Font size
WorksheetsTest Your Skills — Multiple Choice Questions
Total questions: 139
Worksheet time: 1hrs 10mins
You are trying to explain security to a nontechnical manager. She has taken a rather extreme view of computer security. Which of the following is one of the extreme viewpoints about computer security discussed in this chapter?
The federal government will handle security.
Microsoft will handle security.
There are no imminent dangers to your system.
There is no danger if you use Linux.
You have just taken over as network security administrator for a small community college. You want to take steps to secure your network. Before you can formulate a defense for a network, what do you need?
Appropriate security certifications
A clear picture of the dangers to be defended against
To finish this textbook
The help of an outside consultant
Mary is teaching an introductory cybersecurity course to freshmen. She is explaining to them the major threats. Which of the following is not one of the three major classes of threats?
Attempts to intrude on the system
Online auction fraud
Denial of service attacks
A computer virus
Being able to define attack terms is an important skill for a cybersecurity professional. What is a computer virus?
Any program that is downloaded to your system without your permission
Any program that self-replicates
Any program that causes harm to your system
Any program that can change your Windows Registry
Being able to define attack terms is an important skill for a cybersecurity professional. What is spyware?
Any software that monitors your system
Only software that logs keystrokes
Any software used to gather intelligence
Only software that monitors what websites you visit
What is a penetration tester?
A person who hacks a system without being caught
A person who hacks a system by faking a legitimate password
A person who hacks a system to test its vulnerabilities
A person who is an amateur hacker
Elizabeth is explaining various hacking terms to a class. She is in the process of discussing the history of phone system hacking. What is the term for hacking a phone system?
Telco-hacking
Hacking
Cracking
Phreaking
What is malware?
Software that has some malicious purpose
Software that is not functioning properly
Software that damages your system
Software that is not properly configured for your system
What is war-driving?
Driving and seeking a computer job
Driving while using a wireless connection for hacking
Driving looking for wireless networks to hack
Driving and seeking rival hackers
What is the name for the hacking technique that involves using persuasion and deception to get a person to provide information to help compromise security?
Social engineering
Conning
Human intel
Soft hacking
There are many threats on the Internet. Which one is currently the most common may change over time, but certain threats have always been more common than others. Which of the following is the most common threat on the Internet?
Auction fraud
Phreaking
Computer viruses
Illegal software
What are the three approaches to security?
Perimeter, layered, hybrid
High security, medium security, low security
Internal, external, and hybrid
Perimeter, complete, none
Defining your security strategy is an important step in securing a network. You are trying to classify devices based on the approach they take to security. An intrusion detection system is an example of which of the following?
Proactive security
Perimeter security
Hybrid security
Good security practices
Which of the following is the most basic security activity?
Authentication
Firewalls
Password protection
Auditing
The most desirable approach to security is one that is which of the following?
Perimeter and dynamic
Layered and dynamic
Perimeter and static
Layered and static
As of 2022, which of the following is the fastest-growing target for cyber attacks?
IoT
Servers
Laptops
USB devices
Which of the following types of privacy law affects computer security?
Any state privacy law
Any privacy law applicable to your organization
Any privacy law
Any federal privacy law
The first computer incident-response team is affiliated with what university?
Massachusetts Institute of Technology
Carnegie Mellon University
Harvard University
California Technical University
Which of the following is the best definition of the term sensitive information?
Any information that has an impact on national security
Any information that is worth more than $1,000
Any information that, if accessed by unauthorized personnel, could damage your organization in any way
Any information that is protected by privacy laws
Which of the following is the best description of doxing?
A DoS malware attack
Framing someone for a crime
Putting personal information out in the public domain
Stealing personal information
Malek is purchasing cable to use in setting up small office networks. He wants to stock up on commonly used cable. What type of cable do most networks use?
Net cable
STP
Phone cable
UTP
You are assigned to attach connectors to segments of cable. What type of connector is used with network cables?
RJ-11
RJ-85
RJ-12
RJ-45
What type of cable is used in most networks?
Unshielded twisted-pair
Shielded twisted-pair
Unshielded untwisted-pair
Shielded untwisted-pair
John is trying to simply connect three computers in a small network. He does not need any sort of routing capability and is not concerned about network traffic. What is the simplest device for connecting computers?
NIC
Interface
Hub
Router
Sharice is trying to teach a new technician basic networking terms. What should she tell this new technician NIC stands for?
Network interface card
Network interaction card
Network interface connector
Network interaction connector
Which of the following is a device used to connect two or more networks?
