WorksheetsIAS2-NW3A
Total questions: 50
Worksheet time: 50mins
Which of the following interpret requirements and apply them to specific situations?
Policies
Standards
Guidelines
Procedure
Business continuity plans (BCPs) associated with organizational information systems should be developed primarily on the basis of:
Available Resources
Business needs
Levels of Effort
Projected Costs
Which cybersecurity principle is most important when attempting to trace the source of malicious activity?
Availability
Nonrepudiation
Integrity
Confidentiality
Outsourcing poses the greatest risk to an organization when it involves:
Business Support Services
Core Business Functions
Technology Infrastructure
Cybersecurity Capabilies
Risk assessments should be performed:
At the start of a program
On a regular basis
When an asset changes
When a vulnerability is discovered
During which phase of the system development lifecycle (SDLC) should security first be considered?
Analysis
Planning
Design
Implementation
Who has the greatest influence over access security in a password authentication environment?
System Administrators
Users
Business Executives
Security Manager
A cybersecurity architecture designed around the concept of a perimeter is said to be:
Data-centric
System-centric
User-centric
Integrated
Which two factors are used to calculate the likelihood of an event?
Vulnerability and Asset Value
Threat and Vulnerability
Asset Count and Asset Value
Threat and Asset Value
_______________- includes security processes such as conducting risk management exercises, security awareness programs, policy development, and compliance efforts with laws and regulations.
Tactical Management
Strategic Management
Operational Management
Level of Controls
The_____________ to management is a strategy in which the decision-making process occurs at the highest level and is then communicated to the rest of the team. This style can be applied at the project, team, or even the company level, and can be adjusted according to the particular group's needs.
top-down approach
bottom-up approach
Outsourcing
Organizational Maturity
Prior to applying a top-down or bottom-up approach, an organization needs to ___________ the associated factors and costs of protecting information.
secure
analysis
analyze
protect
_______________ where an information assurance management program is managed under a centralized unit with ultimate accountability and responsibility for the program.
Centralized structure
Distributed structure
Hybrid structure
Organizational maturity
_____________________ is important in determining an effective information assurance program.
Centralized structure
Distributed structure
Hybrid structure
Organizational maturity
_______________ will be directly involved in the planning of local security systems.
Managers
Information assets
Executives
Employees
____________________ will have a better understanding of the organization and will be able to effectively play their role and use their authority to protect information.
Managers
Information assets
Executives
Employees
CIA of assets stands for_______.
Confidentiality, Integration and Availability
Confidentiality, Integrity and Accessibility
Continuity, Integrity, and Availability
Confidentiality, Integrity and Availability
The _____________ is the overall process of creating, implementing, and decommissioning information systems through a multistep process from initiation, analysis, design, implementation, and maintenance to disposal.
service acquisition life cycle
information assurance and security
risk mitigation
system development life cycle
In this phase, the need for a system is established, and the requirement capabilities of the system are stated.
initiation
acquisition and development
implementation/maintenance
disposal
Information assurance in the system or service acquisition life cycle, under the system development the ____________ must be able to provide the solutions.
information assrurance teams
system developers
system owners
system acquisition team
_____________ is the process of ensuring changes to the organization are communicated to all relevant stakeholders and impacts are understood prior to changes being implemented.
Change management
Configuration management
Physical and environmental security
Organizations benefit
_____________ –is a subprocess of change management for information systems and services.
Change management
Configuration management
Physical and environmental security
Organizations benefit
_____________ protects an organization’s physical infrastructure, its equipment, and its facilities, as well as its employees, from physical events, threats, or incidents.
Change management
Configuration management
Physical and environmental security
Organizations benefit
The acts of sabotage or vandalism can impair hardware components.
