Deck 7: Securing Information Systems

ملء الشاشة (f)
exit full mode
سؤال
The distributed nature of cloud computing makes it somewhat easier to track unauthorized access.
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
High-availability computing is also referred to as fault tolerance.
سؤال
Sniffers enable hackers to steal proprietary information from anywhere on a network,including e-mail messages,company files,and confidential reports.
سؤال
The term cracker is used to identify a hacker whose specialty is breaking open security systems.
سؤال
Computer worms spread much more rapidly than computer viruses.
سؤال
One form of spoofing involves forging the return address on an e-mail so that the e-mail message appears to come from someone other than the sender.
سؤال
DoS attacks are used to destroy information and access restricted areas of a company's information system.
سؤال
Biometric authentication is the use of physical characteristics such as retinal images to provide identification.
سؤال
An acceptable use policy defines the acceptable level of access to information assets for different users.
سؤال
SSL is a protocol used to establish a secure connection between two computers.
سؤال
Zero defects cannot be achieved in larger software programs because fully testing programs that contain thousands of choices and millions of paths would require thousands of years.
سؤال
NAT conceals the IP addresses of the organization's internal host computers to deter sniffer programs.
سؤال
Smartphones have the same security flaws as other Internet-connected devices.
سؤال
To secure mobile devices,a company will need to implement special mobile device management software.
سؤال
Public key encryption uses two keys.
سؤال
Smartphones typically feature state-of-the-art encryption and security features,making them highly secure tools for businesses.
سؤال
Viruses can be spread through e-mail.
سؤال
Wireless networks are vulnerable to penetration because radio frequency bands are easy to scan.
سؤال
Computers using cable modems to connect to the Internet are more open to penetration than those connecting via dial-up.
سؤال
Packet filtering catches most types of network attacks.
سؤال
Redirecting a Web link to a different address is a form of:

A)snooping.
B)spoofing.
C)sniffing.
D)war driving.
سؤال
Large amounts of data stored in electronic form are ________ than the same data in manual form.

A)less vulnerable to damage
B)more secure
C)vulnerable to many more kinds of threats
D)more critical to most businesses
سؤال
________ refers to all of the methods,policies,and organizational procedures that ensure the safety of the organization's assets,the accuracy and reliability of its accounting records,and operational adherence to management standards.

A)"Legacy systems"
B)"SSID standards"
C)"Vulnerabilities"
D)"Controls"
سؤال
The Internet poses specific security problems because:

A)it was designed to be easily accessible.
B)Internet data is not run over secure lines.
C)Internet standards are universal.
D)it changes so rapidly.
سؤال
In 2004,ICQ users were enticed by a sales message from a supposed anti-virus vendor.On the vendor's site,a small program called Mitglieder was downloaded to the user's machine.The program enabled outsiders to infiltrate the user's machine.What type of malware is this an example of?

A)Trojan horse
B)Virus
C)Worm
D)Spyware
سؤال
An independent computer program that copies itself from one computer to another over a network is called a:

A)worm.
B)Trojan horse.
C)bug.
D)pest.
سؤال
________ refers to policies,procedures,and technical measures used to prevent unauthorized access,alteration,theft,or physical damage to information systems.

A)"Security"
B)"Controls"
C)"Benchmarking"
D)"Algorithms"
سؤال
Specific security challenges that threaten the communications lines in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
سؤال
Specific security challenges that threaten clients in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
سؤال
Using numerous computers to inundate and overwhelm the network from numerous launch points is called a(n)________ attack.

A)DDoS
B)DoS
C)SQL injection
D)phishing
سؤال
Specific security challenges that threaten corporate servers in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
سؤال
A keylogger is a type of:

A)worm.
B)Trojan horse.
C)virus.
D)spyware.
سؤال
Phishing is a form of:

A)spoofing.
B)logging.
C)sniffing.
D)driving.
سؤال
A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's advertising costs up.This is an example of:

A)phishing.
B)pharming.
C)spoofing.
D)click fraud.
سؤال
Which of the following statements about the Internet security is not true?