Switch
Router
Hub
NIC
Juan has just installed a new T1 line in a medical office. The front desk receptionist has asked what speed they can expect. A T1 line sends data at what speed?
100Mbps
1.54Mbps
155Mbps
56.6Kbps
Which of the following best describes polycloud?
Using a private and public cloud
Using cloud and local resources
Using more than one cloud provider for resilience and redundancy
Using more than one cloud provider for the services offered
What protocol translates web addresses into IP addresses?
DNS
TFTP
DHCP
SMTP
What protocol is used to send email, and on what port does it work?
SMTP, port 110
POP3, port 25
SMTP, port 25
POP3, port 110
Gunther is setting up encrypted remote communications so that the server administrators can remotely access servers. What protocol is used for remotely logging on to a computer in a secure manner?
SSH
HTTP
Telnet
SMTP
Mohammed needs to open a firewall port so that web traffic can be passed through the firewall. What protocol is used for web pages, and on which port does it work?
HTTP, port 21
HTTP, port 80
DHCP, port 80
DHCP, port 21
What is the name for the point where the backbones of the Internet connect?
Connectors
Routers
Network access points
Switches
You are examining a list of IP addresses. Some are internal, some are external, and some are not valid. Which of the following is not a valid IP address?
127.0.0.1
295.253.254.01
131.156.5.2
245.200.11.1
What class of address is the IP address 193.44.34.122?
A
B
C
D
The IP address 127.0.0.1 always refers to your what?
Nearest router
ISP
Self
Nearest NAP
Internet addresses of the form www.chuckeasttom.com are called what?
User-friendly web addresses
Uniform resource locators
User-accessible web addresses
Uniform address identifiers
Which U.S. government agency created the distributed network that formed the basis for the Internet?
Advanced Research Projects Agency
Central Intelligence Agency
NASA
Department of Energy
Which of the following was one of the three universities involved in the original distributed network set up by a government agency?
UC Berkeley
Harvard
MIT
Princeton
You are explaining the history of networking to a group of first-year students. What did Vint Cerf invent?
The World Wide Web
TCP
The first computer virus
You are explaining the history of networking to a group of first-year students. What did Tim Berners-Lee invent?
The World Wide Web
TCP
The first computer virus
John is working with command-line utilities to gather diagnostic information about a computer that cannot connect to the network. Which utility provides information about a machine’s network configuration?
Ping
IPConfig
Tracert
MyConfig
Sheryl is explaining the OSI model to new technicians at her company. She is trying to explain what protocols operate at the various layers of the OSI model. At what layer of the OSI model does TCP operate?
Transport
Application
Network
Data link
Which layer of the OSI model is divided into two sublayers?
Data link
Network
Presentation
Session
Which of the following is a unique hexadecimal number that identifies your network card?
NIC address
MAC address
NIC ID
MAC ID
Candice is discussing Internet fraud with a colleague. She is trying to explain the most common types of fraud. What is the term for the most common type of Internet investment fraud?
The Nigerian fraud
The Manhattan fraud
The pump and dump
The bait and switch
You have become quite active in online investing. You want to get some advice but are concerned about the veracity of the advice you receive. What is the most likely problem with unsolicited investment advice?
You might not earn as much as claimed.
The advice might not be truly unbiased.
The advice might not be from a legitimate firm.
You might lose money.
Juan is a security officer for an investment firm. He is explaining various scams to the brokers. What is the term for artificially inflating a stock in order to sell it at a higher value?
Bait and switch
The Nigerian fraud
Pump and dump
The Wall Street fraud
What is the top rule for avoiding Internet fraud?
If it seems too good to be true, it probably is.
Never use your bank account numbers.
Only work with people who have verifiable email addresses.
Don’t invest in foreign deals.
Which of the following is not one of the Security and Exchange Commission’s tips for avoiding investment fraud?
Don’t invest online.
Consider the source of an offer.
Always be skeptical.
Always research an investment.
Aliya is active on online auctions but wants to avoid auction fraud. What are the four categories of auction fraud?
Failure to send, failure to disclose, sending to wrong address, failure to deliver
Failure to send, failure to disclose, sending something of lesser value, failure to deliver
Failure to disclose, sending something to wrong address, failure to send, failure to deliver
Failure to disclose, sending something of lesser value, failure to send, sending something of greater value
What is the term for a seller bidding on her own item to drive up the price?
Bid siphoning
Bid shielding
Shill bidding
Ghost bidding
What is the term for submitting a fake but very high bid to deter other bidders?
Bid siphoning
Bid shielding
Shill bidding
Ghost bidding
What is typically the goal of identity theft?
To make illicit purchases
To discredit the victim
To avoid criminal prosecution
To invade privacy
According to the U.S. Department of Justice, identity theft is generally motivated by what?
Malicious intent
Personal hostility toward the victim
Economic gain
Thrill seeking
Clarence is a police detective with a small-town police department. He is trying to consider how seriously to take reports of cyber stalking. Why is cyber stalking a serious crime?
It is frightening to the victim.
It can be a prelude to violent crime.
It is using interstate communication.
It can be a prelude to identity theft.
What is cyber stalking?
Any use of the Internet to send or post threats
Any use of electronic communications to stalk a person
The use of email to send threats
The use of email to stalk a person
What do law enforcement officials usually require of a victim in order to pursue harassment allegations?
A verifiable threat of death or serious injury
A credible threat of death or serious injury
A verifiable threat of harm
A credible threat of harm
If you are posting anonymously in a chat room and another anonymous poster threatens you with assault or even death, is this person’s post harassment?
Yes; any threat of violence is harassment.
Probably not because both parties are anonymous, so the threat is not credible.
Yes; chat room threats are no different from threats in person.
Probably not because making a chat room threat is not the same as making a threat in person.
What must exist for cyber stalking to be illegal in a state or territory?
Specific laws against cyber stalking in that state or territory
Specific laws against cyber stalking in that nation
Nothing; existing stalking laws can apply
Nothing; existing international cyber stalking laws apply
What is the first step in protecting yourself against identity theft?
Never provide personal data about yourself unless absolutely necessary.
Routinely check your records for signs of identity theft.
Never use your real name on the Internet.
Routinely check for spyware on your computer.
What can you do on your local computer to protect your privacy?
Install a virus scanner.
Install a firewall.
Set your browser’s security settings.
Set your computer’s filter settings.
What is a cookie?
A piece of data that web servers gather about you
A small file that contains data and is stored on your computer
A piece of data that your web browser gathers about you
A small file made that contains data and then is stored on the web server
Which of the following is not an efficient method of protecting yourself from auction fraud?
Only use auctions for inexpensive items.
Only use reputable auction sites.
Only work with well-rated sellers.
Only bid on items that seem realistic.
What is the top rule for chat room safety?
Make certain you have antivirus software installed.
Never use your real name or any real personally identifying characteristics.
Only use chat rooms that encrypt transmissions.
Use chat rooms that are sponsored by well-known websites or companies.
Why is it useful to have a separate credit card dedicated to online purchases?
If the credit card number is used illegally, you will limit your financial liability.
You can keep better track of your auction activities.
If you are defrauded, you can possibly get the credit card company to handle the problem.
You can easily cancel that single card if you need to do so.
What percentage of cyber stalking cases escalate to real-world violence?
Fewer than 1%
About 25%
90% or more
About 19%
If you are a victim of cyber stalking, what should you do to assist the police?
Nothing; it is their job, and you should stay out of it.
Attempt to lure the stalker into a public place.
Keep electronic and hard copies of all harassing communications.
Try to provoke the stalker into revealing personal information about himself.
What is the top way to protect yourself from cyber stalking?
Do not use your real identity online.
Always use a firewall.
Always use a virus scanner.
Do not give out email addresses.
When considering the various attacks that can be executed on your system, it is important to understand which attacks are most common. Of the following, which is one of the most common and simplest attacks on a system?
Denial of service attack
Buffer overflow
Session hacking
Password cracking
All DoS attacks are predicated on overwhelming a system’s workload capacity. Therefore, measuring the workload of a system is critical. Which of the following is not a valid way to define a computer’s workload?
Number of simultaneous users
Storage capacity
Maximum voltage
Speed of network connection
What do you call a DoS attack launched from several machines simultaneously?
Wide-area attack
Smurf attack
SYN flood
DDoS attack
It is important to understand the different types of DoS attacks and the symptoms of those attacks. Leaving a connection half open is a symptom of which type of attack?
Smurf attack
Partial attack
SYN flood attack
DDoS attack
While there are a wide range of different ways to execute a DoS attack, they all are predicated on the same idea. What is the basic concept behind a DoS attack?
Computers don’t handle TCP packets well.
Computers can handle only a finite load.
Computers cannot handle large volumes of TCP traffic.
