ISC2
International Information System Security Certification Consortium.
Getting Started: Your CC Exam Journey
Free knowledge base
Everything from the course in one searchable place: 252 entries. Use it to review before a practice test or look up a word you forgot.
252 results
International Information System Security Certification Consortium.
Getting Started: Your CC Exam Journey
Formal recognition of an individual's knowledge and skills.
Getting Started: Your CC Exam Journey
Positions or certifications for individuals starting a career.
Getting Started: Your CC Exam Journey
A specific area of knowledge covered by an exam or curriculum.
Getting Started: Your CC Exam Journey
A qualification, achievement, or quality indicating competence.
Getting Started: Your CC Exam Journey
Basic or fundamental knowledge upon which other concepts build.
Getting Started: Your CC Exam Journey
Protecting systems, networks, and data from digital attacks.
Getting Started: Your CC Exam Journey
To remember the CC is for 'Cybersecurity Career,' think: 'CC = Cybersecurity Commencement!'
Getting Started: Your CC Exam Journey
The exam tests your understanding of the *purpose* and *target audience* of the CC certification. Be prepared to identify who benefits most from obtaining it and why it's considered an entry-level credential. Keywords like 'foundational,' 'beginner,' and 'career changer' are important.
Getting Started: Your CC Exam Journey
Mistaking the CC for an advanced technical certification; it's foundational.
Getting Started: Your CC Exam Journey
Believing prior cybersecurity work experience is required; it is not.
Getting Started: Your CC Exam Journey
Underestimating the value of the ISC2 brand for entry-level roles.
Getting Started: Your CC Exam Journey
A raw score converted to a standardized scale for fair comparison.
Getting Started: Your CC Exam Journey
A question format with several options, only one of which is correct.
Getting Started: Your CC Exam Journey
Strategically allocating time to complete all exam questions efficiently.
Getting Started: Your CC Exam Journey
The final step to become certified after passing an ISC2 exam.
Getting Started: Your CC Exam Journey
Professional conduct standards all ISC2 members must adhere to.
Getting Started: Your CC Exam Journey
The science of measuring mental capacities and processes, used in exam design.
Getting Started: Your CC Exam Journey
To remember the exam details: '100 Questions, 120 Minutes, 700 to Win it!'
Getting Started: Your CC Exam Journey
The ISC2 CC exam consists of 100 multiple-choice questions. You have 120 minutes to complete it, and a scaled score of 700 out of 1000 is required to pass. Memorize these exact numbers.
Getting Started: Your CC Exam Journey
Spending too much time on a single difficult question, leading to not finishing the exam.
Getting Started: Your CC Exam Journey
Not reading all answer options carefully before selecting one, missing the 'best' answer.
Getting Started: Your CC Exam Journey
Failing to review marked questions at the end if time permits, missing easy corrections.
Getting Started: Your CC Exam Journey
Protecting information from unauthorized disclosure.
Foundations of Security Principles
Ensuring information is accurate, complete, and unaltered.
Foundations of Security Principles
Ensuring authorized users can access information when needed.
Foundations of Security Principles
Foundational model of information security: Confidentiality, Integrity, Availability.
Foundations of Security Principles
An incident where security controls are circumvented, leading to compromise.
Foundations of Security Principles
Converting data into a code to prevent unauthorized access.
Foundations of Security Principles
Mechanisms that restrict who can access what resources.
Foundations of Security Principles
Generating a fixed-size value from data to detect changes.
Foundations of Security Principles
To remember CIA, think of a secret agent: they keep secrets (Confidentiality), ensure their mission plans are accurate (Integrity), and are always ready for action (Availability).
Foundations of Security Principles
Memorize the exact definition for each component of the CIA Triad. On the exam, you will encounter scenarios and need to correctly identify which principle is being violated or upheld.
Foundations of Security Principles
Confusing integrity with confidentiality: Integrity is about unauthorized modification, while confidentiality is about unauthorized viewing.
Foundations of Security Principles
Underestimating the impact of an availability breach: Even if data is secure, if no one can access it, it's useless.
Foundations of Security Principles
Forgetting that the three principles are interconnected: A failure in one often negatively impacts the others.
Foundations of Security Principles
Verifying the identity of a user, process, or device.
Foundations of Security Principles
Determining what resources an authenticated user can access.
Foundations of Security Principles
Tracking and logging user activities and resource consumption.
Foundations of Security Principles
Ensuring a party cannot falsely deny having performed an action.
Foundations of Security Principles
Multi-Factor Authentication; using two or more credential types.
