wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security Worksheet Questions (Grade 13)

Total questions: 153

Worksheet time: 1hrs 17mins

Name
Class
Date
1.

are encrypted message components that can be mathematically proven to be authentic.

a)

Digital signatures

b)

MACs

c)

Message digests

d)

Message certificates

2.

The CISA credential is promoted by ISACA as the certification that is appropriate for all but which type of professionals?

a)

accounting

b)

auditing

c)

security

d)

networking

3.

A(n) reviews the log files generated by servers, network devices, and even other IDPSs looking for patterns and signatures that may indicate an attack or intrusion is in process or has already occurred.

a)

LFM

b)

HIDPS

c)

AppIDPS

d)

stat IDPS

4.

Some cases of are simple, such as requiring employees to begin using a new password on an announced date.

a)

phased implementation

b)

wrap-up

c)

pilot implementation

d)

direct changeover

5.

A step commonly used for Internet vulnerability assessment includes , which occurs when the penetration test engine is unleashed at the scheduled time using the planned target list and test selection.

a)

subrogation

b)

delegation

c)

targeting

d)

scanning

6.

The proxy server is often placed in an unsecured area of the network or is placed in the zone.

a)

demilitarized

b)

cold

c)

hot

d)

fully trusted

7.

benchmark and monitor the status of key system files and detect when an intruder creates, modifies, or deletes monitored files.

a)

HIDPSs

b)

NIDPSs

c)

SIDPSs

d)

AppIDPSs

8.

Which of the following is not a major processing mode category for firewalls?

a)

Packet-filtering

b)

Router Passthrough

c)

Application Layer Proxy

d)

Media Access Control Layer

9.

In TCP/IP networking, port is not used.

a)

1

b)

13

c)

0

d)

1023

10.

Known as the ping service, is a common method for hacker reconnaissance and should be turned off to prevent snooping.

a)

DNS

b)

telnet

c)

RADIUS

d)

ICMP

11.

The ISSMP concentration examination is designed to provide CISSPs with a mechanism to demonstrate competence in

a)

enterprise security management practices

b)

All of these answers are correct

c)

security management practices

d)

business continuity planning and disaster recovery planning

12.

More advanced substitution ciphers use two or more alphabets, and are referred to as substitutions.

a)

polynomic

b)

monoalphabetic

c)

polysyllabic

d)

polyalphabetic

13.

occurs when an authorized person opens a door, and other people, who may or may not be authorized, also enter.

a)

Crowdsurfing

b)

Shoulder surfing

c)

Hitchhiking

d)

Tailgating

14.

Which of the following ports is commonly used for the HTTP protocol?

a)

53

b)

25

c)

80

d)

20

15.

The is the title most commonly associated with the top information security officer in the organization.

a)

CTO

b)

CEO

c)

CFO

d)

CISO

16.

Which of the following versions of TACACS is still in use?

a)

TACACS v2

b)

TACACS+

c)

Extended TACACS

d)

All of these are correct

17.

A filtering firewall can react to an emergent event and update or create rules to deal with the event.

a)

stateless

b)

static

c)

stateful

d)

dynamic

18.

and TACACS are systems that authenticate the credentials of users who are trying to access an organization's network via a dial-up connection.

a)

IPSEC

b)

RADIUS

c)

TUNMAN

d)

RADIAL

19.

Which of the following is NOT a described IDPS control strategy?

a)

decentralized

b)

centralized

c)

partially distributed

d)

fully distributed

20.

To assess the effect that changes will have on the organization's personnel management practices, the organization should conduct a behavioral feasibility study before the program is

a)

budgeted

b)

considered

c)

planned

d)

implemented

21.

A(n) port, also known as a monitoring port, is a specially configured connection on a network device that is capable of viewing all of the traffic that moves through the entire device.

a)

IDSE

b)

NIDPS

c)

DPS

d)

SPAN

22.

The algorithm, developed in 1977, was the first public-key encryption algorithm published for commercial use.

a)

MAC

b)

RSA

c)

AES

d)

DES

23.

An X.509 v3 certificate binds a , which uniquely identifies a certificate entity, to a user's public key.

a)

fingerprint

b)

distinguished name

c)

digital signature

d)

message digest

24.

