🇺🇸 Certified Information Systems Security Professional (CISSP) · flashcards

Certified Information Systems Security Professional (CISSP) Asset Security Flashcards

51 question-and-answer cards covering Asset Security as it is examined in Certified Information Systems Security Professional (CISSP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
12Syllabus topics
~163Chars per answer
FreePrice

24 sample cards from the Asset Security deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is PII (Personally Identifiable Information)?

    Any information that can identify a specific individual, alone or combined with other data — e.g., name, SSN, biometrics, address, or account numbers.

  2. What is PHI and which US law governs it?

    Protected Health Information — individually identifiable health data — governed in the US by HIPAA (Health Insurance Portability and Accountability Act).

  3. What is the difference between anonymization and pseudonymization?

    Anonymization irreversibly removes identifiers so individuals can never be re-identified; pseudonymization replaces identifiers with tokens that CAN be reversed using separately held additional information.

  4. Name the core GDPR data subject rights a CISSP should know.

    Right to access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, and to object to processing.

  5. What is data sovereignty?

    The concept that data is subject to the laws and governance of the nation in which it is physically located or collected.

  6. What is data localization (data residency)?

    A legal requirement that certain data about a country's citizens be collected, processed, and/or stored within that country's geographic borders.

  7. Why are data sovereignty and localization important when using cloud providers?

    Cloud data may be stored in multiple jurisdictions; the organization must ensure storage location complies with applicable laws (e.g., GDPR limits on transfers outside the EU).

  8. What is a security baseline?

    A minimum set of security controls/configurations established as a starting standard that all systems of a given classification or type must meet.

  9. Define scoping in the context of applying a security baseline.

    Reviewing baseline controls and selecting (or excluding) those that apply to a specific system — removing controls that are not relevant to the environment.

  10. Define tailoring in the context of security baselines.

    Modifying or customizing the scoped baseline controls to align precisely with the organization's specific mission, risk, and operating environment (adjusting, supplementing, or applying compensating controls).

  11. State the relationship between baselines, scoping, and tailoring as a process.

    Start with a baseline (minimum controls), apply scoping to remove non-applicable controls, then tailor to customize the remaining controls to the organization's needs.

  12. What is Data Loss Prevention (DLP)?

    A set of technologies and processes that detect and prevent unauthorized use, exfiltration, or transmission of sensitive data by monitoring data in use, in motion, and at rest.

  13. Differentiate network-based DLP from endpoint-based DLP.

    Network DLP inspects data in motion at network egress/gateways; endpoint (host) DLP runs on devices to monitor data in use and at rest, including offline actions like USB copying or printing.

  14. What is the difference between data at rest, data in transit, and data in use?

    At rest = stored on media/disk; in transit (in motion) = moving across a network; in use = actively being processed in memory/CPU.

  15. What is the primary control for protecting data at rest?

    Encryption (e.g., full-disk encryption, file/database encryption) along with access controls; encryption protects confidentiality if media is lost or stolen.

  16. What is the primary control for protecting data in transit?

    Transport encryption protocols such as TLS, IPsec/VPN, and SSH that protect confidentiality and integrity of data moving across networks.

  17. Which protocol secures web traffic and what does it use under the hood?

    HTTPS, which uses TLS (Transport Layer Security) to provide encryption, integrity, and server authentication.

  18. What is Digital Rights Management (DRM)?

    Technology that enforces persistent access and usage restrictions on digital content (copy, print, forward, expiration) even after it leaves the originating system.

  19. Name common DRM enforcement controls.

    License/permission management, encryption tied to entitlements, persistent online verification, expiration/time-bombing, and copy/print restrictions.

  20. What is data obfuscation?

    Techniques that hide or obscure the true value of data to reduce its sensitivity — including masking, tokenization, and anonymization.

  21. What is data masking and give a typical example.

    Replacing sensitive data with realistic but fictitious or partially hidden values — e.g., showing a credit card as ****-****-****-1234 — often for non-production or display use.

  22. What is tokenization and how does it differ from encryption?

    Tokenization substitutes sensitive data with a non-sensitive token that maps back to the original via a secure lookup table (vault); unlike encryption, the token has no mathematical relationship to the data, so there is nothing to decrypt.

  23. What does data labeling/marking provide and how does it differ from classification?

    Classification is the decision about sensitivity level; labeling/marking is the physical or electronic application of that classification tag to the asset so handlers know how to treat it.

  24. When data of different classifications are combined, what classification should the resulting aggregate receive?

    At least the highest classification of any component data — and aggregation may itself raise sensitivity (the aggregation problem), where combined low-level data reveals high-level information.

What this deck covers

The Asset Security deck follows the Certified Information Systems Security Professional (CISSP) Asset Security syllabus — 4 chapters and 12 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 12.8 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 163 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Asset Security flashcards FAQ

How many Asset Security flashcards are in this Certified Information Systems Security Professional (CISSP) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Security Professional (CISSP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Asset Security cards cover?

They follow the Certified Information Systems Security Professional (CISSP) Asset Security syllabus — 4 chapters and 12 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.