wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS1

Total questions: 58

Worksheet time: 29mins

Name
Class
Date
1.
data and data processing activities in physical space;
a)
physical
b)
informationinfrastructure
c)
perceptual
2.
information and data manipulation abilities in cyberspace;
a)
physical
b)
informationinfrastructure
c)
perceptual
3.
knowledge and understanding in human decision space.
a)
physical
b)
informationinfrastructure
c)
perceptual
4.
authorized users are able to access it;
a)
accuracy:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
5.
the information is free of error and has the valueexpected;
a)
accuracy:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
6.
the information is genuine;
a)
accuracy:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
7.
the information has not been disclosed tounauthorized parties;
a)
accuracy:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
8.
the information is whole, complete and uncorrupted;
a)
accuracy:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
9.
the information has value for the intended purpose;
a)
utility:
b)
authenticity:
c)
availability:
d)
confidentiality:
e)
integrity:
10.
the data is under authorized ownership and control.
a)
accuracy:
b)
authenticity:
c)
possession:
d)
confidentiality:
e)
integrity:
11.
devices, computers,people;
a)
physical assets
b)
logical assets
c)
system assets
12.
information, data (intransmission, storage, or processing), andintellectual property;
a)
physical assets
b)
logical assets
c)
system assets
13.
any software, hardware,data, administrative, physical,communications, or personnel resourcewithin an information system.
a)
physical assets
b)
logical assets
c)
system assets
14.

is the resource being protected,

(a)  

15.
a category of entities, or a circumstance, that poses apotential danger to an asset
a)
threat actor
b)
vulnerability
c)
bug
d)
threat
16.
is a specific instance of a threat, e.g. a specifichacker, a particular storm, etc.
a)
threat actor
b)
vulnerability
c)
bug
d)
threat
17.
is a weakness or fault in a system that exposesinformation to attack.
a)
threat actor
b)
vulnerability
c)
bug
d)
threat
18.
in a computer program is a very common vulnerabilityin computer security (e.g. buffer overflow situation).
a)
threat actor
b)
vulnerability
c)
bug
d)
threat
19.

a method for taking advantage of a knownvulnerability.

(a)  

20.
is an attempt to gain access, cause damage to orotherwise compromise information and/or systems that support it.
a)
Attacks
b)
exploit
c)
vulnerability
d)
threat
21.
one that does not pose a danger as there is novulnerability to exploit (threat is there, but can’t do damage).
a)
dangling vulnerability
b)
dangling threat
c)
vulnerability
d)
threat
22.
is one for which there is no known threat(vulnerability is there but not exploitable).
a)
dangling vulnerability
b)
dangling threat
c)
vulnerability
d)
threat
23.
an attack in which the attacker observesinteraction with the system.
a)
Unintentional attack:
b)
Active attack:
c)
Passive attack:
d)
threat
24.
at attack in which the attacker directly interactswith the system.
a)
Unintentional attack:
b)
Active attack:
c)
Passive attack:
d)
threat
25.
an attack where there is not a deliberategoal of misuse
a)
Unintentional attack:
b)
Active attack:
c)
Passive attack:
d)
threat
26.

is an instance when the system is vulnerable to attack.

(a)  

27.
situation in which the attacker has succeeded.
a)
compromise
b)
indicator
c)
aexposure
d)
attacks
28.
is a recognized action—specific, generalized ortheoretical—that an adversary (threat actor) might be expected totake in preparation for an attack.
a)
compromise
b)
indicator
c)
aexposure
d)
attacks
29.
an asset becomes unusable, unavailable, or lost.
a)
Modification
b)
Fabrication
c)
Interruption
d)
Interception
30.
an unauthorized party gains access to an information asset.
a)
Modification
b)
Fabrication
c)
Interruption
d)
Interception
31.
an unauthorized party tampers with an asset.
a)
Modification
b)
Fabrication
c)
Interruption
d)
Interception
32.
an asset has been counterfeit.
a)
Modification
b)
Fabrication
c)
Interruption
d)
Interception
33.

essentially a network burglar alarm, similar to the alarms placed on doors and windows of a building.

