wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT 323 Reviewer

Total questions: 91

Worksheet time: 1hrs 3mins

Name
Class
Date
1.

a “well-informed sense of assurance that the information risks and controls are in balance.”

Security professionals must review the origins of this field to understand its impact on our understanding of information security today

(a)  

2.

Original communication by mailing tapes

Advanced Research Project Agency (ARPA)

Examined feasibility of redundant networked communications

Larry Roberts developed ARPANET from its inception

ARPANET is predecessor to the Internet

(a)  

3.

ARPANET grew in popularity

Potential for misuse grew

Fundamental problems with ARPANET security

Individual remote sites were not secure from unauthorized users

Vulnerability of password structure and formats

(a)  

4.

Early focus of computer security research

System called Multiplexed Information and Computing Service

First operating system created with security as its primary goal
Mainframe, time-sharing OS developed in mid-1960s

GE, Bell Labs, and MIX

(a)  

5.

Networks of computers became more common

Need to interconnect networks grew

Internet became first manifestation of a global network of networks

Initially based on de facto standards

In early Internet deployments, security was treated as a low priority

(a)  

6.

Millions of computer networks communicate

Many of the communication unsecured

Ability to secure a computer’s data influenced by the security of every computer to which it is connected

Growing threat of cyber attacks has increased the need for improved security

(a)  

7.

  • - The quality or state of being secure—to be free from danger

  • - protection of information and its critical elements



(a)  

8.

The protection of all communications media, technology, and content.

(a)  

9.

Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology.

(a)  

10.

need to secure the physical location of computer technology from outside threats.

(a)  

11.

A subset of communications security; the protection of voice and data networking components, connections, and content.

(a)  

12.

A subject or object’s ability to use, manipulate, modify, or affect another subject or object.

(a)  

13.

This is type of Key IS Concepts which organizational resource that is being protected.

(a)  

14.

Type of Key IS Concept which an intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.

(a)  

15.

This is Type of Key IS Concepts which a technique used to compromise a system.

(a)  

16.

Type of Key IS Concept which the single instance of an information asset suffering damage or destruction, unintended or unauthorized modification or disclosure, or denial of use

(a)  

17.

The probability of an unwanted occurrence, such as an adverse event or loss.

(a)  

18.

A condition or state of being exposed; in information security, exposure

exists when a vulnerability is known to an attacker.

(a)  

19.

The entire set of controls and safeguards, including policy, education, training and awareness, and technology, that the organization implements to protect the asset.

The terms are sometimes used interchangeably with the term security program, although a security program often comprises managerial aspects of security, including planning, personnel, and subordinate programs.

(a)  

20.

A computer can be either the subject of an attack—an agent entity used to conduct the attack—or the object of an attack: the target entity.

A computer can also be both the subject and object of an attack. For example, it can be compromised by an attack (object) and then used to attack other systems (subject).

(a)  

21.

Any event or circumstance that has the potential to adversely affect operations and assets.

The term threat source is commonly used interchangeably with the more generic term threat.

While the two terms are technically distinct, in order to simplify discussion, the text will continue to use the term threat to describe threat sources.

(a)  

22.

The specific instance or a component of a threat.

(a)  

23.

A potential weakness in an asset or its defensive control system(s).

For example, a flaw in a software package, an unprotected system

port, and an unlocked door. Some well-known vulnerabilities have been examined,

documented, and published; others remain latent (or undiscovered).

(a)  

24.

entire set of components necessary to use information as a resource in the organization: Software, Hardware, Data, People, Procedures and Networks.

(a)  

25.

Securing information assets is an incremental process that requires coordination, time, and patience. Information security can begin as a grassroots effort in which systems administrators attempt to improve the security of their systems

a)

Bottom-Up Approach

b)

Top-Down Approach

26.

The most successful approach in information security implementations initiated by upper management that dictates the goals and expected outcomes of the project.

a)

Bottom-Up Approach

b)

Top-Down Approach

27.

Methodology for design and implementation of information system

(a)  

28.

Formal approach to problem solving based on structured sequence of procedures.

(a)  

29.

What problem is the system being developed to solve?

Objectives, constraints, and scope of project specified

Preliminary cost-benefit analysis developed

(a)  

30.