Tasks or action steps that come after the task at hand are called

a)

successors

b)

parents

c)

derivatives

d)

predecessors

25.

The commercial site focuses on current security tool resources.

a)

Snort-SIGs

b)

Security Laser

c)

Packet Storm

d)

Nmap-hackerz

26.

The model commonly used by large organizations places the information security department within the department.

a)

physical security

b)

management

c)

information technology

d)

production

27.

Effective planning for information security involves:

a)

collecting information about an organization's objectives.

b)

collecting information about an organization's information security environment.

c)

collecting information about an organization's technical architecture.

d)

All of these answers are correct.

28.

Many organizations use a(n) interview to remind the employee of contractual obligations, such as nondisclosure agreements, and to obtain feedback on the employee's tenure in the organization.

a)

departure

b)

hostile

c)

termination

d)

exit

29.

A(n) works like a burglar alarm in that it detects a violation (some system activities analogous to an opened or broken window) and activates an alarm.

a)

WiFi

b)

UDP

c)

IDPS

d)

DoS

30.

During the phase, specific technologies are selected to support the alternatives identified and evaluated in the prior phases.

a)

analysis

b)

investigation

c)

implementation

d)

physical design

31.

are a component of the "security triple."

a)

All of these are correct

b)

Threats

c)

Vulnerabilities

d)

Assets

32.

inspection firewalls keep track of each network connection between internal and external systems.

a)

Dynamic

b)

Static

c)

Stateless

d)

Stateful

33.

The process is designed to find and document vulnerabilities that may be present because there are misconfigured systems in use within the organization.

a)

SVP

b)

ISP

c)

PSV

d)

ASP

34.

Network behavior analysis system sensors are typically intended for network perimeter use, so they are deployed in close proximity to the perimeter firewalls, often between the firewall and the Internet border router to limit incoming attacks that could overwhelm the firewall.

a)

bypass

b)

inline

c)

passive

d)

offline

35.

The Web site is home to several security tools including the leading free network exploration tool, Nmap.

a)

Packet Storm

b)

Snort-sigs

c)

insecure.org

d)

Security Focus

36.

A(n) IDPS is focused on protecting network information assets.

a)

network-based

b)

server-based

c)

application-based

d)

host-based

37.

is an integrated system of software, encryption methodologies, protocols, legal agreements, and third-party services that enables users to communicate securely.

a)

PKI

b)

AES

c)

DES

d)

MAC

38.

applications use a combination of techniques to detect an intrusion and then follow it back to its source.

a)

Packet sniffer

b)

Trap-and-trace

c)

Honeynet

d)

HIDPS

39.

firewalls examine every incoming packet header and can selectively filter packets based on header information such as destination address, source address, packet type, and other key information.

a)

Packet-filtering

b)

Circuit gateway

c)

MAC layer

d)

Application gateway

40.

was developed by Phil Zimmermann and uses the IDEA cipher for message encoding.

a)

PGP

b)

S/MIME

c)

SSL/TLS

d)

SSH

41.

A device that assures the delivery of electric power without interruption is a(n) ________.

a)

GFCI

b)

GPS

c)

HVAC

d)

UPS

42.

In PKI, the CA periodically distributes a(n) _____ to all users that identifies all revoked certificates.

a)

RA

b)

CRL

c)

RDL

d)

MAC

43.

Many who enter the field of information security are technical professionals such as _____ who find themselves working on information security applications and processes more often than traditional IT assignments.

a)

All of the other answers are correct

b)

programmers

c)

networking experts or systems administrators

d)

database administrators

44.

The _____ vulnerability assessment is a process designed to find and document selected vulnerabilities that are likely to be present on the organization's internal network.

a)

Internet

b)

WAN

c)

intranet

d)

LAN

45.

_____ testing is a straightforward testing technique that looks for vulnerabilities in a program or protocol by feeding random input to the program or a network running the protocol.

a)

Buzz

b)

Black

c)

Spike

d)

Fuzz

46.

In most cases, organizations look for a technically qualified information security _____ who has a solid understanding of how an organization operates.

a)

expert

b)

specialist

c)

internist

d)

generalist

47.

