NEW
Font size
WorksheetsMidterm Prep Prt 1
Total questions: 66
Worksheet time: 33mins
There are three general causes of unethical and illegal behavior: _____, Accident, and Intent.
Curiosity
Revenge
Ignorance
None of the other answers are correct
Security _____ are the areas of trust within which users can freely communicate.
layers
perimeters
rectangles
domains
_____ is a professional association that focuses on auditing, control, and security. The membership comprises both technical and managerial professionals.
ISACA
EC-Council
Information Systems Security Association (ISSA)
_____ uses a number of hard drives to store information across multiple drive units.
Legacy backup
Virtualization
Continuous database protection
RAID
The CPMT should include a _____ who is a high-level manager to support, promote, and endorse the findings of the project and could be the COO or (ideally) the CEO/president.
project manager
executive-in-charge
project instigator
champion
_________ of information is the quality or state of being genuine or original.
Authorization
Confidentiality
Authenticity
Spoofing
_________ security addresses the issues necessary to protect the tangible items, objects, or areas of an organization from unauthorized access and misuse.
Object
Physical
Standard
_______ security addresses the issues necessary to protect the tangible items, objects, or areas of an organization from unauthorized access and misuse.
Object
Physical
Standard
Personal
The _____ hijacking attack uses IP spoofing to enable an attacker to impersonate another entity on the network.
FTP
HTTP
TCP
WWW
_____ equals the probability of a successful attack multiplied by the expected loss from a successful attack plus an element of uncertainty.
Risk
Loss frequency
Loss magnitude
Each of the following is a role for the crisis management response team EXCEPT:
Keeping the public informed about the event
Communicating with major customers and other stakeholders
Supporting personnel and their loved ones during the crisis
Informing local emergency services to respond to the crisis
In the TVA worksheet, assets are placed into a matrix with threats and then the exposure of the assets to specific threats is explored by documenting _____
value
vulnerabilities
variables
verifications
Which of the following is an example of a Trojan horse program?
Klez
Happy99.exe
MyDoom
Netsky
People with the primary responsibility for administering the systems that house the information used by the organization perform the role of ____.
End users
Security professionals
Which of these is NOT a unique function of information security management?
hardware
programs
planning
policy
In 2002, Congress passed the Federal Information Security Management Act (FISMA), which mandates that all federal agencies _____
provide security awareness training
develop policies and procedures based on risk assessments
periodic assessment of risk
all of the other answers are correct
The _____ is the high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.
GSP
EISP
ISSP
SysSP
In a _____, assets or threats can be prioritized by identifying criteria with differing levels of importance, assigning a score for each of the criteria, and then summing and ranking those scores.
risk management program
threat assessment
data classification scheme
weighted table analysis
Flaws or weaknesses in an information asset, security procedure, design, or control that can be exploited accidentally or on purpose to breach security are known as _____
threats
exploits
vulnerabilities
events
In 1993, the first _____ conference was held in Las Vegas. Originally, it was established as a gathering for people interested in information security, including authors, lawyers, government employees, and law enforcement officials.
CyberCom
DEFCON
World Security
A threat _____ is an evaluation of the threats to information assets, including a determination of their likelihood of occurrence and potential impact of an attack.
search
review
assessment
investigation
Which of the following is NOT one of the categories recommended for categorizing information assets?
Firmware
Hardware
Procedures
People
A technique used to compromise a system is known as a(n) ___________.
access method
exploit
risk
asset
The _____ risk treatment strategy attempts to eliminate or reduce any remaining uncontrolled risk through the application of additional controls and safeguards.
acceptance
transference
termination
mitigation
A(n) _____ is an authorization issued by an organization for the repair, modification, or update of a piece of equipment.
CTO
IP
HTTP
FCO
The transfer of transaction data in real time to an off-site facility is called ____.
electronic vaulting
remote journaling
off-site storage
database shadowing
Individuals who are assigned the task of managing a particular set of information and coordinating its protection, storage, and use are known as data _________?
owners
users
analysts
processors
The maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources is ____.
maximum tolerable downtime (MTD)
work recovery time (WRT)
recovery point objective (RPO)
recovery time objective (RTO)
An organization aggregates all local backups to a central repository and then backs up that repository to an online vendor with a ____ backup strategy.
differential
RAID
disk-to-disk-to-tape
disk-to-disk-to-cloud
Which of the following acts is also widely known as the Gramm-Leach-Bliley Act?
Communications Act
Computer Security Act
Health Insurance Portability and Accountability Act
Financial Services Modernization Act
______ is a network project that preceded the Internet.
NIST
ARPANET
DES
FIPS
Standards may be published, scrutinized, and ratified by a group, as in formal or ____ standards.
de facto
de jure
de formale
de public
Advance-Fee fraud is an example of a ______ attack.
spam
social engineering
virus
worm
34. ______ are compromised systems that are directed remotely (usually by a transmitted command) by the attacker to participate in an attack.
botnets
firewalls
proxies
honeypots
Which of the following is a term used to describe computers that have been compromised and are controlled remotely by an attacker?
