Font size
WorksheetsComputer Security Chapter 7: Creating a Security Plan
Total questions: 15
Worksheet time: 13mins
Who has the responsibility for the development of a security policy?
senior management
middle management
executives
clerical staff
What is the most effective means of improving or enforcing security in any environment?
risk assessment
vulnerability assessment
restrict access
user awareness training
What document is a high-level, general statement about the role of security in the organization?
You have recently discovered that a network attack has compromised your database server. In the process, customer credit card numbers might have been taken by an attacker. You have stopped the attack and put measures in place to prevent the same incident from occurring in the future. What else might you be legally required to do?
Which mitigation plan is most appropriate to limit the risk of unauthorized access to workstations?
physically lock workstations
password protection
access control mechanisms
limit the time a user is allowed to use the workstation
Which network devices are capable of blocking network connections that are identified as potentially malicious?
honeypots
intrusion prevention systems (IPS)
intrusion detection systems (IDS)
firewalls
A (a) describes any action that could damage a computer asset.
The weakest link in the security of an IT infrastructure is the server.
True
False
In recent years, identity theft has been more prevalent as part of phishing.
True
False
Unintentional damage to software occurs because of poor training, lack of adherence to simple backup procedures, or simple human error.
True
False
A policy that defines the actions users may or may not perform while accessing systems and networking equipment is known as:
Password Policy
End User License Agreement
Acceptable Use Policy
Email Policy
The boundary between the outer limit of an organization`s security and the beginning of the outside world, is known as the security (a) .
Security (a) provides detailed information and hands-on instruction to employees to prepare them to perform their duties securely.
A (a) plan is prepared by the organization to anticipate, react to, and recover from events that threaten the security of info and info assets in the organization and, subsequently, to restore the organization to normal modes of business operations.
There are __________ stages in the NIST Cyber Security Framework.
3
4
5
6
