🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards

CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security Flashcards

51 question-and-answer cards covering Physical, Environmental and Operational Security as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
10Syllabus topics
~231Chars per answer
FreePrice

24 sample cards from the Physical, Environmental and Operational Security deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is 'change management' (change control) and why is it an operational security control?

    A formal process for requesting, assessing, approving, testing, implementing and reviewing changes to systems. It reduces the risk of changes causing security weaknesses, outages or unintended impacts on confidentiality, integrity or availability.

  2. What is 'capacity management' in operational security and which CIA property does it support?

    Monitoring and planning the use of resources (storage, processing, bandwidth) so future capacity meets demand. It primarily supports availability by preventing resource exhaustion and performance failures.

  3. What is the difference between a backup and an archive?

    A backup is a copy of current data taken for recovery after loss or corruption; an archive is the long-term retention of data that is no longer in active use, kept for legal, regulatory or historical reasons.

  4. State the '3-2-1' backup rule.

    Keep at least 3 copies of data, on 2 different types of media, with 1 copy held off-site (offline/immutable copies further protect against ransomware).

  5. Compare full, incremental and differential backups.

    A full backup copies all selected data. An incremental copies only data changed since the last backup of any type (fast to back up, slower to restore — needs the chain). A differential copies all data changed since the last full backup (larger each day, but restore needs only the full plus the latest differential).

  6. Define RPO (Recovery Point Objective).

    The maximum acceptable amount of data loss measured in time — i.e. how far back in time recovery can be, which dictates how frequently backups/replication must occur.

  7. Define RTO (Recovery Time Objective).

    The maximum acceptable length of time to restore a system or process after a disruption before the impact becomes unacceptable to the business.

  8. If a system performs backups every 24 hours, what is its RPO, and why is it important to test restores?

    The RPO is up to 24 hours (the worst-case data loss equals the time since the last backup). Restores must be tested because a backup is only valuable if it can actually be recovered — untested backups may be corrupt, incomplete or unreadable.

  9. What is the difference between resilience and recovery?

    Resilience is the ability of a system to keep operating (or degrade gracefully) despite faults — built in through redundancy and fault tolerance; recovery is restoring service after a failure has occurred (e.g. from backups or a DR site).

  10. What does the RAID acronym stand for and what is its general purpose?

    Redundant Array of Independent (originally Inexpensive) Disks — combining multiple physical disks to provide fault tolerance and/or performance, so that data availability is maintained despite a disk failure.

  11. Contrast RAID 1 and RAID 5 in terms of redundancy.

    RAID 1 mirrors data identically across two disks (full duplicate, survives one disk failure). RAID 5 stripes data with distributed parity across three or more disks, surviving a single disk failure with less storage overhead than mirroring.

  12. Is RAID a substitute for backups? Explain.

    No. RAID protects against hardware (disk) failure to maintain availability, but it does not protect against accidental deletion, corruption, ransomware or site loss — those changes are written across the array, so backups are still required.

  13. What is the difference between a 'hot', 'warm' and 'cold' standby/recovery site?

    A hot site is fully equipped and continuously synchronised for near-immediate switchover; a warm site has hardware and connectivity but needs data/configuration loading before use; a cold site provides only space and basic infrastructure, requiring equipment and data to be installed before recovery.

  14. What are the main risks associated with removable media (USB drives, optical disks, tapes)?

    Loss or theft leading to data disclosure, introduction of malware to systems, uncontrolled data exfiltration, and inadequate destruction of data when the media is disposed of.

  15. What controls reduce the risk of removable media?

    Encryption of data at rest, registration/management of authorised devices, disabling unauthorised ports/endpoint controls (DLP), scanning media for malware, and secure storage, transport and disposal procedures.

  16. What is the difference between deleting, erasing/wiping, and physically destroying media?

    Deleting only removes the file pointer (data is recoverable); erasing/wiping (secure overwrite or degaussing) renders data unrecoverable; physical destruction (shredding, incineration, crushing) destroys the media itself. The method must match the data's classification.

  17. What is 'degaussing' and which media does it apply to?

    Degaussing uses a strong magnetic field to scramble/erase data on magnetic media such as hard disk drives and tapes, rendering it unrecoverable. It does not work on solid-state (flash/SSD) media, which require secure erase or destruction.

  18. How should media be protected during physical transport off-site?

    Use reliable/authorised couriers, encrypt the data, use tamper-evident or secure packaging, maintain a register/log and chain of custody, and limit and verify who receives it.

  19. What is the purpose of security testing such as penetration testing and vulnerability scanning?

    To proactively identify security weaknesses in systems before attackers exploit them, verify that controls are effective, and provide assurance that the system meets its security requirements.

  20. Compare a vulnerability scan with a penetration test.

    A vulnerability scan is an automated, broad check that identifies and reports known weaknesses without exploiting them; a penetration test is a deeper, often manual exercise that actively attempts to exploit weaknesses to demonstrate real-world impact and chained attack paths.

  21. Contrast black-box, white-box and grey-box security testing.

    Black-box testing is done with no prior knowledge of the system (simulating an external attacker); white-box testing is done with full knowledge (design, code, credentials); grey-box testing is done with partial knowledge, such as a standard user account.

  22. Why must penetration testing be formally authorised and scoped before it begins?

    Because the activities (e.g. exploiting systems) could otherwise be illegal under computer-misuse law and may disrupt services; written authorisation, a defined scope, and rules of engagement protect both tester and organisation and prevent unintended damage.

  23. What is 'technical compliance checking' and how does it differ from an audit?

    Technical compliance checking verifies that systems are configured in accordance with security standards/policies and hardening baselines — often using automated tools. It is a technical conformance check, whereas an audit is a broader, independent assessment of controls, processes and governance.

  24. What is the purpose of event logging and log monitoring in operational security?

    To record security-relevant events (logins, access, changes, errors) so that incidents can be detected, investigated and reconstructed, accountability is supported, and compliance and forensic evidence requirements are met. A SIEM is commonly used to centralise, correlate and alert on logs.

What this deck covers

The Physical, Environmental and Operational Security deck follows the CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security syllabus — 3 chapters and 10 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 231 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Physical, Environmental and Operational Security flashcards FAQ

How many Physical, Environmental and Operational Security flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CISMP (Certificate in Information Security Management Principles) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Physical, Environmental and Operational Security cards cover?

They follow the CISMP (Certificate in Information Security Management Principles) Physical, Environmental and Operational Security syllabus — 3 chapters and 10 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.