🌍 Cybersecurity · flashcards

Cybersecurity Security Fundamentals and Governance Flashcards

51 question-and-answer cards covering Security Fundamentals and Governance as it is examined in Cybersecurity. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
23Syllabus topics
~156Chars per answer
FreePrice

24 sample cards from the Security Fundamentals and Governance deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Differentiate a policy, a standard, and a procedure.

    Policy: high-level management statement of intent (the 'why/what'). Standard: mandatory specific requirement supporting the policy. Procedure: detailed step-by-step instructions (the 'how').

  2. How does a guideline differ from a standard?

    A standard is mandatory and enforceable; a guideline is a recommended, optional best-practice suggestion that is not compulsory.

  3. Name the five core Functions of the NIST Cybersecurity Framework (CSF 1.1).

    Identify, Protect, Detect, Respond, and Recover.

  4. What additional core Function was added in NIST CSF 2.0 and what does it address?

    Govern (GV), which addresses organizational cybersecurity governance, strategy, roles, policy, and risk management oversight across the other functions.

  5. What are the three components/tiers of the NIST CSF structure?

    The Framework Core (functions/categories/subcategories), the Implementation Tiers (1 Partial to 4 Adaptive), and Profiles (current vs. target state).

  6. What is ISO/IEC 27001?

    An international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS); it is certifiable.

  7. How does ISO/IEC 27002 differ from ISO/IEC 27001?

    27001 states the mandatory ISMS requirements and is certifiable; 27002 is a guidance document providing a code of practice / catalog of information security controls (not certifiable itself).

  8. What management model underlies the ISO 27001 ISMS?

    The Plan-Do-Check-Act (PDCA) continual improvement cycle.

  9. What does GDPR regulate and who does it protect?

    The EU General Data Protection Regulation governs the processing of personal data and protects the privacy rights of EU/EEA data subjects, applying to any organization handling their data.

  10. Match these regulations to their domain: HIPAA, PCI DSS, SOX.

    HIPAA: protected health information (US healthcare). PCI DSS: payment card/cardholder data (industry standard). SOX (Sarbanes-Oxley): financial reporting integrity for public companies.

  11. What US law governs the privacy of consumer data in California and grants opt-out of data sale?

    The CCPA (California Consumer Privacy Act), as amended by the CPRA.

  12. Name the three categories of authentication factors.

    Something you know (knowledge, e.g., password), something you have (possession, e.g., token/phone), and something you are (inherence, e.g., biometric).

  13. Beyond the three classic factors, what two additional authentication factors are often cited?

    Somewhere you are (location) and something you do (behavioral, e.g., typing pattern/gait).

  14. What distinguishes true Multi-Factor Authentication (MFA) from two-step verification using two passwords?

    True MFA requires factors from two or more DIFFERENT categories (e.g., password + fingerprint). Two passwords are the same category (knowledge), so they do not constitute MFA.

  15. In biometrics, what are FAR, FRR, and CER?

    FAR (False Acceptance Rate): unauthorized users wrongly accepted. FRR (False Rejection Rate): authorized users wrongly rejected. CER (Crossover Error Rate): the point where FAR equals FRR, indicating overall accuracy (lower is better).

  16. Describe the DAC (Discretionary Access Control) model.

    Access is set at the discretion of the resource owner, who grants permissions to other users (e.g., typical file permissions/ACLs). Owner-controlled and flexible.

  17. Describe the MAC (Mandatory Access Control) model.

    Access is enforced by the system based on security labels/clearances and classifications (e.g., Top Secret, Secret). Users cannot alter permissions; common in military/high-security environments.

  18. Describe the RBAC (Role-Based Access Control) model.

    Access is assigned to roles based on job function, and users inherit permissions by being assigned to roles rather than being granted access individually.

  19. How does ABAC (Attribute-Based Access Control) determine access?

    Access decisions are made dynamically by evaluating policies against attributes of the subject, object, action, and environment/context (e.g., time, location, department).

  20. What is Rule-Based Access Control, and how does it differ from RBAC?

    Rule-Based control grants/denies access according to predefined rules/conditions applied system-wide (e.g., firewall ACLs, time-of-day rules), independent of user role identity; RBAC keys off assigned job roles.

  21. In MAC classifications, what does the 'need to know' principle add on top of a security clearance?

    Even with a sufficient clearance level, a subject may only access information required for their specific duties; clearance alone is not enough without need to know.

  22. What is the difference between a threat, a vulnerability, and an exploit?

    A threat is a potential danger/actor that could cause harm; a vulnerability is a weakness that could be exploited; an exploit is the actual method or code used to take advantage of a vulnerability.

  23. Within the NIST CSF, which core Function includes asset management and risk assessment activities?

    The Identify function, which develops organizational understanding of assets, systems, data, and risks to be managed.

  24. In Zero Trust, what does 'microsegmentation' accomplish?

    It divides the network into small, isolated zones with individual access controls, limiting lateral movement so a breach in one segment cannot spread freely to others.

What this deck covers

The Security Fundamentals and Governance deck follows the Cybersecurity Security Fundamentals and Governance syllabus — 6 chapters and 23 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 8.5 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 156 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Security Fundamentals and Governance flashcards FAQ

How many Security Fundamentals and Governance flashcards are in this Cybersecurity deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Cybersecurity flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Security Fundamentals and Governance cards cover?

They follow the Cybersecurity Security Fundamentals and Governance syllabus — 6 chapters and 23 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.