Foundations of Security Principles
Granting only necessary access rights for a job function.
Foundations of Security Principles
Cryptographic method providing authenticity and non-repudiation.
Foundations of Security Principles
Remember 'AAA' as 'Are you who you say you Are? What Are you allowed to do? What did you do?' Non-Repudiation is 'No-Denial'.
Foundations of Security Principles
The exam frequently tests the distinct definitions and order of AAA. Remember that authentication *always* comes before authorization. Non-repudiation is a separate but related concept ensuring accountability.
Foundations of Security Principles
Confusing authentication (who you are) with authorization (what you can do).
Foundations of Security Principles
Forgetting that accounting is about logging and auditing, not just financial records.
Foundations of Security Principles
Underestimating the importance of non-repudiation in legal and business contexts.
Foundations of Security Principles
Potential for loss or damage from a threat exploiting a vulnerability.
Foundations of Security Principles
Any potential danger that could exploit a vulnerability and cause harm.
Foundations of Security Principles
A weakness in a system or control that a threat can exploit.
Foundations of Security Principles
The magnitude of harm or damage caused by a security incident.
Foundations of Security Principles
The probability or frequency of a threat exploiting a vulnerability.
Foundations of Security Principles
Actions taken to reduce the likelihood or impact of a risk.
Foundations of Security Principles
Deciding to take no action to reduce a risk due to cost/benefit.
Foundations of Security Principles
Shifting the financial burden of a risk to another party, e.g., insurance.
Foundations of Security Principles
TV-IL: Threats, Vulnerabilities, Impact, Likelihood – the four ingredients of Risk!
Foundations of Security Principles
The exam often tests your ability to differentiate between threats and vulnerabilities. Remember: a threat is 'what could happen' (e.g., malware), and a vulnerability is 'a weakness that allows it to happen' (e.g., unpatched software). Risk is the combination of both, plus impact and likelihood.
Foundations of Security Principles
Confusing a threat with a vulnerability (e.g., saying 'malware' is a vulnerability instead of a threat that exploits a vulnerability).
Foundations of Security Principles
Underestimating the 'human element' as both a threat (insider) and a vulnerability (lack of training).
Foundations of Security Principles
Failing to consider both impact and likelihood when assessing the true severity of a risk.
Foundations of Security Principles
Safeguard to reduce risk to assets.
Foundations of Security Principles
High-level statement of security objectives.
Foundations of Security Principles
Specific, mandatory requirements for implementing policies.
Foundations of Security Principles
Adherence to rules, laws, regulations, and policies.
Foundations of Security Principles
Stops an incident before it occurs.
Foundations of Security Principles
Identifies an incident during or after occurrence.
Foundations of Security Principles
Mitigates impact and restores systems after an incident.
Foundations of Security Principles
General Data Protection Regulation for data privacy.
Foundations of Security Principles
P-S-C: Policies Set the rules, Standards Specify how, Controls Carry them out. Compliance Checks everything.
Foundations of Security Principles
The exam often tests your ability to distinguish between policies (what to do), standards (how to do it), and controls (the actual implementation). Look for keywords like 'management directive' for policy, 'specific requirement' for standard, and 'mechanism' or 'safeguard' for control.
Foundations of Security Principles
Confusing a policy (high-level 'what') with a standard (specific 'how').
Foundations of Security Principles
Thinking all controls are technical; remember administrative and physical controls.
Foundations of Security Principles
Underestimating the importance of compliance; it's not just about avoiding fines, but also trust and reputation.
Foundations of Security Principles
Maintaining essential business functions during disruptions.
Resilience: BC, DR & IR Concepts
Restoring IT systems after a disaster.
Resilience: BC, DR & IR Concepts
Maximum acceptable downtime for a system/process.
Resilience: BC, DR & IR Concepts
Maximum acceptable data loss measured in time.
Resilience: BC, DR & IR Concepts
Identifies critical functions and their recovery needs.
Resilience: BC, DR & IR Concepts
Duplication of critical components to ensure availability.
Resilience: BC, DR & IR Concepts
A secondary location for operations during a disaster.
Resilience: BC, DR & IR Concepts
BC is for 'Business Continues', DR is for 'Data Restores'.
Resilience: BC, DR & IR Concepts
The exam often tests the distinction between BC and DR. Remember: BC is about the business continuing, DR is about the IT recovering. Keywords like 'overall organizational resilience' point to BC, while 'restoring servers' points to DR.
