WorksheetsIAS 2
Total questions: 88
Worksheet time: 44mins
Items of fact collected by an organization
Includes raw numbers, facts and words
(a)
Data that has been organized structure and presented to provide additional insight into its context, worth, and usefulness
(a)
The focus of information security; information that has value to the organization, and the systems that store, process, and transmit the information.
(a)
ü As a subset of information assets, the systems and networks that store, process, and transmit information
(a)
Commonly used as a surrogate for information security, data security is the focus of protecting data or information in its various states—at rest (in storage), in processing, and in transmission (over networks)
(a)
A collection of related data stored in a structured form and usually managed by a database management system.
(a)
A subset of information security that focuses on the assessment and protection of information stored in data repositories like database management systems and storage media.
(a)
An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it. Attacks can be active or passive and direct or indirect.
(a)
A technique used to compromise a system.
(a)
Ø A potential weakness in an asset or its defensive control system(s).
(a)
Ø The creation, ownership, and control of original ideas as well as the representation of those ideas
(a)
ü The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property
(a)
Ø An interruption in service, usually from a service provider, which causes an adverse event within an organization
(a)
The percentage of time a particular service is not available; the opposite of uptime.
(a)
Ø A document or part of a document that specifies the expected level of service from a service provider. An SLA usually contains provisions for minimum acceptable availability and penalties or remediation procedures for downtime.
(a)
The percentage of time a particular service is available; the opposite of downtime
(a)
A long-term interruption (outage) in electrical power availability.
(a)
A long-term decrease in electrical power availability.
(a)
A short-term interruption in electrical power availability.
(a)
Ø The presence of additional and disruptive signals in network communications or electrical power delivery.
(a)
A short-term decrease in electrical power availability.
(a)
A short-term increase in electrical power availability, also known as a swell.
(a)
A long-term increase in electrical power availability.
(a)
Ø The collection and analysis of information about an organization’s business competitors through legal and ethical means to gain business intelligence and competitive advantage.
(a)
The collection and analysis of information about an organization’s business competitors, often through illegal or unethical means, to gain an unfair competitive advantage
(a)
Ø The direct, covert observation of individual information or system use
(a)
ü An act of an unauthorized person gains access to information an organization is trying to protect,
(a)
uses extensive knowledge of the inner workings of computer hardware and software to gain unauthorized access to systems and information.
(a)
Ø A person who accesses systems and information without authorization and often illegally.
(a)
Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones). S
(a)
A relatively unskilled hacker who uses the work of expert hackers to perform attacks. Also known as a neophyte, n00b, or newbie
(a)
A script kiddie who uses automated exploits to engage in denial-of-service attacks.
(a)
Ø An information security professional with authorization to attempt to gain system access in an effort to identify and recommend resolutions for vulnerabilities in those systems.
(a)
ü The unauthorized modification of an authorized or unauthorized system user account to gain advanced access and control over system resources.
(a)
conducts attacks for personal financial benefit or for a crime organization or foreign governmen
(a)
Escalating privileges to gain administrator-level control over a computer system (including smartphones). Typically associated with Android OS smartphones
(a)
A hacker of limited skill who uses expertly written software to attack a system
(a)
Unauthorized entry into the real or virtual property of another party
(a)
A hacker who intentionally removes or bypasses software copyright protection designed to prevent unauthorized duplication or use.
(a)
A hacker who manipulates the public telephone system to make free calls or disrupt services.
(a)
Ø An industry recommendation for password structure and strength that specifies passwords should be at least 10 characters long and contain at least one uppercase letter, one lowercase letter, one number, and one special character.
(a)
Ø An attempt to guess a password by attempting every possible combination of characters and numbers in it.
(a)
Attempting to reverse-engineer, remove, or bypass a password or other access control protection, such as the copyright protection on software
(a)
Ø A variation of the brute force password attack that attempts to narrow the range of possible passwords guessed by using a list of common passwords and possibly including attempts based on the target’s personal information.
