Deck 8: Securing Information Systems

ملء الشاشة (f)
exit full mode
سؤال
Which of the following is not an example of a computer used as an instrument of crime?

A) theft of trade secrets
B) intentionally attempting to intercept electronic communication
C) unauthorized copying of software
D) breaching the confidentiality of protected computerized data
E) schemes to defraud
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
Hackers create a botnet by

A) infecting Web search bots with malware.
B) using Web search bots to infect other computers.
C) causing other people's computers to become "zombie" PCs following a master computer.
D) infecting corporate servers with "zombie" Trojan horses that allow undetected access through a back door.
E) pharming multiple computers.
سؤال
Which of the following is not an example of a computer used as a target of crime?

A) knowingly accessing a protected computer to commit fraud
B) sccessing a computer system without authority
C) illegally accessing stored electronic communication
D) threatening to cause damage to a protected computer
E) breaching the confidentiality of protected computerized data
سؤال
Social networking sites have become a new conduit for malware because

A) they are used by so many people.
B) they allow users to post media and image files.
C) they are especially vulnerable to social engineering.
D) they allow users to post software code.
E) they have poor user authentication.
سؤال
Large amounts of data stored in electronic form are ________ than the same data in manual form.

A) less vulnerable to damage
B) more secure
C) vulnerable to many more kinds of threats
D) more critical to most businesses
E) prone to more errors
سؤال
The communications lines in a client/server environment are specifically vulnerable to

A) vandalism.
B) malware.
C) software failure.
D) tapping.
E) errors.
سؤال
The intentional defacement or destruction of a Web site is called

A) spoofing.
B) cybervandalism.
C) cyberwarfare.
D) phishing.
E) pharming.
سؤال
A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's advertising costs up. This is an example of

A) phishing.
B) pharming.
C) spoofing.
D) evil twins.
E) click fraud.
سؤال
________ is malware that hijacks a user's computer and demands payment in return for giving back access.

A) A Trojan horse
B) Ransomware
C) Spyware
D) A virus
E) An evil twin
سؤال
________ refers to policies, procedures, and technical measures used to prevent unauthorized access, alteration, theft, or physical damage to information systems.

A) "Security"
B) "Controls"
C) "Benchmarking"
D) "Algorithms"
E) "Identity management"
سؤال
________ refers to all of the methods, policies, and organizational procedures that ensure the safety of the organization's assets, the accuracy and reliability of its accounting records, and operational adherence to management standards.

A) "Legacy systems"
B) "SSID standards"
C) "Vulnerabilities"
D) "Security policy"
E) "Controls"
سؤال
A Trojan horse

A) is software that appears to be benign but does something other than expected.
B) is a virus that replicates quickly.
C) is malware named for a breed of fast-moving Near-Eastern horses.
D) installs spyware on users' computers.
E) is a type of sniffer used to infiltrate corporate networks.
سؤال
In a client/server environment, corporate servers are specifically vulnerable to

A) unauthorized access.
B) sniffing.
C) malware.
D) radiation.
E) tapping.
سؤال
Electronic data are more susceptible to destruction, fraud, error, and misuse because information systems concentrate data in computer files that

A) are easily decrypted.
B) can be opened with easily available software.
C) may be accessible by anyone who has access to the same network.
D) are unprotected by up-to-date security systems.
E) are rarely validated.
سؤال
The Internet poses specific security problems because

A) it was designed to be easily accessible.
B) Internet data is not run over secure lines.
C) Internet standards are universal.
D) it changes so rapidly.
E) there is no formal controlling body.
سؤال
Using numerous computers to inundate and overwhelm the network from numerous launch points is called a(n) ________ attack.

A) DDoS
B) DoS
C) SQL injection
D) phishing
E) botnet
سؤال
Client software in a client/server environment is specifically vulnerable to

A) DoS attacks.
B) vandalism.
C) fraud.
D) radiation.
E) unauthorized access.
سؤال
Which of the following is a virus that uses flaws in Windows software to take over a computer remotely?

A) Sasser
B) Zeus Trojan
C) Melissa
D) ILOVEYOU
E) Conficker
سؤال
________ is malware that logs and transmits everything a user types.

