Deck 4: Information Security

ملء الشاشة (f)
exit full mode
سؤال
Supervisory control and data acquisition (SCADA) systems require human data input.
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
Trojan horses are software programs that hide in other computer programs and reveal their designed behavior only when they are activated.
سؤال
In most cases, cookies track your path through Web sites and are therefore invasions of your privacy.
سؤال
Voice recognition is an example of "something a user does" authentication.
سؤال
Zero-day attacks use deceptive e-mails to acquire sensitive personal information.
سؤال
IT security is the responsibility of everyone in the organization.
سؤال
The area located between two firewalls within an organization is called the demilitarized zone.
سؤال
Cyberterrorism and cyberwarfare can attack supervisory control and data acquisition (SCADA) systems to cause widespread physical damage.
سؤال
The higher the level of an employee in organization, the greater the threat that he or she poses to the organization.
سؤال
Public-key encryption uses two different keys, one public and one private.
سؤال
The security of each computer on the Internet is independent of the security of all other computers on the Internet.
سؤال
A password refers to "something the user is."
سؤال
The computing skills necessary to be a hacker are decreasing.
سؤال
Having one backup of your business data is sufficient for security purposes.
سؤال
Organizations use authentication to establish privileges to systems operations.
سؤال
Risk analysis involves determining whether security programs are working.
سؤال
Dumpster diving is always illegal because it involves trespassing on private property.
سؤال
Cyberterrorism is usually carried out by nations.
سؤال
Software can be copyrighted.
سؤال
Organizations utilize layers of controls because they face so many diverse threats to information security.
سؤال
Employees in which functional areas of the organization pose particularly grave threats to information security?

A) human resources, finance
B) human resources, management information systems
C) finance, marketing
D) operations management, management information systems
E) finance, management information systems
سؤال
Cybercriminals can obtain the information they need in order to assume another person's identity by:

A) Infiltrating an organization that stores large amounts of personal information.
B) Phishing.
C) Hacking into a corporate database.
D) Stealing mail.
E) All of the above are strategies to obtain information to assume another person's identity.
سؤال
A VPN is a network within the organization.
سؤال
The computing skills necessary to be a hacker are decreasing for which of the following reasons?

A) More information systems and computer science departments are teaching courses on hacking so that their graduates can recognize attacks on information assets.
B) Computer attack programs, called scripts, are available for download from the Internet.
C) International organized crime is training hackers.
D) Cybercrime is much more lucrative than regular white-collar crime.
E) Almost anyone can buy or access a computer today.
سؤال
A _____ is any danger to which an information resource may be exposed.

A) vulnerability
B) risk
C) control
D) threat
E) compromise
سؤال
_____ are segments of computer code that attach to existing computer programs and perform malicious acts.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
سؤال
A URL that begins with https rather than http indicates that the site transmits using an extra layer of security called transport layer security.
سؤال
Rank the following in terms of dollar value of the crime, from highest to lowest.

A) robbery - white collar crime - cybercrime
B) white collar crime - extortion - robbery
C) cybercrime - white collar crime - robbery
D) cybercrime - robbery - white collar crime
E) white collar crime - burglary - robbery
سؤال
The most overlooked people in information security are:

A) consultants and temporary hires.
B) secretaries and consultants.
C) contract laborers and executive assistants.
D) janitors and guards.
E) executives and executive secretaries.
سؤال
_____ are software programs that hide in other computer programs and reveal their designed behavior only when they are activated.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
سؤال
Dumpster diving is:

A) always illegal because it is considered trespassing.
B) never illegal because it is not considered trespassing.
C) typically committed for the purpose of identity theft.
D) always illegal because individuals own the material in the dumpster.
E) always legal because the dumpster is not owned by private citizens.
سؤال
Which of the following factors is not increasing the threats to information security?

A) smaller computing devices
B) downstream liability
C) the Internet
D) limited storage capacity on portable devices
E) due diligence
سؤال
A _____ is intellectual work that is known only to a company and is not based on public information.

