WorksheetsInformation Security Worksheet Questions (Grade 13)
Total questions: 153
Worksheet time: 1hrs 17mins
are encrypted message components that can be mathematically proven to be authentic.
Digital signatures
MACs
Message digests
Message certificates
The CISA credential is promoted by ISACA as the certification that is appropriate for all but which type of professionals?
accounting
auditing
security
networking
A(n) reviews the log files generated by servers, network devices, and even other IDPSs looking for patterns and signatures that may indicate an attack or intrusion is in process or has already occurred.
LFM
HIDPS
AppIDPS
stat IDPS
Some cases of are simple, such as requiring employees to begin using a new password on an announced date.
phased implementation
wrap-up
pilot implementation
direct changeover
A step commonly used for Internet vulnerability assessment includes , which occurs when the penetration test engine is unleashed at the scheduled time using the planned target list and test selection.
subrogation
delegation
targeting
scanning
The proxy server is often placed in an unsecured area of the network or is placed in the zone.
demilitarized
cold
hot
fully trusted
benchmark and monitor the status of key system files and detect when an intruder creates, modifies, or deletes monitored files.
HIDPSs
NIDPSs
SIDPSs
AppIDPSs
Which of the following is not a major processing mode category for firewalls?
Packet-filtering
Router Passthrough
Application Layer Proxy
Media Access Control Layer
In TCP/IP networking, port is not used.
1
13
0
1023
Known as the ping service, is a common method for hacker reconnaissance and should be turned off to prevent snooping.
DNS
telnet
RADIUS
ICMP
The ISSMP concentration examination is designed to provide CISSPs with a mechanism to demonstrate competence in
enterprise security management practices
All of these answers are correct
security management practices
business continuity planning and disaster recovery planning
More advanced substitution ciphers use two or more alphabets, and are referred to as substitutions.
polynomic
monoalphabetic
polysyllabic
polyalphabetic
occurs when an authorized person opens a door, and other people, who may or may not be authorized, also enter.
Crowdsurfing
Shoulder surfing
Hitchhiking
Tailgating
Which of the following ports is commonly used for the HTTP protocol?
53
25
80
20
The is the title most commonly associated with the top information security officer in the organization.
CTO
CEO
CFO
CISO
Which of the following versions of TACACS is still in use?
TACACS v2
TACACS+
Extended TACACS
All of these are correct
A filtering firewall can react to an emergent event and update or create rules to deal with the event.
stateless
static
stateful
dynamic
and TACACS are systems that authenticate the credentials of users who are trying to access an organization's network via a dial-up connection.
IPSEC
RADIUS
TUNMAN
RADIAL
Which of the following is NOT a described IDPS control strategy?
decentralized
centralized
partially distributed
fully distributed
To assess the effect that changes will have on the organization's personnel management practices, the organization should conduct a behavioral feasibility study before the program is
budgeted
considered
planned
implemented
A(n) port, also known as a monitoring port, is a specially configured connection on a network device that is capable of viewing all of the traffic that moves through the entire device.
IDSE
NIDPS
DPS
SPAN
The algorithm, developed in 1977, was the first public-key encryption algorithm published for commercial use.
MAC
RSA
AES
DES
An X.509 v3 certificate binds a , which uniquely identifies a certificate entity, to a user's public key.
fingerprint
distinguished name
digital signature
message digest
Tasks or action steps that come after the task at hand are called
successors
parents
derivatives
predecessors
The commercial site focuses on current security tool resources.
Snort-SIGs
Security Laser
Packet Storm
Nmap-hackerz
The model commonly used by large organizations places the information security department within the department.
physical security
management
information technology
production
Effective planning for information security involves:
collecting information about an organization's objectives.
collecting information about an organization's information security environment.
collecting information about an organization's technical architecture.
All of these answers are correct.
Many organizations use a(n) interview to remind the employee of contractual obligations, such as nondisclosure agreements, and to obtain feedback on the employee's tenure in the organization.
departure
hostile
termination
exit
A(n) works like a burglar alarm in that it detects a violation (some system activities analogous to an opened or broken window) and activates an alarm.
WiFi
UDP
IDPS
DoS
During the phase, specific technologies are selected to support the alternatives identified and evaluated in the prior phases.
analysis
investigation
implementation
physical design
are a component of the "security triple."
All of these are correct
Threats
Vulnerabilities
Assets
inspection firewalls keep track of each network connection between internal and external systems.
Dynamic
Static
Stateless
Stateful
The process is designed to find and document vulnerabilities that may be present because there are misconfigured systems in use within the organization.
SVP
ISP
PSV
ASP
Network behavior analysis system sensors are typically intended for network perimeter use, so they are deployed in close proximity to the perimeter firewalls, often between the firewall and the Internet border router to limit incoming attacks that could overwhelm the firewall.
bypass
inline
passive
offline
The Web site is home to several security tools including the leading free network exploration tool, Nmap.
Packet Storm
Snort-sigs
insecure.org
Security Focus
A(n) IDPS is focused on protecting network information assets.
network-based
server-based
application-based
host-based
is an integrated system of software, encryption methodologies, protocols, legal agreements, and third-party services that enables users to communicate securely.
PKI
AES
DES
MAC
applications use a combination of techniques to detect an intrusion and then follow it back to its source.
Packet sniffer
Trap-and-trace
Honeynet
HIDPS
firewalls examine every incoming packet header and can selectively filter packets based on header information such as destination address, source address, packet type, and other key information.
Packet-filtering
Circuit gateway
MAC layer
Application gateway
was developed by Phil Zimmermann and uses the IDEA cipher for message encoding.
PGP
S/MIME
SSL/TLS
SSH
A device that assures the delivery of electric power without interruption is a(n) ________.
GFCI
GPS
HVAC
UPS
In PKI, the CA periodically distributes a(n) _____ to all users that identifies all revoked certificates.
RA
CRL
RDL
MAC
Many who enter the field of information security are technical professionals such as _____ who find themselves working on information security applications and processes more often than traditional IT assignments.
All of the other answers are correct
programmers
networking experts or systems administrators
database administrators
The _____ vulnerability assessment is a process designed to find and document selected vulnerabilities that are likely to be present on the organization's internal network.
Internet
WAN
intranet
LAN
_____ testing is a straightforward testing technique that looks for vulnerabilities in a program or protocol by feeding random input to the program or a network running the protocol.
Buzz
Black
Spike
Fuzz
In most cases, organizations look for a technically qualified information security _____ who has a solid understanding of how an organization operates.
expert
specialist
internist
generalist
Intrusion _____ activities finalize the restoration of operations to a normal state and seek to identify the source and method of the intrusion in order to ensure that the same type of attack cannot occur again.
reaction
detection
correction
prevention
_____ penetration testing, also known as disclosure testing, is usually used when a specific system or network segment is suspect and the organization wants the pen tester to focus on a particular aspect of the target.
White box
Green box
Black box
Gray box
A methodology and formal development strategy for the design and implementation of an information system is referred to as a _____.
systems development life cycle
systems design
development life project
systems schema
_____ filtering requires that the firewall's filtering rules for allowing and denying packets are manually developed and installed with the firewall.
Static
Stateful
Stateless
Dynamic
According to Schwartz, "_____" are the real techies who create and install security solutions.
Builders
Definers
Administrators
Engineers
A _____ vulnerability scanner listens in on the network and identifies vulnerable versions of both server and client software.
passive
secret
aggressive
active
The application layer proxy firewall is also known as a(n) _____.
application firewall
proxy firewall
client firewall
All of these are correct
Many who move to business-oriented information security were formerly _____ who were often involved in national security or cybersecurity.
marketing managers
business analysts
lawyers
military personnel
Some vulnerability scanners feature a class of attacks called _____, that are so dangerous they should only be used in a lab environment.
aggressive
disruptive
divisive
destructive
Security managers accomplish _____ identified by the CISO and resolve issues identified by technicians
tasks
objectives
tactics
strategies
_____ is an open-source protocol framework that can be used to secure communications across any IP-based network such as LANs, WANs, and the Internet.
SSH-2
IPSec
PEM
SET
Many public organizations must spend all budgeted funds within the fiscal year—otherwise, the subsequent year's budget is _____.
not affected unless the deficit is repeated
automatically audited for questionable expenditures
reduced by the unspent amount
increased by the unspent amount
_____ are decoy systems designed to lure potential attackers away from critical systems.
Honeypots
Designated targets
Bastion hosts
Wasp nests
_____ is one of the most crucial ongoing responsibilities in security management with strategic, tactical, and operating elements that must align with and support organizational and IT objectives.
Controlling
Organizing
Supervision
Planning
_____ make filtering decisions based on the specific host computer's identity, as represented by its network interface card (NIC) address, and operate at the data link layer of the OSI model or the subnet layer of the TCP/IP model.
Application gateway
Media Access Control Layer
Circuit gateway
Packet-filtering
A(n) _____ is a private data network that makes use of the public telecommunication infrastructure, maintaining privacy through the use of a tunneling protocol and security procedures.
SVPN
SESAME
KERBES
VPN
One of the leading causes of damage to sensitive circuitry is __________.
ESD
CPU
HVAC
EPA
Because the _____ host stands as a sole defender on the network perimeter, it is commonly referred to as the sacrificial host.
domain
trusted
DMZ
bastion
The _____ is responsible for the fragmentation, compression, encryption, and attachment of an SSL header to the cleartext prior to transmission.
Standard HTTP
HTTPS
SSL Record Protocol
SFTP
Common vulnerability assessment processes include:
Internet VA
wireless VA
all of these are correct answers
intranet VA
The _____ methodology has been used by many organizations and requires that issues be addressed from the general to the specific, and that the focus be on systematic solutions instead of individual problems.
wrap-up
bull's-eye
parallel
direct changeover
Organizations are moving toward more _____-focused development approaches, seeking to improve not only the functionality of the systems they have in place, but consumer confidence in their product.
security
accessibility
reliability
availability
The _____ layer of the bull's-eye model includes computers used as servers, desktop computers, and systems used for process control and manufacturing.
Applications
Systems
Networks
Policies
The _____ level of the bull's-eye model establishes the ground rules for the use of all systems and describes what is appropriate and what is inappropriate; it enables all other information security components to function correctly.
Applications
Systems
Policies
Networks
A(n) _____ is a software program or hardware appliance that can intercept, copy, and interpret network traffic.
packet sniffer
port scanner
honey packet
honeypot
Computing and other electrical equipment used in areas where water can accumulate must be uniquely grounded using _____ equipment.
HVAC
UPS
ESD
GFCI
Configuring firewall _____ is viewed as much an art as it is a science.
policies
protocols
VPNs
subnets
The (ISC)2 _____ certification program has added a number of concentrations that can demonstrate advanced knowledge beyond the basic certification's common body of knowledge.
CISM
CISSP
C|CISO
CISA
A _____ is a key-dependent, one-way hash function that allows only specific recipients (symmetric key holders) to access the message digest.
MAC
signature
digest
fingerprint
The goal of the _____ is to resolve any pending project-related issues, critique the overall effort of the project, and draw conclusions about how to improve the project management process for the future.
phased implementation
pilot implementation
project wrap-up
direct changeover
Activities that scan networks for active systems and then identify the network services offered by the host systems are known as _____.
doorknob rattling
port knocking
fingerprinting
footprinting
An emerging methodology to integrate the effort of the development team and the operations team to improve the functionality and security of applications is known as _____.
