Skip to content

Rapid Recall 24–45

  1. Confidentiality vs Regulation: where does each originate?
  2. Need-to-know vs Allowed-to-know?
  3. How does Confidentiality aggregate?
  4. How do regulatory categories aggregate?
  5. Name the five confidentiality levels.
  6. Name four sample regulatory families/obligation types from the chapter context.
  7. Excessive privilege vs Legitimate-privilege abuse?
  8. Privilege elevation vs Excessive privilege?
  9. Service account vs Shared account?
  10. IDS vs IPS?
  11. What does SQL injection exploit?
  12. Phishing vs Malware?
  13. Virus vs Worm?
  14. List the five major activity families.
  15. Policy vs Standard?
  16. Who reviews/approves Data Security Policy and who owns/maintains it in the DMBOK chapter model?
  17. Role Assignment Grid vs Role Assignment Hierarchy?
  18. What three things should current-risk assessment evaluate?
  19. What does CRUD/CRUDE map?
  20. Why should security requirements be captured during project analysis?
  21. What remains with the organization when operations are outsourced?
  22. Name the five DMBOK metric groups.

← Recall 01–23 · Answer Key 01–23 →