A) copyright
B) patent
C) trade secret
D) knowledge base
E) private property
سؤال
A _____ is a document that grants the holder exclusive rights on an invention for 20 years.

A) copyright
B) patent
C) trade secret
D) knowledge base
E) private property notice
سؤال
An information system's _____ is the possibility that the system will be harmed by a threat.

A) vulnerability
B) risk
C) control
D) danger
E) compromise
سؤال
Unintentional threats to information systems include all of the following except:

A) malicious software
B) tailgating
C) power outage
D) lack of user experience
E) tornados
سؤال
An organization's e-mail policy has the least impact on which of the following software attacks?

A) virus
B) worm
C) phishing
E) spear phishing
E) zero-day
سؤال
_____ involves building an inappropriate trust relationship with employees for the purpose of gaining sensitive information or unauthorized access privileges.

A) Tailgating
B) Hacking
C) Spoofing
D) Social engineering
E) Spamming
سؤال
A pharmaceutical company's research and development plan for a new class of drugs would be best described as which of the following?

A) Copyrighted material
B) Patented material
C) A trade secret
D) A knowledge base
E) Public property
سؤال
The cost of a stolen laptop includes all of the following except:

A) Loss of intellectual property
B) Loss of data
C) Backup costs
D) Loss of productivity
E) Replacement cost
سؤال
Bob is using public key encryption to send a message to Ted. Bob encrypts the message with Ted's _____ key, and Ted decrypts the message using his _____ key.

A) public, public
B) public, private
C) private, private
D) private, public
E) none of these
سؤال
_____ controls are concerned with user identification, and they restrict unauthorized individuals from using information resources.

A) Access
B) Physical
C) Data security
D) Administrative
E) Input
سؤال
In _____, the organization takes concrete actions against risks.

A) risk management
B) risk analysis
C) risk mitigation
D) risk acceptance
E) risk transference
سؤال
Which of the following is(are) designed to use your computer as a launch pad for sending unsolicited e-mail to other computers?

A) Spyware
B) Spamware
C) Adware
D) Viruses
E) Worms
سؤال
Which of the following is not a strategy for mitigating the risk of threats against information?

A) Continue operating with no controls and absorb any damages that occur
B) Transfer the risk by purchasing insurance.
C) Implement controls that minimize the impact of the threat
D) Install controls that block the risk.
E) All of the above are strategies for mitigating risk.
سؤال
Voice and signature recognition are examples of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
سؤال
_____ is the process in which an organization assesses the value of each asset being protected, estimates the probability that it will be compromised, and compares the probable costs of an attack with the costs of protecting the asset.

A) Risk management
B) Risk analysis
C) Risk mitigation
D) Risk acceptance
E) Risk transference
سؤال
Which of the following is not a characteristic of strong passwords?

A) They are difficult to guess.
B) They contain special characters.
C) They are not a recognizable word.
D) They are not a recognizable string of numbers
E) They tend to be short so they are easy to remember.
سؤال
The term _____ refers to clandestine software that is installed on your PC through duplicitous channels but is not particularly malicious.

A) Alien software
B) Virus
C) Worm
D) Back door
E) Logic bomb
سؤال
In _____, the organization purchases insurance as a means to compensate for any loss.

A) risk management
B) risk analysis
C) risk mitigation
D) risk acceptance
E) risk transference
سؤال
Which of the following statements concerning the difficulties in protecting information resources is not correct?

A) Computing resources are typically decentralized.
B) Computer crimes often remain undetected for a long period of time.
C) Rapid technological changes ensure that controls are effective for years.
D) Employees typically do not follow security procedures when the procedures are inconvenient.
E) Computer networks can be located outside the organization.
سؤال
_____ are segments of computer code embedded within an organization's existing computer programs that activate and perform a destructive action at a certain time or date.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
سؤال
Which of the following statements is false?