Computers cannot handle large loads.
What is the most significant weakness in a DoS attack from the attacker’s viewpoint?
The attack is often unsuccessful.
The attack is difficult to execute.
The attack is easy to stop.
The attack must be sustained.
What is the most common class of DoS attacks?
Distributed denial of service
Smurf attacks
SYN floods
Ping of death
A range of countermeasures can help defend against DoS attacks. What are three methods for protecting against SYN flood attacks?
SYN cookies, RST cookies, and stack tweaking
SYN cookies, DoS cookies, and stack tweaking
DoS cookies, RST cookies, and stack deletion
DoS cookies, SYN cookies, and stack deletion
Juan is explaining various DoS attacks to security operators at his company. Which attack mentioned in this chapter causes a network to perform a DoS attack on one of its own servers?
SYN flood
Ping of death
Smurf attack
DDoS
What is the name for a defense that depends on a hash being sent back to the requesting client?
Stack tweaking
RST cookies
SYN cookies
Hash tweaking
What type of defense depends on sending the client an incorrect SYN/ACK?
Stack tweaking
RST cookies
SYN cookies
Hash tweaking
You are attempting to explain various DoS attacks to a new security technician. You want to make sure she can differentiate between these different attacks and notice the signs of a specific attack. What type of defense depends on changing the server so that unfinished handshaking times out sooner?
Stack tweaking
RST cookies
SYN cookies
Hash tweaking
What type of attack is dependent on sending packets that are too large for the server to handle?
Ping of death
Smurf attack
Slammer attack
DDoS
You want to make sure your team can identify the various DoS attack vectors. What type of attack uses the victim’s own network routers to perform a DoS attack on the target?
Ping of death
Smurf attack
Slammer attack
DDoS
If you are a website developer and concerned about DoS attacks, what is one mitigation technique you can implement in the website itself?
Bandwidth throttling
Web application firewall
Encryption with HTTPS
CAPTCHA
How can securing internal routers help protect against DoS attacks?
Attacks cannot occur if the internal router is secured.
Because attacks originate outside the network, securing internal routers cannot help protect against DoS attacks.
Securing the router will only stop router-based DoS attacks.
It will prevent an attack from propagating across network segments.
What can your do to your internal network routers to help defend against DoS attacks?
Disallow all traffic that is not encrypted
Disallow all traffic that comes from outside the network
Disallow all traffic that comes from inside the network
Disallow all traffic that comes from untrusted sources
Dorothy is a network administrator. Her system has been experiencing an attack that is using bots to send fake requests to the cloud resources her company uses. This is causing disruption of the availability of these resources. How is this attack best described?
PDoS
DDoS
EDoS
DoS
No attack mitigation strategy is perfect, and you need to allow at least some traffic into and out of your network, or else your network is of no use. What can you do with your firewall to defend against at least some DoS attacks?
Block all incoming traffic
Block all incoming TCP packets
Block all incoming traffic on port 80
Block all incoming ICMP packets
You are trying to identify all potential DoS attack vectors. In doing so, you hope to provide mitigation for each of these attack vectors. Why will protecting against Trojan horse attacks reduce DoS attacks?
Many denial of service attacks are conducted by using a Trojan horse to get an unsuspecting machine to execute the DoS attack.
If you can stop a Trojan horse attack, you will also stop DoS attacks.
A Trojan horse will often open ports and thus allow DoS attacks.
A Trojan horse has much the same effect as a DoS attack.
John is a network security administrator for a midsized college. He is trying to explain to a new hire what a virus is. Which of the following is the best definition of virus?
A program that causes harm on your computer
A program used in a DoS attack
A program that slows down networks
A program that self-replicates
Isabelle is responsible for cybersecurity at her company. She is concerned that a virus would cause damage to the IT systems. What is the most common damage caused by virus attacks?
Slowing down networks by the virus traffic
Deleting files
Changing the Windows Registry
Corrupting the operating system
You are trying to form policies for your organization to mitigate the threat of viruses. You want to ensure that you address the most common way for a virus to spread. What is the most common way for a virus to spread?
By copying to shared folders
By email attachment
By FTP
By download from a website
Which of the following is the primary reason that Microsoft Outlook is so often a target for virus attacks?
Many hackers dislike Microsoft.
Outlook copies virus files faster.
It is easy to write programs that access Outlook’s inner mechanisms.
Outlook is more commonly used than other email systems.
