BUS 305 Chapter 7

Unlock all answers in this set

Unlock answers
question
1) The potential for unauthorized access is usually limited to the communications lines of a network.
answer
Answer: FALSE
question
2) Computers using cable modems to connect to the Internet are more open to penetration than those connecting via dial-up.
answer
Answer: TRUE
question
3) Wireless networks are vulnerable to penetration because radio frequency bands are easy to scan.
answer
Answer: TRUE
question
) The range of Wi-Fi networks can be extended up to two miles by using external antennae.
answer
Answer: FALSE
question
5) The WEP specification calls for an access point and its users to share the same 40-bit encrypted password.
answer
Answer: TRUE
question
6) Viruses can be spread through e-mail.
answer
Answer: TRUE
question
7) Computer worms spread much more rapidly than computer viruses.
answer
Answer: TRUE
question
8) One form of spoofing involves forging the return address on an e-mail so that the e-mail message appears to come from someone other than the sender.
answer
Answer: TRUE
question
9) Sniffers enable hackers to steal proprietary information from anywhere on a network, including e-mail messages, company files, and confidential reports.
answer
Answer: TRUE
question
10) DoS attacks are used to destroy information and access restricted areas of a company's information system.
answer
Answer: FALSE
question
11) DOS attacks are one of the most economically damaging kinds of computer crime.
answer
Answer: TRUE
question
12) Zero defects cannot be achieved in larger software programs because fully testing programs that contain thousands of choices and millions of paths would require thousands of years.
answer
Answer: TRUE
question
13) An acceptable use policy defines the acceptable level of access to information assets for different users.
answer
Answer: FALSE
question
14) Biometric authentication is the use of physical characteristics such as retinal images to provide identification.
answer
Answer: TRUE
question
15) Packet filtering catches most types of network attacks.
answer
Answer: FALSE
question
16) NAT conceals the IP addresses of the organization's internal host computers to deter sniffer programs.
answer
Answer: TRUE
question
17) SSL is a protocol used to establish a secure connection between two computers.
answer
Answer: TRUE
question
18) Public key encryption uses two keys.
answer
Answer: TRUE
question
19) High-availability computing is also referred to as fault tolerance.
answer
Answer: FALSE
question
20) Smartphones typically feature state-of-the-art encryption and security features, making them highly secure tools for businesses.
answer
Answer: FALSE
question
21) ________ refers to policies, procedures, and technical measures used to prevent unauthorized access, alternation, theft, or physical damage to information systems. A) "Security" B) "Controls" C) "Benchmarking" D) "Algorithms"
answer
Answer: A
question
22) ________ refers to all of the methods, policies, and organizational procedures that ensure the safety of the organization's assets, the accuracy and reliability of its accounting records, and operational adherence to management standards. A) "Legacy systems" B) "SSID standards" C) "Vulnerabilities" D) "Controls"
answer
Answer: D
question
23) Large amounts of data stored in electronic form are ________ than the same data in manual form. A) less vulnerable to damage B) more secure C) vulnerable to many more kinds of threats D) more critical to most businesses
answer
Answer: C
question
24) Electronic data are more susceptible to destruction, fraud, error, and misuse because information systems concentrate data in computer files that: A) are usually bound up in legacy systems that are difficult to access and difficult to correct in case of error. B) are not secure because the technology to secure them did not exist at the time the files were created. C) have the potential to be accessed by large numbers of people and by groups outside of the organization. D) are frequently available on the Internet.
answer
Answer: C
question
25) Specific security challenges that threaten the communications lines in a client/server environment include: A) tapping; sniffing; message alteration; radiation. B) hacking; vandalism; denial of service attacks. C) theft, copying, alteration of data; hardware or software failure. D) unauthorized access; errors; spyware.
answer
Answer: A
question
26) Specific security challenges that threaten clients in a client/server environment include: A) tapping; sniffing; message alteration; radiation. B) hacking; vandalism; denial of service attacks. C) theft, copying, alteration of data; hardware or software failure. D) unauthorized access; errors; spyware.
answer
Answer: D
question
27) Specific security challenges that threaten corporate servers in a client/server environment include: A) tapping; sniffing; message alteration; radiation. B) hacking; vandalism; denial of service attacks. C) theft, copying, alteration of data; hardware or software failure. D) unauthorized access; errors; spyware.
answer
Answer: B
question
28) The Internet poses specific security problems because: A) it was designed to be easily accessible. B) Internet data is not run over secure lines. C) Internet standards are universal. D) it changes so rapidly.
answer
Answer: A
question
29) Which of the following statements about the Internet security is not true? A) The use of P2P networks can expose a corporate computer to outsiders. B) A corporate network without access to the Internet is more secure than one provides access. C) VoIP is more secure than the switched voice network. D) Instant messaging can provide hackers access to an otherwise secure network.
answer
Answer: C
question
30) An independent computer program that copies itself from one computer to another over a network is called a: A) worm. B) Trojan horse. C) bug. D) pest.