A) Spyware
B) A Trojan horse
C) A keylogger
D) A worm
E) A sniffer
سؤال
Which of the following statements about the Internet security is not true?

A) The use of P2P networks can expose a corporate computer to outsiders.
B) A corporate network without access to the Internet is more secure than one that provides access.
C) VoIP is more secure than the switched voice network.
D) Instant messaging can provide hackers access to an otherwise secure network.
E) Smartphones have the same security weaknesses as other Internet devices.
سؤال
Pharming involves

A) redirecting users to a fraudulent Web site even when the user has typed in the correct address in the Web browser.
B) pretending to be a legitimate business's representative in order to garner information about a security system.
C) setting up fake Web sites to ask users for confidential information.
D) using e-mails for threats or harassment.
E) setting up fake Wi-Fi access points that look as if they are legitimate public networks.
سؤال
A practice in which eavesdroppers drive by buildings or park outside and try to intercept wireless network traffic is referred to as

A) war driving.
B) sniffing.
C) cybervandalism.
D) drive-by tapping.
E) snooping.
سؤال
A computer virus replicates more quickly than a computer worm.
سؤال
Sniffers enable hackers to steal proprietary information from anywhere on a network, including e-mail messages, company files, and confidential reports.
سؤال
A foreign country attempting to access government networks in order to disable a national power grid would be an example of

A) phishing.
B) denial-of-service attacks.
C) cyberwarfare.
D) cyberterrorism.
E) evil twins.
سؤال
One form of spoofing involves forging the return address on an e-mail so that the e-mail message appears to come from someone other than the sender.
سؤال
________ identify the access points in a Wi-Fi network.

A) NICs
B) Mac addresses
C) URLs
D) UTMs
E) SSIDs
سؤال
As discussed in the chapter opening case, magnetic stripes are an old technology that is vulnerable to counterfeit and theft.
سؤال
Smartphones have the same security flaws as other Internet-connected devices.
سؤال
The term cracker is used to identify a hacker whose specialty is breaking open security systems.
سؤال
________ is a crime in which an imposter obtains key pieces of personal information to impersonate someone else.

A) Identity theft
B) Spoofing
C) Social engineering
D) Evil twins
E) Pharming
سؤال
You have been hired as a security consultant for a law firm. Which of the following constitutes the greatest source for network security breaches to the firm?

A) wireless network
B) employees
C) authentication procedures
D) lack of data encryption
E) software quality
سؤال
Viruses can be spread through e-mail.
سؤال
Wireless networks are more difficult for hackers to gain access too because radio frequency bands are difficult to scan.
سؤال
How do software vendors correct flaws in their software after it has been distributed?

A) They issue bug fixes.
B) They issue patches.
C) They re-release the software.
D) They release updated versions of the software.
E) They don't; users purchase software at their own risk.
سؤال
Zero defects cannot be achieved in larger software programs because fully testing programs that contain thousands of choices and millions of paths would require thousands of years.
سؤال
Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is called

A) sniffing.
B) social engineering.
C) phishing.
D) pharming.
E) snooping
سؤال
In 2013, Panda Security reported approximately 30 million new kinds of malware strains.
سؤال
Evil twins are

A) Trojan horses that appears to the user to be a legitimate commercial software application.
B) e-mail messages that mimic the e-mail messages of a legitimate business.
C) fraudulent Web sites that mimic a legitimate business's Web site.
D) computers that fraudulently access a Web site or network using the IP address and identification of an authorized computer.
E) bogus wireless network access points that look legitimate to users.
سؤال
DoS attacks are used to destroy information and access restricted areas of a company's information system.
سؤال
Statements ranking information risks and identifying security goals are included in a(n)

A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.
E) business continuity plan.
سؤال
The most common type of electronic evidence is

A) voice-mail.
B) spreadsheets.
C) instant messages.
D) e-mail.
E) VOIP data.
سؤال
Which of the following specifications replaces WEP with a stronger security standard that features changing encryption keys?

