nerdexam
(ISC)2

CSSLP · Question #281

Which of the following security related areas are used to protect the confidentiality, integrity, and availability of federal information systems and information processed by those systems?

The correct answer is A. Personnel security B. Access control C. Configuration management D. Media protection E. Risk assessment. Protecting the Confidentiality, Integrity, and Availability (CIA) of federal information systems requires a comprehensive approach encompassing multiple security domains.

Secure Software Concepts

Question

Which of the following security related areas are used to protect the confidentiality, integrity, and availability of federal information systems and information processed by those systems?

Options

  • APersonnel security
  • BAccess control
  • CConfiguration management
  • DMedia protection
  • ERisk assessment

How the community answered

(20 responses)
  • A
    100% (20)

Why each option

Protecting the Confidentiality, Integrity, and Availability (CIA) of federal information systems requires a comprehensive approach encompassing multiple security domains.

APersonnel securityCorrect

Personnel security involves screening, training, and managing personnel to ensure they do not pose a risk to information systems, directly supporting CIA.

BAccess controlCorrect

Access control mechanisms restrict who can access what resources and under what conditions, directly protecting confidentiality and integrity.

CConfiguration managementCorrect

Configuration management ensures systems are configured securely and consistently, preventing vulnerabilities that could compromise CIA.

DMedia protectionCorrect

Media protection safeguards physical and electronic media from unauthorized access, modification, or destruction, thereby preserving CIA.

ERisk assessmentCorrect

Risk assessment identifies, analyzes, and evaluates risks to information systems, forming the foundation for implementing controls that protect CIA.

Concept tested: CIA triad protection areas (NIST SP 800-53)

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev5/final

Topics

#CIA triad#Security controls#Information system protection#Risk management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice