WorksheetsIAS_REVIEWER
Total questions: 85
Worksheet time: 50mins
Information security
a “well-informed sense of assurance that the information risks and controls are in balance.”
“the quality or state of being secure – to be free from danger”
relates to the actual input and output processes of the system. It focuses on how data is entered into a system, verified, processed and displayed as output
The branch of philosophy that considers nature, criteria, sources, logic, and the validity of moral judgment.
Security
Feasibility analysis to determine whether project should be continued or outsourced
Components evaluated on make-or-buy decision
“the quality or state of being secure – to be free from danger”
A hacker who intentionally removes or bypasses software copyright protection designed
Laws
oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business
The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level
Main factor is business need
Rules that mandate or prohibit certain behavior and are enforced by the state.
Ethics
The application of controls that reduce the risks to an organization’s information assets to an acceptable leveL
The branch of philosophy that considers nature, criteria, sources, logic, and the validity of moral judgment.
Necessary data support and structures identified
“the quality or state of being secure – to be free from danger”
Cracker
The high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.
A hacker who intentionally removes or bypasses software copyright protection designed to prevent unauthorized duplication or use
is software used by a company to manage key parts of operations, including accounting and resource management.
Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy
Phreaker
a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.
Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy
Feasibility analysis to determine whether project should be continued or outsourced
a hacker who manipulates the public telephone system to make free calls or disrupt services.
Which is not a definition of Logical design
a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.
Creates and develops blueprints for information security
The high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.
Feasibility analysis to determine whether project should be continued or outsourced
Logical design
Main factor is business need
Necessary data support and structures identified
is software used by a company to manage key parts of operations, including accounting and resource management.
Feasibility analysis performed at the end
Technologies to implements physical solution determined
which of the following are the definition of physical design
relates to the actual input and output processes of the system. It focuses on how data is entered into a system, verified, processed and displayed as output.
Needed security technology is evaluated
Alternatives are generated
An intentional or unintentional act that damage or otherwise compromise information and the systems that support it
Final design is selected
In Physical design, At end of phase, feasibility study determines readiness of organization for project such as:
Technologies to support the alternatives identified and evaluated in the logical design are selected
Components evaluated on make-or-buy decision
Feasibility analysis performed
a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.
is software used by a company to manage key parts of operations, including accounting and resource management.
(a)
Enterprise Information Security Policy (EISP)
The high-level information security policy that sets the strategic decision, scope, and tone for all of an organization’s security efforts
Determination of the extent to which the organization’s information assets are exposed or at risk
oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business
Consists of details about user access and use permissions and privileges for an organizational asset or resource, such as a file storage system, software component, or network communications device
Enterprise Information Security Policy (EISP)
The process of examining and documenting the security posture of an organization’s information technology and the risks its faces
In its simplest definition, (or economic feasibility) determines whether a particular control is worth its cost
Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy
Application of controls to reduce the risks to an organization’s data and information systems
CIO (Chief Information Office)
Oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business
–An intentional or unintentional act that damage or otherwise compromise information and the systems that support it.CIO (Chief Information Office)
Is the most prominent dedicated toward the promotion of ethical computer use in the United States
Senior technology office
Primarily responsible for advising senior executives on strategic planning
the definition is not here
The application of controls that reduce the risks to an organization’s information assets to an acceptable leveL
Chief Information Security Officer
Primarily responsible for advising senior executives on strategic planning
All of the it
A senior-level executive within an organization, responsible for establishing and maintaining the enterprise vision, strategy and program to ensure information assets and technologies are adequately protected
oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business,
Attack
An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.
A person who accesses systems and information without authorization and often illegally.
The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property
Exploit
A person who accesses systems and information without authorization and often illegally.
A technique used to compromise a system
A potential weakness in an asset or its defensive control system
Vulnerability
A potential weakness in an asset or its defensive control system.
The probability of an unwanted occurrence, such as an adverse event or loss.
A technique used to compromise a system
Risk identification
this category includes acts performed without intent or malicious purpose or in ignorance by an authorized user
None
Unauthorized access and/or data collection
The recognition, enumeration, and documentation of risks to an organization’s information assets.
Risk assessment
A form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information.
A determination of the extent to which an organization’s information assets are exposed to risk
all
The application of computing and resources to try every possible password combination
Risk management
The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property
The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level
Sometimes called acts of God, can present some of the most dangerous threats because they usually occur with little warning and are beyond the control of people
Risk control
A determination of the extent to which an organization’s information assets are exposed to risk
The probability of an unwanted occurrence, such as an adverse event or loss.
both
none
Software piracy
The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property
A potential weakness in an asset or its defensive control system.
standard that has been widely adopted or accepted by a public group rather than a formal standards organization.