A) TLS
B) AUP
C) VPN
D) WPA2
E) UTM
سؤال
The HIPAA Act of 1996

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
سؤال
The Gramm-Leach-Bliley Act

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
سؤال
What are the security challenges faced by wireless networks?
سؤال
Your company, an online discount stationers, has calculated that a loss of Internet connectivity for 3 hours results in a potential loss of $2,000 to $3,000 and that there is a 50% chance of this occurring each year. What is the annual expected loss from this exposure?

A) $500
B) $1,000
C) $1,250
D) $1,500
E) $2,500
سؤال
Computer forensics tasks include all of the following except

A) presenting collected evidence in a court of law.
B) securely storing recovered electronic data.
C) collecting physical evidence on the computer.
D) finding significant information in a large volume of electronic data.
سؤال
How can a firm's security policies contribute and relate to the six main business objectives?
Give examples.
سؤال
The Sarbanes-Oxley Act

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
سؤال
________ controls ensure that valuable business data files on either disk or tape are not subject to unauthorized access, change, or destruction while they are in use or in storage.

A) Software
B) Administrative
C) Data security
D) Implementation
E) Input
سؤال
Three major concerns of system builders and users are disaster, security, and human error. Of the three, which do you think is most difficult to deal with?
Why?
سؤال
Explain how an SQL injection attack works and what types of systems are vulnerable to this type of attack.
سؤال
Analysis of an information system that rates the likelihood of a security incident occurring and its cost is included in a(n)

A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.
E) business continuity plan.
سؤال
Which of the following is a type of ambient data?

A) computer log containing recent system errors
B) a file deleted from a hard disk
C) a file that contains an application's user settings
D) a set of raw data from an environmental sensor
E) data that has been recorded over
سؤال
Malicious software programs referred to as spyware include a variety of threats such as computer viruses, worms, and Trojan horses.
سؤال
Application controls

A) can be classified as input controls, processing controls, and output controls.
B) govern the design, security, and use of computer programs and the security of data files in general throughout the organization.
C) apply to all computerized applications and consist of a combination of hardware, software, and manual procedures that create an overall control environment.
D) include software controls, computer operations controls, and implementation controls.
E) monitor the use of system software and prevent unauthorized access to software and programs.
سؤال
How is the security of a firm's information system and data affected by its people, organization, and technology?
Is the contribution of one of these dimensions any more important than the other?
Why?
سؤال
Hackers and their companion viruses are an increasing problem, especially on the Internet. What are the most important measurers for a firm to take to protect itself from this?
Is full protection feasible?
Why or why not?
سؤال
An acceptable use policy defines the acceptable level of access to information assets for different users.
سؤال
Smaller firms may outsource some or many security functions to

A) ISPs.
B) MISs.
C) MSSPs.
D) CAs.
E) PKIs.
سؤال
An authentication token is a(n)

A) device the size of a credit card that contains access permission data.
B) type of smart card.
C) gadget that displays passcodes.
D) electronic marker attached to a digital authorization file.
سؤال
Most antivirus software is effective against

A) only those viruses active on the Internet and through e-mail.
B) any virus.
C) any virus except those in wireless communications applications.
D) only those viruses already known when the software is written.
E) only viruses that are well-known and typically several years old.
سؤال
A digital certificate system

A) uses third-party CAs to validate a user's identity.
B) uses digital signatures to validate a user's identity.
C) uses tokens to validate a user's identity.
D) is used primarily by individuals for personal correspondence.
E) protects a user's identity by substituting a certificate in place of identifiable traits.
سؤال
All of the following are types of information systems general controls except

A) application controls.
B) computer operations controls.
C) physical hardware controls.
D) software controls.
E) administrative controls
سؤال
A firewall allows the organization to

A) enforce a security policy on data exchanged between its network and the Internet.
B) check the accuracy of all transactions between its network and the Internet.
C) create an enterprise system on the Internet.
D) check the content of all incoming and outgoing e-mail messages.
E) create access rules for a network.
سؤال
The dispersed nature of cloud computing makes it difficult to track unauthorized access.
سؤال
Biometric authentication

A) is inexpensive.
B) is used widely in Europe for security applications.
C) can use a person's voice as a unique, measurable trait.
D) only uses physical measurements for identification.
E) only uses biographical details for identification.
سؤال
For 100-percent availability, online transaction processing requires

A) high-capacity storage.
B) a multi-tier server network.
C) fault-tolerant computer systems.
D) dedicated phone lines.
E) a digital certificate system.
سؤال
In controlling network traffic to minimize slow-downs, a technology called ________ is used to examine data files and sort low-priority data from high-priority data.

