Contains 20 questions.
Discuss the difference between 'Authorization' and 'Authentication' and provide an example of how they work together in a secure system.
What is the primary role of a 'Security Governance' framework?
The practice of splitting tasks among multiple individuals to prevent fraud and errors is called ________ of duties.
Which of the following is a technical control used to support the principle of confidentiality?
Explain the concept of 'Defense in Depth'.
Which security principle suggests that a user should be granted the minimum level of access necessary to perform their job functions?
The process of verifying the identity of a user, process, or device is known as ________.
What is the primary objective of 'Non-repudiation' within the security framework?
Which of the following best defines the 'CIA triad' in the context of information security?
Which element of the CIA triad is most directly impacted by a Denial of Service (DoS) attack?
Which of the following describes a scenario where an attacker uses a legitimate user's session token to gain unauthorized access to a web application?
In the context of the Bell-LaPadula model, what does the 'no read up' rule represent?
A ________ is a process of evaluating the risks to an organization's assets and determining the potential impact of a loss.
When an organization moves to a public cloud provider, which security responsibility is most likely to be shifted to the provider according to the shared responsibility model?
What is the primary purpose of an HSM (Hardware Security Module) in an enterprise environment?
Which of the following is an example of an 'Administrative' security control?
An organization is victimized by a ransomware attack that encrypts critical database files. Which pillar of the CIA triad is primarily compromised?
Explain the difference between Symmetric and Asymmetric encryption and provide a real-world scenario where each is typically used.
The principle of ________ dictates that users should be granted only the minimum level of access necessary to perform their job functions.
Which type of firewall inspects traffic based on the state of the network connection rather than just the packet headers?