Deck 1: Computer Systems Overview

ملء الشاشة (f)
exit full mode
سؤال
Assurance is the process of examining a computer product or system
with respect to certain criteria.
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
Computer security is protection of the integrity,availability,and
confidentiality of information system resources.
سؤال
The first step in devising security services and mechanisms is to
develop a security policy.
سؤال
Data integrity assures that information and programs are changed only
in a specified and authorized manner.
سؤال
Security mechanisms typically do not involve more than one particular
algorithm or protocol.
سؤال
Threats are attacks carried out.
سؤال
__________ assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.

A)Availability
B)Privacy
C)System Integrity
D)Data Integrity
سؤال
A ________ level breach of security could be expected to have a severe or catastrophic adverse effect on organizational operations,organizational assets,or individuals.

A)low
B)moderate
C)normal
D)high
سؤال
X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
سؤال
The more critical a component or service,the higher the level of
availability required.
سؤال
A loss of _________ is the unauthorized disclosure of information.

A)confidentiality
B)authenticity
C)integrity
D)availability
سؤال
Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
سؤال
Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
سؤال
In the context of security our concern is with the vulnerabilities of
system resources.
سؤال
T F 4.Availability assures that systems works promptly and service is not
denied to authorized users.
سؤال
________ assures that a system performs its intended function in an unimpaired manner,free from deliberate or inadvertent unauthorized manipulation of the system.

A)System Integrity
B)Availability
C)Data Integrity
D)Confidentiality
سؤال
The "A" in the CIA triad stands for "authenticity".
سؤال
Contingency planning is a functional area that primarily requires
computer security technical measures.
سؤال
Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
سؤال
A flaw or weakness in a system's design,implementation,or operation and management that could be exploited to violate the system's security policy is a(n)__________.

A)countermeasure
B)adversary
C)vulnerability
D)risk
سؤال
In the United States,student grade information is an asset whose confidentiality is regulated by the __________.
سؤال
__________ is the protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity,availability,and confidentiality of information system resources.
سؤال
A loss of _________ is the disruption of access to or use of information or an information system.
سؤال
A __________ is any action that compromises the security of information owned by an organization.

A)security mechanism
B)security policy
C)security attack
D)security service
سؤال
An example of __________ is an attempt by an unauthorized user to gain access to a system by posing as an authorized user.

A)masquerade
B)repudiation
C)interception
D)inference
سؤال
The assets of a computer system can be categorized as hardware,software,communication lines and networks,and _________.
سؤال
Misappropriation and misuse are attacks that result in ________ threat consequences.
سؤال
__________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

A)Traffic padding
B)Traffic control
C)Traffic routing
D)Traffic integrity
سؤال
A(n)_________ is an attempt to learn or make use of information from the system that does not affect system resources.

A)passive attack
B)outside attack
C)inside attack
D)active attack
سؤال
A(n)_________ is a threat that is carried out and,if successful,leads to an undesirable violation of security,or threat consequence.
سؤال
A threat action in which sensitive data are directly released to an unauthorized entity is __________.

A)corruption
B)intrusion
C)disruption
D)exposure
سؤال
A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.

A)attack
B)adversary
C)countermeasure
D)protocol
سؤال
An assault on system security that derives from an intelligent act that is a deliberate attempt to evade security services and violate the security policy of a system is a(n)__________.

A)risk
B)attack
C)asset
D)vulnerability
سؤال
Replay,masquerade,modification of messages,and denial of service are example of _________ attacks.
سؤال
Confidentiality,Integrity,and Availability form what is often referred to as the _____.
سؤال
Release of message contents and traffic analysis are two types of _________ attacks.
سؤال
Masquerade,falsification,and repudiation are threat actions that cause __________ threat consequences.

A)unauthorized disclosure
B)disruption
C)deception
D)usurpation
سؤال
The assurance that data received are exactly as sent by an authorized entity is __________.

A)authentication
B)access control
C)data confidentiality
D)data integrity
سؤال
A(n)_________ is any means taken to deal with a security attack.
سؤال
The _________ prevents or inhibits the normal use or management of communications facilities.

