job role determines access.

300

VLAN vs VPN?

VLAN = segments INTERNAL network. VPN = secure tunnel OVER internet for remote access.

300

What does a File Integrity Monitor (FIM) do?

Compares files against known-good baseline using hash values to detect unauthorized changes.

400

Explain due diligence vs due care.

Due diligence = researching risks (homework). Due care = implementing measures (action).

400

BCP vs DRP  what's the difference?

BCP = keeping ENTIRE BUSINESS running. DRP = restoring IT SYSTEMS after disaster.

400

Least privilege vs need-to-know?

Least privilege = minimum access rights for job. Need-to-know = limited to info for current task.

400

Hub, Switch, Router  which OSI layer for each?

Hub = L1 (Physical). Switch = L2 (Data Link/MAC). Router = L3 (Network/IP).

400

What is a compensating control?

An alternative safeguard when the primary control isn't possible. E.g., WAF when no patch exists.

500

What is the difference between governance and management in security?

Governance = strategic direction by board (WHAT/WHY). Management = tactical execution (HOW).

500

Name the four DR test types from least to most disruptive.

Tabletop → Simulation → Parallel → Full Interruption

500

Ex-employee still has credentials. What failed?

Deprovisioning/offboarding. Account should be disabled immediately.

500

Shared responsibility: what is ALWAYS customer's and provider's?

Customer ALWAYS: data + access. Provider ALWAYS: physical security + hardware.

500

Preventive vs detective vs corrective controls with examples?

Preventive = stops (firewall, policy, fence). Detective = discovers (IDS, log, camera). Corrective = fixes (patch, termination, extinguisher).

M
e
n
u