A type of SDLC in which each phase of the process “flows from” the information gained in the previous phase, with multiple opportunities to return to previous phases and make adjustments.

(a)  

31.

begins with the information gained during the investigation phase. This phase consists primarily of assessments of the organization, its current systems, and its capability to support the proposed systems.

(a)  

32.

the information gained from the analysis phase is used to begin creating a systems solution for a business problem.

a)

Logical design

b)

Physical design

33.

Specific technologies are selected to support the alternatives identified and evaluated in this phase.

a)

Physical design

b)

Logical design

34.

Components are ordered, received, and tested. Afterward, users are trained and supporting documentation created.

(a)  

35.

Longest and most expensive of the process. This phase consists of the tasks necessary to support and modify the system for the remainder of its useful life cycle.

(a)  

36.

Typically considered the top information security officer in an organization. The CISO is usually not an executive-level position, and frequently the person in this role reports to the CIO.

(a)  

37.

such as trade secrets, copyrights, trademarks, or patents, are intangible assets that may be attacked via software piracy or the exploitation of asset protection controls.

a)

Compromises to intellectual property

b)

Deviation in quality of service

38.

Organizations rely on services provided by others. Losses can come from interruptions to those

a)

Deviation in quality of service

b)

Espionage or trespass

39.

Asset losses may result when electronic and human activities breach the confidentiality of information.

a)

Espionage or trespass

b)

Forces of nature

40.

A wide range of natural events can overwhelm control systems and preparations to cause losses to data and availability

a)

Forces of nature

b)

Human error or failure

41.

Losses to assets may come from intentional or accidental actions by people inside and outside the organization.

a)

Human error or failure

b)

Information extortion

42.

Stolen or inactivated assets may be held hostage to extract payment of ransom.

a)

Information extortion

b)

Sabotage or vandalism

43.

- Losses may result from the deliberate sabotage of a computer system or business, or from acts of vandalism. These acts can either destroy an asset or damage the image of an organization.

a)

Sabotage or vandalism

b)

Software attacks

44.

- Losses may result when attackers use software to gain unauthorized access to systems or cause disruptions in systems availability.

a)

Software attacks

b)

Techinical hardware failures or error

45.

- Technical defects in hardware systems can cause unexpected results, including unreliable service or lack of availability

a)

Technical hardware failure or error

b)

Technical software

46.

Software used by systems may have purposeful or unintentional errors that result in failures, which can lead to loss of availability or unauthorized access to information.

a)

Technical software

b)

Technological obsolescence

47.

Antiquated or outdated infrastructure can lead to unreliable and untrustworthy systems that may result in loss of availability or unauthorized access to information.

a)

Technological obsolescence

b)

Theft

48.

can result from a wide variety of attacks.

a)

Theft

b)

Technological obsolescence

49.

Acts of trespass can lead to unauthorized real or virtual action that enable information gathers to enter premises or systems without permission

a)

Hackers

b)

Cracker

50.

commonly associated with software copyright bypassing and password decryption. With the removal of the copyright protection, software can be easily distributed and installed. With the decryption of user passwords from stolen system files, user accounts can be illegally accessed. In current usage, the terms hacker and cracker both denote criminal intent

a)

Cracker

b)

Hackers

51.

attempting to guess or reverse-calculate a password is often called cracking.

a)

Password attacks

b)

cracker

52.

the application of computing and network resources to try every possible password combination

a)

Brute force

b)

Rainbow tables

53.

is a variation of the brute force attack that narrows the field by using a dictionary of common passwords and includes information related to the target user

a)

Dictionary

b)

Brute force

54.

a far more sophisticated and potentially much faster password attack is possible if the attacker can gain access to an encrypted password file

a)

Rainbow tables

b)

Social engineering

55.

used by attackers to gain system access or information that may lead to system access.

a)

Social Engineering

b)

Pretexting

56.

a form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information

a)

Phishing

b)

Pretexting

57.

attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information.

a)

Pretexting

b)

Phishing

58.

A hacker who attacks systems to conduct terrorist activities via networks or Internet pathways.

a)

cyberterrorist

b)

cyberwarfare

c)

hacktivist

59.

