Access Controls
Security & Personnel
Security Technology
Implementing Info Sec
Info Sec Maintenance
100

This is the process of validating and verifying an unauthenticated entity's purported identity.

What is authentication?

100

These people provide day-to-day systems monitoring to support an organization's goals and objectives.

Who are security administrators?

100

This is a software program or hardware appliance that can intercept, copy, and interpret network traffic.

What is a packet sniffer?

100

This phase is considered the longest and most expensive stage of the systems development life cycle.

What is maintenance and change?

100

Over time, these may become inadequate due to changes in the organization's mission and operational requirements, threats, or the environment.

What are policies and procedures?

200

This is the matching of an authenticated entity to a list of information assets and corresponding access levels.

What is accountability?

200

This is the title most commonly associated with the top information security officer in the organization.  

Who is the CISO?

200

This type of vulnerability scanner listens in on the network and identifies vulnerable versions of both server and client software.

What is passive?

200

This is an emerging methodology that integrates the efforts of the development team and the operations team to improve functionality and security of applications. 

What is DevOps?

200

This is an essential part of effective remediation because it helps organizations keep track of specific vulnerabilities as they are reported and remediated.

What is a vulnerability database?

300

This can be a dedicated port on a firewall device linking a single bastion host.

What is a DMZ?

300

This is one of the most crucial ongoing responsibilities in security management with strategic, tactical, and operating elements that must align with and support organizational and IT objectives.

What is planning?

300

This is a type of testing is a testing technique that looks for vulnerabilities in a program or protocol by feeding random input to the program or a network running the protocol. 

What is fuzz testing?

300

This is a methodology and formal development strategy for the design and implementation of an information system.

What is the systems development life cycle?

300

This is the process of removing or repairing flaws in information assets that cause a vulnerability or reducing or removing the risk associated with the vulnerability.  

What is remediation?

400

These help to deny all data that is not verifiably authentic.  

What are firewall rules?

400

This must always be conducted to determine the level of trust the business can place in a candidate for an information security position.

What is a background check?

400

These are decoy systems designed to lure potential attackers away from critical systems.

What are honeypots?

400

Planners need to estimate this for each task, subtask, or action step in a project plan.

What is effort?

400

This is an approach to implementing system change that uses policies, procedures, techniques, and tools to manage and evaluate proposed changes, track changes through completion, and maintain supporting documentation.

What is configuration change management?

500

This is a network device that allows administrators to restrict access to internal content from external users.

What is a content filter?

500

These are the technically qualified individuals tasked to configure firewalls, deploy IDSs, implement security software, diagnose and troubleshoot problems, and coordinate with systems and network administrators to ensure that the organization's security technology is properly implemented.

Who are security analysts?

500
This is the process of scanning a network for active systems and then identifying the network services offered by the host system.  

What is fingerprinting?

500

This document must describe how to acquire and implement the needed security controls and create a setting in which those controls achieve the desired outcome.

What is a project plan?

500

This is the process of identifying and documenting specific and potential flaws in the organization's information asset environment.  

What is vulnerability assessment?

M
e
n
u