Domain 1: Security and Risk Management - Security Frameworks
17 important questions on Domain 1: Security and Risk Management - Security Frameworks
What is meant with "security through obscurity"?
Can you describe a non tech example of security through obscurity?
In what was can vulnerabilities been spot by an attacker?
2. Fuzzing
3. Data validation inputs
4. Etc...
- Higher grades + faster learning
- Never study anything twice
- 100% sure, 100% understanding
Is it smart to develop your own inhouse cryptographic algorithm?
Of which entities is a security program (framework) made up of?
2. Administrative (controls)
3. Physical (controls)
4. Procedures
5. Business processes
6. People working together on protecting the environment
A framework has multiple layers which protect each other, how?
How do you build a security program (framework)?
What standards are being developed for the security industry?
- ISO/IEC 27000 series
- Zachman Framework
- TOGAF
- DoDAF
- MODAF
- SABSA model
- COBIT 5
- NIST SP 800-53
- COSO Internal Control - Integrated Framework
- ITIL
- Six Sigma
- Capability Maturity Model Integration (CMMI)
What is the ISO/IEC 27000 series about?
What is the Zachman Framework about?
What is the TOGAF model about?
What is the DoDAF framework about?
What is the MODAF Framework about?
What is the SABSA model about?
What is the COBIT 5 Framework about?
What is the COSO Internal Control - Integrated Framework about?
What is the Capability Maturity Model Integration (CMMI) about?
The question on the page originate from the summary of the following study material:
- A unique study and practice tool
- Never study anything twice again
- Get the grades you hope for
- 100% sure, 100% understanding