Start Here
Six review stations, each a different way to practice Chapter 1. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or lab.
What this chapter asked you to be able to do
- Classify security controls by type (administrative, operational, technical, physical) and by function (preventative, detective, responsive, corrective).
- Define and tell apart risk concepts: appetite, tolerance, inherent, residual, and effective risk.
- Evaluate the four risk strategies (accept, transfer, avoid, mitigate) for a given scenario.
- Explain how policies, governance frameworks, and Service Level Objectives (SLOs) shape security posture.
- Map business objectives to control choices and risk decisions.
Your progress this session
These counters update as you check answers on each station. They reset when you reload the page.
Key Terms Flashcards
Select a card to reveal its definition, then select again to flip it back. Try to state the definition before you flip. The counter tracks how many distinct cards you have opened.
Mapping the Risk Chain
Chapter 1 models risk as a chain: a threat agent exploits a vulnerability to compromise an asset, causing impact. For each scenario, label the four highlighted parts.
Classifying Controls by Type and Function
Every control has one type and one function, and the two are independent. For each control, choose both, then check your answer.
Reference: control classification matrix (type × function)
| Function \ Type | Administrative | Technical | Physical |
|---|---|---|---|
| Preventative | Security policy, background checks | Firewalls, encryption, MFA | Locked doors, badge access |
| Detective | Audit reviews, compliance reports | SIEM, IDS, log analysis | CCTV, motion sensors |
| Responsive | IR procedures, escalation protocols | Auto-lockout, quarantine | Guard response, lockdown |
| Corrective | Lessons learned, policy revision | Backup restore, reimaging | Facility repair, equipment replacement |
Operational controls are the recurring activities that carry out administrative rules (patch cycles, log review, account provisioning, backup testing). A control can shift type depending on whether you mean the written rule, the running activity, or the device that enforces it.
Choosing a Risk Strategy
Every risk decision resolves to one of four strategies: accept, transfer, avoid, or mitigate. Read each scenario and pick the strategy it describes.
Governance, Frameworks, and Compliance
Three short matching sets: the policy framework tiers, the NIST Cybersecurity Framework functions, and the major regulations. Choose a match for each item, then check.
A. Policy framework tiers
Match each statement to its place in the hierarchy: policy, standard, procedure, or guideline.
B. NIST Cybersecurity Framework functions
The NIST CSF organizes work into five functions. Match each description to Identify, Protect, Detect, Respond, or Recover.
C. Major compliance requirements
Match each regulation to the organizations it governs.
Knowledge Check
Ten multiple-choice questions across the whole chapter. Answer them all, then select Score my answers for feedback and a final total.