🇬🇧 CISMP (Certificate in Information Security Management Principles) · flashcards

CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls Flashcards

51 question-and-answer cards covering Procedural and People Security Controls as it is examined in CISMP (Certificate in Information Security Management Principles). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
9Syllabus topics
~180Chars per answer
FreePrice

24 sample cards from the Procedural and People Security Controls deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Define 'pretexting' and 'tailgating' as social-engineering techniques.

    Pretexting is inventing a fabricated scenario/identity to extract information or access; tailgating (piggybacking) is following an authorised person through a physical access point without authenticating.

  2. What is 'baiting' in social engineering?

    Luring a victim with something enticing (e.g. a USB drive labelled 'payroll' left in a car park, or a free download) that delivers malware or harvests credentials when used.

  3. List key organisational defences against social engineering.

    Staff awareness/training, clear verification procedures for requests, reporting channels, simulated phishing tests, least-privilege access, and policies forbidding sharing of credentials.

  4. What is the single most effective defence against social engineering, and why?

    A well-informed, sceptical workforce - because social engineering targets people, trained staff who verify requests and report suspicious activity directly neutralise the attack vector.

  5. Define identification, authentication, and authorisation, in that order.

    Identification: claiming an identity (e.g. a username). Authentication: proving that claimed identity is genuine. Authorisation: granting the authenticated identity the specific rights/permissions to access resources.

  6. What are the three classic categories of authentication factors?

    Something you know (knowledge, e.g. password/PIN), something you have (possession, e.g. token/smartcard), and something you are (inherence, e.g. biometric).

  7. What additional authentication factor categories are sometimes added to the classic three?

    Somewhere you are (location, e.g. geolocation/IP) and something you do (behavioural, e.g. typing rhythm or gait).

  8. Define multi-factor authentication (MFA) and why it is stronger than single-factor.

    MFA requires two or more factors from different categories. It is stronger because an attacker must compromise multiple independent factors, so stealing just a password is insufficient to gain access.

  9. Why is using two passwords NOT multi-factor authentication?

    Both are the same factor category (something you know), so it is two-step single-factor; true MFA combines distinct factor types (e.g. password + token).

  10. In biometrics, define the False Acceptance Rate (FAR) and False Rejection Rate (FRR).

    FAR is the rate at which the system wrongly accepts an unauthorised person (a security failure); FRR is the rate at which it wrongly rejects an authorised person (a usability failure).

  11. What is the Crossover Error Rate (CER / Equal Error Rate) in biometrics?

    The point at which the False Acceptance Rate equals the False Rejection Rate ($FAR = FRR$); a lower CER indicates a more accurate biometric system.

  12. As a biometric system's sensitivity threshold is raised, how do FAR and FRR change?

    FAR decreases (fewer impostors accepted) while FRR increases (more legitimate users rejected); the two trade off against each other, balanced at the CER.

  13. What is single sign-on (SSO) and one of its key risks?

    SSO lets a user authenticate once to access multiple systems. Key risk: it creates a single point of failure - if the SSO credential is compromised, all linked systems are exposed (keys-to-the-kingdom).

  14. Define the Discretionary Access Control (DAC) model.

    DAC lets the owner of a resource decide who may access it and grant permissions at their discretion (e.g. file owners setting permissions). It is flexible but harder to centrally enforce.

  15. Define the Mandatory Access Control (MAC) model.

    MAC enforces access based on system-wide security labels/clearances set by a central authority; users cannot change permissions. Access is decided by comparing subject clearance to object classification (e.g. military systems).

  16. Define Role-Based Access Control (RBAC).

    RBAC assigns permissions to roles rather than individuals; users acquire permissions by being assigned to roles. It simplifies administration and supports least privilege in large organisations.

  17. Define Attribute-Based Access Control (ABAC).

    ABAC grants access by evaluating policies against attributes of the user, resource, action, and environment (e.g. department, time, location), enabling fine-grained, context-aware decisions.

  18. Compare DAC and MAC on flexibility versus control.

    DAC is flexible and user-driven but harder to enforce consistently; MAC is rigid and centrally controlled, offering strong, uniform enforcement at the cost of flexibility.

  19. State the principle of least privilege.

    Users (and processes) should be granted only the minimum access rights necessary to perform their legitimate tasks, and no more - limiting the damage from misuse, error, or compromise.

  20. State the principle of separation (segregation) of duties.

    Splitting a sensitive task across multiple people so no single individual can complete it alone, reducing the risk of fraud and error (e.g. one person requests, another approves).

  21. What is the 'need to know' principle?

    Access to specific information is granted only to those who require it to perform their duties, even if they hold the necessary clearance level - limiting exposure of sensitive data.

  22. Why are shared/generic accounts discouraged in privilege management?

    They break accountability - actions cannot be traced to an individual - and complicate revocation, weaken audit trails, and increase the risk of credential misuse.

  23. What controls should govern privileged (administrator) accounts?

    Restrict to named individuals, apply least privilege, use separate accounts for admin vs normal tasks, enforce MFA, log and monitor all activity, and review/recertify access regularly.

  24. What is the purpose of periodic access reviews (recertification)?

    To regularly verify that each user's access rights are still appropriate, detecting and removing access creep, orphaned accounts, and excessive privileges to maintain least privilege over time.

What this deck covers

The Procedural and People Security Controls deck follows the CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls syllabus — 3 chapters and 9 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 180 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Procedural and People Security Controls flashcards FAQ

How many Procedural and People Security Controls flashcards are in this CISMP (Certificate in Information Security Management Principles) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CISMP (Certificate in Information Security Management Principles) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Procedural and People Security Controls cards cover?

They follow the CISMP (Certificate in Information Security Management Principles) Procedural and People Security Controls syllabus — 3 chapters and 9 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.