A)The use of P2P networks can expose a corporate computer to outsiders.
B)A corporate network without access to the Internet is more secure than one that provides access.
C)VoIP is more secure than the switched voice network.
D)Instant messaging can provide hackers access to an otherwise secure network.
سؤال
An example of phishing is:

A)setting up a bogus Wi-Fi hot spot.
B)setting up a fake medical Web site that asks users for confidential information.
C)pretending to be a utility company's employee in order to garner information from that company about their security system.
D)sending bulk e-mail that asks for financial aid under a false pretext.
سؤال
Electronic data are more susceptible to destruction,fraud,error,and misuse because information systems concentrate data in computer files that:

A)are easily decrypted.
B)can be opened with easily available software.
C)may be accessible by anyone who has access to the same network.
D)are unprotected by up-to-date security systems.
سؤال
Hackers create a botnet by:

A)infecting Web search bots with malware.
B)using Web search bots to infect other computers.
C)causing other people's computers to become "zombie" PCs following a master computer.
D)infecting corporate servers with "zombie" Trojan horses that allow undetected access through a back door.
سؤال
Which of the following is not an example of a computer used as a target of crime?

A)Knowingly accessing a protected computer to commit fraud
B)Accessing a computer system without authority
C)Illegally accessing stored electronic communication
D)Threatening to cause damage to a protected computer
سؤال
Which of the following is not an example of a computer used as an instrument of crime?

A)Theft of trade secrets
B)Intentionally attempting to intercept electronic communication
C)Unauthorized copying of software
D)Breaching the confidentiality of protected computerized data
سؤال
How do software vendors correct flaws in their software after it has been distributed?

A)They issue bug fixes.
B)They issue patches.
C)They re-release the software.
D)They release updated versions of the software.
سؤال
Evil twins are:

A)Trojan horses that appears to the user to be a legitimate commercial software application.
B)e-mail messages that mimic the e-mail messages of a legitimate business.
C)fraudulent Web sites that mimic a legitimate business's Web site.
D)bogus wireless network access points that look legitimate to users.
سؤال
Analysis of an information system that rates the likelihood of a security incident occurring and its cost is included in a(n):

A)security policy.
B)AUP.
C)risk assessment.
D)business impact analysis.
سؤال
Rigorous password systems:

A)are one of the most effective security tools.
B)may hinder employee productivity.
C)are costly to implement.
D)are often disregarded by employees.
سؤال
Biometric authentication:

A)is inexpensive.
B)is used widely in Europe for security applications.
C)can use a person's voice as a unique,measurable trait.
D)only uses physical measurements for identification.
سؤال
________ controls ensure that valuable business data files on either disk or tape are not subject to unauthorized access,change,or destruction while they are in use or in storage.

A)Software
B)Administrative
C)Data security
D)Implementation
سؤال
Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is called:

A)sniffing.
B)social engineering.
C)phishing.
D)pharming.
سؤال
The most common type of electronic evidence is:

A)voice-mail.
B)spreadsheets.
C)instant messages.
D)e-mail.
سؤال
You have been hired as a security consultant for a law firm.Which of the following constitutes the greatest source of security threats to the firm?

A)Wireless network
B)Employees
C)Authentication procedures
D)Lack of data encryption
سؤال
Electronic evidence on computer storage media that is not visible to the average user is called ________ data.

A)defragmented
B)ambient
C)forensic
D)fragmented
سؤال
Application controls:

A)can be classified as input controls,processing controls,and output controls.
B)govern the design,security,and use of computer programs and the security of data files in general throughout the organization.
C)apply to all computerized applications and consist of a combination of hardware,software,and manual procedures that create an overall control environment.
D)include software controls,computer operations controls,and implementation controls.
سؤال
An authentication token is a(n):

A)device the size of a credit card that contains access permission data.
B)type of smart card.
C)gadget that displays passcodes.
D)electronic marker attached to a digital authorization file.
سؤال
The Sarbanes-Oxley Act:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
سؤال
The Gramm-Leach-Bliley Act:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
سؤال
A firewall identifies all of the following characteristics of incoming traffic,except:

A)user names.
B)biometric authentication.
C)IP addresses.
D)applications.
سؤال
Which of the following specifications replaces WEP with a stronger security standard that features changing encryption keys?

