← All CSC Flashcard Decks

Mixed Deck — All CSC Topics Flashcards

100 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CSC Topics flashcards as text
  1. What is the purpose of a System Security Plan (SSP) in the federal compliance context?

    Answer: It documents the security requirements and controls implemented for an information system

    An SSP describes the security requirements of a system and documents how controls are implemented to satisfy those requirements, typically required by FISMA.

  2. Which of the following best describes the primary purpose of the 'Prepare' step in the NIST Risk Management Framework (RMF)?

    Answer: To establish the context and foundation for managing security and privacy risk at both the organization and system levels.

    The 'Prepare' step (Step 1) is foundational and focuses on activities at both the organization and system levels to ensure that the organization is ready to manage its security and privacy risks. This includes establishing a risk management strategy, identifying key roles, determining risk tolerance, and identifying common controls.

  3. Which regulatory framework specifically requires covered entities to have Business Associate Agreements with vendors that handle protected health information?

    Answer: HIPAA

    HIPAA mandates Business Associate Agreements (BAAs) with any vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity.

  4. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement?

    Answer: Implementing a Privileged Access Management (PAM) solution with session recording

    PAM solutions with session recording provide direct evidence of privileged activity monitoring, including command logs and video playback.

  5. Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing:

    Answer: Data that is likely to result in high risk to individuals' rights and freedoms

    GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for large-scale processing or systematic monitoring.

  6. What is the primary purpose of a vendor offboarding process from a cybersecurity perspective?

    Answer: To revoke all vendor access and retrieve or destroy organizational data

    Secure offboarding ensures that vendor access credentials are revoked, shared data is returned or destroyed, and no residual access vectors remain.

  7. Under PCI DSS, what is the maximum number of digits that may be displayed when masking a primary account number (PAN)?

    Answer: The first six and last four digits

    PCI DSS allows displaying the first six and last four digits of a PAN; all other digits must be masked.

  8. During a security control audit, an auditor discovers that a firewall rule set has not been reviewed in 18 months. Which audit finding category best describes this?

    Answer: Control deficiency

    An unreviewed firewall rule set represents a control deficiency where the control is not operating as designed or intended.

  9. A controller claims they anonymised their dataset, but re-identification is possible using publicly available data. Under GDPR, this dataset should be treated as:

    Answer: Personal data subject to all GDPR principles

    If re-identification is reasonably possible, the data is still personal data under GDPR regardless of the controller's anonymisation claims.

  10. A federal agency is deploying a new information system that will process, store, and transmit personally identifiable information (PII). According to the NIST Risk Management Framework (RMF), which of the following steps must be completed FIRST to determine the necessary level of security controls?

    Answer: Categorize the information system based on impact.

    The NIST RMF is a sequential process. The 'Categorize' step (Step 2) is critical and must be performed early in the lifecycle. This step involves assessing the potential adverse impact on the organization's assets and operations, individuals, other organizations, and the Nation if the information and the information system were to be compromised (i.e., a loss of confidentiality, integrity, or availability). The result of the categorization determines the selection of baseline security controls in the next step.

  11. New York's SHIELD Act primarily expands which existing state law?

    Answer: New York data breach notification law

    The SHIELD Act expanded New York's data breach notification law by broadening the definition of private information and adding reasonable cybersecurity requirements.

  12. A healthcare organization experiences a ransomware attack affecting 400 patient records. Under HIPAA, media notification is required when the breach affects more than:

    Answer: 500 individuals in a state or jurisdiction

    HIPAA requires covered entities to notify prominent local media outlets when a breach affects more than 500 individuals in a state or jurisdiction.

  13. The EU NIS2 Directive expanded cybersecurity requirements compared to NIS1 by:

    Answer: Expanding scope to more sectors and increasing penalties up to €10 million or 2% of global turnover

    NIS2 significantly expanded the original directive by covering more sectors, strengthening requirements, and increasing penalties to up to €10 million or 2% of global annual turnover.

  14. A healthcare organization shares patient billing data with a third-party payment processor. Under HIPAA, the payment processor is classified as a:

    Answer: Business associate

    A third party that performs functions involving PHI on behalf of a covered entity is classified as a business associate and must sign a Business Associate Agreement (BAA).

  15. A financial services company is preparing for its annual security control audit. The IT team wants to move from a point-in-time audit approach to a more proactive model that provides real-time insights into control effectiveness. Which of the following methodologies should they implement?

    Answer: Continuous Controls Monitoring (CCM)

    Continuous Controls Monitoring (CCM) is a technology-driven approach that continuously assesses and reports on the effectiveness of an organization's security controls in real-time or near-real-time. This proactive method moves away from traditional, periodic audits and allows for immediate identification and mitigation of risks as they arise.

  16. A vendor refuses to complete your security questionnaire, citing trade secrets. What is the best response?

    Answer: Request an independent third-party attestation or audit report instead

    Third-party attestations such as SOC 2 or ISO 27001 certificates can satisfy due diligence requirements without exposing the vendor's proprietary details.

  17. A hospital's IT team is concerned about ransomware attacks. They have implemented antivirus software on all endpoints and servers. To enhance their defenses in line with ISO 27001 principles for malware protection, what additional measure should they prioritize?

    Answer: Conducting user awareness training on phishing and social engineering.

    While antivirus software is a crucial technical control for malware protection (related to the former A.12.2.1 and now part of broader technological controls like A.8.7), a comprehensive defense must also address the human element. Many malware incidents, including ransomware, begin with phishing or social engineering attacks. Therefore, user awareness training (A.6.3) is a critical preventative measure to complement technical controls.

  18. Which NIST publication provides guidance specifically on security and privacy controls assessment procedures used in the RMF Assess step?

    Answer: NIST SP 800-53A

    NIST SP 800-53A provides assessment procedures and methods for evaluating the effectiveness of controls documented in NIST SP 800-53.

  19. What is the PRIMARY purpose of a Risk Register in an organization?

    Answer: To document identified risks, their likelihood, impact, and treatment plans

    A Risk Register is a central document that captures identified risks along with their attributes and management strategies.

  20. A financial institution is implementing the NIST RMF. During the 'Select' step, the security team identifies a set of controls that are applicable to multiple information systems across the enterprise. What is the correct term for these types of controls?

    Answer: Common controls

    In the 'Select' step of the RMF, controls that can be inherited by one or more organizational systems are designated as 'common controls'. These are controls that are managed and implemented by a central entity and can be leveraged by multiple systems, reducing redundant effort and ensuring consistency.