JAD/RAD
DevOps
SecOps
SecSDLC
Which of the following are NOT technologies commonly deployed in biometric locks?
proximity card
fingerprint reader
iris scanner
facial recognition
_____ functions are mathematical algorithms that generate a message summary or digest to confirm the identity of a specific message and to confirm that there have not been any changes to the content.
Key
MAC
Hash
Encryption
Detailed intelligence on the highest risk warnings can include identifying which _____ apply to which vulnerabilities as well as which types of defenses have been found to work against the specific vulnerabilities reported.
vendor updates
threats
assets
risks
Digital signatures should be created using processes and products that are based on the _____.
NIST
SSL
DSS
HTTPS
Using a database of precomputed hashes from sequentially calculated passwords called a(n) _____, an attacker can simply look up a hashed password and read out the text version.
smurf list
rainbow table
hash matrix
hashapedia
A _____ is usually the best approach to security project implementation.
pilot implementation
phased implementation
direct changeover
parallel operation
A(n) _____ determines the impact that a specific technology or approach can have on the organization’s information assets and what it may cost.
RFP
WBS
SDLC
CBA
_____ is a hybrid cryptosystem that combines some of the best available cryptographic algorithms and has become the open-source de facto standard for encryption and authentication of e-mail and file storage applications.
PGP
DES
ESP
AH
_____ is the action of luring an individual into committing a crime to get a conviction.
Intrusion
Enticement
Padding
Entrapment
Kerberos _____ provides tickets to clients who request services.
TGS
KDS
VPN
AS
_____ are hired by the organization to serve in a temporary position or to supplement the existing workforce.
Temporary employees
Consultants
Self-employees
Contractors
The date for sending the final RFP to vendors is considered a milestone because it signals that __________.
the budget is approved
the bid by date has passed
all RFP preparation work is complete
all approvals have been obtained
In some organizations, the CISO’s position may be combined with physical security responsibilities or may even report to a security manager who is responsible for both logical (information) security and physical security and such a position is generally referred to as a _____.
CPSO
CSO
CTO
CNSO
The ability to detect a target computer’s _____ is very valuable to an attacker.
manufacturer
BIOS
peripherals
operating system
_____, a level beyond vulnerability testing, is a set of security tests and evaluations that simulate attacks by a malicious external source like a hacker.
Attack simulation
Penetration testing
Penetration simulation
Attack testing
The ISSEP concentration allows CISSP certificate holders to demonstrate expert knowledge of all of the following except _____.
technical management
systems security engineering
certification and accreditation/risk management framework
international laws
At the World Championships in Athletics in Helsinki in August 2005, a virus called Cabir infected dozens of _____, the first time this occurred in a public setting.
Bluetooth mobile phones
WiFi routers
hearing aids
iPad tablets
A method of encryption that requires the same secret key to encipher and decipher the message is known as _____ encryption.
hash
asymmetric
public
symmetric
A primary mailing list for new vulnerabilities, called simply _____, provides time-sensitive coverage of emerging vulnerabilities, documenting how they are exploited and reporting on how to remediate them. Individuals can register for the flagship mailing list or any one of the entire family of its mailing lists.
Bugfix
Bugtraq
Buglist
Bugs
The _____ protocol provides system-to-system authentication and data integrity verification, but does not provide secrecy for the content of a network communication.
HA
ESP
AH
SEP
In a _____ when significant deviation occurs, corrective action is taken to bring the deviating task back into compliance with the project plan; otherwise, the project is revised in light of the new information.
gap analysis
turnover
wrap-up
direct changeover
Most guards have clear __________ that help them to act decisively in unfamiliar situations.