Resilience: BC, DR & IR Concepts
Confusing Business Continuity (BC) with Disaster Recovery (DR) and using the terms interchangeably.
Resilience: BC, DR & IR Concepts
Developing a DR plan without first conducting a Business Impact Analysis (BIA) to prioritize systems.
Resilience: BC, DR & IR Concepts
Creating BC/DR plans but failing to regularly test and update them, rendering them ineffective.
Resilience: BC, DR & IR Concepts
Structured approach to manage cybersecurity incidents.
Resilience: BC, DR & IR Concepts
A widely recognized guideline for computer security incident handling.
Resilience: BC, DR & IR Concepts
Limiting the scope and impact of an incident.
Resilience: BC, DR & IR Concepts
Removing the root cause of an incident.
Resilience: BC, DR & IR Concepts
Restoring systems and data to normal operation.
Resilience: BC, DR & IR Concepts
Post-incident review for continuous improvement.
Resilience: BC, DR & IR Concepts
Detailed, step-by-step instructions for specific incident types.
Resilience: BC, DR & IR Concepts
PRIDE: **P**reparation, **R**ecognition (Detection & Analysis), **I**solation (Containment), **D**econtamination (Eradication & Recovery), **E**valuation (Post-Incident Activity).
Resilience: BC, DR & IR Concepts
The exam often tests your knowledge of the phases of the incident response lifecycle. Memorize the order and purpose of each phase, especially 'Containment' and 'Eradication' – they are distinct steps.
Resilience: BC, DR & IR Concepts
Confusing containment with eradication: Containment stops the spread, eradication removes the threat's cause.
Resilience: BC, DR & IR Concepts
Neglecting post-incident review: Skipping this step means missing opportunities to improve defenses.
Resilience: BC, DR & IR Concepts
Lack of communication: Failing to inform relevant stakeholders can escalate an incident's impact.
Resilience: BC, DR & IR Concepts
An activity essential for an organization's survival and operations.
Resilience: BC, DR & IR Concepts
Period when a system or service is unavailable.
Resilience: BC, DR & IR Concepts
Irrecoverable destruction or corruption of data.
Resilience: BC, DR & IR Concepts
RTO is 'Time' (how long till it's back up?), RPO is 'Point' (how much data did we lose up to this point?).
Resilience: BC, DR & IR Concepts
The exam often tests your ability to distinguish between RTO and RPO. Remember, RTO is about time to recover functionality, and RPO is about the amount of data lost. The BIA is the foundational step for determining both.
Resilience: BC, DR & IR Concepts
Confusing RTO with RPO: RTO is about time to recovery, RPO is about data loss.
Resilience: BC, DR & IR Concepts
Skipping the BIA: Without a proper BIA, RTO and RPO are arbitrary and not aligned with business needs.
Resilience: BC, DR & IR Concepts
Setting unrealistic RTO/RPO: Very low RTO/RPO targets are expensive and may not be necessary for all systems.
Resilience: BC, DR & IR Concepts
A copy of data used to restore original data after loss.
Resilience: BC, DR & IR Concepts
Copies all selected data, regardless of prior backups.
Resilience: BC, DR & IR Concepts
Copies only data changed since the last full or incremental backup.
Resilience: BC, DR & IR Concepts
Copies data changed since the last full backup.
Resilience: BC, DR & IR Concepts
Redundant Array of Independent Disks for data redundancy.
Resilience: BC, DR & IR Concepts
Systems designed to operate continuously without failure.
Resilience: BC, DR & IR Concepts
Storing backups in a location separate from the primary site.
Resilience: BC, DR & IR Concepts
To remember the 3-2-1 backup rule, think of a '3-course meal, 2 different drinks, and 1 dessert to go!'
Resilience: BC, DR & IR Concepts
The exam often tests your understanding of the '3-2-1 rule' for backups. Memorize '3 copies, 2 different media, 1 offsite.' Also, know the difference between incremental and differential backups regarding restore time and storage.
Resilience: BC, DR & IR Concepts
Forgetting to test backups regularly, leading to failed recovery when needed.
Resilience: BC, DR & IR Concepts
Confusing redundancy with backups; redundancy prevents downtime, backups recover data.
Resilience: BC, DR & IR Concepts
Not storing backups offsite, making them vulnerable to site-specific disasters.
Resilience: BC, DR & IR Concepts
Mechanism to regulate who or what can use resources.
Controlling Access to Resources
Restricts direct interaction with physical assets.
Controlling Access to Resources
Restricts access to computer systems, networks, and data.
Controlling Access to Resources
Layered security approach using multiple controls.
