CIA:DAD
Integrity:_________
What is Alteration?
A standardized identifier for a known cybersecurity vulnerability.
What is a CVE?
This is needed to understand why and how a business uses a given system.
What is mission/business purpose.
Hardware, software, data, and people can all fall into this category when they have value to an organization.
What are assets?
This assessment identifies weaknesses without attempting to exploit them.
What is a vulnerability assessment?
These two factors are combined to determine the level of risk.
What are likelihood/probability and impact?
This scoring system identifies the severity of a vulnerability.
What is CVSS?
This establishes how a system is set up right now, including hardware, software, and settings.
What is the current configuration?
Customer Social Security numbers and employee medical information would generally fall into this information classification.
What is protected or private information?
This type of testing attempts to exploit identified weaknesses.
What is penetration testing?
An organization decides to purchase cyber insurance to address the financial consequences of a risk. Which risk-handing strategy is it using?
What is risk transference?
This structure of cybersecurity safeguards helps organizations protect systems and data.
What are the CIS Controls?
This resource is used to document system configurations.
What are network/system diagrams?
An organization's product brochures or testimonials generally fall into this information classification.
What is public information?
Which is the technical control?
What is the security token?
An employee falls for a phishing email. Identify the exploit.
What is social engineering?
The risk remaining after controls have been implemented.
What is residual risk?
This process sets and maintains an approved, known state for systems and devices.
What is configuration management?
The amount required to purchase an equivalent new asset is its ________.
What is replacement value?
A vulnerability scanner reports that a server may be vulnerable to a known exploit. What has the analyst identified: a confirmed successful exploit or a potential vulnerability?
What is a potential vulnerability?
An employee falls for a phishing email. Identify the vulnerability.
What is lack of employee training or awareness?
This is a weakness that can be exploited, but it is not the event or actor that might exploit it.
What is a vulnerability?
This process controls an documents modifications to systems so that changes don't introduce new risk.
What is change management?
The replacement value of a server is $5,000, but restoring its software, configuration, and data adds another $8,000. What value should the organization use when planning for this loss?
What is recovery value?
A new security control consumes so many server resources that a critical application stops functioning. What important factor was overlooked?
What is operational impact of the control?