A company encrypts all sensitive customer data so that only authorized users can view it. Which security principle is being maintained?
A hacker alters the prices of products in an online store’s database. Which security principle was violated?
A hospital’s patient portal goes offline for several hours, preventing doctors from accessing medical records. Which principle has failed?
A user denies deleting a critical file, but system logs show their account performed the action. What concept allowed the organization to prove this?
A phishing attacker successfully logs into an employee’s account using stolen credentials. Which security principle was bypassed?
A company gives interns full administrative access to the financial system by mistake. Which principle has been violated?
An organization monitors user activity, including when they log in and what files they modify. Which security principle does this describe?
A company uses multiple layers of protection: firewalls, intrusion detection systems, and employee training. What strategy are they using?
Why do organizations implement multiple layers of defense instead of relying on just one control?
A retail company uses a firewall to block unauthorized access, antivirus software to detect malware, and data backups to restore lost files. What advantage does this layered approach provide?
A health services company implements encryption and secure storage of medical data to comply with HIPAA regulations. What factor influenced this decision?
Before installing an expensive new firewall, a business compares the cost of purchase and maintenance with the potential financial loss from a data breach. What is this process called?
A small company chooses an affordable, easy-to-manage antivirus solution over a more advanced enterprise suite. What factor likely influenced this decision?
A cyber defender decides to prioritize controls that address attacks likely to happen and that could cause major damage. What is being considered?
A cyber analyst studies how an attacker could exploit a web app vulnerability and recommends installing a patch to stop it. What type of reasoning is being applied?
Installing security cameras and door locks in a data center are examples of which type of control?
A company installs a firewall and antivirus software to secure its network. What type of security control are these examples of?
A company enforces policies requiring password changes every 90 days and conducts annual access reviews. What type of security control does this represent?
A network firewall blocks unauthorized connections from outside users. What type and function of control does this best represent?
After a cyberattack damages several systems, IT staff restore functionality by reinstalling software and applying patches. What type of control are they using?