Controlling Access to Resources
Uses unique biological traits for identification.
Controlling Access to Resources
List of permissions attached to an object.
Controlling Access to Resources
Think 'P' for Physical, 'P' for People and Places. Think 'L' for Logical, 'L' for Login and Laptops.
Controlling Access to Resources
The exam will test your ability to differentiate between physical and logical controls. Look for keywords like 'door,' 'fence,' 'guard' for physical, and 'password,' 'firewall,' 'encryption' for logical. Remember that defense in depth applies to both.
Controlling Access to Resources
Confusing physical and logical controls: Remember physical protects the hardware, logical protects the data/software.
Controlling Access to Resources
Underestimating the importance of physical security: A strong firewall is useless if someone can just walk in and steal the server.
Controlling Access to Resources
Ignoring the need for layered security: Relying on a single control leaves a single point of failure.
Controlling Access to Resources
Claiming an identity to a system.
Controlling Access to Resources
Proof of identity, like passwords or tokens.
Controlling Access to Resources
Think 'IAA' as 'I Am Allowed' – I (Identify) Am (Authenticate) Allowed (Authorize).
Controlling Access to Resources
The exam will test your ability to distinguish between identification, authentication, and authorization. Remember: Identification is 'who you say you are,' Authentication is 'proving you are who you say you are,' and Authorization is 'what you are allowed to do.'
Controlling Access to Resources
Confusing authentication with authorization; they are distinct steps.
Controlling Access to Resources
Believing that successful identification automatically grants access.
Controlling Access to Resources
Underestimating the importance of strong authentication methods.
Controlling Access to Resources
Requires two or more distinct authentication factors for verification.
Controlling Access to Resources
A category of proof used to verify identity (e.g., something you know, have, are).
Controlling Access to Resources
A secret piece of information only the user should know, like a password or PIN.
Controlling Access to Resources
A physical item possessed by the user, such as a token or smartphone.
Controlling Access to Resources
A unique biological characteristic of the user, like a fingerprint or face.
Controlling Access to Resources
Allows users to log in once to access multiple independent applications.
Controlling Access to Resources
The system that authenticates the user and provides identity assertions in SSO.
Controlling Access to Resources
An application or service that relies on an IdP for user authentication.
Controlling Access to Resources
K-H-A for Know, Have, Are. Think of it like a KHA-p (cap) you wear for security!
Controlling Access to Resources
The exam often tests your understanding of the three primary authentication factors: something you know, something you have, and something you are. Be able to provide examples for each. Also, remember that MFA requires at least two *different* factors, not just two pieces of the same factor.
Controlling Access to Resources
Confusing MFA with simply using a stronger password. MFA requires *multiple types* of factors.
Controlling Access to Resources
Believing SSO is a security measure on its own. SSO enhances convenience; its security depends on the strength of the initial authentication (ideally MFA).
Controlling Access to Resources
Thinking 'something you do' (like a specific gesture) is one of the three primary factors. While a factor, it's less common than know, have, or are.
Controlling Access to Resources
Framework for managing digital identities and access to resources.
Controlling Access to Resources
Resource owner controls access permissions.
Controlling Access to Resources
Permissions are assigned to roles, users are assigned to roles.
Controlling Access to Resources
Central authority assigns security labels; strict access rules.
Controlling Access to Resources
Process of creating and assigning user accounts and permissions.
Controlling Access to Resources
Process of revoking access and removing user accounts.
Controlling Access to Resources
To remember the access models, think 'DR. MAC': Discretionary, Role-Based, Mandatory Access Control.
Controlling Access to Resources
On the exam, understand the core difference: DAC is owner-centric, RBAC is role-centric, and MAC is label-centric (system-wide policy). Least privilege is a fundamental security principle applicable across all models.
Controlling Access to Resources
Granting 'temporary' administrative access and forgetting to revoke it.
Controlling Access to Resources
Assigning users to roles with more permissions than their job requires.
Controlling Access to Resources
Not regularly auditing user permissions to ensure they still align with current job functions.
Controlling Access to Resources
Physical or logical arrangement of network devices.
Securing the Network Perimeter
Device that forwards data frames to specific ports.
Securing the Network Perimeter
Device that forwards data packets between different networks.
Securing the Network Perimeter
Set of rules governing data communication.
Securing the Network Perimeter
Suite of protocols forming the internet's foundation.
Securing the Network Perimeter
7-layer conceptual framework for network communication.
Securing the Network Perimeter
Logical network segment created on a switch.