A)TLS
B)AUP
C)VPN
D)WPA2
سؤال
Pharming involves:

A)redirecting users to a fraudulent Web site even when the user has typed in the correct address in the Web browser.
B)pretending to be a legitimate business's representative in order to garner information about a security system.
C)setting up fake Web sites to ask users for confidential information.
D)using e-mails for threats or harassment.
سؤال
The HIPAA Act of 1996:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
سؤال
A firewall allows the organization to:

A)enforce a security policy on data exchanged between its network and the Internet.
B)check the accuracy of all transactions between its network and the Internet.
C)create an enterprise system on the Internet.
D)check the content of all incoming and outgoing e-mail messages.
سؤال
Statements ranking information risks and identifying security goals are included in a(n):

A)security policy.
B)AUP.
C)risk assessment.
D)business impact analysis.
سؤال
A walkthrough is a type of software testing used before software is even written.
سؤال
________ use scanning software to look for known problems such as bad passwords,the removal of important files,security attacks in progress,and system administration errors.

A)Stateful inspections
B)Intrusion detection systems
C)Application proxy filtering technologies
D)Packet filtering technologies
سؤال
________ identify the access points in a Wi-Fi network.

A)NICs
B)Mac addresses
C)URLs
D)SSIDs
سؤال
A(n)________ audit examines the firm's overall security environment as well as the controls governing individual information systems.

A)security
B)MIS
C)network
D)software
سؤال
Currently,the protocols used for secure information transfer over the Internet are:

A)TCP/IP and SSL.
B)S-HTTP and CA.
C)HTTP and TCP/IP.
D)SSL,TLS,and S-HTTP.
سؤال
In controlling network traffic to minimize slow-downs,a technology called ________ is used to examine data files and sort low-priority data from high-priority data.

A)high availability computing
B)deep-packet inspection
C)application proxy filtering
D)stateful inspection
سؤال
________ is a crime in which an imposter obtains key pieces of personal information to impersonate someone else.

A)Identity theft
B)Spoofing
C)Social engineering
D)Evil twins
سؤال
When errors are discovered in software programs,the sources of the errors are found and eliminated through a process called debugging.
سؤال
In which method of encryption is a single encryption key sent to the receiver so both sender and receiver share the same key?

A)SSL
B)Symmetric key encryption
C)Public key encryption
D)Private key encryption
سؤال
The development and use of methods to make computer systems resume their activities more quickly after mishaps is called:

A)high-availability computing.
B)recovery-oriented computing.
C)fault-tolerant computing.
D)disaster-recovery planning.
سؤال
A digital certificate system:

A)uses third-party CAs to validate a user's identity.
B)uses digital signatures to validate a user's identity.
C)uses tokens to validate a user's identity.
D)is used primarily by individuals for personal correspondence.
سؤال
Most antivirus software is effective against:

A)only those viruses active on the Internet and through e-mail.
B)any virus.
C)any virus except those in wireless communications applications.
D)only those viruses already known when the software is written.
سؤال
Downtime refers to periods of time in which a:

A)computer system is malfunctioning.
B)computer system is not operational.
C)company or organization is not operational.
D)computer is not online.
سؤال
Comprehensive security management products,with tools for firewalls,VPNs,intrusion detection systems,and more,are called ________ systems.

A)DPI
B)MSSP
C)NSP
D)UTM
سؤال
Malicious software programs referred to as spyware include a variety of threats such as computer viruses,worms,and Trojan horses.
سؤال
For 100% availability,online transaction processing requires:

A)high-capacity storage.
B)a multi-tier server network.
C)fault-tolerant computer systems.
D)dedicated phone lines.
سؤال
Computer forensics tasks include all of the following except:

A)presenting collected evidence in a court of law.
B)securely storing recovered electronic data.
C)collecting physical evidence on the computer.
D)finding significant information in a large volume of electronic data.
سؤال
A practice in which eavesdroppers drive by buildings or park outside and try to intercept wireless network traffic is referred to as:

A)war driving.
B)sniffing.
C)cybervandalism.
D)driveby tapping.
سؤال
Authorization refers to the ability to know that a person is who he or she claims to be.
سؤال
Smaller firms may outsource some or many security functions to:

A)ISPs.
B)MISs.
C)MSSPs.
D)CAs.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/90
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 7: Securing Information Systems
1
The distributed nature of cloud computing makes it somewhat easier to track unauthorized access.
False
2
High-availability computing is also referred to as fault tolerance.
False
3
Sniffers enable hackers to steal proprietary information from anywhere on a network,including e-mail messages,company files,and confidential reports.
True
4
The term cracker is used to identify a hacker whose specialty is breaking open security systems.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
5
Computer worms spread much more rapidly than computer viruses.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
6
One form of spoofing involves forging the return address on an e-mail so that the e-mail message appears to come from someone other than the sender.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
7
DoS attacks are used to destroy information and access restricted areas of a company's information system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
8
Biometric authentication is the use of physical characteristics such as retinal images to provide identification.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
9
An acceptable use policy defines the acceptable level of access to information assets for different users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
10
SSL is a protocol used to establish a secure connection between two computers.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
11
Zero defects cannot be achieved in larger software programs because fully testing programs that contain thousands of choices and millions of paths would require thousands of years.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
12
NAT conceals the IP addresses of the organization's internal host computers to deter sniffer programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
13
Smartphones have the same security flaws as other Internet-connected devices.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
14
To secure mobile devices,a company will need to implement special mobile device management software.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
15
Public key encryption uses two keys.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
16
Smartphones typically feature state-of-the-art encryption and security features,making them highly secure tools for businesses.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
17
Viruses can be spread through e-mail.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
18
Wireless networks are vulnerable to penetration because radio frequency bands are easy to scan.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
19
Computers using cable modems to connect to the Internet are more open to penetration than those connecting via dial-up.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
20
Packet filtering catches most types of network attacks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
21
Redirecting a Web link to a different address is a form of:

A)snooping.
B)spoofing.
C)sniffing.
D)war driving.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
22
Large amounts of data stored in electronic form are ________ than the same data in manual form.

A)less vulnerable to damage
B)more secure
C)vulnerable to many more kinds of threats
D)more critical to most businesses
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
23
________ refers to all of the methods,policies,and organizational procedures that ensure the safety of the organization's assets,the accuracy and reliability of its accounting records,and operational adherence to management standards.

A)"Legacy systems"
B)"SSID standards"
C)"Vulnerabilities"
D)"Controls"
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
24
The Internet poses specific security problems because:

A)it was designed to be easily accessible.
B)Internet data is not run over secure lines.
C)Internet standards are universal.
D)it changes so rapidly.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
25
In 2004,ICQ users were enticed by a sales message from a supposed anti-virus vendor.On the vendor's site,a small program called Mitglieder was downloaded to the user's machine.The program enabled outsiders to infiltrate the user's machine.What type of malware is this an example of?

A)Trojan horse
B)Virus
C)Worm
D)Spyware
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
26
An independent computer program that copies itself from one computer to another over a network is called a:

A)worm.
B)Trojan horse.
C)bug.
D)pest.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
27
________ refers to policies,procedures,and technical measures used to prevent unauthorized access,alteration,theft,or physical damage to information systems.

A)"Security"
B)"Controls"
C)"Benchmarking"
D)"Algorithms"
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
28
Specific security challenges that threaten the communications lines in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
29
Specific security challenges that threaten clients in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
30
Using numerous computers to inundate and overwhelm the network from numerous launch points is called a(n)________ attack.

A)DDoS
B)DoS
C)SQL injection
D)phishing
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
31
Specific security challenges that threaten corporate servers in a client/server environment include:

A)tapping;sniffing;message alteration;radiation.
B)hacking;vandalism;denial of service attacks.
C)theft,copying,alteration of data;hardware or software failure.
D)unauthorized access;errors;spyware.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
32
A keylogger is a type of:

A)worm.
B)Trojan horse.
C)virus.
D)spyware.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
33
Phishing is a form of:

A)spoofing.
B)logging.
C)sniffing.
D)driving.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
34
A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's advertising costs up.This is an example of:

A)phishing.
B)pharming.
C)spoofing.
D)click fraud.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
35
Which of the following statements about the Internet security is not true?