Intrusion _____ activities finalize the restoration of operations to a normal state and seek to identify the source and method of the intrusion in order to ensure that the same type of attack cannot occur again.

a)

reaction

b)

detection

c)

correction

d)

prevention

48.

_____ penetration testing, also known as disclosure testing, is usually used when a specific system or network segment is suspect and the organization wants the pen tester to focus on a particular aspect of the target.

a)

White box

b)

Green box

c)

Black box

d)

Gray box

49.

A methodology and formal development strategy for the design and implementation of an information system is referred to as a _____.

a)

systems development life cycle

b)

systems design

c)

development life project

d)

systems schema

50.

_____ filtering requires that the firewall's filtering rules for allowing and denying packets are manually developed and installed with the firewall.

a)

Static

b)

Stateful

c)

Stateless

d)

Dynamic

51.

According to Schwartz, "_____" are the real techies who create and install security solutions.

a)

Builders

b)

Definers

c)

Administrators

d)

Engineers

52.

A _____ vulnerability scanner listens in on the network and identifies vulnerable versions of both server and client software.

a)

passive

b)

secret

c)

aggressive

d)

active

53.

The application layer proxy firewall is also known as a(n) _____.

a)

application firewall

b)

proxy firewall

c)

client firewall

d)

All of these are correct

54.

Many who move to business-oriented information security were formerly _____ who were often involved in national security or cybersecurity.

a)

marketing managers

b)

business analysts

c)

lawyers

d)

military personnel

55.

Some vulnerability scanners feature a class of attacks called _____, that are so dangerous they should only be used in a lab environment.

a)

aggressive

b)

disruptive

c)

divisive

d)

destructive

56.

Security managers accomplish _____ identified by the CISO and resolve issues identified by technicians

a)

tasks

b)

objectives

c)

tactics

d)

strategies

57.

_____ is an open-source protocol framework that can be used to secure communications across any IP-based network such as LANs, WANs, and the Internet.

a)

SSH-2

b)

IPSec

c)

PEM

d)

SET

58.

Many public organizations must spend all budgeted funds within the fiscal year—otherwise, the subsequent year's budget is _____.

a)

not affected unless the deficit is repeated

b)

automatically audited for questionable expenditures

c)

reduced by the unspent amount

d)

increased by the unspent amount

59.

_____ are decoy systems designed to lure potential attackers away from critical systems.

a)

Honeypots

b)

Designated targets

c)

Bastion hosts

d)

Wasp nests

60.

_____ is one of the most crucial ongoing responsibilities in security management with strategic, tactical, and operating elements that must align with and support organizational and IT objectives.

a)

Controlling

b)

Organizing

c)

Supervision

d)

Planning

61.

_____ make filtering decisions based on the specific host computer's identity, as represented by its network interface card (NIC) address, and operate at the data link layer of the OSI model or the subnet layer of the TCP/IP model.

a)

Application gateway

b)

Media Access Control Layer

c)

Circuit gateway

d)

Packet-filtering

62.

A(n) _____ is a private data network that makes use of the public telecommunication infrastructure, maintaining privacy through the use of a tunneling protocol and security procedures.

a)

SVPN

b)

SESAME

c)

KERBES

d)

VPN

63.

One of the leading causes of damage to sensitive circuitry is __________.

a)

ESD

b)

CPU

c)

HVAC

d)

EPA

64.

Because the _____ host stands as a sole defender on the network perimeter, it is commonly referred to as the sacrificial host.

a)

domain

b)

trusted

c)

DMZ

d)

bastion

65.

The _____ is responsible for the fragmentation, compression, encryption, and attachment of an SSL header to the cleartext prior to transmission.

a)

Standard HTTP

b)

HTTPS

c)

SSL Record Protocol

d)

SFTP

66.

Common vulnerability assessment processes include:

a)

Internet VA

b)

wireless VA

c)

all of these are correct answers

d)

intranet VA

67.

The _____ methodology has been used by many organizations and requires that issues be addressed from the general to the specific, and that the focus be on systematic solutions instead of individual problems.

a)

wrap-up

b)

bull's-eye

c)

parallel

d)

direct changeover

68.

