Answers
Chapter 1
- 1.1 Correct Answer: B. Preventive, Detective, Corrective.
Explanation: These are the three primary categories of cybersecurity controls based on timing. They indicate whether a control prevents, detects, or responds to incidents.
- 1.2 Correct Answer: C. A firewall filtering network traffic.
Explanation: Firewalls are designed to prevent unauthorized access by blocking suspicious or harmful network traffic. This makes them a key example of preventive controls.
- 1.3 Correct Answer: B. Detect and alert about ongoing or past incidents.
Explanation: Detective controls identify and provide alerts for security incidents, enabling quick response. They do not stop incidents but provide critical information for mitigation.
- 1.4 Correct Answer: C. They focus on restoring systems to normal after an incident.
Explanation: Corrective controls respond to incidents by minimizing harm and restoring functionality. Examples include backups and system repair tools.
- 1.5 Correct Answer: B. Enforcing policies and governance measures.
Explanation: Administrative controls involve creating and enforcing policies and procedures to guide organizational cybersecurity efforts. They help shape security culture and compliance.
- 1.6 Correct Answer: C. Multi‐factor authentication (MFA).
Explanation: MFA is a technical control that enhances security by requiring multiple forms of verification for user access. This technology‐driven measure prevents unauthorized access.
- 1.7 Correct Answer: B. ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access