NEW
Font size
WorksheetsMidExam InfoAssuSec2
Total questions: 50
Worksheet time: 25mins
What are the Five Information Assurance Pillars?
Confidentiality, Integrity, Availability, Authentication, Authorization
Confidentiality, Integrity, Availability, Authorization, Non-Repudiation
Confidentiality, Integrity, Availability, Authentication, Non-Repudiation
Confidentiality, Integrity, Availability, Authentication, Accountability
What is the main goal of Information Assurance?
To ensure the confidentiality, integrity, and availability of information
To delete all information
To provide unlimited access to information
To restrict access to information
What is the main purpose of Security Countermeasures in Information Assurance?
To slow down information processing
To protect information systems from threats
To expose information to unauthorized parties
To increase vulnerabilities
What does Defense in Depth refer to?
Securing the physical door
Security through layers of a building
Securing only the external perimeter
Securing only the internal part of a building
Which of the following is part of the CIA Triangle?
Confidentiality, Integrity, and Authorization
Confidentiality, Integrity, and Authentication
Confidentiality, Integrity, and Accountability
Confidentiality, Integrity, and Availability
What is the main goal of Non-repudiation?
Proving the legitimacy of a message or data transfer
Ensuring data is accurate and valid
Protecting data from unauthorized changes
Providing undeniable evidence of authenticity and integrity
What are Assets in the context of information security?
Organizational resources being protected
Weaknesses in data confidentiality
Probabilities of threats becoming realities
Parameters implemented to protect data
What is a Threat in the context of information security?
An organizational resource being protected
The act of verifying identification
A weakness in data confidentiality
A possibility of data or systems being compromised
What do Security Controls refer to?
Regulations on user access levels
Processes to limit or allow access based on roles
Parameters implemented to protect data
Safeguards or countermeasures used to protect data and infrastructure
What is the purpose of Administrative Network Security?
Manage user access levels within the network
Focus on protecting data within the network
Prevent unauthorized personnel from accessing network components
Implement measures to ensure only authorized individuals interact with network elements
What is Cryptology concerned with?
Providing confidentiality, integrity, and accuracy
Transforming information into a form that is impossible to duplicate
Converting plaintext into cipher text
Storing data in secure and secret form
What do Security Tools refer to?
Software applications and solutions designed to enhance the security of computer systems, networks, and data.
Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.
Detect, prevent, and remove malicious software from a computer system.
Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.
What do Security Tools refer to?What is the purpose of Firewalls?
Software applications and solutions designed to enhance the security of computer systems, networks, and data.
Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.
Detect, prevent, and remove malicious software from a computer system.
Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.
What is the function of Antivirus/Anti-malware Software?
Software applications and solutions designed to enhance the security of computer systems, networks, and data.
Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.
Detect, prevent, and remove malicious software from a computer system.
Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.
What do Intrusion Detection Systems (IDS) do?
Software applications and solutions designed to enhance the security of computer systems, networks, and data.
Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.
Detect, prevent, and remove malicious software from a computer system.
Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.
What do Vulnerability Scanners help organizations with?
Assist in bookkeeping and accounting.
Measure body temperature.
Scan barcodes at a supermarket.
Identify security weaknesses in systems, applications, or networks.
What do Data Loss Prevention (DLP) tools prevent?
Unauthorized access, transmission, or leakage of sensitive data by monitoring and enforcing data usage policies.
Manage user identities, permissions, and access rights within an organization's IT environment.
Individual devices such as computers, laptops, smartphones, and tablets from malware, unauthorized access, and other security threats.
Collect, analyze, and correlate security event data from various sources across an organization's IT infrastructure.
What is the function of Identity and Access Management (IAM) solutions?
Unauthorized access, transmission, or leakage of sensitive data by monitoring and enforcing data usage policies.
Manage user identities, permissions, and access rights within an organization's IT environment.
Individual devices such as computers, laptops, smartphones, and tablets from malware, unauthorized access, and other security threats.
Collect, analyze, and correlate security event data from various sources across an organization's IT infrastructure.
What is the goal of vulnerability analysis?
To identify, assess, and prioritize weaknesses in systems
To ignore security risks
To create new vulnerabilities in organizations
To hack into networks and applications
Which type of vulnerability analysis focuses on network infrastructure?
Web Application Vulnerability Analysis
Host-based Vulnerability Analysis
Network Vulnerability Analysis
Physical Security Vulnerability Analysis
What does Network Device Security refer to?
Optimizing network speed
Controlling network bandwidth usage
Securing physical access points only
Monitoring and protecting internet-connected devices within a network
What is the difference between a software firewall and a hardware firewall?
Software firewalls are more secure than hardware firewalls
Software firewalls are only used for cloud deployment, while hardware firewalls are for physical deployment
Hardware firewalls are more cost-effective than software firewalls
Software firewalls are installed on servers or virtual machines, while hardware firewalls are physical devices
What is the purpose of Content Filtering?
