Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Activity 1

Total questions: 10

Worksheet time: 10mins

Name
Class
Date
1.

Hidden fields within web pages can be used to save information about a client session. This option can also be applied in order to store session variables that enable persistence across multiple website pages, such as maintaining the contents of a shopping cart on a retail web site. The most probable web-based attack due to the use of hidden fields is:

a)

parameter tampering

b)

cross-site scripting

c)

cookie poisoning

d)

stealth commanding

2.

Which control is the best way to ensure that the data in a file has not been changed during transmission?

a)

Hash values

b)

parity bits

c)

reasonableness check

d)

check digits

3.

Which of the following techniques can be used to pinpoint a transaction from a stolen credit card?

a)

Stateful Inspection Firewall

b)

Intrusion Detection System

c)

Packet filtering routers

d)

Data mining

4.

Which of the following best ensures integrity of a Server's operating system?

a)

Protecting the server in a secure location

b)

Setting a boot password

c)

Hardening Server Configuration

d)

Implementing Activity Logging

5.

Which of the following will MOST effectively prevent unauthorized access to a System Administration Account on a Webserver.

a)

Two Factor Authenticaiton

b)

Password complexity rules

c)

Password Expiration and Lockout Policy

d)

Host Intrusion Detection Software Installed on the Server

6.

An Organization's IT Director has approved installation of a Wireless local area network access point in conference room for a team of consultants to access internet with their laptops. The BEST control to protect corporate servers from unauthorized access is to ensure that:

a)

Enable Encryption on Access point

b)

Conference Room network on a separate VLAN

c)

Antivirus signatures and patch levels are updated on consultants' laptops

d)

Default user IDs are disabled and strong passwords are set on Corporate Servers

7.

An IS Auditor has been asked by Management to review a potentially fraud transaction. The PRIMARY focus of the auditor should be:

a)

maintain impartiality

b)

maintain IS Auditor Independence

c)

Assuring integrity of the evidence

d)

Assess all relevant evidence for the transaction

8.

Which of the following is an effective preventive control to ensure that a Database Administrator complies with the custodianship of the enterprise's data?

a)

Exception Reports

b)

Segregation of duties

c)

Review of access logs and activities

d)

management supervision

9.

An IS Auditor discovers that password controls are more stringent for business users than for IT developers. Which of the following is the BEST action for the IS auditor to take?

a)

Determine whether this is a policy violation and document it

b)

Document the observation as an Exception

c)

Recommend all password settings be identical

d)

Recommend that logs of IT developer access are reviewed periodically

10.

An organization is developing a web based application. Which of the following security should NOT be taken at all:

a)

Ensure that port 80 and 443 are blocked at firewall

b)

Inspect file and access permission on server

c)

perform a web application security review

d)

Making sure that IP addresses are whitelisted to access the application