Which of the following is NOT an accepted classification of security controls?
Answer(s): A
Which three of the following characteristics form the AAA Triad in Information Security?1. Authentication2. Availability3. Accounting4. Asymmetry5. Authorisation
The AAA Triad in Information Security refers to the three characteristics of Authentication, Availability, and Accounting.
According to ISO/IEC 27000, which of the following is the definition of a vulnerability?
VulnerabilityA vulnerability is a weakness of an asset or control that could potentially be exploited by one or more threats. An asset is any tangible or intangible thing or characteristic that has value to an organization, a control is any administrative, managerial, technical, or legal method that can be used to modify or manage risk, and a threat is any potential event that could harm an organization or system.https://www.praxiom.com/iso-27000-definitions.htm
Which term describes the acknowledgement and acceptance of ownership of actions, decisions, policies and deliverables?
https://hr.nd.edu/assets/17442/behavior_model_4_ratings_3_.pdf
Which security concept provides redundancy in the event a security control failure or the exploitation of a vulnerability?
Answer(s): D
https://en.wikipedia.org/wiki/Defense_in_depth_(computing)
Share your comments for BCS CISMP-V9 exam with other users:
the aaa triad in information security is authentication, accounting and authorisation so the answer should be d 1, 3 and 5.