Organizations are moving toward more _____-focused development approaches, seeking to improve not only the functionality of the systems they have in place, but consumer confidence in their product.

a)

security

b)

accessibility

c)

reliability

d)

availability

69.

The _____ layer of the bull's-eye model includes computers used as servers, desktop computers, and systems used for process control and manufacturing.

a)

Applications

b)

Systems

c)

Networks

d)

Policies

70.

The _____ level of the bull's-eye model establishes the ground rules for the use of all systems and describes what is appropriate and what is inappropriate; it enables all other information security components to function correctly.

a)

Applications

b)

Systems

c)

Policies

d)

Networks

71.

A(n) _____ is a software program or hardware appliance that can intercept, copy, and interpret network traffic.

a)

packet sniffer

b)

port scanner

c)

honey packet

d)

honeypot

72.

Computing and other electrical equipment used in areas where water can accumulate must be uniquely grounded using _____ equipment.

a)

HVAC

b)

UPS

c)

ESD

d)

GFCI

73.

Configuring firewall _____ is viewed as much an art as it is a science.

a)

policies

b)

protocols

c)

VPNs

d)

subnets

74.

The (ISC)2 _____ certification program has added a number of concentrations that can demonstrate advanced knowledge beyond the basic certification's common body of knowledge.

a)

CISM

b)

CISSP

c)

C|CISO

d)

CISA

75.

A _____ is a key-dependent, one-way hash function that allows only specific recipients (symmetric key holders) to access the message digest.

a)

MAC

b)

signature

c)

digest

d)

fingerprint

76.

The goal of the _____ is to resolve any pending project-related issues, critique the overall effort of the project, and draw conclusions about how to improve the project management process for the future.

a)

phased implementation

b)

pilot implementation

c)

project wrap-up

d)

direct changeover

77.

Activities that scan networks for active systems and then identify the network services offered by the host systems are known as _____.

a)

doorknob rattling

b)

port knocking

c)

fingerprinting

d)

footprinting

78.

An emerging methodology to integrate the effort of the development team and the operations team to improve the functionality and security of applications is known as _____.

a)

JAD/RAD

b)

DevOps

c)

SecOps

d)

SecSDLC

79.

Which of the following are NOT technologies commonly deployed in biometric locks?

a)

proximity card

b)

fingerprint reader

c)

iris scanner

d)

facial recognition

80.

_____ functions are mathematical algorithms that generate a message summary or digest to confirm the identity of a specific message and to confirm that there have not been any changes to the content.

a)

Key

b)

MAC

c)

Hash

d)

Encryption

81.

Detailed intelligence on the highest risk warnings can include identifying which _____ apply to which vulnerabilities as well as which types of defenses have been found to work against the specific vulnerabilities reported.

a)

vendor updates

b)

threats

c)

assets

d)

risks

82.

Digital signatures should be created using processes and products that are based on the _____.

a)

NIST

b)

SSL

c)

DSS

d)

HTTPS

83.

Using a database of precomputed hashes from sequentially calculated passwords called a(n) _____, an attacker can simply look up a hashed password and read out the text version.

a)

smurf list

b)

rainbow table

c)

hash matrix

d)

hashapedia

84.

A _____ is usually the best approach to security project implementation.

a)

pilot implementation

b)

phased implementation

c)

direct changeover

d)

parallel operation

85.

A(n) _____ determines the impact that a specific technology or approach can have on the organization’s information assets and what it may cost.

a)

RFP

b)

WBS

c)

SDLC

d)

CBA

86.

_____ is a hybrid cryptosystem that combines some of the best available cryptographic algorithms and has become the open-source de facto standard for encryption and authentication of e-mail and file storage applications.

a)

PGP

b)

DES

c)

ESP

d)

AH

87.

_____ is the action of luring an individual into committing a crime to get a conviction.

a)

Intrusion

b)

Enticement

c)

Padding

d)

Entrapment

88.

Kerberos _____ provides tickets to clients who request services.

a)

TGS

b)

KDS

c)

VPN

d)

AS

89.

