Security – Chapter 02 – Review*

Flashcard maker : Lily Taylor
Why is information security a management problem? What can management do that technology cannot?
Answers soon
Why is data the most important asset an organization possesses? What other assets in the organization require protection?
Answers soon
Which management groups are responsible for implementing information security to protect the organization’s ability to function?
Has the implementation of networking technology created more or less risk for businesses that use information technology? Why?
What is information extortion? Describe how such an attack can cause losses, using an example not found in the text.
Why do employees constitute one of the greatest threats to information security?
What measures can individuals take to protect against shoulder surfing?
How has the perception of the hacker changed over recent years? What is the profile of a hacker today?
What is the difference between a skilled hacker and an unskilled hacker (other than skill levels)? How does the protection against each differ?
What are the various types of malware? How do worms differ from viruses? Do Trojan horses carry viruses or worms?
Why does polymorphism cause greater concern than traditional malware? How does it affect detection?
What is the most common form of violation of intellectual property? How does an organization protect against it? What agencies fight it?
What are the various types of force majeure? Which type might be of greatest concern to an organization in Las Vegas? Oklahoma City? Miami? Los Angeles?
How does technological obsolescence constitute a threat to information security? How can an organization protect against it?
Does the intellectual property owned by an organization usually have value? If so, how can attackers threaten that value?
What are the types of password attacks? What can a systems administrator do to protect against them?
What is the difference between a denial-of-service attack and a distributed denial-of-service attack? Which is more dangerous? Why?
For a sniffer attack to succeed, what must the attacker do? How can an attacker gain access to a network to use the sniffer system?
What methods does a social engineering hacker use to gain information about a user’s login id and password? How would this method differ if it were targeted towards an administrator’s assistant versus a data-entry clerk?
What is a buffer overflow, and how is it used against a Web server?

Get instant access to
all materials

Become a Member