Helpers
Drones
Zombies
Servants
The _____ risk treatment strategy is the choice to do nothing to protect a vulnerability and to accept the outcome of its exploitation.
mitigation
defense
acceptance
transference
Risk _____ is the application of security mechanisms to reduce the risks to an organization’s data and information systems.
identification
avoidance
assessment
treatment
The redirection of legitimate user Web traffic to illegitimate Web sites with the intent to collect personal information is known as ______.
phishing
sniffing
pharming
spoofing
An information system is the entire set of __________, people, procedures, and networks that enable the use of information resources in the organization.
software
hardware
data
All of the above
The goals of information security governance include all but which of the following?
Regulatory compliance by using information security knowledge and infrastructure to support minimum standards of due care
Risk management by executing appropriate measures to manage and mitigate threats to information resources
Strategic alignment of information security with business strategy to support organizational objectives
Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved
The SETA program is a control measure designed to reduce the instances of _____ security breaches by employees.
accidental
intentional
physical
external
A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file is known as a(n) _____
crack file
crib
dictionary
rainbow table
A _____ site provides only rudimentary services and facilities.
warm
commercial
hot
cold
The Digital _____ Copyright Act is the American contribution to an international effort by the World Intellectual Properties Organization (WIPO) to reduce the impact of copyright, trademark, and privacy infringement.
Information
Master
Millennium
Management
According to NIST SP 800-14's security principles, security should _____
support the mission of the organization
require a comprehensive and integrated approach
be cost-effective
All of the above
Microsoft acknowledged that if you type a res:// URL (a Microsoft-devised type of URL) longer than _____ characters in Internet Explorer 4.0, the browser will crash.
128
64
512
256
The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures, is known as ______.
mean time to diagnose (MTTD)
mean time to repair (MTTR)
mean time between failure (MTBF)
mean time to failure (MTTF)
An information security _____ is a specification of a model to be followed during the design, selection, and initial and ongoing implementation of all subsequent security controls, including information security policies, security education, and training.
model
plan
policy
framework
A _____ is an attack in which a coordinated stream of requests is launched against a target from many locations at the same time.
virus
spam
distributed denial-of-service
denial-of-service
A(n) _____ plan is a plan for the organization’s intended efforts over the next several years (long-term).
tactical
strategic
operational
standard
The _____ is a respected professional society that was established in 1947. Today it is “the world’s largest educational and scientific computing society.”
EC-Council
International Information Systems Security Certification Consortium, Inc.
Information Systems Security Association (ISSA)
Association for Computing Machinery
A(n) _____ scheme is a formal access control methodology used to assign a level of confidentiality to an information asset and thus restrict the number of people who can access it.
risk management
security clearance
data recovery
_____ is simply how often you expect a specific type of attack to occur.
ALE
CBA
SLE
ARO
Risk _____ defines the quantity and nature of risk that organizations are willing to accept as they evaluate the trade-offs between perfect security and unlimited accessibility.
appetite
benefit
residual
acceptance
The _____ defines stiffer penalties for prosecution of terrorism-related activities.
Gramm-Leach-Bliley Act
USA PATRIOT Act
Economic Espionage Act
Sarbanes-Oxley Act
Understanding the _____ context means understanding the impact of elements such as the business environment, the legal/regulatory/compliance environment, as well as the threat environment.
internal
external
design
risk evaluation
The stated purpose of ISO/IEC 27002:2013 is to give guidelines for organizational information security standards and information security _____ practices.
management
implementation
certification
accreditation
The Health Insurance Portability and Accountability Act of 1996, also known as the _____ Act, protects the confidentiality and security of health-care data by establishing and enforcing standards and by standardizing electronic data interchange.
Gramm-Leach-Bliley
Privacy
Kennedy-Kessebaum
The point in time before a disruption or system outage to which business process data can be recovered after an outage is ____.
recovery point objective (RPO)
maximum tolerable downtime (MTD)
work recovery time (WRT)
recovery time objective (RTO)
A ____ is an agency that provides physical facilities in the event of a disaster for a fee.
mobile site
service bureau
time-share
cold site
____ law comprises a wide variety of laws pertaining to relationships among individuals and organizations.
Civil
Criminal
Constitutional
Statutory
________ was the first operating system to integrate security as one of its core functions.
DOS
UNIX
ARPANET
MULTICS
____ is the rapid determination of the scope of the breach in the confidentiality, integrity, and availability of information and information assets during or just following an incident.
Disaster assessment
Damage assessment
Incident response
Containment development
As each information asset is identified, categorized, and classified, a(n) ____ value must be assigned to it.
relative
positional
secondary
significant
Digital forensics involves the _____, identification, extraction, documentation, and interpretation of digital media.
preservation
investigation
confiscation
determination
The most common schedule for tape-based backup is a _____ backup, either incremental or differential, with a weekly off-site full backup.
daily on-site
hourly off-site
daily off-site
12-hour on-site
