🇺🇸 Certified Information Systems Security Professional (CISSP) · flashcards

Certified Information Systems Security Professional (CISSP) Security Operations Flashcards

71 question-and-answer cards covering Security Operations as it is examined in Certified Information Systems Security Professional (CISSP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

71Cards in deck
24Free preview
15Syllabus topics
~215Chars per answer
FreePrice

24 sample cards from the Security Operations deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. In backup terms, what role does the 'archive bit' play in incremental vs differential backups?

    Incremental backups reset (clear) the archive bit after copying, so each captures only new changes; differential backups do not clear it, so each captures all changes since the last full backup.

  2. What is the 3-2-1 backup rule?

    Keep at least 3 copies of data, on 2 different media types, with 1 copy stored offsite.

  3. What is electronic vaulting versus remote journaling?

    Electronic vaulting transfers batched backup copies of files/databases to a remote site periodically; remote journaling transmits only the transaction logs (journals) to the remote site in near real-time for faster, more current recovery.

  4. Compare hot, warm, and cold recovery sites.

    Cold site: space/power/HVAC only, no equipment or data—longest recovery, cheapest. Warm site: hardware and connectivity in place but data not current—moderate cost/recovery. Hot site: fully equipped and near-real-time data, ready almost immediately—fastest recovery, most expensive.

  5. What is a mobile site and a reciprocal (mutual aid) agreement?

    A mobile site is a transportable, prefitted recovery facility (e.g., trailer). A reciprocal agreement is a mutual arrangement where two organizations agree to host each other's operations during a disaster—cheap but legally weak and capacity-uncertain.

  6. What is the difference between RAID 1, RAID 5, and RAID 6?

    RAID 1 mirrors data across drives (full redundancy, 50% usable). RAID 5 stripes with single distributed parity (survives one drive failure). RAID 6 stripes with dual parity (survives two simultaneous drive failures).

  7. What is the difference between high availability clustering and fault tolerance?

    Fault tolerance keeps a system running without interruption despite a component failure (redundant hardware, no downtime). High-availability clustering minimizes downtime by failing over to another node, possibly with a brief interruption.

  8. List common disaster recovery plan test types from least to most disruptive.

    Checklist/read-through review, structured walk-through (tabletop), simulation, parallel test (recovery systems run alongside production), and full-interruption test (production is actually failed over).

  9. What is the difference between a DRP and a BCP?

    A BCP (Business Continuity Plan) is the overall strategy to keep the whole organization operating during/after a disruption; a DRP (Disaster Recovery Plan) is the IT-focused subset for recovering systems, data, and infrastructure.

  10. During DRP execution, who typically decides to invoke the plan and to declare a disaster?

    A designated senior individual/team with declaration authority (e.g., the incident/recovery manager or executive), based on predefined criteria for disaster declaration.

  11. What CPTED principle uses environmental design to reduce crime, and name its three strategies?

    CPTED (Crime Prevention Through Environmental Design). Its strategies are natural surveillance, natural access control, and natural territorial reinforcement.

  12. What is a mantrap (access control vestibule) and what attack does it prevent?

    A two-door entry system where one door must close/lock before the next opens, allowing one person through at a time. It prevents tailgating/piggybacking and controls entry to secure areas.

  13. What is the difference between tailgating and piggybacking?

    Tailgating is an unauthorized person following an authorized person through a controlled door without their knowledge; piggybacking occurs with the authorized person's consent/awareness. Both bypass access control.

  14. What lighting and fencing facts should a security operations student know for physical deterrence?

    A fence of 3-4 ft deters casual trespassers, 6-7 ft is too high to climb easily, and 8 ft with 3 strands of barbed wire deters determined intruders. Critical-area lighting should illuminate at least 8 ft high with 2 foot-candles of intensity.

  15. In fire safety, what does the safety mnemonic prioritize, and why does it matter in personnel safety?

    Human life/safety is always the top priority over assets and data. Evacuation and life safety take precedence over protecting equipment in any emergency.

  16. What are the four classes of fire and the appropriate suppression for each (A, B, C, D)?

    Class A: common combustibles (water/soda acid). Class B: flammable liquids/gases (CO2, foam, dry chemical). Class C: electrical fires (CO2, non-conductive agents—never water). Class D: combustible metals (dry powder).

  17. Compare wet pipe, dry pipe, deluge, and preaction sprinkler systems.

    Wet pipe: water always in pipes, fastest, risk of leaks/freezing. Dry pipe: pipes hold pressurized air, water released on valve open—prevents freezing. Deluge: like dry pipe but with open heads, releases large water volume at once. Preaction: combines dry/wet—water enters pipes on first trigger and releases only after a second (heat) trigger, reducing accidental discharge (best for data centers).

  18. Why is FM-200 (or inert gas) used instead of Halon in modern data centers?

    Halon is an effective clean agent but was banned under the Montreal Protocol for depleting the ozone layer; FM-200 and inert gases are ozone-safe clean agents that suppress fire without damaging electronics or harming personnel at design concentrations.

  19. What is duress signaling and where is it used in personnel safety?

    A covert way for personnel under coercion to silently signal for help (e.g., a duress code or panic button), used at access points, guard stations, and reception to alert security without alarming an attacker.

  20. What two power conditioning/protection technologies guard against power fluctuations and outages?

    A UPS (Uninterruptible Power Supply) provides immediate battery backup and conditioning to bridge short outages and ride-through to generators; backup generators supply longer-term power during extended outages.

  21. Define brownout, blackout, sag, spike, and surge in power terms.

    Blackout: total loss of power. Brownout: prolonged drop in voltage. Sag: momentary low voltage. Spike: momentary high voltage. Surge: prolonged high voltage.

  22. What is the purpose of Service Level Agreements (SLAs) in operational security coordination?

    SLAs define measurable performance and availability commitments (e.g., uptime, response times) between providers and customers, ensuring security and operational expectations are documented and enforceable.

  23. What is the difference between MTBF and MTTR?

    MTBF (Mean Time Between Failures) is the average operational time between failures of a repairable component (reliability). MTTR (Mean Time To Repair/Restore) is the average time to fix it and return it to service (recoverability).

  24. What is the Maximum Tolerable Downtime (MTD) and how does it relate to RTO?

    MTD (also MTPD) is the longest time a business process can be unavailable before causing unacceptable harm. RTO must be less than MTD; the difference accounts for restoring the work/data backlog (WRT).

What this deck covers

The Security Operations deck follows the Certified Information Systems Security Professional (CISSP) Security Operations syllabus — 5 chapters and 15 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 14.2 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 215 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Security Operations flashcards FAQ

How many Security Operations flashcards are in this Certified Information Systems Security Professional (CISSP) deck?

71 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Security Professional (CISSP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 71-card deck is free inside the Examius app.

What do the Security Operations cards cover?

They follow the Certified Information Systems Security Professional (CISSP) Security Operations syllabus — 5 chapters and 15 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.