A)The use of P2P networks can expose a corporate computer to outsiders.
B)A corporate network without access to the Internet is more secure than one that provides access.
C)VoIP is more secure than the switched voice network.
D)Instant messaging can provide hackers access to an otherwise secure network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
36
An example of phishing is:

A)setting up a bogus Wi-Fi hot spot.
B)setting up a fake medical Web site that asks users for confidential information.
C)pretending to be a utility company's employee in order to garner information from that company about their security system.
D)sending bulk e-mail that asks for financial aid under a false pretext.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
37
Electronic data are more susceptible to destruction,fraud,error,and misuse because information systems concentrate data in computer files that:

A)are easily decrypted.
B)can be opened with easily available software.
C)may be accessible by anyone who has access to the same network.
D)are unprotected by up-to-date security systems.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
38
Hackers create a botnet by:

A)infecting Web search bots with malware.
B)using Web search bots to infect other computers.
C)causing other people's computers to become "zombie" PCs following a master computer.
D)infecting corporate servers with "zombie" Trojan horses that allow undetected access through a back door.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
39
Which of the following is not an example of a computer used as a target of crime?

A)Knowingly accessing a protected computer to commit fraud
B)Accessing a computer system without authority
C)Illegally accessing stored electronic communication
D)Threatening to cause damage to a protected computer
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
40
Which of the following is not an example of a computer used as an instrument of crime?

A)Theft of trade secrets
B)Intentionally attempting to intercept electronic communication
C)Unauthorized copying of software
D)Breaching the confidentiality of protected computerized data
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
41
How do software vendors correct flaws in their software after it has been distributed?

A)They issue bug fixes.
B)They issue patches.
C)They re-release the software.
D)They release updated versions of the software.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
42
Evil twins are:

A)Trojan horses that appears to the user to be a legitimate commercial software application.
B)e-mail messages that mimic the e-mail messages of a legitimate business.
C)fraudulent Web sites that mimic a legitimate business's Web site.
D)bogus wireless network access points that look legitimate to users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
43
Analysis of an information system that rates the likelihood of a security incident occurring and its cost is included in a(n):

A)security policy.
B)AUP.
C)risk assessment.
D)business impact analysis.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
44
Rigorous password systems:

A)are one of the most effective security tools.
B)may hinder employee productivity.
C)are costly to implement.
D)are often disregarded by employees.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
45
Biometric authentication:

A)is inexpensive.
B)is used widely in Europe for security applications.
C)can use a person's voice as a unique,measurable trait.
D)only uses physical measurements for identification.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
46
________ controls ensure that valuable business data files on either disk or tape are not subject to unauthorized access,change,or destruction while they are in use or in storage.

A)Software
B)Administrative
C)Data security
D)Implementation
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
47
Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is called:

A)sniffing.
B)social engineering.
C)phishing.
D)pharming.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
48
The most common type of electronic evidence is:

A)voice-mail.
B)spreadsheets.
C)instant messages.
D)e-mail.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
49
You have been hired as a security consultant for a law firm.Which of the following constitutes the greatest source of security threats to the firm?

A)Wireless network
B)Employees
C)Authentication procedures
D)Lack of data encryption
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
50
Electronic evidence on computer storage media that is not visible to the average user is called ________ data.

A)defragmented
B)ambient
C)forensic
D)fragmented
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
51
Application controls:

A)can be classified as input controls,processing controls,and output controls.
B)govern the design,security,and use of computer programs and the security of data files in general throughout the organization.
C)apply to all computerized applications and consist of a combination of hardware,software,and manual procedures that create an overall control environment.
D)include software controls,computer operations controls,and implementation controls.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
52
An authentication token is a(n):

A)device the size of a credit card that contains access permission data.
B)type of smart card.
C)gadget that displays passcodes.
D)electronic marker attached to a digital authorization file.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
53
The Sarbanes-Oxley Act:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
54
The Gramm-Leach-Bliley Act:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
55
A firewall identifies all of the following characteristics of incoming traffic,except:

A)user names.
B)biometric authentication.
C)IP addresses.
D)applications.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
56
Which of the following specifications replaces WEP with a stronger security standard that features changing encryption keys?