_____ are hired by the organization to serve in a temporary position or to supplement the existing workforce.

a)

Temporary employees

b)

Consultants

c)

Self-employees

d)

Contractors

90.

The date for sending the final RFP to vendors is considered a milestone because it signals that __________.

a)

the budget is approved

b)

the bid by date has passed

c)

all RFP preparation work is complete

d)

all approvals have been obtained

91.

In some organizations, the CISO’s position may be combined with physical security responsibilities or may even report to a security manager who is responsible for both logical (information) security and physical security and such a position is generally referred to as a _____.

a)

CPSO

b)

CSO

c)

CTO

d)

CNSO

92.

The ability to detect a target computer’s _____ is very valuable to an attacker.

a)

manufacturer

b)

BIOS

c)

peripherals

d)

operating system

93.

_____, a level beyond vulnerability testing, is a set of security tests and evaluations that simulate attacks by a malicious external source like a hacker.

a)

Attack simulation

b)

Penetration testing

c)

Penetration simulation

d)

Attack testing

94.

The ISSEP concentration allows CISSP certificate holders to demonstrate expert knowledge of all of the following except _____.

a)

technical management

b)

systems security engineering

c)

certification and accreditation/risk management framework

d)

international laws

95.

At the World Championships in Athletics in Helsinki in August 2005, a virus called Cabir infected dozens of _____, the first time this occurred in a public setting.

a)

Bluetooth mobile phones

b)

WiFi routers

c)

hearing aids

d)

iPad tablets

96.

A method of encryption that requires the same secret key to encipher and decipher the message is known as _____ encryption.

a)

hash

b)

asymmetric

c)

public

d)

symmetric

97.

A primary mailing list for new vulnerabilities, called simply _____, provides time-sensitive coverage of emerging vulnerabilities, documenting how they are exploited and reporting on how to remediate them. Individuals can register for the flagship mailing list or any one of the entire family of its mailing lists.

a)

Bugfix

b)

Bugtraq

c)

Buglist

d)

Bugs

98.

The _____ protocol provides system-to-system authentication and data integrity verification, but does not provide secrecy for the content of a network communication.

a)

HA

b)

ESP

c)

AH

d)

SEP

99.

In a _____ when significant deviation occurs, corrective action is taken to bring the deviating task back into compliance with the project plan; otherwise, the project is revised in light of the new information.

a)

gap analysis

b)

turnover

c)

wrap-up

d)

direct changeover

100.

Most guards have clear __________ that help them to act decisively in unfamiliar situations.

a)

OPSs

b)

POSs

c)

MACs

d)

SOPs

101.

The _____ is an intermediate area between a trusted network and an untrusted network.

a)

domain

b)

firewall

c)

perimeter

d)

DMZ

102.

To use a packet sniffer legally, the administrator must _____.

a)

be on a network that the organization owns

b)

All of these are correct

c)

be under direct authorization of the network’s owners

d)

have knowledge and consent of the content’s creators

103.

The _____ vulnerability assessment is designed to find and document vulnerabilities that may be present in the organization’s wireless local area networks.

a)

phone-in

b)

battle-dialing

c)

network

d)

wireless

104.

A(n) _____ is a simple project management planning tool used to break the project plan into smaller and smaller steps.

a)

SDLC

b)

RFP

c)

ISO 17799

d)

WBS

105.

_____ is the process of classifying IDPS alerts so that they can be more effectively managed.

a)

Alarm filtering

b)

Alarm clustering

c)

Alarm attenuation

d)

Alarm compaction

106.

Which of the following is not one of the categories of positions defined by Schwartz?

a)

User

b)

Administrator

c)

Builder

d)

Definer

107.

A process called _____ examines the data packets that flows through a system and its associated devices to identify the most frequently used devices.

a)

schema analysis

b)

data flow assessment

c)

traffic analysis

d)

difference analysis

108.

The _____ layer of the bull’s-eye model receives attention last.

a)

Systems

b)

Applications

c)

Networks

d)

Policies

109.

In most common implementation models, the content filter has two components: _____.

a)

rating and decryption

b)

allow and deny

c)

rating and filtering

d)

filtering and encoding

110.