Formally sanctioned offensive operations conducted by a government or state against information or systems of another government or state. Sometimes called information warfare.

a)

cyberwarfare

b)

cyberterrorist

c)

hacktivist

60.

A hacker who seeks to interfere with or disrupt systems to protest the operations, policies, or actions of an organization or government agency.

a)

hacktivist

b)

cyberwarfare

c)

cyberterrorist

61.

A software program or hardware appliance that can intercept, copy, and interpret network traffic.

a)

Packet sniffer

b)

Spoofing

c)

Man-in-the-middle

62.

A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.

a)

Spoofing

b)

Packet sniffer

c)

Man-in-the-middle

63.

a group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner.

a)

Man-in-the-middle

b)

Spoofing

c)

Packet sniffer

64.
  • - sometimes enforced in civil courts, where large damages can be rewarded to plaintiffs who bring suits against organization.

- a system of rules, regulation, and principles established by governments

a)

Law

b)

Policy

65.

moral principles that govern behavior and decision-making, distinguishing right from wrong

(a)  

66.

- refers to principles of right or wrong behavior

(a)  

67.

- Guidelines that dictate certain behavior within the organization.

a)

Policy

b)

Law

68.

sets the long-term direction to be taken by the organization and each of its component parts.

a)

Strategic planning

b)

Tactical planning

c)

Operational planning

69.

focuses on short-term undertakings that will be completed within one or two years.

a)

Tactical planning

b)

Strategic planning

c)

Operational planning

70.

derived from tactical planning to organize the ongoing, day-to-day performance of tasks.

a)

Operational planning

b)

Tactical planning

c)

Strategic planning

71.

A standard that has been widely adopted or accepted by a public group rather than a formal standards organization. Contrast with a de jure standard.

a)

De facto standards

b)

De jure standards

72.

a standard that has been formally evaluated, approved, and ratified by a formal standards organization. Contrast with a de facto standard.

a)

De jure standards

b)

De facto standards

73.

also known as a general security policy, organizational security policy, IT security policy, or information security policy.

high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.

a)

Enterprise Information Security Policy (EISP)

b)

Issue-specific security policy, or ISSP

74.

are formalized as written documents readily identifiable as policy,

a)

Issue-specific security policy, or ISSP

b)

Enterprise Information Security Policy (EISP)

75.

Specifications of authorization that govern the rights and privileges of users to a particular information asset.

a)

Access Control Lists (ACL)

b)

Issue-specific security policy, or ISSP

76.

is any resource with economic value that an individual, corporation, or country owns or controls with the expectation that it will provide future benefit

a)

Disaster recovery planning (DRP)

b)

Business continuity planning (BCP)

77.

The actions taken by senior management to develop and implement the BC policy, plan, and continuity teams in preparation for adverse events that become incidents or disasters.

a)

Business continuity planning (BCP)

b)

Disaster recovery planning (DRP)

78.

The actions taken during and after a disaster

a)

Crisis Management

b)

Risk Assessment

79.

the process of identifying, assessing, and mitigating potential risks that could negatively impact an individual, organization, or project.

a)

RISK MANAGEMENT

b)

Risk Assessment

80.

determination of the extent to which the organization’s information assets are exposed or at risk

a)

Risk Assessment

b)

Risk Identification

81.

The recognition, enumeration, and documentation of risks to an organization’s information assets.

a)

Risk Identification

b)

Risk Assessment

82.

The application of controls that reduce the risks to an organization’s information assets to an acceptable level.

a)

RIsk Control

b)

Risk Identification

83.

An attempt to improve information security practices by comparing an organization’s efforts against practices of a similar organization or an industry-developed standard to produce results it would like to duplicate. Sometimes

a)

Benchmarking

b)

Baselining

84.

the process of conducting a baseline

a)

Baselining

b)

Benchmarking

85.

current location of file or folder

a)

pwd

b)

cd

c)

touch

86.

create file

a)

touch

b)

chmod

87.

change directory

a)

cd

b)

pwd

c)

mkdir

88.

create folder

a)

mkdir

b)

touch

89.

command use to move folder or file

a)

mv

b)

cd

90.

command use to remove/delete

a)

rm

b)

mv

91.

command use to change file permission

a)

chmod

b)

ls