โ† All SC-900 Flashcard Decks

Security, Compliance & Identity Concepts Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security, Compliance & Identity Concepts flashcards as text
  1. What is 'identity governance' primarily concerned with?

    Answer: Managing and enforcing policies around who has access to what and certifying that access is appropriate

    Identity governance ensures the right people have the right access to the right resources through policy enforcement, access reviews, and audit trails.

  2. Which of the following best describes a 'Distributed Denial of Service (DDoS)' attack?

    Answer: Flooding a target system with traffic from multiple sources to make it unavailable

    A DDoS attack overwhelms a target (website, server, or network) with massive traffic from many compromised systems, rendering it unavailable to legitimate users.

  3. What is the purpose of 'eDiscovery' in a compliance context?

    Answer: Identifying, collecting, and producing electronically stored information for legal proceedings

    eDiscovery is the process of locating, preserving, and producing electronically stored information (ESI) in response to legal requests, audits, or investigations.

  4. In a zero trust model, which of the following is a core guiding principle?

    Answer: Assume breach and verify every request explicitly, regardless of origin

    Zero trust operates on the principle of 'assume breach,' requiring explicit verification of every access request and granting least-privilege access continuously.

  5. What distinguishes 'authentication' from 'authorization'?

    Answer: Authentication verifies who a user is; authorization determines what they are allowed to do

    Authentication is the process of verifying identity (who you are), while authorization determines what resources and actions an authenticated identity is permitted to access.

  6. What is a 'security baseline' in the context of compliance?

    Answer: The minimum security requirements and configurations that all systems must meet

    A security baseline defines the minimum set of security controls and configurations required for all systems to reduce risk to an acceptable level.

  7. Which standard provides a framework of best practices for information security management?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 is an internationally recognized standard that specifies requirements for establishing, implementing, and maintaining an Information Security Management System (ISMS).

Security, Compliance & Identity Concepts Flashcards โ€” SC-900 Study Cards with Answers