02 — Exam Map & High-Yield Targets
Weight: 6% of Fundamentals · Posture: breadth, discrimination, role/control logic, and scenario recognition—not deep security engineering.
Highest-yield rule
Prefer the answer that protects sensitive/regulated data, preserves legitimate access, and produces auditable evidence.
Priority tiers
Tier 1 — very high
- Vulnerability vs Threat vs Risk
- Four A’s + Entitlement
- Confidentiality vs Regulation
- Authentication vs Authorization
- Persistent vs Dynamic masking
- Policy vs Standard
- Role-based access
- Monitoring vs Audit
- Excessive vs legitimate-privilege abuse
- Auditability/evidence
Tier 2 — high
- CRD / HRD / MRD risk classifications
- Active vs Passive monitoring
- In-flight vs In-place masking
- Service vs Shared accounts
- IDS vs IPS
- Data Steward vs Information Security
- CRUD/CRUDE
- Outsourcing/cloud accountability + chain of custody
Tier 3 — medium
Facility/device/credential/e-communication security; network vocabulary; malware recognition; regulatory families; role grid vs hierarchy; tools/techniques; Data Security architecture.
Tier 4 — supporting recognition
Specific named algorithms, historical regulation examples, older statistics, and product examples.
20 trigger phrases
| Stem clue | Think |
|---|---|
| Who are you? | Authentication |
| What may you see/do? | Authorization |
| All data exposed by one authorization | Entitlement |
| Independent review / compliance evidence | Audit |
| Real-time alert or interruption | Active monitoring |
| Periodic snapshots / trends | Passive monitoring |
| Weakness or defect | Vulnerability |
| Potential offensive/adverse action | Threat |
| Likelihood + damage/cost | Risk |
| Need-to-know | Confidentiality |
| Allowed-to-know / external rule | Regulation |
| Highest item sets one internal level | Confidentiality aggregation |
| Several external categories all apply | Regulatory categorization |
| Permanent change before non-prod | Persistent masking |
| Display changes; source value stays | Dynamic masking |
| More rights than needed | Excessive privilege |
| Valid rights used wrongly | Legitimate-privilege abuse |
| Ordinary/lower user becomes admin | Privilege elevation |
| C/R/U/D/E permission mapping | CRUD/CRUDE |
| Vendor runs it; who remains answerable? | Organization retains accountability |
Common distractor traps
- Identity already verified but wrong data exposed → Authorization/Entitlement, not Authentication.
- External legal/contract rule → Regulatory category, not merely Confidentiality.
- Regulations do not collapse to one highest category; they are additive.
- Not every log review is an Audit; independence matters.
- Masking and encryption are not automatic synonyms.
- Vendor/cloud operation does not remove organizational accountability.
- Do not choose a network control when the stem is really classification, role entitlement, policy, or evidence.
- “Follow policy” is not proof; choose a measurable control/evidence trail when the stem asks how to demonstrate compliance.
60-second cram route
- Weakness → potential action → evaluated loss → proportionate control.
- Authentication → Authorization → Access; know the resulting Entitlement; preserve Audit evidence.
- One highest confidentiality level + all additive regulatory categories.
- Policy → Standard → Control/Procedure → Evidence → independent Audit.
- Reduce sensitive copies; protect non-production; mask when legitimate use still requires the data.
- Vendors may implement controls; the organization remains accountable.
Must-explain pairs
Authentication/Authorization · Confidentiality/Regulation · Persistent/Dynamic masking · Excessive privilege/Legitimate abuse · Monitoring/Audit · IDS/IPS · Policy/Standard · CRUD/CRUDE/RACI.
Answered readiness checks
- Vulnerability / Threat / Risk: weakness; possible adverse action/event; evaluated likelihood + impact/cost.
- Identity/access: Authentication = who; Authorization = what may do; Access = actual use; Entitlement = total exposure; Audit = independent evidence/compliance review.
- Restriction model: internal confidentiality uses highest level; external regulatory categories are additive.
- Masking: Persistent changes stored masked copy; Dynamic changes presentation. In-flight changes during movement; In-place overwrites at current location.
- Privilege: Excessive = too much granted; Legitimate abuse = valid access misused; Elevation = rights increased through exploit.
- Monitoring/Audit: Active = real time; Passive = periodic trends; Audit = independent assurance.
- Policy chain: intent → measurable rule → control/procedure → evidence → audit.
- Outsourcing: implementation can be delegated; accountability remains.
- Role design: role grid = data first; hierarchy = people/workgroups first; CRUD = data operations; RACI = accountability.
- Metrics: actionable, baselined, interpretable, tied to improvement; five groups = Implementation, Awareness, Protection, Incident, Proliferation.
Changed-fact drills
- Cannot verify login identity → Authentication. Identity verified but salary exposed outside role → Authorization/Entitlement.
- Internal executive-only strategy → Confidentiality. Restriction comes from law/contract/industry → Regulation.
- Test copy permanently altered → Persistent masking. Production truth stays; screen shows last four → Dynamic masking.
- Whole-table access wrongly granted → Excessive privilege. Correct one-record access used to exfiltrate population → Legitimate-privilege abuse.
- Alert/lock abnormal access now → Active monitoring. Independent reviewer later examines evidence → Audit.
- Detect/notify intrusion → IDS. Automatically block/prevent → IPS.
- “Passwords must be protected” → Policy intent. Minimum length/complexity rule → Standard.
- Vendor operates encryption/access/logs → vendor implements controls. Who remains answerable? → Organization.
- Start with classifications and map roles → Role grid. Start with job families/inheritance → Role hierarchy.
- Watch unusual events → Monitoring. Leadership needs baselined trend tied to action → Security metric.
Source boundary: DAMA-DMBOK2 Revised, Chapter 7, pp. 209–256.