A) high availability computing
B) deep-packet inspection
C) application proxy filtering
D) stateful inspection
E) unified threat management
سؤال
Packet filtering catches most types of network attacks.
سؤال
In which method of encryption is a single encryption key sent to the receiver so both sender and receiver share the same key?

A) SSL/TLS
B) symmetric key encryption
C) public key encryption
D) private key encryption
E) distributed encryption
سؤال
An authentication system in which a user must provide two types of identification, such as a bank card and PIN, is called

A) smart card authentication.
B) biometric authentication.
C) two-factor authentication.
D) symmetric key authorization.
E) token authentication.
سؤال
Organizations can use existing network security software to secure mobile devices.
سؤال
________ use scanning software to look for known problems such as bad passwords, the removal of important files, security attacks in progress, and system administration errors.

A) Stateful inspections
B) Intrusion detection systems
C) Application proxy filtering technologies
D) Packet filtering technologies
E) Firewalls
سؤال
NAT conceals the IP addresses of the organization's internal host computers to deter sniffer programs.
سؤال
Currently, the protocols used for secure information transfer over the Internet are

A) TCP/IP and SSL.
B) S-HTTP and CA.
C) HTTP and TCP/IP.
D) S-HTTP and SHTML.
E) SSL, TLS, and S-HTTP.
سؤال
Comprehensive security management products, with tools for firewalls, VPNs, intrusion detection systems, and more, are called ________ systems.

A) DPI
B) MSSP
C) NSP
D) PKI
E) UTM
سؤال
Biometric authentication is the use of personal, biographic details such as the high school you attended and the first street you lived on to provide identification.
سؤال
Rigorous password systems

A) are one of the most effective security tools.
B) may hinder employee productivity.
C) are costly to implement.
D) are often disregarded by employees.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/90
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 8: Securing Information Systems
1
Which of the following is not an example of a computer used as an instrument of crime?

A) theft of trade secrets
B) intentionally attempting to intercept electronic communication
C) unauthorized copying of software
D) breaching the confidentiality of protected computerized data
E) schemes to defraud
D
2
Hackers create a botnet by

A) infecting Web search bots with malware.
B) using Web search bots to infect other computers.
C) causing other people's computers to become "zombie" PCs following a master computer.
D) infecting corporate servers with "zombie" Trojan horses that allow undetected access through a back door.
E) pharming multiple computers.
C
3
Which of the following is not an example of a computer used as a target of crime?

A) knowingly accessing a protected computer to commit fraud
B) sccessing a computer system without authority
C) illegally accessing stored electronic communication
D) threatening to cause damage to a protected computer
E) breaching the confidentiality of protected computerized data
C
4
Social networking sites have become a new conduit for malware because

A) they are used by so many people.
B) they allow users to post media and image files.
C) they are especially vulnerable to social engineering.
D) they allow users to post software code.
E) they have poor user authentication.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
5
Large amounts of data stored in electronic form are ________ than the same data in manual form.

A) less vulnerable to damage
B) more secure
C) vulnerable to many more kinds of threats
D) more critical to most businesses
E) prone to more errors
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
6
The communications lines in a client/server environment are specifically vulnerable to

A) vandalism.
B) malware.
C) software failure.
D) tapping.
E) errors.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
7
The intentional defacement or destruction of a Web site is called

A) spoofing.
B) cybervandalism.
C) cyberwarfare.
D) phishing.
E) pharming.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
8
A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's advertising costs up. This is an example of

A) phishing.
B) pharming.
C) spoofing.
D) evil twins.
E) click fraud.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
9
________ is malware that hijacks a user's computer and demands payment in return for giving back access.

A) A Trojan horse
B) Ransomware
C) Spyware
D) A virus
E) An evil twin
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
10
________ refers to policies, procedures, and technical measures used to prevent unauthorized access, alteration, theft, or physical damage to information systems.

