260 Unit 1 Quiz

¡Supera tus tareas y exámenes ahora con Quizwiz!

Which act requires banks and financial institutions to alert their customers of their policies in disclosing customer information? Financial and Personal Services Disclosure Act Health Insurance Portability and Accountability Act (HIPAA) Gramm-Leach-Bliley Act (GLBA) Sarbanes-Oxley Act (Sarbox)

GLBA

Which tool is most commonly associated with nation state threat actors? Closed-Source Resistant and Recurrent Malware (CSRRM) Advanced Persistent Threat (APT) Unlimited Harvest and Secure Attack (UHSA) Network Spider and Worm Threat (NSAWT)

APT

What is the category of threat actors that sell their knowledge of vulnerabilities to other attackers or governments? Competitors Brokers Cyberterrorists Resource managers

Brokers

Which of the following ensures that only authorized parties can view protected information? Authorization Availability Integrity Confidentiality

Confidentiality

An organization that practices purchasing products from different vendors is demonstrating which security principle? Obscurity Limiting Layering Diversity

Diversity

Gunnar is creating a document that explains risk response techniques. Which of the following would he NOT list and explain in his document? Mitigate risk Extinguish risk Transfer risk Avoid risk

Extinguish Risk

Which the following is NOT a reason why it is difficult to defend against today's attackers? Delays in security updating Greater sophistication of defense tools Increased speed of attacks Simplicity of attack tools

Greater sophistication of defense tools

Which of the following is an enterprise critical asset? Outsourced computing services System software Information Servers, routers, and power supplies

Information

Alyona has been asked by her supervisor to give a presentation regarding reasons why security attacks continue to be successful. She has decided to focus on the issue of widespread vulnerabilities. Which of the following would Alyona NOT include in her presentation? Misconfigurations End-of-life systems Large number of vulnerabilities Lack of vendor support

Misconfigurations

Signe wants to improve the security of the small business where she serves as a security manager. She determines that the business needs to do a better job of not revealing the type of computer, operating system, software, and network connections they use. What security principle does Signe want to use? Obscurity Layering Diversity Limiting

Obscurity

Which of the following is NOT a successive layer in which information security is achieved? Procedures People Purposes Products

Purposes

What are industry-standard frameworks and reference architectures that are required by external agencies known as? Compulsory Required Regulatory Mandatory

Regulatory

Ian recently earned his security certification and has been offered a promotion to a position that requires him to analyze and design security solutions as well as identifying users' needs. Which of these generally recognized security positions has Ian been offered? Security officer Security manager Security administrator Security technician

Security administrator

Adone is attempting to explain to his friend the relationship between security and convenience. Which of the following statements would he use? Whenever security and convenience intersect, security always wins. Security and convenience are inversely proportional. Security and convenience are not related. Convenience always outweighs security.

Security and convenience are inversely proportional.

Why do cyberterrorists target power plants, air traffic control centers, and water systems? The targets are privately owned and cannot afford high levels of security. These targets are government-regulated and any successful attack would be considered a major victory. They can cause significant disruption by destroying only a few targets. These targets have notoriously weak security and are easy to penetrate.

They can cause significant disruption by destroying only a few targets.

What is an objective of state-sponsored attackers? To amass fortune over of fame To right a perceived wrong To sell vulnerabilities to the highest bidder To spy on citizens

To spy on citizens

Tatyana is discussing with her supervisor potential reasons why a recent attack was successful against one of their systems. Which of the following configuration issues would NOT be covered? Vulnerable business processes Misconfigurations Weak configurations Default configurations

Vulnerable business processes

What is a race condition? When a vulnerability is discovered and there is a race to see if it can be patched before it is exploited by attackers. When an attack finishes its operation before antivirus can complete its work. When two concurrent threads of execution access a shared resource simultaneously, resulting in unintended consequences. When a software update is distributed prior to a vulnerability being discovered.

When two concurrent threads of execution access a shared resource simultaneously, resulting in unintended consequences.

Complete this definition of information security: That which protects the integrity, confidentiality, and availability of information _____. on electronic digital devices and limited analog devices that can connect via the Internet or through a local area network using both open-sourced as well as supplier-sourced hardware and software that interacts appropriately with limited resources through a long-term process that results in ultimate security through products, people, and procedures on the devices that store, manipulate, and transmit the information

through products, people, and procedures on the devices that store, manipulate, and transmit the information

Which of the following is NOT true regarding security? Security is a goal. Security is a process. Security includes the necessary steps to protect from harm. Security is a war that must be won at all costs.

Security is a war that must be won at all costs.


Conjuntos de estudio relacionados

Nutrition Consultant Exam Chp 1-3

View Set

WEEK 3: CHAPTER 12 - SOLVING A PROBLEM: CRIME AND JUSTICE

View Set

Peds Exam 1: Genitourinary & Respiratory

View Set

International Business Ch. 6: International Trade Theory

View Set

AGEC 330 Lecture 1, AGEC 330, Chapter 2 (pt 2) Time Value of Money Basics, AGEC 330 Exam 1, Ch. 9 Practice Problems, TAMU AGEC 330 with Leatham, AGEC 330 Lecture 15, AGEC 330, AGEC 330 Exam 4, AGEC 330 Lecture 24, AGEC 330 Exam 3 Review, AGEC 330 fin...

View Set