Domain 1: Security and Risk Management - Control Types

23 important questions on Domain 1: Security and Risk Management - Control Types

What name is oftenly used for administrative controls?

Soft controls, for the reason that they are more management orientated.

Which 4 examples of administrative controls are there?

1. Security documentation
2. Risk management
3. Personnel security
4. Training

How are technical controls also being refered to?

Logical controls
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

Which 5 examples of technical controls you can name?

Software and hardware components as in:
1. Firewalls
2. IDS
3. Encryption
4. Identification and authentication mechanisms

What is meant with physical controls?

Items put into place to protect facilities, personnel, and resources.

What is meant with defense-in-depth?

This is the coordinated use of multiple security controls in a layered approach.

Why use a multilayered defense systems?

To minimize the probability of successful penetration and compromise because an attacker would have to get through several different types of protection mechanisms before she gained access to the critical assets.

Which 7 examples of physical controls can you name?

1. Fence
2. Locked external doors
3. Closed-circuit TV (CCTV)
4. Security guards / dogs
5. Locked internal doors
6. Locked server room / badges / swipe cards
7. Physically secures computers (cable locks)

Which 6 examples of technical controls can you name?

1. Firewalls
2. Intrusion Detection System (IDS)
3. Intrusion Prevention Systems (IPS)
4. Antimalware,
5. Access Control lists
6. Encryption, secure protocols, call-back systems, database views, constrained user interfaces
7. Passwords, biometrics, smart cards

How to determine what types of controls that need to be implemented?

They need to map the threats that an organization faces

How to determine the number of control layers that need to be put in to place?

This is determined by the sensitivity of the asset

Which Functionalities can security controls provide?

1. Preventive
2. Detective
3. Corrective
4. Deterrent
5. Recovery
6. Compensating

What is meant with preventive controls?

Intended to avoid an incident from occurring

What is meant with detective controls?

Helps identify an incident's activities and potentially an intruder

What is meant with Corrective controls?

Fixes components or systems after an incident has occurred

What is meant with Deterrent controls?

Intended to discourage a potential attacker

What is meant with recovery controls?

Intended to bring the environment back to regular operations

What is meant with compensating controls?

Controls that provide an alternative measure of control

When looking at a security structure of an environment, were do you first start?

It's most productive to start with the preventive model and then use detective, corrective, and recovery mechanisms to help support this model

In what categories falls the administrative, physical and technical controls?

Generally in the preventive controls category

Which 6 examples of preventive administrative controls can you name?

1. Policies and procedures
2. Effective hiring practices
3. Pre-employment background checks
4. Controlled termination processes
5. Data classification and labeling
6. Security awareness

What kind of control is a computer image?

A corrective control, because images are being reloaded when data is corrupted.

Can you describe an example of compensating control?

Instead of hiring a security guard, make use of fences which is lowering the cost and compensating the absence of a security guard.

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo