Security Operations Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations flashcards as text
Which concept in security operations describes the process of proactively searching for threats that have evaded existing security controls?
Answer: Threat hunting
Threat hunting is a proactive, human-led activity that assumes compromise has occurred and searches for attacker activity not caught by automated tools.
A company wants to ensure that a departing system administrator cannot retain access to any systems after their last day. Which process BEST addresses this?
Answer: Implementing an automated offboarding workflow that revokes all accounts and credentials upon HR termination
Automated offboarding tied to HR systems ensures immediate, comprehensive revocation of all access rights when an employee is terminated.
What is the purpose of a Security Information and Event Management (SIEM) system's correlation engine?
Answer: Combining events from multiple sources to identify patterns that indicate a security incident
The correlation engine aggregates and analyzes events across disparate systems to surface attack patterns that individual log sources would not reveal alone.
An organization stores backup tapes off-site. Which backup type copies only data that has changed since the LAST FULL backup, allowing for a two-tape restore?
Answer: Differential backup
A differential backup captures all changes since the last full backup, so restoration requires only the most recent full backup and the latest differential tape.
Which principle ensures that security controls protect information at the level of its classification, regardless of where it resides or who requests it?
Answer: Tranquility
The tranquility principle in the Bell-LaPadula model states that security labels do not change while subjects are actively accessing objects, preserving classification integrity.
A zero-day vulnerability is being actively exploited in the wild before a patch is available. Which interim security control BEST reduces exposure?
Answer: Applying compensating controls such as WAF rules, network segmentation, or enhanced monitoring
Compensating controls provide risk reduction when a patch is unavailable by limiting exploitability through alternative protective measures.
Which international standard provides a framework specifically for information security incident management processes?
Answer: ISO/IEC 27035
ISO/IEC 27035 is the international standard dedicated to information security incident management, covering planning, detection, assessment, response, and lessons learned.