Securing the Network Perimeter
Please Do Not Throw Sausage Pizza Away (Physical, Data Link, Network, Transport, Session, Presentation, Application)
Securing the Network Perimeter
Memorize the order of the OSI model layers from 7 (Application) down to 1 (Physical). On the exam, you might be asked to identify which layer a specific device or protocol operates at.
Securing the Network Perimeter
Confusing a hub with a switch: Hubs broadcast, switches intelligently forward.
Securing the Network Perimeter
Incorrectly identifying the primary function of a router vs. a switch: Routers connect different networks, switches connect devices within the same network segment.
Securing the Network Perimeter
Forgetting the OSI model layers or their order: This framework is key to understanding network communication and troubleshooting.
Securing the Network Perimeter
Latest and most secure Wi-Fi Protected Access standard.
Securing the Network Perimeter
Dividing a network into isolated sub-networks.
Securing the Network Perimeter
Creates a secure, encrypted connection over a public network.
Securing the Network Perimeter
Connects individual users to a private network.
Securing the Network Perimeter
Connects two or more private networks together.
Securing the Network Perimeter
Suite of protocols for securing IP communications.
Securing the Network Perimeter
Advanced Encryption Standard, a strong symmetric encryption algorithm.
Securing the Network Perimeter
To remember the order of Wi-Fi security: 'WEP Was Pretty Awful, WPA Was Pretty Adequate, WPA2 Was Pretty Good, WPA3 is Pretty Perfect!'
Securing the Network Perimeter
On the exam, recognize WPA3 as the strongest wireless security protocol. Understand that network segmentation (e.g., VLANs) limits the blast radius of a breach. For VPNs, differentiate between Remote-Access and Site-to-Site and know their primary purpose is secure remote connectivity.
Securing the Network Perimeter
Using WEP or WPA (original) for wireless security instead of WPA2 or WPA3, leaving the network vulnerable.
Securing the Network Perimeter
Failing to segment critical systems, allowing an attacker who breaches one part of the network to easily access sensitive data elsewhere.
Securing the Network Perimeter
Assuming a VPN alone is sufficient for remote access security without also implementing strong authentication like MFA.
Securing the Network Perimeter
Defines security duties between cloud provider and customer.
Securing the Network Perimeter
Monitors and responds to threats on endpoints in real-time.
Securing the Network Perimeter
Prevents sensitive data from leaving the organization's control.
Securing the Network Perimeter
Centrally manages and secures mobile devices.
Securing the Network Perimeter
Secures and manages specific applications on mobile devices.
Securing the Network Perimeter
Enforces security policies across multiple cloud services.
Securing the Network Perimeter
CEM: Cloud, Endpoint, Mobile. Remember to secure all three parts of your digital world!
Securing the Network Perimeter
The exam often tests the Shared Responsibility Model for cloud security. Remember that the cloud provider is generally responsible for 'security OF the cloud' (physical infrastructure, virtualization), while the customer is responsible for 'security IN the cloud' (data, applications, network configuration, IAM). Keywords to look for are 'customer's responsibility' or 'provider's responsibility' in cloud scenarios.
Securing the Network Perimeter
Assuming the cloud provider handles all security aspects in a SaaS model.
Securing the Network Perimeter
Neglecting to implement strong authentication (MFA) for cloud services and mobile access.
Securing the Network Perimeter
Failing to regularly patch and update endpoint operating systems and applications.
Securing the Network Perimeter
Deceptive emails to trick users into revealing info.
Securing the Network Perimeter
Email authentication to prevent sender spoofing.
Securing the Network Perimeter
Protects web applications from common attacks.
Securing the Network Perimeter
Protocols for encrypting web communication.
Securing the Network Perimeter
Collects, aggregates, analyzes security logs.
Securing the Network Perimeter
Linking disparate events to identify patterns.
Securing the Network Perimeter
Impersonating executives for financial fraud.
Securing the Network Perimeter
For SIEM functions, remember 'CAN-DO': Collect, Aggregate, Normalize, Detect (Correlate), Output (Reports/Alerts).
Securing the Network Perimeter
The exam often tests the purpose of SPF, DKIM, and DMARC in preventing email spoofing. Remember that a WAF protects web applications, not the network layer. For SIEM, focus on its ability to centralize logs, correlate events, and provide real-time alerts for incident detection.
Securing the Network Perimeter
Confusing a WAF with a traditional network firewall; a WAF operates at the application layer (Layer 7).
Securing the Network Perimeter
Underestimating the importance of user training in preventing phishing and web-based attacks; technology alone isn't enough.