A) Credit card companies usually block stolen credit cards rather than prosecute.
B) People tend to shortcut security procedures because the procedures are inconvenient.
C) It is easy to assess the value of a hypothetical attack.
D) The online commerce industry isn't willing to install safeguards on credit card transactions.
E) The cost of preventing computer crimes can be very high.
سؤال
Passwords and passphrases are examples of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
سؤال
Access controls involve _____ before _____.

A) biometrics, signature recognition
B) authentication, authorization
C) iris scanning, voice recognition
D) strong passwords, biometrics
E) authorization, authentication
سؤال
When companies attempt to counter _____ by requiring users to accurately select characters in turn from a series of boxes, attackers respond by using _____.

A) keyloggers, screen scrapers
B) screen scrapers, uninstallers
C) keyloggers, spam
D) screen scrapers, keyloggers
E) spam, keyloggers
سؤال
Biometrics are an example of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
سؤال
Which of the following is not an example of a weak password?

A) IloveIT
B) 08141990
C) 9AmGt/*
D) Rainer
E) InformationSecurity
سؤال
In a _____ attack, a coordinated stream of requests is launched against a target system from many compromised computers at the same time.

A) phishing
B) zero-day
C) worm
D) back door
E) distributed denial-of-service
سؤال
A _____ attack uses deception to fraudulently acquire sensitive personal information by masquerading as an official e-mail.

A) Zero-day
B) Denial-of-service
C) Distributed denial-of-service
D) Phishing
E) Brute force dictionary
سؤال
Contrast unintentional and deliberate threats to an information resource. Provide examples of both.
سؤال
Describe public key encryption.
سؤال
Discuss the possible consequences of a terrorist attack on a supervisory control and data acquisition (SCADA) system.
سؤال
Which of the following statements concerning firewalls is not true?

A) Firewalls prevent unauthorized Internet users from accessing private networks.
B) Firewalls examine every message that enters or leaves an organization's network.
C) Firewalls filter network traffic according to categories of activities that are likely to cause problems.
D) Firewalls filter messages the same way as anti-malware systems do.
E) Firewalls are sometimes located inside an organization's private network.
سؤال
You start a dog-walking service, and you store your client's records on your cell phone. You don't need to worry about information security.
سؤال
Contrast the following types of attacks created by programmers: Trojan horse, back door, and logic bomb
سؤال
Your company's headquarters was just hit head on by a hurricane, and the building has lost power. The company sends you to their hot site to minimize downtime from the disaster. Which of the following statements is true?

A) The site will not have any servers.
B) The site will not have any workstations, so you need to bring your laptop.
C) The site is probably in the next town.
D) The site should be an almost exact replica of the IT configuration at headquarters.
E) The site will not have up-to-date data.
سؤال
Define identity theft, and explain the types of problems that it creates for the victims.
سؤال
Contrast spyware and spamware.
سؤال
In a process called _____, a company allows nothing to run unless it is approved, whereas in a process called _____, the company allows everything to run unless it is not approved.

A) whitelisting, blacklisting
B) whitelisting, encryption
C) encryption, whitelisting
D) encryption, blacklisting
E) blacklisting, whitelisting
سؤال
Compare trade secrets, patents, and copyrights as forms of intellectual property.
سؤال
Explain why anti-malware software is classified as reactive.
سؤال
Contrast the following types of remote attacks: virus, worm, phishing, and spear phishing.
سؤال
Identify and discuss the factors that are contributing to the increasing vulnerability of organizational information assets.
سؤال
Contrast risk acceptance, risk limitation, and risk transference.
سؤال
Compare a hot site, a warm site, and a cold site as strategies for business continuity.
سؤال
Contrast the four types of authentication.
سؤال
Describe how a digital certificate works.
سؤال
Define the principle of least privilege, and consider how an organization's senior executives might view the application of this principle.
سؤال
Organizations use hot sites, warm sites, and cold sites to insure business continuity. Which of the following statements is not true?

A) A cold site has no equipment.
B) A warm site has no user workstations.
C) A hot site needs to be located close to the organization's offices.
D) A hot site duplicates all of the organization's resources.
E) A warm site does not include actual applications.
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/84
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 4: Information Security
1
Supervisory control and data acquisition (SCADA) systems require human data input.
False
2
Trojan horses are software programs that hide in other computer programs and reveal their designed behavior only when they are activated.
True
3
In most cases, cookies track your path through Web sites and are therefore invasions of your privacy.
True
4
Voice recognition is an example of "something a user does" authentication.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
5
Zero-day attacks use deceptive e-mails to acquire sensitive personal information.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
6
IT security is the responsibility of everyone in the organization.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
7
The area located between two firewalls within an organization is called the demilitarized zone.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
8
Cyberterrorism and cyberwarfare can attack supervisory control and data acquisition (SCADA) systems to cause widespread physical damage.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
9
The higher the level of an employee in organization, the greater the threat that he or she poses to the organization.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
10
Public-key encryption uses two different keys, one public and one private.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
11
The security of each computer on the Internet is independent of the security of all other computers on the Internet.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
12
A password refers to "something the user is."
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
13
The computing skills necessary to be a hacker are decreasing.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
14
Having one backup of your business data is sufficient for security purposes.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
15
Organizations use authentication to establish privileges to systems operations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
16
Risk analysis involves determining whether security programs are working.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
17
Dumpster diving is always illegal because it involves trespassing on private property.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
18
Cyberterrorism is usually carried out by nations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
19
Software can be copyrighted.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
20
Organizations utilize layers of controls because they face so many diverse threats to information security.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
21
Employees in which functional areas of the organization pose particularly grave threats to information security?

A) human resources, finance
B) human resources, management information systems
C) finance, marketing
D) operations management, management information systems
E) finance, management information systems
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
22
Cybercriminals can obtain the information they need in order to assume another person's identity by:

A) Infiltrating an organization that stores large amounts of personal information.
B) Phishing.
C) Hacking into a corporate database.
D) Stealing mail.
E) All of the above are strategies to obtain information to assume another person's identity.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
23
A VPN is a network within the organization.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
24
The computing skills necessary to be a hacker are decreasing for which of the following reasons?

A) More information systems and computer science departments are teaching courses on hacking so that their graduates can recognize attacks on information assets.
B) Computer attack programs, called scripts, are available for download from the Internet.
C) International organized crime is training hackers.
D) Cybercrime is much more lucrative than regular white-collar crime.
E) Almost anyone can buy or access a computer today.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
25
A _____ is any danger to which an information resource may be exposed.

A) vulnerability
B) risk
C) control
D) threat
E) compromise
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
26
_____ are segments of computer code that attach to existing computer programs and perform malicious acts.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
27
A URL that begins with https rather than http indicates that the site transmits using an extra layer of security called transport layer security.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
28
Rank the following in terms of dollar value of the crime, from highest to lowest.

A) robbery - white collar crime - cybercrime
B) white collar crime - extortion - robbery
C) cybercrime - white collar crime - robbery
D) cybercrime - robbery - white collar crime
E) white collar crime - burglary - robbery
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
29
The most overlooked people in information security are:

A) consultants and temporary hires.
B) secretaries and consultants.
C) contract laborers and executive assistants.
D) janitors and guards.
E) executives and executive secretaries.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
30
_____ are software programs that hide in other computer programs and reveal their designed behavior only when they are activated.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
31
Dumpster diving is:

A) always illegal because it is considered trespassing.
B) never illegal because it is not considered trespassing.
C) typically committed for the purpose of identity theft.
D) always illegal because individuals own the material in the dumpster.
E) always legal because the dumpster is not owned by private citizens.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
32
Which of the following factors is not increasing the threats to information security?

A) smaller computing devices
B) downstream liability
C) the Internet
D) limited storage capacity on portable devices
E) due diligence
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
33
A _____ is intellectual work that is known only to a company and is not based on public information.

A) copyright
B) patent
C) trade secret
D) knowledge base
E) private property
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
34
A _____ is a document that grants the holder exclusive rights on an invention for 20 years.

