🔐
Cyber Security Medium

Security Frameworks and Compliance

Security standards, compliance regulations and risk management concepts!

15 Questions
30s Per Question
2+ Plays
← All Cyber Security Quizzes 📚 Study Guide for this category →
💡 Create account to save scores & earn XP
📋 View All 15 Questions & Answers

1. What does "attack surface" mean?

  • A. The physical area of a server room
  • B. The total number of different points where an attacker could try to enter or extract data ✓
  • C. The strength of a firewall
  • D. The number of security vulnerabilities

💡 The attack surface is all the possible entry points an attacker could exploit — reducing it is a core principle of security hardening.

2. What is "threat intelligence"?

  • A. Guessing about threats
  • B. Collecting and analyzing information about current and emerging cyber threats to make informed security decisions ✓
  • C. A type of penetration testing
  • D. A firewall feature

💡 Threat intelligence gathers data about attackers, their tools, techniques, and procedures to help organizations proactively defend against threats.

3. What is "ISO 27001"?

  • A. A network protocol
  • B. An international standard for establishing and managing information security management systems (ISMS) ✓
  • C. A type of encryption
  • D. A hardware security standard

💡 ISO 27001 is the international standard specifying requirements for establishing, implementing, and maintaining an information security management system.

4. What is "least privilege principle"?

  • A. Giving users maximum access
  • B. Granting users only the minimum access rights necessary to perform their job functions ✓
  • C. Restricting all user access
  • D. A type of authentication

💡 Least privilege limits user access to only what is needed for their role, minimizing the potential damage from breaches or insider threats.

5. What does "SOC" stand for in cybersecurity?

  • A. System Operations Center
  • B. Security Operations Center — a team monitoring and responding to security incidents ✓
  • C. Software Operations Control
  • D. Secure Online Communication

💡 A SOC is a centralized unit staffed with security analysts who continuously monitor, detect, and respond to cybersecurity threats.

6. What is "business continuity planning" (BCP)?

  • A. Day-to-day business planning
  • B. A strategy ensuring critical business functions continue during and after a disaster or cyber attack ✓
  • C. A financial planning process
  • D. A marketing strategy

💡 BCP ensures an organization can continue operating essential functions during disruptions like cyberattacks, natural disasters, or system failures.

7. What is the NIST Cybersecurity Framework?

  • A. A government hacking tool
  • B. A voluntary framework of standards and best practices for managing cybersecurity risk ✓
  • C. A mandatory security law
  • D. A type of antivirus

💡 The NIST CSF provides organizations with a common language and systematic approach to managing and reducing cybersecurity risk.

8. What is "GDPR"?

  • A. A type of firewall
  • B. General Data Protection Regulation — EU law protecting personal data and privacy rights ✓
  • C. A cybersecurity certification
  • D. A network security standard

💡 GDPR is the European Union's comprehensive data protection law giving individuals control over their personal data and imposing obligations on organizations.

9. What is "SIEM" in cybersecurity?

  • A. Security Information and Event Management — collecting and analyzing security data for threat detection ✓
  • B. A type of firewall
  • C. Security Interface Encryption Module
  • D. A penetration testing tool

💡 SIEM systems collect, aggregate, and analyze security event data from across an organization to detect threats and support incident response.

10. What does the "CIA triad" stand for in cybersecurity?

  • A. Central Intelligence Agency
  • B. Confidentiality, Integrity, and Availability — the three core principles of information security ✓
  • C. Computer Information Architecture
  • D. Cyber Intelligence Assessment

💡 The CIA triad represents the three pillars of security: keeping data private (confidentiality), accurate (integrity), and accessible (availability).

11. What is "data classification"?

  • A. Organizing data alphabetically
  • B. Categorizing data by sensitivity level to apply appropriate security controls ✓
  • C. A type of encryption
  • D. A backup strategy

💡 Data classification categorizes information (public, internal, confidential, top secret) so appropriate security controls can be applied to each level.

12. What is "risk assessment" in cybersecurity?

  • A. Assessing financial risks only
  • B. Identifying, analyzing, and evaluating security risks to prioritize mitigation efforts ✓
  • C. A type of penetration test
  • D. A compliance checklist

💡 Risk assessment identifies potential threats, their likelihood, and impact to help organizations prioritize their security investments.

13. What is "vulnerability management"?

  • A. Creating new vulnerabilities
  • B. A continuous process of identifying, classifying, and remediating security vulnerabilities ✓
  • C. A type of penetration testing
  • D. A firewall configuration process

💡 Vulnerability management is an ongoing cycle of discovering vulnerabilities through scanning, assessing their risk, and applying patches or mitigations.

14. What is "security awareness training"?

  • A. Technical security training for IT staff only
  • B. Educating all employees about cybersecurity threats and safe practices ✓
  • C. A type of penetration testing
  • D. A compliance audit

💡 Security awareness training educates all staff about threats like phishing, safe password practices, and how to report suspicious activity.

15. What is "incident response"?

  • A. Responding to customer complaints
  • B. A structured approach to handling and managing the aftermath of a security breach or attack ✓
  • C. A type of penetration testing
  • D. A backup procedure

💡 Incident response is a planned approach to addressing security incidents — containing damage, investigating, recovering, and preventing recurrence.

More Cyber Security Quizzes

View all Cyber Security quizzes →