WorksheetsCO2521 Recap Week 09
Total questions: 22
Worksheet time: 24mins
Information Security often refers to the CIA Triad, what does the 'C' stand for?
Conservation
Complexity
Confidentiality
Checkguard
Information Security often refers to the CIA Triad, what does the 'A' stand for?
Authentication
Authority
Availability
Access
Which part of the CIA Triad ensures that information is present at the time when authorized parties require it.
Authorisation
Authentication
Confidentiality
Availalibility
(a) is an example of physical asset
(a) is the Intentional or unintentional act that causes damage/compromise information or systems
(a) action that has the potential to adversely affect operations and assets.
(a) is the probability that a (b) will be exploited
Authenication
The process by which a control establishes whether a user is the entity it claims to be.
Accountability
The mechanism that records all actions
Authorisation
the mechnanism that represents the matching of authenicated users to assets and access levels.
Which of these is NOT a direct threat to Integrity?
Unauthorised access.
Malicious modification
ntentional replacement
System back doors
Sniffing
Events that lead to availability violation include; (select two)
Failing to fully authenticate a remote system before transferring data.
Under-allocating resources
Mislabelling or incorrectly classifying objects
None of these
Process of verifying a claimed identity is (a)
Authenication + (a) + Accounting = AAA
Which of these is not a protective mechanism for AAA?
Layering
Encryption
Abstraction
Backups
With Cryptography (a) can be ensured since it (b) information can only be viewed by those who have been provided the key
(a) – actions that illustrate compliance with policies
Once risks have been mitigated and security put in place, a (a) is formally reviewed and agreed upon, after which all further comparisons and development are measured against it
(a) –main responsibility is to guarantee the physical and technical security
Which of these is not a principle of ISM?
Planning
Protection
Projects
Policy
Pricing
(a) in InfoSec are operations that are specifically managed as (b) entities.
Which of the following is not part of the Information Life Cycle ?
Acquisition
Use
Archival
Disposal
Contact Details
Please these in the correct order for classifing information ;
Define classification levels
Specify the criteria that will determine how data is classified
Identify data owners who will be responsible for classifying data
Identify the data custodian who will be responsible for maintaining data and
its security level
Indicate the security controls, or protection mechanisms, required for each
classification level
Which of these could be considered compromises to Intellectual Property ?
Software Piracy
Advanced Persistent Attack
Mudslide