A)TLS
B)AUP
C)VPN
D)WPA2
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
57
Pharming involves:

A)redirecting users to a fraudulent Web site even when the user has typed in the correct address in the Web browser.
B)pretending to be a legitimate business's representative in order to garner information about a security system.
C)setting up fake Web sites to ask users for confidential information.
D)using e-mails for threats or harassment.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
58
The HIPAA Act of 1996:

A)requires financial institutions to ensure the security of customer data.
B)specifies best practices in information systems security and control.
C)imposes responsibility on companies and management to safeguard the accuracy of financial information.
D)outlines medical security and privacy rules.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
59
A firewall allows the organization to:

A)enforce a security policy on data exchanged between its network and the Internet.
B)check the accuracy of all transactions between its network and the Internet.
C)create an enterprise system on the Internet.
D)check the content of all incoming and outgoing e-mail messages.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
60
Statements ranking information risks and identifying security goals are included in a(n):

A)security policy.
B)AUP.
C)risk assessment.
D)business impact analysis.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
61
A walkthrough is a type of software testing used before software is even written.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
62
________ use scanning software to look for known problems such as bad passwords,the removal of important files,security attacks in progress,and system administration errors.

A)Stateful inspections
B)Intrusion detection systems
C)Application proxy filtering technologies
D)Packet filtering technologies
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
63
________ identify the access points in a Wi-Fi network.

A)NICs
B)Mac addresses
C)URLs
D)SSIDs
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
64
A(n)________ audit examines the firm's overall security environment as well as the controls governing individual information systems.

A)security
B)MIS
C)network
D)software
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
65
Currently,the protocols used for secure information transfer over the Internet are:

A)TCP/IP and SSL.
B)S-HTTP and CA.
C)HTTP and TCP/IP.
D)SSL,TLS,and S-HTTP.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
66
In controlling network traffic to minimize slow-downs,a technology called ________ is used to examine data files and sort low-priority data from high-priority data.

A)high availability computing
B)deep-packet inspection
C)application proxy filtering
D)stateful inspection
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
67
________ is a crime in which an imposter obtains key pieces of personal information to impersonate someone else.

A)Identity theft
B)Spoofing
C)Social engineering
D)Evil twins
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
68
When errors are discovered in software programs,the sources of the errors are found and eliminated through a process called debugging.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
69
In which method of encryption is a single encryption key sent to the receiver so both sender and receiver share the same key?

A)SSL
B)Symmetric key encryption
C)Public key encryption
D)Private key encryption
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
70
The development and use of methods to make computer systems resume their activities more quickly after mishaps is called:

A)high-availability computing.
B)recovery-oriented computing.
C)fault-tolerant computing.
D)disaster-recovery planning.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
71
A digital certificate system:

A)uses third-party CAs to validate a user's identity.
B)uses digital signatures to validate a user's identity.
C)uses tokens to validate a user's identity.
D)is used primarily by individuals for personal correspondence.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
72
Most antivirus software is effective against:

A)only those viruses active on the Internet and through e-mail.
B)any virus.
C)any virus except those in wireless communications applications.
D)only those viruses already known when the software is written.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
73
Downtime refers to periods of time in which a:

A)computer system is malfunctioning.
B)computer system is not operational.
C)company or organization is not operational.
D)computer is not online.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
74
Comprehensive security management products,with tools for firewalls,VPNs,intrusion detection systems,and more,are called ________ systems.

A)DPI
B)MSSP
C)NSP
D)UTM
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
75
Malicious software programs referred to as spyware include a variety of threats such as computer viruses,worms,and Trojan horses.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
76
For 100% availability,online transaction processing requires:

A)high-capacity storage.
B)a multi-tier server network.
C)fault-tolerant computer systems.
D)dedicated phone lines.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
77
Computer forensics tasks include all of the following except:

A)presenting collected evidence in a court of law.
B)securely storing recovered electronic data.
C)collecting physical evidence on the computer.
D)finding significant information in a large volume of electronic data.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
78
A practice in which eavesdroppers drive by buildings or park outside and try to intercept wireless network traffic is referred to as:

A)war driving.
B)sniffing.
C)cybervandalism.
D)driveby tapping.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
79
Authorization refers to the ability to know that a person is who he or she claims to be.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
80
Smaller firms may outsource some or many security functions to:

A)ISPs.
B)MISs.
C)MSSPs.
D)CAs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 90 في هذه المجموعة.