Objective 1.3CC

1.3 Understand security controls.

Objective 1.3 sits in Security Principles, which carries 26% of the Certified in Cybersecurity exam. The questions below are original, written from the official objective title above, and each explanation cites the ISC2 page it rests on.

Objective title verbatim from the official objectives. ISC2 exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

1-3Security PrinciplesEasy

An information security program must combine which three categories of safeguards?

Administrative, technical, and physicalCorrect · your answerCorrect. Those are the three safeguard categories the Rule names.
Preventive, punitive, and financialPunishment and finance are consequences an organization faces, never classes of protection it deploys.
Manual, automated, and outsourcedManual versus automated only says how a control runs.
Corporate, departmental, and publicPick org-chart labels when asking who owns a control; the taxonomy asks what kind it is.

Correct.

Concept

Controls are grouped by how they act: through people and process, through technology, or through the physical environment. A program missing a category leaves a whole class of attack unanswered.

Why A

The Safeguards Rule requires an information security program with administrative, technical, and physical safeguards designed to protect customer information.

#controls#categories

Now you: objective 1.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

1-3Security PrinciplesModerate

A finance team adds locked cabinets for paper loan files. Which safeguard category is that?

Sample question 2 of 3

1-3Security PrinciplesModerate

A written policy requires quarterly reviews of who can open customer records. The policy itself is which safeguard category?

Sample question 3 of 3

1-3Security PrinciplesModerate

During an access review, the team finds analysts from a finished project still able to read customer records. What does the Safeguards Rule expect?

Full Certified in Cybersecurity question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Principles