Font size
WorksheetsFINALS AISPRE5
Total questions: 130
Worksheet time: 2hrs 10mins
The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level. This must become an integral part of the economic basis for
making business decisions.
(a)
You must identify, examine, and understand the
current information and systems in your organization. To
protect information assets, which were defined earlier in
this book as information and the systems that use, store,
and transmit information, you must know what those assets
are, where they are, how they add value to the organization,
and the vulnerabilities to which they are susceptible.
(a)
This means identifying, examining, and understanding
the threats facing the organization. You must determine
which threat aspects most directly affect the security of the
organization and its information assets, and then use this
information to create a list of threats, each one ranked
according to the importance of the information assets that
it threatens.
(a)
Each community of interest has a role to play in managing the
risks that an organization encounters. Because members of the
information security community best understand the threats
and attacks that introduce risk into the organization, they often
take a leadership role in addressing risk to information assets.
Management and users, when properly trained and kept aware
of the threats the organization faces, play a part in early
detection and response.
(a)
must also ensure that sufficient time,
money, personnel, and other resources are allocated to the
information security and information technology groups to
meet the organization’s security needs.
(a)
must work together to address all
levels of risk, which range from disasters that can devastate the
whole organization to the smallest employee mistakes.
(a)
A determination of the extent to which an organization’s information assets are exposed to risk.
(a)
The application of controls that reduce the risks to an organization’s information assets to an acceptable
level.
(a)
The recognition, enumeration, and documentation of risks to an organization’s information
assets.
(a)
The risk to information assets that
remains even after current controls have been applied.
(a)
The quantity and nature of risk that
organizations are willing to accept as they evaluate the
trade-offs between perfect security and unlimited
accessibility.
(a)
also known as risk tolerance
(a)
When vulnerabilities have been controlled as much as possible,
any remaining risk that has not been removed, shifted, or
planned for is called
(a)
A risk management strategy requires that
information security professionals know their
organizations’ information assets that is, how to
identify, classify, and prioritize them.
(a)
It compares the categorizations of a standard information
system (people, procedures, data and information, software, and
hardware) with those in an enhanced version that incorporates risk
management principles.
(a)
A formal access control methodology used to assign a level of confidentiality to an
information asset and restricts number of people who can access it.
(a)
Used for the most sensitive corporate
information that must be tightly controlled, even within the
company. Access to information with this classification is strictly
on a need-to-know basis or as required by the terms of a contract.
(a)
Used for all internal information that does not meet
the criteria for the confidential category. Internal information is to
be viewed only by corporate employees, authorized contractors,
and other third parties.
(a)
All information that has been approved by
management for public release.
(a)
A personnel security structure in which
each user of an information asset is assigned an authorization level that
identifies the level of classified information he or she is “cleared” to
access.
(a)
An organizational policy that specifies
employees must inspect their work areas and ensure that all classified
information, documents, and materials are secured at the end of every
work day.
(a)
An information attack that involves searching
through a target organization’s trash and recycling bins for sensitive
information.
(a)
The process of assigning financial value or worth to each information asset.
(a)
An evaluation of the threats to information assets, including a
determination of their potential to endanger the organization.
(a)
The number of successful attacks that are expected to occur within a specified time period.
(a)
The probability that a specific vulnerability within
an organization will be the target of an attack.
(a)
The calculation of the likelihood of an attack
coupled with the attack frequency to determine the expected number
of losses within a specified time range.
(a)
Also known as event loss magnitude,
the combination of an asset’s value and the percentage of it
that might be lost in an attack.
(a)
The risk control strategy that attempts to eliminate or reduce any remaining
uncontrolled risk through the application of additional controls
and safeguards.
(a)
Also known as the avoidance strategy.
(a)
The risk control strategy that attempts to shift risk to other assets, other
processes, or other organizations.
(a)
The risk control strategy that attempts to reduce the impact of the loss caused by a
realized incident, disaster, or attack through effective contingency planning and preparation.
(a)
The risk control strategy that indicates the organization is willing to accept the
current level of risk.
(a)
The risk control strategy that eliminates all risk associated with an information asset by removing it from service.
(a)
An asset valuation approach that uses categorical or non-
numeric values rather than absolute numerical
measures.
(a)
An asset valuation approach that attempts to assign
absolute numerical measures.
(a)
An attempt to improve information security
practices by comparing an organization’s efforts against practices of a
similar organization to produce results it would like to duplicate.
(a)
Security efforts that are considered among the best in the industry.
(a)
Performance measures or metrics
based on observed numerical data.
(a)
The difference between an organization’s observed and desired performance.
(a)
Performance measures or metrics
based on intangible activities.
(a)
is a security risk you should
closely monitor. Use strong passwords and be especially cautious about wireless networks.
(a)
are the network’s command center.
(a)
An assessment of the performance of some
action or process against which future performance is assessed;
the first measurement (benchmark) in benchmarking.
(a)
The process of conducting a baseline.