OPSs
POSs
MACs
SOPs
The _____ is an intermediate area between a trusted network and an untrusted network.
domain
firewall
perimeter
DMZ
To use a packet sniffer legally, the administrator must _____.
be on a network that the organization owns
All of these are correct
be under direct authorization of the network’s owners
have knowledge and consent of the content’s creators
The _____ vulnerability assessment is designed to find and document vulnerabilities that may be present in the organization’s wireless local area networks.
phone-in
battle-dialing
network
wireless
A(n) _____ is a simple project management planning tool used to break the project plan into smaller and smaller steps.
SDLC
RFP
ISO 17799
WBS
_____ is the process of classifying IDPS alerts so that they can be more effectively managed.
Alarm filtering
Alarm clustering
Alarm attenuation
Alarm compaction
Which of the following is not one of the categories of positions defined by Schwartz?
User
Administrator
Builder
Definer
A process called _____ examines the data packets that flows through a system and its associated devices to identify the most frequently used devices.
schema analysis
data flow assessment
traffic analysis
difference analysis
The _____ layer of the bull’s-eye model receives attention last.
Systems
Applications
Networks
Policies
In most common implementation models, the content filter has two components: _____.
rating and decryption
allow and deny
rating and filtering
filtering and encoding
SHA-1 produces a(n) _____-bit message digest, which can then be used as an input to a digital signature algorithm.
256
56
160
48
The dominant architecture used to secure network access today is the _____ firewall.
bastion
unlimited
static
screened subnet
If the task is to write firewall specifications for the preparation of a(n) _____, the planner would note that the deliverable is a specification document suitable for distribution to vendors.
WBS
RFP
CBA
SDLC
In SESAME, the user is first authenticated to an authentication server and receives a token. The token is then presented to a privilege attribute server as proof of identity to gain a(n) _____.
VPN
ticket
ECMA
PAC
One approach that can improve the situational awareness of the information security function is to use a process known as _____ to quickly identify changes to the internal environment.
baselining
differentials
difference analysis
revision
In _____ mode, the data within an IP packet is encrypted, but the header information is not.
transport
symmetric
public
tunnel
U.S. Department of Homeland Security’s Cybersecurity & Infrastructure Security Agency (CISA) coordinates CERT services at __________.
US-CERT
CERT/CC
CM-CERT
Bugtraq
_____ access control is a form of _____ access control in which users are assigned a matrix of authorizations for particular areas of access.
mandatory, discretionary
task-based, discretionary
lattice-based, nondiscretionary
role-based, nondiscretionary
Like the CISSP, the SSCP certification is more applicable to the security_____ than to the security _____.
manager, technician
executive, technician
_____ is the amount of effort (usually in hours) required to perform cryptanalysis to decode an encrypted message when the key or algorithm (or both) are unknown.
Cryptology
Decryption
Cryptography
Work factor
Data or the trends in data that may indicate the effectiveness of security countermeasures or technical and managerial controls implemented in the organization are known as performance _____.
measurements
monitors
evaluators
indices
_____ allows for major security control components to be reviewed on a periodic basis to ensure that they are current, accurate, and appropriate.
Application review
Vulnerability assessment
System review
Program review
_____ is a cornerstone in the protection of information assets and in the prevention of financial loss.
Fire suppression
Separation of duties
Collusion
Business separation
Technology _____ guides how frequently technical systems are updated, and how technical updates are approved and funded, and also facilitates communication about technical advances and issues across the organization.
turnover
changeover
governance
wrap-up
The service within Kerberos that generates and issues session keys is known as _____.
VPN
AS
KDC
TGS
The InfoSec measurement development process recommended by NIST is divided into major activities that include all of the following EXCEPT _____.
Development and selection of specific measurements to gauge the implementation, effectiveness, efficiency, and impact of the security controls.
Identification and definition of the current InfoSec program.
Usage of the selected metrics.
All other answers here are included in the NIST development process recommendation.
The Cybersecurity Analyst+ certification from _____ is an intermediate certification with both knowledge-based and performance-based assessment.
