Font size
WorksheetsInfasec Reviewer
Total questions: 56
Worksheet time: 42mins
Includes acts performed without intent or malicious purpose
(a)
is far more sophisticated and potentially much faster password attack is possible if the attacker can gain access to an encrypted password file, such as the Security Account Manager (SAM) data file.
(a)
Malware payload that provides access to a system by bypasssing normal access controls
(a)
is a long term increase in electrical power availability
(a)
is a software program or hardware appliance that can intercept, copy, and interpret network traffic.
(a)
is an alert or alarm that occurs in the absence of an actual attack
(a)
Competitive Intelligence is the collection and analysis of information about an organization's competitors through illegal means.
True
False
The top-down approach has a higher probability of success.
True
False
is the probability of an unwanted occurrence, such as an adverse event or loss.
(a)
is a collection of related data stored in structure form.
(a)
The classic perpetrator of espionage or trespass is the (a) who is frequently
glamorized in fictional accounts as a person who stealthily manipulates a maze of computer
networks, systems, and data to find information that solves the mystery and heroically saves
the day.
is a category of entities or circumstances that poses a potential danger to an asset.
(a)
is abstract in nature and concerned with the management of perceptions of a target.
(a)
is a long term interruption in electric power availability.
(a)
A technique used to compromise a system.
(a)
Security mechanisms, policies, or
procedures that can successfully counter
attacks, reduce risk, resolve
vulnerabilities, and otherwise improve
security within an organization.
(a)
The entire set of controls and safeguards,
including policy, education, training and
awareness, and technology, that the
organization implements to protect the
asset.
(a)
An intentional or unintentional act that
can damage or otherwise compromise
information and the systems that support
it.
(a)
is a set of practices intended to keep data secure from unauthorized access or alterations, both when it's being stored and when it's being transmitted from one machine or physical location to another.
(a)
is a subset of information security that focuses on the assessment and protection of information stored in data repositories.
(a)
Large quantities of computer code are written, debugged, published, and sold after all their
bugs are detected and resolved.
True
False
A mail bomb is a undesired email typically commercial advertising sent in bulk.
True
False
Information security is the protection of all media, technology, and content.
True
False
It is about protecting your information assets from destruction, degradation, manipulation and exploitation
by an opponent.
ISO
IA
IAS
IO
Antiquated or Outdated infrastructure can lead to unreliable and untrustworthy systems.
True
False
The three communities of interest: general management, IT management, and physical
security management
True
False
Physical Theft can be controlled easily using a wide variety of measures, from locked doors to trained security personnel, and installation of alarm systems.
True
False
A Trusted VPN, also known as legacy VPN, uses leased circuits from a service provider and conducts packet...
True
False
Secure VPNs, uses security protocols like IPsec to encrypt traffic, transmitted across unsecured network.
True
False
A network IDPS monitors and analyzes wireless network traffic
True
False
A network based IDPS (NIDPS) consists of a specialized hardware appliance and/or software designed.
True
False
Scanning tools are typically used as part of an attack protocol to collect information that an attacker needs.
True
False
Modification of an asset means that some unauthorized party tampers with the asset
True
False
it is an occurence of an event caused by a threat agent
(a)
Threat event is a category of objects, people, or other entities that represents the origin of danger to an asset- in other words, a category of threat agents.
True
False
The HMG Strategy for IA defines it as: Actions taken that protect and defend information and information
systems by ensuring their availability, integrity, authentication, confidentiality and nonrepudiation. This
includes providing for restoration of information systems by incorporating protection, detection and
reaction capabilities.
True
False
The growth of the Internet currently allows organisations around the globe to communicate with each other
in ways that were not previously heard of.
True
False
Many organizations create or support the development of intellectual property (IP) as part of
their business operations.
True
False
Attack protocls are tools that can either perform generic scans or those for specific types.
True
False
Any business, educational institution, or government agency that operates within the modern
context of connected and responsive services does not rely on information systems.
True
False
The confidentiality of information is the quality or state of ownership or control.
True
False
It is the preservation of confidentiality, integrity, and availability of information
Information Operations
Information Assurance
Information Assets
Information Security
Footprinting refers to the activities that scan network locales for active systems and then identify the network services offered by the host systems.
True
False
An IDPS is capable of interdirecting the attack by itself, without human intervention. This could be accomplished by:
Terminating the user session or network connection
Blocking Access to the target system or system
Blocking all access to the targeted infromation
Gives Contractual assurance thta no one else is allowed to use
Can set up tunneling points across the internet
An information asset of the system becomes unusable, unavailable or lost.
Interruption
Fabrication
Modification
Interception
Information assurance is sometimes referred to as information operations (10s) that protect and defend
information systems by ensuring their:
Availability
Integrity
Authentication
Confidentiality
Non-repudiation
is the process of adjusting an IDPS to maximize its efficiency in detecting true positives, while minimizing both false positives and false negatives.
(a)
are items or fact collected by an organization
(a)
It is often the most valuable asset of an
organization and therefore is the main
target of intentional attacks.
(a)
It is often overlooked in computer
security considerations, it have always
been a threat to information security.
(a)
It is the IS component that created much
of the need for increased computer and
information security.
(a)
These are written instructions for
accomplishing a specific task.
(a)
can include legal activities, such as marketing and advertising, and illegal activities such as espionage and hacking. Information operations are performed in the context of a strategy that has a desired objective (or end state) that may be achieved by influencing a target (the object of influence).
(a)
Wireless IDPS can detect the following types of events:
Unauthorized WLANs
Poorly Secured WLAN devices
Unusual usage patterns
The use of wireless network scanners
DoS attacks and conditions
In order for an information consumer to acquire information it has to know:
Why use only one source of information in its decision-making proce
Where that information can be obtained
What information has been validated
How much the consumer is to pay to obtain that information
Who should attempt to validate that information
Information security performs important functions for an organization:
Ensuring that information assets remain safe and useful.
Protecting the data and information the organization collects and uses, whether physical
or electronic
Protecting the organization's ability to function
Enabling the safe operation of applications running on the organization's IT systems
Safeguarding the organization's business reputation
