Asset Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Asset Security flashcards as text
Which framework provides a standardized vocabulary for describing hardware and software asset information to support vulnerability management?
Answer: Common Platform Enumeration (CPE)
Common Platform Enumeration (CPE) is a structured naming scheme for IT systems, software, and packages that enables consistent identification of assets in vulnerability databases like NVD.
An employee transfers to a new role with different access requirements. Which process ensures their old access rights are removed?
Answer: Privilege creep prevention via access reviews
Regular access reviews and timely revocation of previous role permissions prevent privilege creep, where users accumulate access rights beyond what their current role requires.
Which type of data classification is MOST common in private sector organizations?
Answer: Public / Internal / Confidential / Restricted
Private sector organizations typically use a four-tier model of Public, Internal Use Only, Confidential, and Restricted (or similarly named tiers) as opposed to the government's classification scheme.
What is the FIRST step an organization should take when establishing a data classification program?
Answer: Identify and inventory all data assets owned by the organization
Before data can be classified or protected, organizations must first identify and inventory all data assets to understand what they have, where it is, and who is responsible for it.
Which secure disposal method is REQUIRED for solid-state drives (SSDs) when the data contains classified information?
Answer: Physical destruction or verified cryptographic erasure
SSDs are not effectively sanitized by degaussing (no magnetic media) or overwriting (wear leveling may leave residual data); physical destruction or cryptographic erasure are the only reliable methods for classified data.
A company acquires another firm and inherits its data assets. Which responsibility does the acquiring company immediately assume regarding the inherited customer data?
Answer: The acquirer becomes the data controller with all associated privacy obligations
Upon acquisition, the inheriting organization becomes the data controller and assumes full legal responsibility for protecting inherited personal data in compliance with applicable privacy regulations.
Which concept refers to protecting information by ensuring it is only accessible to those with the verified need and authorization to see it?
Answer: Confidentiality
Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes, which is the primary goal of data classification and access control.