SANS
ACM
CompTIA
ISACA
_____ are the technically qualified individuals tasked to configure firewalls, deploy IDPSs, implement security software, diagnose and troubleshoot problems, and coordinate with systems and network administrators to ensure that an organization’s security technology is properly implemented.
CISOs
Security analysts
Security managers
CSOs
_____ is the process of converting an original message into a form that is unreadable to unauthorized individuals.
Cryptology
Cryptography
Encryption
Decryption
Project managers can reduce resistance to change by involving employees in the project plan. In the systems development parts of a project, this is referred to as _____.
SDLC
WBS
JAD
DMZ
Which of the following phases is often considered the longest and most expensive phase of the systems development life cycle?
implementation
maintenance and change
logical design
investigation
_____ is the requirement that every employee be able to perform the work of another employee.
Two-man control
Task rotation
Collusion
Duty exchange
A type of SDLC in which each phase has results that flow into the next phase is called the _____ model.
Method 7
agile
waterfall
SA&D
DES uses a(n) _____-bit block size.
128
64
256
32
_____ are usually passive devices, but cannot analyze encrypted packets, making some traffic invisible to the process.
HIPSs
AppIDPSs
NIDPSs
SIDPSs
The _____ design phase of an SDLC methodology is implementation independent, meaning that it contains no reference to specific technologies, vendors, or products.
logical
physical
conceptual
integral
To determine whether an attack has occurred or is underway, NIDPSs compare measured activity to known _____ in their knowledge base.
signatures
fingerprints
vulnerabilities
footprints
By managing the _____, the organization can reduce unintended consequences by having a process to resolve the potential conflict and disruption that uncoordinated change can introduce.
governance
process of change
conversion process
wrap-up
Bit stream methods commonly use algorithm functions like the _____ OR operation.
extreme
exclusive
enhanced
extensive
_____ is the current federal information processing standard that specifies a cryptographic algorithm used within the U.S. government to protect information in federal agencies that are not a part of the national defense infrastructure.
DES
3DES
AES
2DES
The Lewin change model includes _____.
unfreezing
moving
All of these are correct
refreezing
The monitoring process has three primary deliverables. Which of the following is NOT one of them?
Periodic summaries of external information
All of these are correct
Detailed intelligence on the highest-risk warnings
Specific warning bulletins issued when developing threats and specific attacks pose a measurable risk to the organization
The breadth and depth covered in each of the domains makes the _____ one of the most difficult-to-attain certifications on the market.
CISA
CISSP
Security+
ISEP
Most network behavior analysis system sensors can be deployed in _____ mode only, using the same connection methods as network-based IDPSs.
active
passive
dynamic
reactive
In a _____ implementation, the entire security system is put in place in a single office, department, or division before expanding to the rest of the organization.
pilot
loop
direct
parallel
The former System Administration, Networking, and Security Organization is now better known as _____.
SANSO
SAN
SANO
SANS
A(n) _____ is an event that triggers an alarm when no actual attack is in progress.
false neutral
false negative
false attack stimulus
noise
The latest forecasts for information security-related positions expect _____ openings than in many previous years.
many fewer
the same number of
fewer
more
A _____ is the information used in conjunction with an algorithm to create the ciphertext from the plaintext or derive the plaintext from the ciphertext.
passphrase
cipher
key
password
The information security function can be placed within the _____.
insurance and risk management function
legal department
All of the other answers are correct
administrative services function
_____ is the entire range of values that can possibly be used to construct an individual key.
Keyspace
Code
An algorithm
A cryptogram
Telnet protocol packets usually go to TCP port _____, whereas SMTP packets go to port _____.
23,25
23,52
80,25
80,52
The restrictions most commonly implemented in packet-filtering firewalls are based on _____.
TCP or UDP source and destination port requests
All of these answers are correct
Direction (inbound or outbound)
IP source and destination address
The primary benefit of a VPN that uses _____ is that an intercepted packet reveals nothing about the true destination system.
tunnel mode
transport mode
reversion mode
intermediate mode