Environmental disruption
Interruptions to service
Loss of system integrity
Physical damage
The concept of a layered defense approach which also known as _____________, is that if an intruder successfully manages to penetrate one control layer, there will be other control layers in his way before he can access the organization’s assets.
defense-in-depth approach
physical security
environmental security
system security
The first line of defense in safeguarding employees, information resources, and property is the ____________.
security perimeter
physical protection
perimeter protection
system protection
_______________ also includes deploying lockable doors and windows, grills for windows, and fire escapes.
security perimeter
physical protection
perimeter protection
system protection
____________ completely erases the information stored on the magnetic surface.
shredding
burning
degaussing
disposing
_________ to teach or improve an individual’s skill, knowledge, or attitude, which allows a person to carry out a specific function.
training aims
training environment
awareness aims
education context
In a _________________, the employee is taught to use specific skills as part of specific job performance.
training aims
training environment
awareness aims
education context
In an ________________, the employee would be encouraged to examine and evaluate not only skills and methods of work but fundamental operating principles and tenants upon which job skills are based.
training aims
training environment
awareness aims
education context
______________ is a technique for hiding information by transforming it so that only authorized individuals can access it in its original form.
Cryptography
Cryptographic tools
Encryption techniques
Firewalls
_______________–for hosts range from encryption of the entire hard disk, database encryption, selective folder (group of files) encryption, or individual file encryption.
Cryptography
Cryptographic tools
Encryption techniques
Firewalls
A __________________ inspects network traffic based on organizational information assurance policy and configuration.
network intrusion prevention system (NIPS)
signatures
anomaly-based NIPS
proxy servers
To detect attacks, the contents of the network packets are checked for distinctive sequences called ________________.
network intrusion prevention system (NIPS)
signatures
anomaly-based NIPS
proxy servers
The simplest form of a ______________ is called a gateway.
network intrusion prevention system (NIPS)
signatures
anomaly-based NIPS
proxy servers
A _____________ is a copy of information assets: data, software, or hardware.
backup
Backing up systems
document
restoration
______________ is an effective means of mitigating information assurance risks.
Change management
Configuration management
Patch Management
Documentation
______________ requires performing planned and timely system patches to maintain operational efficiency and effectiveness, mitigate information security vulnerabilities, and maintain the stability of IT systems.
Change management
Configuration management
Patch Management
Documentation
If intruders are able to gain physical access to hardware components, they may be able to bypass logical access controls.
Environmental disruption
Interruptions to service
Loss of system integrity
Physical damage
Serious business interruption may cause business disaster.
Environmental disruption
Interruptions to service
Loss of system integrity
Physical damage
In handling of media, ______________ all media used to store information.
secure
protect
safeguard
dispose
To ensure that an _______________ is introduced effectively, it needs to be designed and customized to the needs of the organization.
information assurance requirements
information-processing systems
information assurance plan
information assurance enterprise architectures
An information assurance policy is the basis of an effective information assurance program.
Information Assurance Awareness
Obtain management commitment
Appoint personnel to lead the planning process
Ensure establishment of an information assurance program and associated policy
Management’s commitment should be clearly stated in the information assurance policy.
Information Assurance Awareness
Obtain management commitment
Appoint personnel to lead the planning process
Ensure establishment of an information assurance program and associated policy
Organizations should assemble a team or taskforce to begin the process of planning an awareness program.
Information Assurance Awareness
Obtain management commitment
Appoint personnel to lead the planning process
Ensure establishment of an information assurance program and associated policy
The _____________ gives all teams a voice in these types of decisions.
top-down approach
bottom-up approach
Outsourcing
Organizational Maturity
_______________ where roles, responsibilities, and authorities are spread throughout the organization’s business units, operations areas, and geographical locations.
Centralized structure
Distributed structure
Hybrid structure
Organizational Maturity
_______________ that is a mix of the centralized and distributed structures.
Centralized structure
Distributed structure
Hybrid structure
Organizational Maturity
__________________ will be securely managed by the organization as per information handling categorization.
Managers
Information assets
Executives
Employees