(a)
An examination of how well a particular solution fits within the organization’s culture
and the extent to which users are expected to accept the
solution. Also known as behavioral feasibility.
(a)
An examination of how well a particular solution fits within the organization’s strategic
planning objectives and goals.
(a)
An examination of how well a particular solution fits within the organization’s political environment
for example, the working relationship within the organization’s
communities of interest or between the organization and its external
environment.
(a)
An examination of how well a particular solution is supportable given the organization’s current
technological infrastructure and resources, which include hardware,
software, networking, and personnel.
(a)
The results of risk management activities can be delivered
via a report on a systematic approach to risk management, a
project-based risk assessment, or a topic-specific risk
assessment.
(a)
is the method by which systems
determine whether and how to admit a user into a trusted area
of the organization that is, information systems, restricted
areas such as computer rooms, and the entire physical location.
(a)
it provide the ability to share resources in a peer-to-peer configuration
that allows users to control and possibly provide access to
information or resources at their disposal. The users can allow
general, unrestricted access, or they can allow specific people
or groups of people to access these resources.
(a)
are managed by a central authority in the organization.
(a)
A form of nondiscretionary access controls in which users are
assigned a matrix of authorizations for particular areas of
access.
(a)
are also a form of lattice-based, nondiscretionary access controls that use
data classification schemes; they give users and data owners
limited control over access to information resources.
(a)
is a mechanism whereby unverified or unauthenticated entities who seek access to a resource provide a label by which they are known to the system.
(a)
it must be mapped to one and only one entity within the security domain.
(a)
is the process of validating an
unauthenticated entity’s purported identity.
(a)
There are three widely used authentication mechanisms, or
authentication factors:
• Something you ____
• Something you ____
• Something you ___
(a)
PIN stands for?
(a)
This factor of authentication relies on
what the unverified user or system knows and can recall for
example, a password, passphrase, or other unique
authentication code,
(a)
is a private word or combination of characters
that only the user should know.
(a)
is a series of characters that is typically
longer than a password and can be used to derive a virtual
password.
(a)
This authentication factor relies on
something an unverified user or system has and can produce
when necessary.
(a)
both the server and token use the same time or a time-based
database to generate a number that must be entered during the
user login phase.
(a)
don’t require that the server and tokens maintain the same time setting. Instead, they use a
challenge/response system, in which the server challenges the
unauthenticated entity during login with a numerical sequence.
(a)
This authentication factor relies on individual
characteristics, such as fingerprints, palm prints, hand
topography, hand geometry, or retina and iris scans,
or something an unverified user can produce on
demand, such as voice patterns, signatures, or
keyboard kinetic measurements.
(a)
is the matching of an authenticated
entity to a list of information assets and corresponding access
levels. This list is usually an ACL or access control matrix.
(a)
also known as auditability,
ensures that all actions on a system whether
authorized or unauthorized can be attributed to an
authenticated identity.
(a)
relies on recognition, the same thing you rely on to identify
friends, family, and other people you know.
(a)
is an international
set of criteria for evaluating computer systems, is very
similar to TCSEC.
(a)
are compared to detailed security function specifications, resulting in an
assessment of systems functionality and comprehensive
penetration testing.
(a)
is an international standard
(ISO/IEC 15408) for computer security certification.
(a)
is a “state machine reference model”- in other words, a model of an
automated system that is able to manipulate its state or status
over time.
(a)
is similar to BLP. It is based on the premise that higher levels of integrity are more worthy
of trust than lower ones. The intent is to provide access
controls to ensure that objects or subjects cannot have less
integrity as a result of read/write operations.
(a)
which is built upon principles of change control rather than integrity
levels, was designed for the commercial environment.
(a)
This model has three parts: a set of objects, a set of subjects, and a set of
rights.
(a)
is the set of constraints that control
how subjects may access objects.
(a)
governs how subjects may manipulate the passive objects.
(a)
This model describes eight primitive protection rights,
which subjects can execute to have an effect on other subjects
or objects.
(a)
model defines a method to allow changes to access rights and the addition and removal of
subjects and objects, a process that the Bell-LaPadula model does not allow.
(a)
commonly known as a Chinese Wall, is designed to prevent a conflict of interest between two
parties. Imagine that a law firm represents two people who are
involved in a car accident. One sues the other, and the firm has to represent both.
(a)
examines the header information of data packets that come into a
network.
(a)
requires that the filtering rules be developed and installed with the firewall
(a)
can react to an emergent event and update or create rules to deal with that event.
(a)
also called stateful inspection firewalls, keep track of each network connection between internal and
external systems using a state table.
(a)
tracks the state and context of each packet
in the conversation by recording which station sent what packet and when.
(a)
occurs when an attacker attempts to gain
entry into an organization’s information systems or disrupt
their normal operations.
(a)
became commercially available in the
late 1990s. It works like a burglar alarm in that it detects a
violation and activates an alarm.