answer
Answer: A
question
31) A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's advertising costs up. This is an example of: A) phishing. B) pharming. C) spoofing. D) click fraud.
answer
Answer: D
question
32) In 2004, ICQ users were enticed by a sales message from a supposed anti-virus vendor. On the vendor's site, a small program called Mitglieder was downloaded to the user's machine. The program enabled outsiders to infiltrate the user's machine. What type of malware is this an example of? A) Trojan horse B) Virus C) Worm D) Spyware
answer
Answer: A
question
33) Redirecting a Web link to a different address is a form of: A) snooping. B) spoofing. C) sniffing. D) war driving.
answer
Answer: B
question
34) A keylogger is a type of: A) worm. B) Trojan horse. C) virus. D) spyware.
answer
Answer: D
question
35) Hackers create a botnet by: A) infecting Web search bots with malware. B) by using Web search bots to infect other computers. C) by causing other people's computers to become "zombie" PCs following a master computer. D) by infecting corporate servers with "zombie" Trojan horses that allow undetected access through a back door.
answer
Answer: C
question
36) Using numerous computers to inundate and overwhelm the network from numerous launch points is called a ________ attack. A) DDoS B) DoS C) SQL injection D) phishing
answer
Answer: A
question
37) Which of the following is not an example of a computer used as a target of crime? A) Knowingly accessing a protected computer to commit fraud B) Accessing a computer system without authority C) Illegally accessing stored electronic communication D) Threatening to cause damage to a protected computer
answer
Answer: C
question
38) Which of the following is not an example of a computer used as an instrument of crime? A) Theft of trade secrets B) Intentionally attempting to intercept electronic communication C) Unauthorized copying of software D) Breaching the confidentiality of protected computerized data
answer
Answer: D
question
39) Phishing is a form of: A) spoofing. B) logging. C) sniffing. D) driving.
answer
Answer: A
question
40) An example of phishing is: A) setting up a bogus Wi-Fi hot spots. B) setting up a fake medical Web site that asks users for confidential information. C) pretending to be a utility company's employee in order to garner information from that company about their security system. D) Sending bulk e-mail that asks for financial aid under a false pretext.
answer
Answer: B
question
41) Evil twins are: A) Trojan horses that appears to the user to be a legitimate commercial software application. B) e-mail messages that mimic the e-mail messages of a legitimate business. C) fraudulent Web sites that mimic a legitimate business's Web site. D) bogus wireless network access points that look legitimate to users.
answer
Answer: D
question
42) Pharming involves: A) redirecting users to a fraudulent Web site even when the user has typed in the correct address in the Web browser. B) pretending to be a legitimate business's representative in order to garner information about a security system. C) setting up fake Web sites to ask users for confidential information. D) using e-mails for threats or harassment.
answer
Answer: A
question
43) You have been hired as a security consultant for a law firm. Which of the following constitutes the greatest source of security threats to the firm? A) Wireless network B) Employees C) Authentication procedures D) Lack of data encryption
answer
Answer: B
question
44) Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is called: A) sniffing. B) social engineering. C) phishing. D) pharming.
answer
Answer: B
question
45) How do software vendors correct flaws in their software after it has been distributed? A) Issue bug fixes B) Issue patches C) Re-release software D) Issue updated versions
answer
Answer: B
question
46) The HIPAA Act of 1997: A) requires financial institutions to ensure the security of customer data. B) specifies best practices in information systems security and control. C) imposes responsibility on companies and management to safeguard the accuracy of financial information. D) outlines medical security and privacy rules.
answer
Answer: D
question
47) The Gramm-Leach-Bliley Act: A) requires financial institutions to ensure the security of customer data. B) specifies best practices in information systems security and control. C) imposes responsibility on companies and management to safeguard the accuracy of financial information. D) outlines medical security and privacy rules.
answer
Answer: A
question
48) The Sarbanes-Oxley Act: A) requires financial institutions to ensure the security of customer data. B) specifies best practices in information systems security and control. C) imposes responsibility on companies and management to safeguard the accuracy of financial information. D) outlines medical security and privacy rules.
answer
Answer: C
question
49) The most common type of electronic evidence is: A) voice-mail. B) spreadsheets. C) instant messages. D) e-mail.
answer
Answer: D
question
50) Electronic evidence on computer storage media that is not visible to the average user is called ________ data. A) defragmented B) ambient C) forensic D) fragmented
answer
Answer: B
question
51) Application controls: A) can be classified as input controls, processing controls, and output controls. B) govern the design, security, and use of computer programs and the security of data files in general throughout the organization. C) apply to all computerized applications and consist of a combination of hardware, software, and manual procedures that create an overall control environment. D) include software controls, computer operations controls, and implementation controls.
answer
Answer: A
question
52) ________ controls ensure that valuable business data files on either disk or tape are not subject to unauthorized access, change, or destruction while they are in use or in storage. A) Software B) Administrative C) Data security D) Implementation
answer
Answer: C
question
53) Analysis of an information system that rates the likelihood of a security incident occurring and its cost is included in a(n) A) security policy. B) AUP. C) risk assessment. D) business impact analysis.