Hacker
A person who accesses systems and information without authorization and often illegally.
both
An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.
Brute force
The application of computing and resources to try every possible password combination
Specification of authorization that governs the rights and privileges of users to a particular information asset
all
The probability of an unwanted occurrence, such as an adverse event or loss.
Espionage (categories of threat)
Unauthorized access and/or data collection
Accidents, employee mistakes
this category includes acts performed without intent or malicious purpose or in ignorance by an authorized user
Fire, flood, earthquake, lightning
Force of nature (categories of threat)
Floods / fire / earthquake (categories of threat)
Fire, flood, earthquake, lightning
Forces of nature
Accidents, employee mistakes
Forces of nature
Unauthorized access and/or data collection
Forces of nature
Human error or failure (categories of threat)
A. this category includes acts performed without intent or malicious purpose or in ignorance by an authorized userA.
B. Accidents, employee mistakes
both a n b
C. Non Mandatory recommendations the employee may use as reference in complying with a policy.
Phishing
Specification of authorization that governs the rights and privileges of users to a particular information asset
A type of phishing campaign that target a specific person or group and often will include information known to be of interest of target market
A form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information.
Spear Phishing: choose the definitions
A type of phishing campaign that target a specific person or group and often will include information known to be of interest of target market
Any highly targeted phishing attack
The process of defining and specifying the long-term direction (strategy) to be taken by an organization, and the allocation and acquisition of resources needed to pursue this effort
Strategic planning
The process of defining and specifying the long-term direction (strategy) to be taken by an organization, and the allocation and acquisition of resources needed to pursue this effort
target a specific person or group and often will include information known to be of interest of target market
Operational planning
none
The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives.
Also known as an economic feasibility study, the formal assessment and presentation of the economic expenditures needed for a particular security control, contrasted with its projected value to the organization.
Tactical Planning
the actions taken by management to specify the intermediate goals and objectives of the organization in order to obtain specified strategic goals, followed by estimates and schedules for allocation of resources necessary to achieve those goals and objectives.
property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies. - The organizational resource that is being protected
form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone
The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives
which is not the definition of Guidelines?
standard that has been widely adopted or accepted by a public group rather than a formal standards organization.
Non Mandatory recommendations the employee may use as reference in complying with a policy
consist of details about user access and use permissions and privileges for an organizational asset resource, such as a file storage system, software component or network communications device
Access control list
consist of details about user access and use permissions and privileges for an organizational asset resource, such as a file storage system, software component or network communications device.
Specification of authorization that governs the rights and privileges of users to a particular information asset
Include user access lists, matrices, and capabilities tables,
all
CBA formula
Also known as an economic feasibility study, the formal assessment and presentation of the economic expenditures needed for a particular security control, contrasted with its projected value to the organization.
The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives
property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies
choose the definitions of Asset
property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies
The organizational resource that is being protected
none
Can be logical, such as a website, software information, or data; or can be physical, such as a person, computer system, hardware, or other tangible object. company information or personal data, and generating profit.
De facto Standard
Standard that has been widely adopted or accepted by a public group rather than a formal standards organization.
A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.
the best way to detect a rootkit infection, which your antivirus solution can initiate
form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.
Wireless Hacking Tools
A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.
Are used to intentionally hack into wireless networks to detect security vulnerabilities
A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.
Rootkit detector
the best way to detect a rootkit infection, which your antivirus solution can initiate
are hardware and software tools that can be used to aid in the recovery and preservation of digital evidence
A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.
Forensic tools
are hardware and software tools that can be used to aid in the recovery and preservation of digital evidence
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
the best way to detect a rootkit infection, which your antivirus solution can initiate
Rainbow table
A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.
a software program or hardware appliance that can intercept, copy, and interpret network traffic
Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.
Packet sniffer
all
Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones).
Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.
a software program or hardware appliance that can intercept, copy, and interpret network traffic.
Debuggers
Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones)
none
Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.
The average amount of time a computer repair technician needs to determine the cause of a failure
Jailbreaking
Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones). See also root.
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.
Spoofing
A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.
none
The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker
A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.
Social engineering
The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker
form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures
Pretexting
form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.
The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker
Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.
Man-in-the-middle
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.
Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones)
Mean time between failure (MTBF)
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
The average amount of time a computer repair technician needs to determine the cause of a failure.
The average amount of time until the next hardware failure
The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.
Mean time to diagnose (MTTD
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
- The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.
The average amount of time a computer repair technician needs to determine the cause of a failure.
The average amount of time until the next hardware failure.