A)passive attack
B)denial of service
C)traffic encryption
D)masquerade
سؤال
The OSI security architecture focuses on security attacks,__________,and services.
سؤال
A __________ is data appended to,or a cryptographic transformation of,a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
سؤال
Establishing,maintaining,and implementing plans for emergency response,backup operations,and post disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations is a __________ plan.
سؤال
A(n)_________ assessment is periodically assessing the risk to organizational operations,organizational assets,and individuals,resulting from the operation of organizational information systems and the associated processing,storage,or transmission or organizational information.
سؤال
Security implementation involves four complementary courses of action: prevention,detection,response,and _________.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/45
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 1: Computer Systems Overview
1
Assurance is the process of examining a computer product or system
with respect to certain criteria.
False
2
Computer security is protection of the integrity,availability,and
confidentiality of information system resources.
True
3
The first step in devising security services and mechanisms is to
develop a security policy.
True
4
Data integrity assures that information and programs are changed only
in a specified and authorized manner.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
5
Security mechanisms typically do not involve more than one particular
algorithm or protocol.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
6
Threats are attacks carried out.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
7
__________ assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.

A)Availability
B)Privacy
C)System Integrity
D)Data Integrity
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
8
A ________ level breach of security could be expected to have a severe or catastrophic adverse effect on organizational operations,organizational assets,or individuals.

A)low
B)moderate
C)normal
D)high
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
9
X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
10
The more critical a component or service,the higher the level of
availability required.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
11
A loss of _________ is the unauthorized disclosure of information.

A)confidentiality
B)authenticity
C)integrity
D)availability
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
12
Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
13
Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
14
In the context of security our concern is with the vulnerabilities of
system resources.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
15
T F 4.Availability assures that systems works promptly and service is not
denied to authorized users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
16
________ assures that a system performs its intended function in an unimpaired manner,free from deliberate or inadvertent unauthorized manipulation of the system.

A)System Integrity
B)Availability
C)Data Integrity
D)Confidentiality
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
17
The "A" in the CIA triad stands for "authenticity".
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
18
Contingency planning is a functional area that primarily requires
computer security technical measures.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
19
Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
20
A flaw or weakness in a system's design,implementation,or operation and management that could be exploited to violate the system's security policy is a(n)__________.

A)countermeasure
B)adversary
C)vulnerability
D)risk
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
21
In the United States,student grade information is an asset whose confidentiality is regulated by the __________.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
22
__________ is the protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity,availability,and confidentiality of information system resources.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
23
A loss of _________ is the disruption of access to or use of information or an information system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
24
A __________ is any action that compromises the security of information owned by an organization.

A)security mechanism
B)security policy
C)security attack
D)security service
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
25
An example of __________ is an attempt by an unauthorized user to gain access to a system by posing as an authorized user.

A)masquerade
B)repudiation
C)interception
D)inference
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
26
The assets of a computer system can be categorized as hardware,software,communication lines and networks,and _________.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
27
Misappropriation and misuse are attacks that result in ________ threat consequences.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
28
__________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

A)Traffic padding
B)Traffic control
C)Traffic routing
D)Traffic integrity
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
29
A(n)_________ is an attempt to learn or make use of information from the system that does not affect system resources.

A)passive attack
B)outside attack
C)inside attack
D)active attack
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
30
A(n)_________ is a threat that is carried out and,if successful,leads to an undesirable violation of security,or threat consequence.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
31
A threat action in which sensitive data are directly released to an unauthorized entity is __________.

A)corruption
B)intrusion
C)disruption
D)exposure
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
32
A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.

A)attack
B)adversary
C)countermeasure
D)protocol
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
33
An assault on system security that derives from an intelligent act that is a deliberate attempt to evade security services and violate the security policy of a system is a(n)__________.

A)risk
B)attack
C)asset
D)vulnerability
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
34
Replay,masquerade,modification of messages,and denial of service are example of _________ attacks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
35
Confidentiality,Integrity,and Availability form what is often referred to as the _____.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
36
Release of message contents and traffic analysis are two types of _________ attacks.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
37
Masquerade,falsification,and repudiation are threat actions that cause __________ threat consequences.

A)unauthorized disclosure
B)disruption
C)deception
D)usurpation
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
38
The assurance that data received are exactly as sent by an authorized entity is __________.

A)authentication
B)access control
C)data confidentiality
D)data integrity
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
39
A(n)_________ is any means taken to deal with a security attack.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
40
The _________ prevents or inhibits the normal use or management of communications facilities.

A)passive attack
B)denial of service
C)traffic encryption
D)masquerade
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
41
The OSI security architecture focuses on security attacks,__________,and services.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
42
A __________ is data appended to,or a cryptographic transformation of,a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
43
Establishing,maintaining,and implementing plans for emergency response,backup operations,and post disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations is a __________ plan.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
44
A(n)_________ assessment is periodically assessing the risk to organizational operations,organizational assets,and individuals,resulting from the operation of organizational information systems and the associated processing,storage,or transmission or organizational information.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
45
Security implementation involves four complementary courses of action: prevention,detection,response,and _________.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 45 في هذه المجموعة.