Start Here
Six review stations, each a different way to practice Chapter 1. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.
What this chapter asked you to be able to do
- Define confidentiality, integrity, and availability and explain how each applies to a real security decision.
- Describe the risk management lifecycle: identify assets, threats, and vulnerabilities; assess likelihood and impact; document in a risk register; and select a treatment.
- Tell apart control categories (technical, managerial, physical, operational) from control types (preventive, detective, corrective, compensating, deterring, directive).
- Explain AAA, non-repudiation, defense in depth, Zero Trust, and least privilege as foundational principles.
- Apply the framework to a scenario by identifying assets, assessing threats, and recommending controls.
Your progress this session
These counters update as you check answers on each station. They reset when you reload the page.
Key Terms Flashcards
Select a card to reveal its definition, then select again to flip it back. Try to state the definition before you flip. The counter tracks how many distinct cards you have opened.
Classifying Scenarios by the CIA Triad
Every security event touches at least one leg of the triad. Read each scenario and choose the principle that is primarily at stake, then check your answer.
Classifying Controls by Category and Type
Every control has one category (what the control is) and one type (what the control does), and the two are independent. For each control, choose both, then check your answer.
Reference: control matrix (category × type)
| Type \ Category | Technical | Managerial | Physical | Operational |
|---|---|---|---|---|
| Preventive | Firewall rule blocking malicious IPs | Background check policy | Locked server room door | Change management approval |
| Detective | IDS alert on anomalous traffic | Audit and compliance review | Security camera | Daily log review |
| Corrective | Antivirus quarantine of malware | Lessons learned report | Fire suppression system | System restore from backup |
| Compensating | Enhanced logging on a legacy system | Documented risk acceptance | Guard when a badge reader fails | Manual check when automation fails |
| Deterring | Account lockout after failed attempts | Acceptable use policy | "Authorized Personnel Only" sign | Published incident response penalties |
| Directive | Group Policy enforcing password rules | Regulatory compliance requirement | Building evacuation procedure | Mandatory security training schedule |
A control can shift category depending on whether you mean the written rule (managerial), the running activity (operational), or the device that enforces it (technical or physical).
Choosing a Risk Treatment
After a risk is assessed, the organization picks one of four treatments: mitigate, transfer, accept, or avoid. Read each scenario and choose the treatment it describes.
Matching the Foundational Principles
Match each description to the principle it defines: the three steps of AAA, plus non-repudiation, defense in depth, Zero Trust, and least privilege.
Knowledge Check
Ten multiple-choice questions across the whole chapter. Answer them all, then select Score my answers for feedback and a final total.