Juan is a network administrator for a small graphic design company. In April 2021 his company was hit by a virus that specifically targeted macOS and was a first-stage downloader for other malware components. What attack was this?
Schlayer
Pegasus
Mirai
Sasser
What factor about the WannaCry virus is especially interesting to security practitioners?
It could have been prevented with good patch management.
It deleted critical system files.
It was difficult to protect against.
It was very sophisticated and likely an example of nation-state weaponized malware.
What is the name of the very first virus ever detected?
Creeper
Wabbit
Mimail
Unnamed
Elizabeth has found malware on a system in her company. The malware blocks about 600 Windows processes, and demands ransom. What has Elizabeth found?
Thanatos
Clop
Kedi RAT
Schlayer
Mohaned has found malware on his network. This malware encrypts files demanding ransom and also blocks approximately 600 Windows processes. What malware has Mohaned found?
Schlayer
Thanatos
Cl0p
Pegasus
Which of the following is a method that any person can use to protect against virus attacks?
Set up a firewall.
Use encrypted transmissions.
Use secure email software.
Never open unknown email attachments.
You are trying to develop methods to mitigate the threat of viruses in your company. Which of the following is the safest way to send and receive attachments?
Use a code word indicating that an attachment is legitimate.
Send only spreadsheet attachments.
Use encryption.
Use virus scanners before opening attachments.
Shelly is trying to teach new employees how to handle emailed security alerts. Which of the following is true regarding emailed security alerts?
You must follow them.
Most companies do not send alerts via email.
You can trust attachments on security alerts.
Most companies send alerts via email.
Which of the following is something a Trojan horse might do?
Open a backdoor for malicious software.
Change your memory configuration.
Change ports on your computer.
Alter your IP address.
Jared is explaining various attacks to students in an introduction to cybersecurity class. He wants to make certain they fully understand the different attacks. What does a buffer-overflow attack do?
It overflows a port with too many packets.
It puts more email in an email system than it can hold.
It overflows the system.
It puts more data in a buffer than it can hold.
What virus exploited buffer overflows?
Sobig virus
Mimail virus
Sasser virus
Schlayer virus
What can you do with a firewall to help protect against virus attacks?
There is nothing you can do on a firewall to stop virus attacks.
Shut down all unneeded ports.
Close all incoming ports.
None of the above are correct.
Malek is explaining various malware types to new technical support personnel. He is explaining to them the various types of malware so that they can recognized them. What type of malware is a key logger?
Virus
Buffer overflow
Trojan horse
Spyware
Which of the following is a step that all computer users should take to protect against virus attacks?
Purchase and configure a firewall.
Shut down all incoming ports.
Use nonstandard email clients.
Install and use antivirus software.
What is the primary way a virus scanner works?
By comparing files against a list of known virus profiles
By blocking files that copy themselves
By blocking all unknown files
By looking at files for virus-like behavior
In addition to the primary way a virus scanner works, what other way can a virus scanner work?
By comparing files against a list of known virus profiles
By blocking files that copy themselves
By blocking all unknown files
By looking at files for virus-like behavior
Elizabeth is describing web-based attacks to a group of students in a computer security course. What does an SQL injection attack require?
Having database admin privileges
Creating an SQL statement that is always true
Creating an SQL statement that will force access
Understanding web programming
Juan is using a rainbow table to circumvent passwords on a Windows computer. What is the best description of a rainbow table?
A table of precomputed hashes
A brute-force password attack
A dictionary attack on passwords
A multi pronged attempt to crack passwords
You are responsible for security on an e-commerce system. You want to mitigate as many attacks as you can. How can you prevent cross-site scripting?
Filter user input.
Use an IDS.
Use a firewall.
It cannot be prevented.
What is an advantage of using Shodan.io?
It is free.
It can check for a wide range of vulnerabilities.
It is designed for Windows systems.
It includes an IDS.
Perez is exploring different password cracking tools. A friend has told him about ophcrack. ophcrack depends on the attacker doing what?
Getting physical access to the machine
Getting domain admin privileges
Using social engineering
Using a scanning tool
If you wish to view items that have been removed from a website, what is the best way to do so?
Use Nessus.
Use Nmap.
Use www.netcraft.com.
Use www.archive.org.
Malek needs a port scanner so he can scan open ports on his own network. Which of the following is a popular port scanner?
Nessus
ophcrack
MBSA
Nmap
Jane wants to mitigate as many attacks as she can. A colleague suggested that she block ICMP packets. Blocking incoming ICMP packets will prevent what type of scan?
