WorksheetsInformation Security and Cybersecurity Quiz
Total questions: 47
Worksheet time: 31mins
A computer virus consists of segments of code that perform (a) actions.
Intellectual property is defined as “the creation, ownership, and control of ideas as well as the representation of those ideas.” ______
True
False
The ______ hijacking attack uses IP spoofing to enable an attacker to impersonate another entity on the network.
WWW
TCP
FTP
HTTP
When voltage levels lag (experience a momentary increase), the extra voltage can severely damage or destroy equipment. ______
True
False
In the context of information security, ______ is the process of using social skills to convince people to reveal access credentials or other valuable information to the attacker.
Suppose an act of theft performed by a hacker was accompanied by defacement actions to delay discovery. The first act is obviously in the category of “theft” but the second act is another category—in this case it is a “force of nature.”
True
False
Information security’s primary mission is to ensure that systems and their contents retain their confidentiality at any cost.
True
False
The malicious code attack includes the execution of viruses, worms, Trojan horses, and active Web scripts with the intent to destroy or steal information. ______
True
False
Software code known as a(n) cookie can allow an attacker to track a victim's activity on Web sites. ______
True
False
______ occurs when an application running on a Web server inserts commands into a user’s browser session and causes information to be sent to a hostile server.
When information gatherers employ techniques that cross a legal or ethical threshold, they are conducting ______.
industrial espionage
competitive intelligence
opposition research
hostile investigation
Cyberterrorists hack systems to conduct terrorist activities via network or Internet pathways. ______
True
False
Web hosting services are usually arranged with an agreement defining minimum service levels known as a(n) ____.
SSL
SLA
MSL
MIN
A(n) (a) hacks the public telephone network to make free calls or disrupt services.
______ are malware programs that hide their true nature and reveal their designed behavior only when activated.
Viruses
Worms
Spam
Trojan horses
A device (or a software program on a computer) that can monitor data traveling on a network is known as a socket sniffer. ______
True
False
A(n) (a) is an act against an asset that could result in a loss.
______ are compromised systems that are directed remotely (usually by a transmitted command) by the attacker to participate in an attack.
Drones
Helpers
Zombies
Servants
Much human error or failure can be prevented with effective training and ongoing awareness activities.
True
False
Microsoft acknowledged that if you type a res:// URL (a Microsoft-devised type of URL) longer than ______ characters in Internet Explorer 4.0, the browser will crash.
64
128
256
512
One form of e-mail attack that is also a DoS attack is called a mail spoof, in which an attacker overwhelms the receiver with excessive quantities of e-mail. ______
True
False
Which of the following is an example of a Trojan horse program?
Netsky
MyDoom
Klez
Happy99.exe
A momentary low voltage is called a(n) (a) .
A number of technical mechanisms—digital watermarks and embedded code, copyright codes, and even the intentional placement of bad sectors on software media—have been used to deter or prevent the theft of software intellectual property.
True
False
Hackers are “persons who access systems and information without authorization and often illegally.” ______
True
False
What is the purpose of the SETA program?
Within security perimeters the organization can establish security redundancies, each with differing levels of security, between which traffic must be screened. _____
True
False
The global information security community has universally agreed with the justification for the code of practices as identified in the ISO/IEC 17799.
True
False
(a) controls are security processes that are designed by strategic planners and implemented by the security administration of the organization.
The security framework is a more detailed version of the security blueprint.
True
False
The ISSP is a plan which sets out the requirements that must be met by the information security blueprint or framework.
True
False
In early 2014, in response to Executive Order 13636, NIST published the Cybersecurity Framework, which intends to allow organizations to _____.
identify and prioritize opportunities for improvement within the context of a continuous and repeatable process
assess progress toward a recommended target state
communicate among local, state, and national agencies about cybersecurity risk
None of these
To remain viable, security policies must have a responsible manager, a schedule of reviews, a method for making recommendations for reviews, and a policy issuance and revision date. _____
True
False
Systems-specific security policies are organizational policies that provide detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies. _____
True
False
A policy should state that if employees violate a company policy or any law using company technologies, the company will protect them, and the company will provide for the employee's legal defense.
True
False
To remain viable, security policies must have a responsible individual, a schedule of reviews, a method for making recommendations for reviews, and policy issuance and planned revision dates.
True
False
_____often function as standards or procedures to be used when configuring or maintaining systems.
ESSPs
EISPs
ISSPs
SysSPs
The goals of information security governance include all but which of the following?
Regulatory compliance by using information security knowledge and infrastructure to support minimum standards of due care
Strategic alignment of information security with business strategy to support organizational objectives
Risk management by executing appropriate measures to manage and mitigate threats to information resources
Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved
(a) controls are information security safeguards focusing on lower-level planning that deals with the functionality of the organization’s security. These safeguards include disaster recovery and incident response planning.
The process of (a) planning is that of defining and specifying the long-term direction to be taken by an organization.
NIST 800-14's Principles for Securing Information Technology Systems can be used to make sure the needed key elements of a successful effort are factored into the design of an information security program and to produce a blueprint for an effective security architecture.
True
False
The SETA program is a control measure designed to reduce the instances of _____ security breaches by employees.
intentional
external
accidental
physical
_____ controls cover security processes that are designed by strategic planners and implemented by the security administration of the organization.
Managerial
Technical
Operational
Informational
A security (a) defines the boundary between the outer limit of an organization’s security and the beginning of the outside world.
The stated purpose of ISO/IEC 27002 is to offer guidelines and voluntary directions for information security management. _____
True
False
Technical controls are the tactical and technical implementations of security in the organization. _____
True
False
The key components of the security perimeter include firewalls, DMZs (demilitarized zones), Web servers, and IDPSs. _____
True
False