A) copyright
B) patent
C) trade secret
D) knowledge base
E) private property notice
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
35
An information system's _____ is the possibility that the system will be harmed by a threat.

A) vulnerability
B) risk
C) control
D) danger
E) compromise
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
36
Unintentional threats to information systems include all of the following except:

A) malicious software
B) tailgating
C) power outage
D) lack of user experience
E) tornados
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
37
An organization's e-mail policy has the least impact on which of the following software attacks?

A) virus
B) worm
C) phishing
E) spear phishing
E) zero-day
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
38
_____ involves building an inappropriate trust relationship with employees for the purpose of gaining sensitive information or unauthorized access privileges.

A) Tailgating
B) Hacking
C) Spoofing
D) Social engineering
E) Spamming
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
39
A pharmaceutical company's research and development plan for a new class of drugs would be best described as which of the following?

A) Copyrighted material
B) Patented material
C) A trade secret
D) A knowledge base
E) Public property
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
40
The cost of a stolen laptop includes all of the following except:

A) Loss of intellectual property
B) Loss of data
C) Backup costs
D) Loss of productivity
E) Replacement cost
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
41
Bob is using public key encryption to send a message to Ted. Bob encrypts the message with Ted's _____ key, and Ted decrypts the message using his _____ key.

A) public, public
B) public, private
C) private, private
D) private, public
E) none of these
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
42
_____ controls are concerned with user identification, and they restrict unauthorized individuals from using information resources.

A) Access
B) Physical
C) Data security
D) Administrative
E) Input
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
43
In _____, the organization takes concrete actions against risks.

A) risk management
B) risk analysis
C) risk mitigation
D) risk acceptance
E) risk transference
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
44
Which of the following is(are) designed to use your computer as a launch pad for sending unsolicited e-mail to other computers?

A) Spyware
B) Spamware
C) Adware
D) Viruses
E) Worms
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
45
Which of the following is not a strategy for mitigating the risk of threats against information?

A) Continue operating with no controls and absorb any damages that occur
B) Transfer the risk by purchasing insurance.
C) Implement controls that minimize the impact of the threat
D) Install controls that block the risk.
E) All of the above are strategies for mitigating risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
46
Voice and signature recognition are examples of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
47
_____ is the process in which an organization assesses the value of each asset being protected, estimates the probability that it will be compromised, and compares the probable costs of an attack with the costs of protecting the asset.

A) Risk management
B) Risk analysis
C) Risk mitigation
D) Risk acceptance
E) Risk transference
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
48
Which of the following is not a characteristic of strong passwords?

A) They are difficult to guess.
B) They contain special characters.
C) They are not a recognizable word.
D) They are not a recognizable string of numbers
E) They tend to be short so they are easy to remember.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
49
The term _____ refers to clandestine software that is installed on your PC through duplicitous channels but is not particularly malicious.

A) Alien software
B) Virus
C) Worm
D) Back door
E) Logic bomb
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
50
In _____, the organization purchases insurance as a means to compensate for any loss.

A) risk management
B) risk analysis
C) risk mitigation
D) risk acceptance
E) risk transference
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
51
Which of the following statements concerning the difficulties in protecting information resources is not correct?

A) Computing resources are typically decentralized.
B) Computer crimes often remain undetected for a long period of time.
C) Rapid technological changes ensure that controls are effective for years.
D) Employees typically do not follow security procedures when the procedures are inconvenient.
E) Computer networks can be located outside the organization.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
52
_____ are segments of computer code embedded within an organization's existing computer programs that activate and perform a destructive action at a certain time or date.

A) Viruses
B) Worms
C) Trojan horses
D) Back doors
E) Logic bombs
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
53
Which of the following statements is false?

A) Credit card companies usually block stolen credit cards rather than prosecute.
B) People tend to shortcut security procedures because the procedures are inconvenient.
C) It is easy to assess the value of a hypothetical attack.
D) The online commerce industry isn't willing to install safeguards on credit card transactions.
E) The cost of preventing computer crimes can be very high.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
54
Passwords and passphrases are examples of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
55
Access controls involve _____ before _____.