answer
Answer: C
question
54) Statements ranking information risks and identifying security goals are included in a(n): A) security policy. B) AUP. C) risk assessment. D) business impact analysis.
answer
Answer: A
question
55) An analysis of the firm's most critical systems and the impact a system's outage would have on the business is included in a(n): A) security policy. B) AUP. C) risk assessment. D) business impact analysis.
answer
Answer: D
question
56) Rigorous password systems A) are one of the most effective security tools. B) may hinder employee productivity. C) are costly to implement. D) are often disregarded by employees.
answer
Answer: B
question
57) An authentication token is a(n): A) device the size of a credit card that contains access permission data. B) type of smart card. C) gadget that displays passcodes. D) electronic marker attached to a digital authorization file.
answer
Answer: C
question
58) Biometric authentication: A) is inexpensive. B) is used widely in Europe for security applications. C) can use a person's voice as a unique, measurable trait. D) only uses physical measurements for identification.
answer
Answer: C
question
59) A firewall allows the organization to: A) enforce a security policy on traffic between its network and the Internet. B) check the accuracy of all transactions between its network and the Internet. C) create an enterprise system on the Internet. D) check the content of all incoming and outgoing e-mail messages.
answer
Answer: A
question
60) In which technique are network communications are analyzed to see whether packets are part of an ongoing dialogue between a sender and a receiver? A) Stateful inspection B) Intrusion detection system C) Application proxy filtering D) Packet filtering
answer
Answer: A
question
61) ________ use scanning software to look for known problems such as bad passwords, the removal of important files, security attacks in progress, and system administration errors. A) Stateful inspections B) Intrusion detection systems C) Application proxy filtering technologies D) Packet filtering technologies
answer
Answer: B
question
62) Currently, the protocols used for secure information transfer over the Internet are: A) TCP/IP and SSL. B) S-HTTP and CA. C) HTTP and TCP/IP. D) SSL, TLS, and S-HTTP.
answer
Answer: D
question
63) Most antivirus software is effective against:A) only those viruses active on the Internet and through e-mail. B) any virus.C) any virus except those in wireless communications applications. D) only those viruses already known when the software is written.
answer
Answer: D
question
64) In which method of encryption is a single encryption key sent to the receiver so both sender and receiver share the same key? A) SSL B) Symmetric key encryption C) Public key encryption D) Private key encryption
answer
Answer: B
question
65) A digital certificate system: A) uses third-party CAs to validate a user's identity. B) uses digital signatures to validate a user's identity. C) uses tokens to validate a user's identity. D) is used primarily by individuals for personal correspondence.
answer
Answer: A
question
66) Downtime refers to periods of time in which a: A) computer system is malfunctioning. B) computer system is not operational. C) company or organization is not operational. D) computer is not online.
answer
Answer: B
question
67) For 100% availability, online transaction processing requires: A) high-capacity storage. B) a multi-tier server network. C) fault-tolerant computer systems. D) dedicated phone lines.
answer
Answer: C
question
68) In controlling network traffic to minimize slow-downs, a technology called ________ is used to examine data files and sort low-priority data from high-priority data. A) high availability computing B) deep-packet inspection C) application proxy filtering D) stateful inspection
answer
Answer: B
question
69) The development and use of methods to make computer systems resume their activities more quickly after mishaps is called: A) high availability computing. B) recovery oriented computing. C) fault tolerant computing. D) disaster recovery planning.
answer
Answer: B
question
70) Smaller firms may outsource some or many security functions to: A) ISPs. B) MISs. C) MSSPs. D) CAs.
answer
Answer: A
question
71) A practice in which eavesdroppers drive by buildings or park outside and try to intercept wireless network traffic is referred to as ________.
answer
Answer: war driving
question
72) Malicious software programs referred to as ________ include a variety of threats such as computer viruses, worms, and Trojan horses.
answer
Answer: malware
question
73) ________ is a crime in which an imposter obtains key pieces of personal information to impersonate someone else.
answer
Answer: Identity theft
question
74) ________ is the scientific collection, examination, authentication, preservation, and analysis of data held on or retrieved from computer storage media in such a way that the information can be used as evidence in a court of law.
answer
Answer: Computer forensics
question
75) On the whole, ________ controls apply to all computerized applications and consist of a combination of hardware, software, and manual procedures that create an overall control environment.
answer
Answer: general
question
76) A(n) ________ examines the firm's overall security environment as well as the controls governing individual information systems.
answer
Answer: MIS audit
question
77) ________ refers to the ability to know that a person is who he or she claims to be.
answer
Answer: Authentication
question
78) Comprehensive security management products, with tools for firewalls, VPNs, intrusion detection systems, and more, are called ________ systems.
answer
Answer: unified threat management
question
79) PKI is the use of public key cryptography working with a(n) ________.
answer
Answer: certificate authority
question
80) When errors are discovered in software programs, the sources of the errors are found and eliminated through a process called ________.
answer
Answer: debugging
Get an explanation on any task
Get unstuck with the help of our AI assistant in seconds
New