(a)
Ø A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.
(a)
ü A form of social engineering, typically conducted via e-mail, in which an organization or some third party indicates that the recipient is due an exorbitant amount of money and needs only a small advance fee or personal banking information to facilitate the transfer.
(a)
ü A form of social engineering in which the attacker provides what appears to be a legitimate communication (usually e-mail), but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information.
(a)
A form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential informatio
(a)
The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker.
(a)
ü Any highly targeted phishing attack.
(a)
The act of an attacker or trusted insider who steals or interrupts access to information from a computer system and demands compensation for its return or for an agreement not to disclose the information
(a)
Computer software specifically designed to identify and encrypt valuable information in a victim’s system in order to extort payment for the key needed to unlock the encryption
(a)
Ø involves the deliberate sabotage of a computer system or business, or acts of vandalism to destroy an asset or damage the image of an organization
(a)
A hacker who attacks systems to conduct terrorist activities via networks or Internet pathways
(a)
ü Formally sanctioned offensive operations conducted by a government or state against information or systems of another government or state. Sometimes called information warfare
(a)
ü A hacker who seeks to interfere with or disrupt systems to protest the operations, policies, or actions of an organization or government agency.
(a)
ü Social media outlets, such as Facebook, MySpace, Twitter, and YouTube, are commonly used to perform fundraising, raise awareness of social issues, gather support for legitimate causes, and promote involvement.
(a)
Ø occur when an individual or group designs and deploys software to attack a system
(a)
ü Computer software specifically designed to perform malicious or unwanted actions.
(a)
Any technology that aids in gathering information about people or organizations without their knowledge.
(a)
intended to provide undesired marketing and advertising, including popups and banners on a user’s screens.
(a)
A type of malware that is attached to other executable programs.
(a)
a type of virus that targets the boot sector or Master Boot Record (MBR) of a computer system’s hard drive or removable storage media.
(a)
A type of virus written in a specific macro language to target applications that use the language. The virus is activated when the application’s product is opened.
(a)
A virus that is capable of installing itself in a computer’s operating system, starting when the computer is activated, and residing in the system’s memory even after the host application is terminated
(a)
A virus that terminates after it has been activated, infected its host system, and replicated itself
(a)
ü A type of malware that is capable of activation and replication without being attached to an existing program
(a)
Malware (a virus or worm) that over time changes the way it appears to antivirus software programs, making it undetectable by techniques that look for preconfigured signatures.
(a)
A malware program that hides its true nature and reveals its designed behavior only when activated
(a)
A message that reports the presence of a nonexistent virus or worm and wastes valuable time as employees share the message
(a)
ü An attack that makes use of malware that is not yet known by the anti-malware software companies
(a)
A malware payload that provides access to a system by bypassing normal access controls.
(a)
doors are left behind by system designers or maintenance staff
(a)
An abbreviation of robot, an automated software program that executes certain commands when it receives a specific input
(a)
An attack that attempts to overwhelm a computer target’s ability to handle incoming communications, prohibiting legitimate users from accessing those systems.
(a)
n A form of DoS attack in which a coordinated stream of requests is launched against a target from many locations at the same time using bots or zombies
(a)
ü An attack designed to overwhelm the receiver with excessive quantities of e-mail.
(a)
ü Undesired e-mail, typically commercial advertising transmitted in bulk.
(a)
ü A software program or hardware appliance that can intercept, copy, and interpret network traffic.
(a)
A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host
(a)
ü The redirection of legitimate user Web traffic to illegitimate Web sites with the intent to collect personal information.
(a)
ü A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner
(a)
A form of man-in-the-middle attack whereby the attacker inserts himself into TCP/IP-based communications.
(a)
The intentional hacking and modification of a DNS database to redirect legitimate traffic to illegitimate Internet locations
(a)
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failure
(a)
The average amount of time a computer repair technician needs to determine the cause of a failure.
(a)
The average amount of time until the next hardware failure.
(a)
ü The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.
(a)