A) biometrics, signature recognition
B) authentication, authorization
C) iris scanning, voice recognition
D) strong passwords, biometrics
E) authorization, authentication
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
56
When companies attempt to counter _____ by requiring users to accurately select characters in turn from a series of boxes, attackers respond by using _____.

A) keyloggers, screen scrapers
B) screen scrapers, uninstallers
C) keyloggers, spam
D) screen scrapers, keyloggers
E) spam, keyloggers
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
57
Biometrics are an example of:

A) something the user is.
B) something the user wants.
C) something the user has.
D) something the user knows.
E) something the user does.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
58
Which of the following is not an example of a weak password?

A) IloveIT
B) 08141990
C) 9AmGt/*
D) Rainer
E) InformationSecurity
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
59
In a _____ attack, a coordinated stream of requests is launched against a target system from many compromised computers at the same time.

A) phishing
B) zero-day
C) worm
D) back door
E) distributed denial-of-service
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
60
A _____ attack uses deception to fraudulently acquire sensitive personal information by masquerading as an official e-mail.

A) Zero-day
B) Denial-of-service
C) Distributed denial-of-service
D) Phishing
E) Brute force dictionary
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
61
Contrast unintentional and deliberate threats to an information resource. Provide examples of both.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
62
Describe public key encryption.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
63
Discuss the possible consequences of a terrorist attack on a supervisory control and data acquisition (SCADA) system.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
64
Which of the following statements concerning firewalls is not true?

A) Firewalls prevent unauthorized Internet users from accessing private networks.
B) Firewalls examine every message that enters or leaves an organization's network.
C) Firewalls filter network traffic according to categories of activities that are likely to cause problems.
D) Firewalls filter messages the same way as anti-malware systems do.
E) Firewalls are sometimes located inside an organization's private network.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
65
You start a dog-walking service, and you store your client's records on your cell phone. You don't need to worry about information security.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
66
Contrast the following types of attacks created by programmers: Trojan horse, back door, and logic bomb
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
67
Your company's headquarters was just hit head on by a hurricane, and the building has lost power. The company sends you to their hot site to minimize downtime from the disaster. Which of the following statements is true?

A) The site will not have any servers.
B) The site will not have any workstations, so you need to bring your laptop.
C) The site is probably in the next town.
D) The site should be an almost exact replica of the IT configuration at headquarters.
E) The site will not have up-to-date data.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
68
Define identity theft, and explain the types of problems that it creates for the victims.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
69
Contrast spyware and spamware.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
70
In a process called _____, a company allows nothing to run unless it is approved, whereas in a process called _____, the company allows everything to run unless it is not approved.

A) whitelisting, blacklisting
B) whitelisting, encryption
C) encryption, whitelisting
D) encryption, blacklisting
E) blacklisting, whitelisting
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
71
Compare trade secrets, patents, and copyrights as forms of intellectual property.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
72
Explain why anti-malware software is classified as reactive.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
73
Contrast the following types of remote attacks: virus, worm, phishing, and spear phishing.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
74
Identify and discuss the factors that are contributing to the increasing vulnerability of organizational information assets.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
75
Contrast risk acceptance, risk limitation, and risk transference.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
76
Compare a hot site, a warm site, and a cold site as strategies for business continuity.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
77
Contrast the four types of authentication.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
78
Describe how a digital certificate works.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
79
Define the principle of least privilege, and consider how an organization's senior executives might view the application of this principle.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
80
Organizations use hot sites, warm sites, and cold sites to insure business continuity. Which of the following statements is not true?

A) A cold site has no equipment.
B) A warm site has no user workstations.
C) A hot site needs to be located close to the organization's offices.
D) A hot site duplicates all of the organization's resources.
E) A warm site does not include actual applications.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 84 في هذه المجموعة.