SYN
Ping
FIN
Stealth
It is important that you understand cybersecurity terminology, including terms for different actors in cybersecurity. What is the correct term for a person who uses hacking techniques for illegal activities?
A hacker
A gray hat hacker
A phreaker
A cracker
What is the term for a person who hacks into phone systems?
A hacker
A gray hat hacker
A phreaker
A cracker
Penelope is teaching an introductory cybersecurity course and is trying to explain the terminology to students. What is the term for a person who uses tools to hack without understanding the underlying technology?
A script kiddy
A gray hat hacker
A novice
A white hat hacker
What is the name for the process of trying to list all the servers on a network?
Port scanning
Enumeration
Vulnerability scanning
Scouting
Terrance is performing a scan. What response will a Windows machine give to a FIN scan?
ACK
None
SYN
RST
Jaron is trying to do a port scan of his own company. He wants to test to see if the company’s security systems will be able to detect his scan. Which of the following is considered the stealthiest port scan?
SYN
Connect
Ping
Nmap
What is the stealthiest way to find out what type of server a website is running?
Use Nmap.
Use Cain and Abel.
Use www.netcraft.com.
Use www.archive.org.
Terrance is trying to explain industrial espionage to a group of new security techs. What is the ultimate goal of espionage?
To subvert a rival government
To obtain information that has value
To subvert a rival business
To obtain information not otherwise available
In order to truly understand industrial espionage, you need to understand the mindset of the spy. What is the best outcome for a spy attempting an espionage activity?
To obtain information without the target even realizing he did so
To obtain information with or without the target realizing he did so
To obtain information and discredit the target
To obtain information and cause harm to the target
What is the usual motivating factor for corporate/industrial espionage?
Ideological
Political
Economic
Revenge
Which of the following types of information would be a likely target for industrial espionage?
A new algorithm that the company’s IT department has generated
A new marketing plan that the company has formulated
A list of all the company’s customers
All of these answers are correct
Accurate statistics on corporate espionage are difficult to obtain. One reason is that the victims don’t always report the crime, as they often don’t want the incidents to become public. Which of the following is a likely reason that an organization might be reluctant to admit it has been a victim of corporate espionage?
It would embarrass the IT department.
It would embarrass the CEO.
It might cause stock value to decline.
It might lead to involvement in a criminal prosecution.
What is the difference between corporate and industrial espionage?
None; they are interchangeable terms.
Industrial espionage only refers to heavy industry, such as factories.
Corporate espionage only refers to executive activities.
Corporate espionage only refers to publicly traded companies.
Information is a valuable asset. It can be useful to calculate that value in order to determine how much effort should be put into protecting it. What formula can you use to calculate the value of information?
Resources needed to produce the information plus resources gained from the information
Resources needed to produce the information multiplied by resources gained from the information
Time taken to derive the information plus money needed to derive the information
Time taken to derive the information multiplied by money needed to derive the information
If a company purchases a high-end UNIX server to use for its research and development department, what is probably the most valuable part of the system?
The high-end UNIX server
The information on the server
The devices used to protect the server
The room to store the server
Information is an asset to your company if it
cost any sum of money to produce.
cost a significant sum of money to produce.
might have economic value.
might cost significant money to reproduce.
What is the greatest security risk to any company?
Disgruntled employees
Hackers
Industrial spies
Faulty network security
Which of the following is the best definition for spyware?
Software that assists in corporate espionage
Software that monitors activity on a computer
Software that logs computer keystrokes
Software that steals data
What is the highest level of security you can expect to obtain?
A level of security that makes the effort required to get information more costly than the value of the information
A level of security comparable with government security agencies, such as the Central Intelligence Agency
A level of security that has a 92.5% success rate in stopping intrusion
A level of security that has a 98.5% success rate in stopping intrusion
In the context of preventing industrial espionage, why might you wish to limit the number of company CD burners and control access to them in your organization?
An employee could use such media to take sensitive data.
An employee could use such media to copy software from the company.
CDs could be a vehicle for spyware to get on your system.
CDs could be a vehicle for a virus to get on your system.
Why would you want to scan an employee’s computer when he leaves the organization?
To check the workflow prior to his leaving
To check for signs of corporate espionage
To check for illegal software
To check for pornography
What is the reason for encrypting hard drives on laptop computers?
To prevent a hacker from reading the data while you are online
To ensure that data transmissions are secure
To ensure that another user on that machine will not see sensitive data
To prevent a thief from getting data off of a stolen laptop
