Security Operations Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Operations flashcards as text
Which security operations principle requires that no single individual can complete a sensitive transaction without the involvement of at least one other person?
Answer: Separation of duties
Separation of duties splits critical tasks among multiple people so that no one person can commit fraud or error without detection.
An organization uses a honeynet to gather threat intelligence. Which is the GREATEST risk associated with this approach?
Answer: Attackers may use the honeynet as a pivot point to attack real systems
If a honeynet is not properly isolated, a compromised decoy system can serve as a launchpad for attacks against production systems.
What is the role of an evidence custodian in a forensic investigation?
Answer: Maintaining and documenting the chain of custody for all evidence
The evidence custodian is responsible for the secure storage of evidence and ensuring the chain of custody is documented and unbroken.
A company's BCP requires that critical systems be restored within 4 hours of a disaster. Which metric defines this requirement?
Answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) specifies the maximum acceptable duration for restoring a system or process after an outage.
Which access control model is BEST suited for a military environment where data classification levels (Top Secret, Secret, Unclassified) govern information access?
Answer: Mandatory Access Control (MAC)
MAC enforces access based on data classification labels and subject clearance levels, making it ideal for environments with strict classification hierarchies.
During an incident, a responder runs a live memory acquisition tool on a compromised server before shutting it down. Which forensic principle motivates this action?
Answer: Volatile data in RAM is lost when the system powers off
RAM contains volatile artifacts such as running processes, encryption keys, and network connections that are permanently lost upon shutdown.
Which security operations center (SOC) tier is typically responsible for developing new detection rules and performing threat hunting?
Answer: Tier 3 — Advanced analysis and threat hunting
Tier 3 analysts are senior specialists who proactively hunt for threats, reverse malware, and create custom detection logic based on threat intelligence.