A) "Security"
B) "Controls"
C) "Benchmarking"
D) "Algorithms"
E) "Identity management"
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
11
________ refers to all of the methods, policies, and organizational procedures that ensure the safety of the organization's assets, the accuracy and reliability of its accounting records, and operational adherence to management standards.

A) "Legacy systems"
B) "SSID standards"
C) "Vulnerabilities"
D) "Security policy"
E) "Controls"
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
12
A Trojan horse

A) is software that appears to be benign but does something other than expected.
B) is a virus that replicates quickly.
C) is malware named for a breed of fast-moving Near-Eastern horses.
D) installs spyware on users' computers.
E) is a type of sniffer used to infiltrate corporate networks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
13
In a client/server environment, corporate servers are specifically vulnerable to

A) unauthorized access.
B) sniffing.
C) malware.
D) radiation.
E) tapping.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
14
Electronic data are more susceptible to destruction, fraud, error, and misuse because information systems concentrate data in computer files that

A) are easily decrypted.
B) can be opened with easily available software.
C) may be accessible by anyone who has access to the same network.
D) are unprotected by up-to-date security systems.
E) are rarely validated.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
15
The Internet poses specific security problems because

A) it was designed to be easily accessible.
B) Internet data is not run over secure lines.
C) Internet standards are universal.
D) it changes so rapidly.
E) there is no formal controlling body.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
16
Using numerous computers to inundate and overwhelm the network from numerous launch points is called a(n) ________ attack.

A) DDoS
B) DoS
C) SQL injection
D) phishing
E) botnet
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
17
Client software in a client/server environment is specifically vulnerable to

A) DoS attacks.
B) vandalism.
C) fraud.
D) radiation.
E) unauthorized access.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
18
Which of the following is a virus that uses flaws in Windows software to take over a computer remotely?

A) Sasser
B) Zeus Trojan
C) Melissa
D) ILOVEYOU
E) Conficker
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
19
________ is malware that logs and transmits everything a user types.

A) Spyware
B) A Trojan horse
C) A keylogger
D) A worm
E) A sniffer
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
20
Which of the following statements about the Internet security is not true?

A) The use of P2P networks can expose a corporate computer to outsiders.
B) A corporate network without access to the Internet is more secure than one that provides access.
C) VoIP is more secure than the switched voice network.
D) Instant messaging can provide hackers access to an otherwise secure network.
E) Smartphones have the same security weaknesses as other Internet devices.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
21
Pharming involves

A) redirecting users to a fraudulent Web site even when the user has typed in the correct address in the Web browser.
B) pretending to be a legitimate business's representative in order to garner information about a security system.
C) setting up fake Web sites to ask users for confidential information.
D) using e-mails for threats or harassment.
E) setting up fake Wi-Fi access points that look as if they are legitimate public networks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
22
A practice in which eavesdroppers drive by buildings or park outside and try to intercept wireless network traffic is referred to as

A) war driving.
B) sniffing.
C) cybervandalism.
D) drive-by tapping.
E) snooping.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
23
A computer virus replicates more quickly than a computer worm.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
24
Sniffers enable hackers to steal proprietary information from anywhere on a network, including e-mail messages, company files, and confidential reports.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
25
A foreign country attempting to access government networks in order to disable a national power grid would be an example of

A) phishing.
B) denial-of-service attacks.
C) cyberwarfare.
D) cyberterrorism.
E) evil twins.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
26
One form of spoofing involves forging the return address on an e-mail so that the e-mail message appears to come from someone other than the sender.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
27
________ identify the access points in a Wi-Fi network.

A) NICs
B) Mac addresses
C) URLs
D) UTMs
E) SSIDs
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
28
As discussed in the chapter opening case, magnetic stripes are an old technology that is vulnerable to counterfeit and theft.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
29
Smartphones have the same security flaws as other Internet-connected devices.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
30
The term cracker is used to identify a hacker whose specialty is breaking open security systems.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
31
________ is a crime in which an imposter obtains key pieces of personal information to impersonate someone else.