Mean time to failure (MTTF)
The average amount of time until the next hardware failure.
The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit
The average amount of time a computer repair technician needs to determine the cause of a failure.
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
Mean time to repair (MTTR)
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.
The average amount of time a computer repair technician needs to determine the cause of a failure.
The average amount of time until the next hardware failure
The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.
Cyber security
A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors. For example, a virus might send copies of itself to all users in the infected system’s e-mail program
the application of technologies, processes, and controls to protect systems, networks, programs, devices and data from cyber attacks.
are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive
Cyber criminals
none
are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive
A type of malware that is capable of activation and replication without being attached to an existing program.
A malware program that hides its true nature and reveals its designed behavior only when activated.
Cyberactivist also known as
hacktivist
cyberhacker
hacker
security activist
Cyber terrorist
A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.
is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.
none
Copyright
Computer software specifically designed to perform malicious or unwanted actions.
Copyright Act (update to U.S. Copyright Law (17 USC)) 1976 - Protects intellectual property, including publications and software
Unauthorized entry into the real or virtual property of another party.
Badware
is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.
A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.
Computer software specifically designed to perform malicious or unwanted actions.
Malware
Computer software specifically designed to perform malicious or unwanted actions.
The severity of the penalty depends on the value of the information obtained
is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.
Virus
ALL
A type of malware that is capable of activation and replication without being attached to an existing program.
A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors. For example, a virus might send copies of itself to all users in the infected system’s e-mail program.
A malware program that hides its true nature and reveals its designed behavior only when activated.
Worm
A malware program that hides its true nature and reveals its designed behavior only when activated.
A type of malware that is capable of activation and replication without being attached to an existing program
none
A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors.
Trojan horse
Malware (a virus or worm) that over time changes the way it appears to antivirus software programs, making it undetectable by techniques that look for preconfigured signatures.
A type of malware that is capable of activation and replication without being attached to an existing program
A malware program that hides its true nature and reveals its designed behavior only when activated.
Polymorphic threat
Copyright Act (update to U.S. Copyright Law (17 USC)) 1976 - Protects intellectual property, including publications and softwar
Malware (a virus or worm) that over time changes the way it appears to antivirus software programs, making it undetectable by techniques that look for preconfigured signatures.
An attack that attempts to overwhelm a computer target’s ability to handle incoming communications, prohibiting legitimate users from accessing those systems.
Denial-of-service (DoS) attack
is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.
Computer software specifically designed to perform malicious or unwanted actions.
An attack that attempts to overwhelm a computer target’s ability to handle incoming communications, prohibiting legitimate users from accessing those systems.
The severity of the penalty depends on the value of the information obtained
Trespass
Unauthorized entry into the real or virtual property of another party.
Computer software specifically designed to perform malicious or unwanted actions.
are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive
The severity of the penalty depends on the value of the information obtained and whether the offense is judged to have been committed for the following reasons:
Financial gain
Fame Seeking
Password attacks
none
In Financial gain, the offense is judged to have been committed for what following reasons:
• For purposes of commercial
• For private financial gain
• In furtherance of a criminal act
Necessary data support and structures identified
Fame Seeking
Computer software specifically designed to perform malicious or unwanted actions.
Attempting to guess or reverse-calculate a password is often called cracking
Widespread reputation, especially of a favorable character, renown
all
Password cracker
Attempting to guess or reverse-calculate a password is often called cracking.
Widespread reputation, especially of a favorable character, renown
fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.
none
In password cracker, there are a number of alternative approaches to password cracking:
• Brute force
• Dictionary
• Rainbow tables
• Social engineering
•Malware
Password attacks
Computer software specifically designed to perform malicious or unwanted actions.
A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.
Attempting to guess or reverse-calculate a password is often called cracking.
fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.
Password Based attack
are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive
typically facilitated through the use of software that expedites cracking or guessing passwords
fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.
Any various method used to maliciously authenticate into password-protected accounts
Computer Ethics Institute
fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.
Is the most prominent dedicated toward the promotion of ethical computer use in the United States
none
typically facilitated through the use of software that expedites cracking or guessing passwords
Thou shalt not use a computer to harm other (a) :
Thou shalt not (a) with other people's computer work
Thou shalt not (a) in other people's computer files:
Thou shalt not use a computer to steal
(a)
Thou shalt not use a computer to bear (a)
Thou shalt not (a) for which you have not paid:
Thou shalt not use other people's computer resources without (a) :
Thou shalt not appropriate other people's (a) :
Thou shalt think about the social consequences of the program you are writing or the (a)
Thou shalt always use a computer in ways that ensure (a) for your fellow humans