SHA-1 produces a(n) _____-bit message digest, which can then be used as an input to a digital signature algorithm.

a)

256

b)

56

c)

160

d)

48

111.

The dominant architecture used to secure network access today is the _____ firewall.

a)

bastion

b)

unlimited

c)

static

d)

screened subnet

112.

If the task is to write firewall specifications for the preparation of a(n) _____, the planner would note that the deliverable is a specification document suitable for distribution to vendors.

a)

WBS

b)

RFP

c)

CBA

d)

SDLC

113.

In SESAME, the user is first authenticated to an authentication server and receives a token. The token is then presented to a privilege attribute server as proof of identity to gain a(n) _____.

a)

VPN

b)

ticket

c)

ECMA

d)

PAC

114.

One approach that can improve the situational awareness of the information security function is to use a process known as _____ to quickly identify changes to the internal environment.

a)

baselining

b)

differentials

c)

difference analysis

d)

revision

115.

In _____ mode, the data within an IP packet is encrypted, but the header information is not.

a)

transport

b)

symmetric

c)

public

d)

tunnel

116.

U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) coordinates CERT services at __________.

a)

US-CERT

b)

CERT/CC

c)

CM-CERT

d)

Bugtraq

117.

_____ access control is a form of _____ access control in which users are assigned a matrix of authorizations for particular areas of access.

a)

mandatory, discretionary

b)

task-based, discretionary

c)

lattice-based, nondiscretionary

d)

role-based, nondiscretionary

118.

Like the CISSP, the SSCP certification is more applicable to the security_____ than to the security _____.

a)

manager, technician

b)

executive, technician

119.

_____ is the amount of effort (usually in hours) required to perform cryptanalysis to decode an encrypted message when the key or algorithm (or both) are unknown.

a)

Cryptology

b)

Decryption

c)

Cryptography

d)

Work factor

120.

Data or the trends in data that may indicate the effectiveness of security countermeasures or technical and managerial controls implemented in the organization are known as performance _____.

a)

measurements

b)

monitors

c)

evaluators

d)

indices

121.

_____ allows for major security control components to be reviewed on a periodic basis to ensure that they are current, accurate, and appropriate.

a)

Application review

b)

Vulnerability assessment

c)

System review

d)

Program review

122.

_____ is a cornerstone in the protection of information assets and in the prevention of financial loss.

a)

Fire suppression

b)

Separation of duties

c)

Collusion

d)

Business separation

123.

Technology _____ guides how frequently technical systems are updated, and how technical updates are approved and funded, and also facilitates communication about technical advances and issues across the organization.

a)

turnover

b)

changeover

c)

governance

d)

wrap-up

124.

The service within Kerberos that generates and issues session keys is known as _____.

a)

VPN

b)

AS

c)

KDC

d)

TGS

125.

The InfoSec measurement development process recommended by NIST is divided into major activities that include all of the following EXCEPT _____.

a)

Development and selection of specific measurements to gauge the implementation, effectiveness, efficiency, and impact of the security controls.

b)

Identification and definition of the current InfoSec program.

c)

Usage of the selected metrics.

d)

All other answers here are included in the NIST development process recommendation.

126.

The Cybersecurity Analyst+ certification from _____ is an intermediate certification with both knowledge-based and performance-based assessment.

a)

SANS

b)

ACM

c)

CompTIA

d)

ISACA

127.

_____ are the technically qualified individuals tasked to configure firewalls, deploy IDPSs, implement security software, diagnose and troubleshoot problems, and coordinate with systems and network administrators to ensure that an organization’s security technology is properly implemented.

a)

CISOs

b)

Security analysts

c)

Security managers

d)

CSOs

128.

_____ is the process of converting an original message into a form that is unreadable to unauthorized individuals.

a)

Cryptology

b)

Cryptography

c)

Encryption

d)

Decryption

129.

Project managers can reduce resistance to change by involving employees in the project plan. In the systems development parts of a project, this is referred to as _____.

a)

SDLC

b)

WBS

c)

JAD

d)

DMZ

130.

Which of the following phases is often considered the longest and most expensive phase of the systems development life cycle?

a)

implementation

b)

maintenance and change

c)

logical design

d)

investigation

131.