(a)
A process of grouping almost identical alarms that occur nearly at the
same time into a single higher-level alarm. This consolidation
reduces the number of alarms, which reduces administrative
overhead and identifies a relationship among multiple alarms.
(a)
The process of classifying IDPS alerts so they can be more effectively managed. An IDPS
administrator can set up alarm filtering by running the system for a while to track the types of false positives it generates and then adjusting the alarm classifications.
(a)
An indication or notification that a
system has just been attacked or is under attack. IDPS alerts
and alarms take the form of audible signals, e-mail messages,
pager notifications, or pop-up windows.
(a)
The measure of an IDPS’s ability to
correctly detect and identify certain types of attacks.
(a)
The process by which attackers change the format
and/or timing of their activities to avoid being detected by an
IDPS.
(a)
An event that triggers an
alarm when no actual attack is in progress.
(a)
The failure of an IDPS to react to an
actual attack event. This is the most grievous IDPS failure,
given that its purpose is to detect and respond to attacks.
(a)
An alert or alarm that occurs in the
absence of an actual attack.
(a)
Alarm events that are accurate and noteworthy but do not
pose significant threats to information security.
(a)
The rules and configuration guidelines governing
the implementation and operation of IDPSs within the organization.
(a)
An IDPS’s ability to dynamically
modify its configuration in response to environmental activity.
(a)
An event that triggers an alarm
and causes an IDPS to react as if a real attack is in progress.
The event may be an actual attack, in which an attacker is
attempting a system compromise, or it may be a drill, in which
security personnel are using hacker tools to test a network segment.
(a)
The process of adjusting an IDPS to maximize its
efficiency in detecting true positives while minimizing false
positives and false negatives.
(a)
are unable to respond to a rapidly
changing threat environment.
(a)
are unknown or undisclosed vulnerabilities that can’t be predicted
or prepared for.
(a)
it serves as a deterrent by increasing the fear of
detection among would-be attackers.
(a)
consists of a specialized hardware appliance and/or software designed to
monitor network traffic.
(a)
- resides on a particular computer or server, known as the host, and monitors activity
only on that system.
- also known as system integrity verifiers because they benchmark and monitor the status of key system files and detect when an intruder creates, modifies, or deletes monitored files.
(a)
An IDPS that uses signature-based detection (sometimes called knowledge-based
detection or misuse detection) examines network traffic in
search of patterns that match known signatures that is,
preconfigured, predetermined attack patterns.
(a)
or called as behavior-based detection collects statistical summaries by observing
traffic that is known to be normal.
(a)
it uses the opposite of a signature approach. Instead of comparing known
attack patterns against observed traffic or data, the system compares
known normal or benign protocol profiles against observed traffic.
(a)
the system reviews the log files generated by servers,
network devices, and even other IDPSs, looking for patterns and
signatures that may indicate an attack or intrusion is in process or
has already occurred. This attack detection is enhanced by the fact
that the LFM can look at multiple log files from different systems.
(a)
protect an IDPS from being circumvented or
defeated by an attacker.
(a)
comes from the Greek words
kryptos, meaning “hidden,” and graphein, meaning “to
write,” involves making and using codes to secure messages.
(a)
involves cracking or breaking
encrypted messages back into their unencrypted origins.
(a)
The mathematical formula or method
used to convert an unencrypted message into an encrypted
message.
(a)
An encryption method that
involves converting plaintext to cipher text one bit at a time.
(a)
An encryption method that involves
dividing the plaintext into blocks or sets of bits and then
converting the plaintext to cipher text one block at a time.
(a)
the transformation of the
individual components (characters, bytes, or bits) of an
unencrypted message into encrypted components or vice versa
(see decipher and encipher).
(a)
The unintelligible
encrypted or encoded message resulting from an encryption.
(a)
The process of converting components (words or
phrases) of an unencrypted message into encrypted
components.
(a)
The process of converting an encoded or
enciphered message (ciphertext) back to its original readable form
(plaintext). Also referred to as deciphering.
(a)
The process of converting an original message
(plaintext) into a form that cannot be used by unauthorized
individuals (ciphertext). Also referred to as enciphering.
(a)
The information used in
conjunction with the algorithm to create the ciphertext from the
plaintext; it can be a series of bits used in a mathematical algorithm
or the knowledge of how to manipulate the plaintext.
(a)
The entire range of values that can be used to
construct an individual key.
(a)
A series of encryptions and decryptions
between a number of systems, wherein each system in a network
decrypts the message sent to it and then re-encrypts the message
using different keys and sends it to the next neighbor.
(a)
The original unencrypted
message that is encrypted and is the result of successful decryption.
(a)
The process of hiding messages;
(a)
The amount of effort (usually
expressed in units of time) required to perform
cryptanalysis on an encoded message.
(a)
exchanges one value for
another for example, it might exchange a letter in the
alphabet with the letter three values to the right, or it might
substitute one bit for another bit four places to its left.
(a)
More advanced substitution ciphers use two or more alphabets, and are
referred to as
(a)