(a)  

34.
takes hash values of all of the important system files on the host.
a)
anomaly-based.
b)
signature-based HIDS
35.
creates a statistical baseline representation of normal and acceptable network traffic over a representative period of time and then compares all future traffic to that baseline.
a)
anomaly-based.
b)
signature-based HIDS
36.

is a small, lightweight open source IDS written by Marty Roesch which has become the most widely used IDS.

(a)  

37.
is a GUI environment developed by Engage Security designed to allow users to quickly and easily configure Snort and its operation in the windows environment.
a)
ACID
b)
PureSecure
c)
IDScenter
d)
SnortCenter
e)
SnortSnarf
38.
is a GUI front-end, written in PHP, which allows users to track attack patterns and trends and historical alerts.
a)
ACID
b)
PureSecure
c)
IDScenter
d)
SnortCenter
e)
SnortSnarf
39.
is a GUI environment developed by DeMarc Security that combines IDS with host file system integrity.
a)
ACID
b)
PureSecure
c)
IDScenter
d)
SnortCenter
e)
SnortSnarf
40.
is a GUI environment developed by Stefan Dens. SnortCenter is written in PHP and Perl and is designed primarily to assist users in configuring Snort and keeping the signature files up-to-date.
a)
ACID
b)
PureSecure
c)
IDScenter
d)
SnortCenter
e)
SnortSnarf
41.
is a PHP utility developed by Silicon Defense is a small utility written in Perl which is designed to group Snort alerts and conveniently display them in Web pages for easy analysis.
a)
ACID
b)
PureSecure
c)
IDScenter
d)
SnortCenter
e)
SnortSnarf
42.
is a small utility to help manage Snort’s unified output.
a)
Swatch
b)
Barnyard
c)
SnortSam
d)
SnortFE
e)
RazorBack
43.
is a small alert monitoring utility written in Perl and developed by Todd Atkins.
a)
Swatch
b)
Barnyard
c)
SnortSam
d)
SnortFE
e)
RazorBack
44.
is another alert monitoring utility which allows a system to respond to certain types of events by reconfiguring a firewall to block a specific source IP.
a)
Swatch
b)
Barnyard
c)
SnortSam
d)
SnortFE
e)
RazorBack
45.
is a Windows-based GUI front end developed by Anthony Scalzitti for quickly displaying Snort real-time alerts.
a)
Swatch
b)
Barnyard
c)
SnortSam
d)
SnortFE
e)
RazorBack
46.
is a small GUI front end developed by Intersect Alliance. RazorBack runs only in the Linux/Gnome environment and is used for quickly displaying real-time alerts.
a)
Swatch
b)
Barnyard
c)
SnortSam
d)
SnortFE
e)
RazorBack
47.
is a Mac OS X port of Snort 2.0 developed by Nick Zitzmann.
a)
Swatch
b)
HenWen
c)
SnortSam
d)
SnortFE
e)
RazorBack
48.

is a combination of hardware and software used to implement a security policy

(a)  

49.

means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.

(a)  

50.

is about building systems to remain dependable in the face of malice, error, or mischance.

(a)  

51.

is a computer network defense mechanism which includes response to actions and critical infrastructure protection and information assurance for organizations, government entities and other possible networks.

(a)  

52.

is the practice of assuring information and managing risks related to the use, processing, storage, and transmission of information or data and the systems and processes used for those purposes.

(a)  

53.

is the process of adding business benefit through the use of IRM (Information Risk Management) which increases the utility of information to authorized users, and reduces the utility of information to those unauthorized.

(a)  

54.

is the practice of defending information from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.

(a)  

55.

is a branch of computer technology known as information security as applied to computers and networks.

(a)  

56.
is a set of rules that limits access to information.
a)
confidentiality
b)
availability
c)
integrity
57.
is the assurance that the information is trustworthy and accurate.
a)
confidentiality
b)
availability
c)
integrity
58.
is very much a concern beyond the traditional boundaries of computer security.
a)
confidentiality
b)
availability
c)
integrity