A) Identity theft
B) Spoofing
C) Social engineering
D) Evil twins
E) Pharming
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
32
You have been hired as a security consultant for a law firm. Which of the following constitutes the greatest source for network security breaches to the firm?

A) wireless network
B) employees
C) authentication procedures
D) lack of data encryption
E) software quality
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
33
Viruses can be spread through e-mail.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
34
Wireless networks are more difficult for hackers to gain access too because radio frequency bands are difficult to scan.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
35
How do software vendors correct flaws in their software after it has been distributed?

A) They issue bug fixes.
B) They issue patches.
C) They re-release the software.
D) They release updated versions of the software.
E) They don't; users purchase software at their own risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
36
Zero defects cannot be achieved in larger software programs because fully testing programs that contain thousands of choices and millions of paths would require thousands of years.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
37
Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is called

A) sniffing.
B) social engineering.
C) phishing.
D) pharming.
E) snooping
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
38
In 2013, Panda Security reported approximately 30 million new kinds of malware strains.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
39
Evil twins are

A) Trojan horses that appears to the user to be a legitimate commercial software application.
B) e-mail messages that mimic the e-mail messages of a legitimate business.
C) fraudulent Web sites that mimic a legitimate business's Web site.
D) computers that fraudulently access a Web site or network using the IP address and identification of an authorized computer.
E) bogus wireless network access points that look legitimate to users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
40
DoS attacks are used to destroy information and access restricted areas of a company's information system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
41
Statements ranking information risks and identifying security goals are included in a(n)

A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.
E) business continuity plan.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
42
The most common type of electronic evidence is

A) voice-mail.
B) spreadsheets.
C) instant messages.
D) e-mail.
E) VOIP data.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
43
Which of the following specifications replaces WEP with a stronger security standard that features changing encryption keys?

A) TLS
B) AUP
C) VPN
D) WPA2
E) UTM
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
44
The HIPAA Act of 1996

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
45
The Gramm-Leach-Bliley Act

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
46
What are the security challenges faced by wireless networks?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
47
Your company, an online discount stationers, has calculated that a loss of Internet connectivity for 3 hours results in a potential loss of $2,000 to $3,000 and that there is a 50% chance of this occurring each year. What is the annual expected loss from this exposure?

A) $500
B) $1,000
C) $1,250
D) $1,500
E) $2,500
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
48
Computer forensics tasks include all of the following except

A) presenting collected evidence in a court of law.
B) securely storing recovered electronic data.
C) collecting physical evidence on the computer.
D) finding significant information in a large volume of electronic data.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
49
How can a firm's security policies contribute and relate to the six main business objectives?
Give examples.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
50
The Sarbanes-Oxley Act

A) requires financial institutions to ensure the security of customer data.
B) specifies best practices in information systems security and control.
C) imposes responsibility on companies and management to safeguard the accuracy of financial information.
D) outlines medical security and privacy rules.
E) identifies computer abuse as a crime and defines abusive activities.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
51
________ controls ensure that valuable business data files on either disk or tape are not subject to unauthorized access, change, or destruction while they are in use or in storage.

A) Software
B) Administrative
C) Data security
D) Implementation
E) Input
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
52
Three major concerns of system builders and users are disaster, security, and human error. Of the three, which do you think is most difficult to deal with?
Why?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
53
Explain how an SQL injection attack works and what types of systems are vulnerable to this type of attack.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
54
Analysis of an information system that rates the likelihood of a security incident occurring and its cost is included in a(n)

A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.
E) business continuity plan.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
55
Which of the following is a type of ambient data?