Securing the Network Perimeter
Believing a SIEM automatically fixes problems; it detects and alerts, but human analysts are still needed for investigation and response.
Securing the Network Perimeter
Automated process to identify known security weaknesses.
Operational Security Practices
Simulated cyberattack to find exploitable vulnerabilities.
Operational Security Practices
Systematic evaluation of controls against standards/policies.
Operational Security Practices
Common Vulnerabilities and Exposures database of known flaws.
Operational Security Practices
Authorized hacking to test system security.
Operational Security Practices
Pen test with no prior knowledge of the target system.
Operational Security Practices
To remember the differences: 'V' is for 'Vulnerabilities', 'P' is for 'Penetrating' (exploiting), 'A' is for 'Auditing' (compliance).
Operational Security Practices
The exam often distinguishes between 'finding' vulnerabilities (scans) and 'exploiting' them (pen tests). Remember that audits are about 'verifying compliance' and 'control effectiveness.'
Operational Security Practices
Confusing a vulnerability scan with a penetration test; scans identify, pen tests exploit.
Operational Security Practices
Believing that passing a vulnerability scan means a system is perfectly secure.
Operational Security Practices
Assuming a security audit is a technical test; it's primarily a compliance and control review.
Operational Security Practices
Continuous observation of systems and networks for security incidents.
Operational Security Practices
Process of collecting, storing, analyzing, and disposing of system logs.
Operational Security Practices
Monitors network or system activity for malicious patterns or policy violations.
Operational Security Practices
Educating employees about security risks, policies, and best practices.
Operational Security Practices
Rules defining how long data, including logs, must be kept.
Operational Security Practices
Identifying patterns in data that deviate significantly from expected behavior.
Operational Security Practices
To remember the key aspects: 'MAL' for Monitoring, Awareness, and Logs. MALware is bad, but MAL security practices are good!
Operational Security Practices
The exam emphasizes the 'why' behind these practices. Know that monitoring detects, log management records, and awareness training prevents. Keywords like 'proactive defense,' 'forensic analysis,' and 'human element' are important.
Operational Security Practices
Treating logs as mere storage; they must be actively analyzed.
Operational Security Practices
Conducting security awareness training only once a year instead of ongoing.
Operational Security Practices
Failing to integrate monitoring alerts with incident response procedures.
Operational Security Practices
Process of applying updates to software to fix bugs and security vulnerabilities.
Operational Security Practices
Ensuring systems adhere to secure baselines and consistent settings.
Operational Security Practices
Identifying, tracking, and managing all IT assets throughout their lifecycle.
Operational Security Practices
A minimum set of security configurations for a system or application.
Operational Security Practices
Software or data that takes advantage of a vulnerability to cause unintended behavior.
Operational Security Practices
The entire lifespan of an asset, from acquisition to disposal.
Operational Security Practices
To remember the three, think 'PAC Man': P-atch, A-sset, C-onfiguration. PAC Man eats up security threats!
Operational Security Practices
The exam often tests your understanding of the *purpose* and *benefits* of each management practice. Keywords like 'reduce attack surface' for configuration management, 'address known vulnerabilities' for patch management, and 'maintain inventory' for asset management are key.
Operational Security Practices
Confusing configuration management with change management (configuration is about *state*, change is about *process*).
Operational Security Practices
Forgetting that patch management includes testing, not just deployment.
Operational Security Practices
Underestimating the importance of asset disposal in asset management.
Operational Security Practices
Categorizing data by sensitivity to apply appropriate security controls.
Operational Security Practices
Data stored on a physical or digital storage medium.
Operational Security Practices
Data actively moving across a network or between systems.
Operational Security Practices
Protection of physical assets from threats like theft and unauthorized access.
Operational Security Practices
Measures to ensure employees are trustworthy and follow security policies.
Operational Security Practices
Using a magnetic field to erase data from magnetic storage media.
Operational Security Practices
Granting users only the minimum access needed to perform their job.
Operational Security Practices
Remember 'APP' for the three types of security: Assets (Physical), People (Personnel), and Processes (Data Handling).
Operational Security Practices
Memorize the three states of data (at rest, in transit, in process) and the primary control for each. The exam often asks to match a data state with its most effective security measure.
Operational Security Practices
Underestimating the importance of physical security in a digital world.
Operational Security Practices
Failing to classify data, leading to over- or under-protection.
Operational Security Practices
Neglecting proper employee offboarding procedures, creating insider threats.
Operational Security Practices