CSSLP · Question #168
Which of the following are included in Technical Controls? Each correct answer represents a complete solution. Choose all that apply.
The correct answer is A. Identification and authentication methods B. Configuration of the infrastructure C. Password and resource management D. Implementing and maintaining access control mechanisms E. Security devices. Technical controls include identification and authentication methods, configuration of infrastructure, password and resource management, access control mechanisms, and security devices.
Question
Which of the following are included in Technical Controls? Each correct answer represents a complete solution. Choose all that apply.
Options
- AIdentification and authentication methods
- BConfiguration of the infrastructure
- CPassword and resource management
- DImplementing and maintaining access control mechanisms
- ESecurity devices
- FConducting security-awareness training
How the community answered
(28 responses)- A86% (24)
- F14% (4)
Why each option
Technical controls include identification and authentication methods, configuration of infrastructure, password and resource management, access control mechanisms, and security devices.
Identification and authentication methods, such as multi-factor authentication, are technical mechanisms implemented in software or hardware to verify user identity.
The configuration of infrastructure components (e.g., firewalls, operating systems, network devices) involves technical settings and parameters to enforce security policies.
Password and resource management involves technical controls like password policies, lockout mechanisms, and automated resource allocation/deallocation to secure system access.
Implementing and maintaining access control mechanisms (e.g., ACLs, role-based access control) are technical configurations that govern who can access specific resources.
Security devices, such as firewalls, intrusion detection systems, and antivirus software, are hardware and software technical controls designed to protect information systems.
Conducting security-awareness training is an administrative or procedural control, focusing on educating users rather than implementing technical safeguards.
Concept tested: Security Controls - Technical Controls
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-53r4.pdf
Topics
Community Discussion
No community discussion yet for this question.