Skip to content

02 — Exam Map & High-Yield Targets

Weight: 6% of Fundamentals · Posture: breadth, discrimination, role/control logic, and scenario recognition—not deep security engineering.

Highest-yield rule

Prefer the answer that protects sensitive/regulated data, preserves legitimate access, and produces auditable evidence.

Priority tiers

Tier 1 — very high

  • Vulnerability vs Threat vs Risk
  • Four A’s + Entitlement
  • Confidentiality vs Regulation
  • Authentication vs Authorization
  • Persistent vs Dynamic masking
  • Policy vs Standard
  • Role-based access
  • Monitoring vs Audit
  • Excessive vs legitimate-privilege abuse
  • Auditability/evidence

Tier 2 — high

  • CRD / HRD / MRD risk classifications
  • Active vs Passive monitoring
  • In-flight vs In-place masking
  • Service vs Shared accounts
  • IDS vs IPS
  • Data Steward vs Information Security
  • CRUD/CRUDE
  • Outsourcing/cloud accountability + chain of custody

Tier 3 — medium

Facility/device/credential/e-communication security; network vocabulary; malware recognition; regulatory families; role grid vs hierarchy; tools/techniques; Data Security architecture.

Tier 4 — supporting recognition

Specific named algorithms, historical regulation examples, older statistics, and product examples.

20 trigger phrases

Stem clue Think
Who are you? Authentication
What may you see/do? Authorization
All data exposed by one authorization Entitlement
Independent review / compliance evidence Audit
Real-time alert or interruption Active monitoring
Periodic snapshots / trends Passive monitoring
Weakness or defect Vulnerability
Potential offensive/adverse action Threat
Likelihood + damage/cost Risk
Need-to-know Confidentiality
Allowed-to-know / external rule Regulation
Highest item sets one internal level Confidentiality aggregation
Several external categories all apply Regulatory categorization
Permanent change before non-prod Persistent masking
Display changes; source value stays Dynamic masking
More rights than needed Excessive privilege
Valid rights used wrongly Legitimate-privilege abuse
Ordinary/lower user becomes admin Privilege elevation
C/R/U/D/E permission mapping CRUD/CRUDE
Vendor runs it; who remains answerable? Organization retains accountability

Common distractor traps

  • Identity already verified but wrong data exposed → Authorization/Entitlement, not Authentication.
  • External legal/contract rule → Regulatory category, not merely Confidentiality.
  • Regulations do not collapse to one highest category; they are additive.
  • Not every log review is an Audit; independence matters.
  • Masking and encryption are not automatic synonyms.
  • Vendor/cloud operation does not remove organizational accountability.
  • Do not choose a network control when the stem is really classification, role entitlement, policy, or evidence.
  • “Follow policy” is not proof; choose a measurable control/evidence trail when the stem asks how to demonstrate compliance.

60-second cram route

  1. Weakness → potential action → evaluated loss → proportionate control.
  2. Authentication → Authorization → Access; know the resulting Entitlement; preserve Audit evidence.
  3. One highest confidentiality level + all additive regulatory categories.
  4. Policy → Standard → Control/Procedure → Evidence → independent Audit.
  5. Reduce sensitive copies; protect non-production; mask when legitimate use still requires the data.
  6. Vendors may implement controls; the organization remains accountable.

Must-explain pairs

Authentication/Authorization · Confidentiality/Regulation · Persistent/Dynamic masking · Excessive privilege/Legitimate abuse · Monitoring/Audit · IDS/IPS · Policy/Standard · CRUD/CRUDE/RACI.

Answered readiness checks

  1. Vulnerability / Threat / Risk: weakness; possible adverse action/event; evaluated likelihood + impact/cost.
  2. Identity/access: Authentication = who; Authorization = what may do; Access = actual use; Entitlement = total exposure; Audit = independent evidence/compliance review.
  3. Restriction model: internal confidentiality uses highest level; external regulatory categories are additive.
  4. Masking: Persistent changes stored masked copy; Dynamic changes presentation. In-flight changes during movement; In-place overwrites at current location.
  5. Privilege: Excessive = too much granted; Legitimate abuse = valid access misused; Elevation = rights increased through exploit.
  6. Monitoring/Audit: Active = real time; Passive = periodic trends; Audit = independent assurance.
  7. Policy chain: intent → measurable rule → control/procedure → evidence → audit.
  8. Outsourcing: implementation can be delegated; accountability remains.
  9. Role design: role grid = data first; hierarchy = people/workgroups first; CRUD = data operations; RACI = accountability.
  10. Metrics: actionable, baselined, interpretable, tied to improvement; five groups = Implementation, Awareness, Protection, Incident, Proliferation.

Changed-fact drills

  1. Cannot verify login identity → Authentication. Identity verified but salary exposed outside role → Authorization/Entitlement.
  2. Internal executive-only strategy → Confidentiality. Restriction comes from law/contract/industry → Regulation.
  3. Test copy permanently altered → Persistent masking. Production truth stays; screen shows last four → Dynamic masking.
  4. Whole-table access wrongly granted → Excessive privilege. Correct one-record access used to exfiltrate population → Legitimate-privilege abuse.
  5. Alert/lock abnormal access now → Active monitoring. Independent reviewer later examines evidence → Audit.
  6. Detect/notify intrusion → IDS. Automatically block/prevent → IPS.
  7. “Passwords must be protected” → Policy intent. Minimum length/complexity rule → Standard.
  8. Vendor operates encryption/access/logs → vendor implements controls. Who remains answerable? → Organization.
  9. Start with classifications and map roles → Role grid. Start with job families/inheritance → Role hierarchy.
  10. Watch unusual events → Monitoring. Leadership needs baselined trend tied to action → Security metric.

Source boundary: DAMA-DMBOK2 Revised, Chapter 7, pp. 209–256.

← Guided Learning · Visual Atlas →