Rapid Recall 24–45
- Confidentiality vs Regulation: where does each originate?
- Need-to-know vs Allowed-to-know?
- How does Confidentiality aggregate?
- How do regulatory categories aggregate?
- Name the five confidentiality levels.
- Name four sample regulatory families/obligation types from the chapter context.
- Excessive privilege vs Legitimate-privilege abuse?
- Privilege elevation vs Excessive privilege?
- Service account vs Shared account?
- IDS vs IPS?
- What does SQL injection exploit?
- Phishing vs Malware?
- Virus vs Worm?
- List the five major activity families.
- Policy vs Standard?
- Who reviews/approves Data Security Policy and who owns/maintains it in the DMBOK chapter model?
- Role Assignment Grid vs Role Assignment Hierarchy?
- What three things should current-risk assessment evaluate?
- What does CRUD/CRUDE map?
- Why should security requirements be captured during project analysis?
- What remains with the organization when operations are outsourced?
- Name the five DMBOK metric groups.
← Recall 01–23 · Answer Key 01–23 →