_____ is the requirement that every employee be able to perform the work of another employee.

a)

Two-man control

b)

Task rotation

c)

Collusion

d)

Duty exchange

132.

A type of SDLC in which each phase has results that flow into the next phase is called the _____ model.

a)

Method 7

b)

agile

c)

waterfall

d)

SA&D

133.

DES uses a(n) _____-bit block size.

a)

128

b)

64

c)

256

d)

32

134.

_____ are usually passive devices, but cannot analyze encrypted packets, making some traffic invisible to the process.

a)

HIPSs

b)

AppIDPSs

c)

NIDPSs

d)

SIDPSs

135.

The _____ design phase of an SDLC methodology is implementation independent, meaning that it contains no reference to specific technologies, vendors, or products.

a)

logical

b)

physical

c)

conceptual

d)

integral

136.

To determine whether an attack has occurred or is underway, NIDPSs compare measured activity to known _____ in their knowledge base.

a)

signatures

b)

fingerprints

c)

vulnerabilities

d)

footprints

137.

By managing the _____, the organization can reduce unintended consequences by having a process to resolve the potential conflict and disruption that uncoordinated change can introduce.

a)

governance

b)

process of change

c)

conversion process

d)

wrap-up

138.

Bit stream methods commonly use algorithm functions like the _____ OR operation.

a)

extreme

b)

exclusive

c)

enhanced

d)

extensive

139.

_____ is the current federal information processing standard that specifies a cryptographic algorithm used within the U.S. government to protect information in federal agencies that are not a part of the national defense infrastructure.

a)

DES

b)

3DES

c)

AES

d)

2DES

140.

The Lewin change model includes _____.

a)

unfreezing

b)

moving

c)

All of these are correct

d)

refreezing

141.

The monitoring process has three primary deliverables. Which of the following is NOT one of them?

a)

Periodic summaries of external information

b)

All of these are correct

c)

Detailed intelligence on the highest-risk warnings

d)

Specific warning bulletins issued when developing threats and specific attacks pose a measurable risk to the organization

142.

The breadth and depth covered in each of the domains makes the _____ one of the most difficult-to-attain certifications on the market.

a)

CISA

b)

CISSP

c)

Security+

d)

ISEP

143.

Most network behavior analysis system sensors can be deployed in _____ mode only, using the same connection methods as network-based IDPSs.

a)

active

b)

passive

c)

dynamic

d)

reactive

144.

In a _____ implementation, the entire security system is put in place in a single office, department, or division before expanding to the rest of the organization.

a)

pilot

b)

loop

c)

direct

d)

parallel

145.

The former System Administration, Networking, and Security Organization is now better known as _____.

a)

SANSO

b)

SAN

c)

SANO

d)

SANS

146.

A(n) _____ is an event that triggers an alarm when no actual attack is in progress.

a)

false neutral

b)

false negative

c)

false attack stimulus

d)

noise

147.

The latest forecasts for information security-related positions expect _____ openings than in many previous years.

a)

many fewer

b)

the same number of

c)

fewer

d)

more

148.

A _____ is the information used in conjunction with an algorithm to create the ciphertext from the plaintext or derive the plaintext from the ciphertext.

a)

passphrase

b)

cipher

c)

key

d)

password

149.

The information security function can be placed within the _____.

a)

insurance and risk management function

b)

legal department

c)

All of the other answers are correct

d)

administrative services function

150.

_____ is the entire range of values that can possibly be used to construct an individual key.

a)

Keyspace

b)

Code

c)

An algorithm

d)

A cryptogram

151.

Telnet protocol packets usually go to TCP port _____, whereas SMTP packets go to port _____.

a)

23,25

b)

23,52

c)

80,25

d)

80,52

152.

The restrictions most commonly implemented in packet-filtering firewalls are based on _____.

a)

TCP or UDP source and destination port requests 

b)

All of these answers are correct 

c)

Direction (inbound or outbound) 

d)

IP source and destination address 

153.

The primary benefit of a VPN that uses _____ is that an intercepted packet reveals nothing about the true destination system.

a)

tunnel mode 

b)

transport mode 

c)

reversion mode

d)

intermediate mode