A) computer log containing recent system errors
B) a file deleted from a hard disk
C) a file that contains an application's user settings
D) a set of raw data from an environmental sensor
E) data that has been recorded over
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
56
Malicious software programs referred to as spyware include a variety of threats such as computer viruses, worms, and Trojan horses.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
57
Application controls

A) can be classified as input controls, processing controls, and output controls.
B) govern the design, security, and use of computer programs and the security of data files in general throughout the organization.
C) apply to all computerized applications and consist of a combination of hardware, software, and manual procedures that create an overall control environment.
D) include software controls, computer operations controls, and implementation controls.
E) monitor the use of system software and prevent unauthorized access to software and programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
58
How is the security of a firm's information system and data affected by its people, organization, and technology?
Is the contribution of one of these dimensions any more important than the other?
Why?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
59
Hackers and their companion viruses are an increasing problem, especially on the Internet. What are the most important measurers for a firm to take to protect itself from this?
Is full protection feasible?
Why or why not?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
60
An acceptable use policy defines the acceptable level of access to information assets for different users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
61
Smaller firms may outsource some or many security functions to

A) ISPs.
B) MISs.
C) MSSPs.
D) CAs.
E) PKIs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
62
An authentication token is a(n)

A) device the size of a credit card that contains access permission data.
B) type of smart card.
C) gadget that displays passcodes.
D) electronic marker attached to a digital authorization file.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
63
Most antivirus software is effective against

A) only those viruses active on the Internet and through e-mail.
B) any virus.
C) any virus except those in wireless communications applications.
D) only those viruses already known when the software is written.
E) only viruses that are well-known and typically several years old.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
64
A digital certificate system

A) uses third-party CAs to validate a user's identity.
B) uses digital signatures to validate a user's identity.
C) uses tokens to validate a user's identity.
D) is used primarily by individuals for personal correspondence.
E) protects a user's identity by substituting a certificate in place of identifiable traits.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
65
All of the following are types of information systems general controls except

A) application controls.
B) computer operations controls.
C) physical hardware controls.
D) software controls.
E) administrative controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
66
A firewall allows the organization to

A) enforce a security policy on data exchanged between its network and the Internet.
B) check the accuracy of all transactions between its network and the Internet.
C) create an enterprise system on the Internet.
D) check the content of all incoming and outgoing e-mail messages.
E) create access rules for a network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
67
The dispersed nature of cloud computing makes it difficult to track unauthorized access.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
68
Biometric authentication

A) is inexpensive.
B) is used widely in Europe for security applications.
C) can use a person's voice as a unique, measurable trait.
D) only uses physical measurements for identification.
E) only uses biographical details for identification.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
69
For 100-percent availability, online transaction processing requires

A) high-capacity storage.
B) a multi-tier server network.
C) fault-tolerant computer systems.
D) dedicated phone lines.
E) a digital certificate system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
70
In controlling network traffic to minimize slow-downs, a technology called ________ is used to examine data files and sort low-priority data from high-priority data.

A) high availability computing
B) deep-packet inspection
C) application proxy filtering
D) stateful inspection
E) unified threat management
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
71
Packet filtering catches most types of network attacks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
72
In which method of encryption is a single encryption key sent to the receiver so both sender and receiver share the same key?

A) SSL/TLS
B) symmetric key encryption
C) public key encryption
D) private key encryption
E) distributed encryption
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
73
An authentication system in which a user must provide two types of identification, such as a bank card and PIN, is called

A) smart card authentication.
B) biometric authentication.
C) two-factor authentication.
D) symmetric key authorization.
E) token authentication.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
74
Organizations can use existing network security software to secure mobile devices.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
75
________ use scanning software to look for known problems such as bad passwords, the removal of important files, security attacks in progress, and system administration errors.

A) Stateful inspections
B) Intrusion detection systems
C) Application proxy filtering technologies
D) Packet filtering technologies
E) Firewalls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
76
NAT conceals the IP addresses of the organization's internal host computers to deter sniffer programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
77
Currently, the protocols used for secure information transfer over the Internet are

A) TCP/IP and SSL.
B) S-HTTP and CA.
C) HTTP and TCP/IP.
D) S-HTTP and SHTML.
E) SSL, TLS, and S-HTTP.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
78
Comprehensive security management products, with tools for firewalls, VPNs, intrusion detection systems, and more, are called ________ systems.

A) DPI
B) MSSP
C) NSP
D) PKI
E) UTM
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
79
Biometric authentication is the use of personal, biographic details such as the high school you attended and the first street you lived on to provide identification.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
80
Rigorous password systems

A) are one of the most effective security tools.
B) may hinder employee productivity.
C) are costly to implement.
D) are often disregarded by employees.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.