Providing unlimited access to all websites
Blocking all incoming traffic
Increasing network speed
Helping users filter or categorize content according to certain parameters
What is the function of Blacklisting?
Blocking items by adding them to a banned list
Allowing all content
Increasing network security
Monitoring user activity
What does Whitelisting do?
Provides unlimited access to all websites
Increases network speed
Blocks all content
Allows content by adding items to an allowed list
What is the purpose of a honeypot in network security?
To provide free internet access
To increase network speed
To block legitimate users
To trap hackers within the system
What does NAT stand for in network security?
Network Authentication Token
Network Analysis Tool
Network Access Terminal
Network Address Translation
What is the purpose of protocol spoofing in network attacks?
To improve network performance
To enhance network security
To create a secure tunnel over a public network
To misrepresent a network protocol to attack a network
What is the role of IPsec in network security?
To analyze network packets
To manage network traffic
To provide free internet access
To protect data by creating an encrypted tunnel
What is the purpose of network sniffing tools?
To block all incoming connections
To increase network speed
To trap hackers within the system
To analyze data packets in a network
What are the main threats for physical and environmental security?
Cyber attacks, phishing, and malware
Financial fraud, insider threats, and espionage
Energy, equipment, fire, and human threats
Water, air, and soil pollution
What do Content Filters control in the context of Preventive Information Assurance Tools?
Access to streaming platforms
Access to online shopping websites
Access to specific portions of the Internet based on policy
Access to social media websites
What is the primary function of Cryptographic Protocols and Tools in information security?
To hide information and provide confidentiality, integrity, and nonrepudiation protection
To provide physical security to buildings
To manage user access control
To monitor network traffic for anomalies
What is the purpose of Firewalls in information assurance technology?
To encrypt data transmissions
To act as a primary control for network security
To establish virtual private networks
To provide secure communication over public networks
What is the role of a Network Intrusion Prevention System (NIPS) in preventing attacks?
To manage hardware and software configurations
To act as a proxy server
To provide secure communication between clients and the Internet
To inspect network traffic based on organizational policy and detect attacks
What is the purpose of a Virtual Private Network (VPN) in network security?
To act as a backup system for data
To provide secure communication over public networks
To manage configuration changes in IT systems
To monitor and prevent network intrusions
Why is Change Management important in organizations?
To provide IT support for day-to-day operations
To ensure proper labeling of media
To establish secure communication channels
To manage and implement changes to IT infrastructure in a controlled manner
What is the purpose of Backups in information assurance?
To provide a copy of information assets and ensure business continuity
To track changes to configuration items
To act as a proxy server for network connections
To prevent unauthorized access to media
What do Media Controls and Documentation address in information security?
Protection against natural disasters
Safeguarding all media including tapes, disks, and printouts
Ensuring proper encryption of data transmissions
Managing hardware and software configurations
What is the purpose of Patch Management in maintaining IT systems?
To ensure standardized methods and procedures for implementing changes
To provide IT support for day-to-day operations
To perform planned and timely system patches to mitigate security vulnerabilities
To track changes to configuration items
What is the main purpose of an access control system?
To enhance system speed
To improve network connectivity
To prevent actions on an object by unauthorized individuals
To increase system storage capacity
Which type of access control model uses a centrally managed set of rules based on subject roles?
Discretionary Access Control Model
Mandatory Access Control Model
Role-Based Access Control Model
Access Control Matrix
What is the benefit of using a Role-Based Access Control (RBAC) model?
It is only suitable for small organizations
It simplifies access management as subjects acquire permissions through their roles
It requires constant maintenance and monitoring
It allows subjects to directly assign permissions to objects
What is the benefit of using a Role-Based Access Control (RBAC) model?
It is only suitable for small organizations
It simplifies access management as subjects acquire permissions through their roles
It requires constant maintenance and monitoring
It allows subjects to directly assign permissions to objects
Which technique uses simple rules to determine the privileges a subject can have over an object?
Access Control Matrix
Rule-Based Access Control
Access Control Lists
Capability Tables
What is the purpose of a Constrained User Interface in access control?
To provide unlimited access to all subjects
To limit access to resources based on subject roles
To restrict access to specific resources based on subject privileges
To grant access to all resources without any restrictions
In which access control model does the system decide on access control based on information security classification and policy rules?
Role-Based Access Control Model
Discretionary Access Control Model
Access Control Matrix
Mandatory Access Control Model
Which mode of access control administration gives control to people closer to the objects?
Role-Based Access Control Administration
Decentralized Access Control Administration
Centralized Access Control Administration
Mandatory Access Control Administration
What is the purpose of an Access Control Matrix?
To use simple rules to determine privileges
To control access based on information security classification
To determine access rights based on subject roles
To represent accessibility using individual or group permissions
Which technique aims at controlling the availability of information by means of views in databases?
Access Control Lists
Rule-Based Access Control
Context-Dependent Access Control
Content-Dependent Access Control
