VERSION !!!|A+ GRADED|EXAM READY|95%
Which is the MOST reliable sender authentication? - ANSWER Digital certificates
Which of the following provides the GREATEST assurance of message authenticity? -
ANSWER The prehash code is encrypted using the sender's private key.
An IS auditor performing detailed network assessments and access control reviews should
FIRST: - ANSWER determine the points of entry
The PRIMARY objective of Secure Sockets Layer (SSL) is to ensure: - ANSWER only the
sender and receiver are able to encrypt/decrypt the data
Which of the following ensures a sender's authenticity and an email's confidentiality? -
ANSWER encrypting the hash of the message with the sender's private key and
thereafter encrypting the message with the receiver's public key
An efficient use of public key infrastructure (PKI) should encrypt the: -
ANSWER symmetric session key
When auditing security for a data center, an IS auditor should look for the presence of a
voltage regulator to ensure that the: - ANSWER hardware is protected against power
surges
What is a risk associated with attempting to control physical access to sensitive areas such as
computer rooms using card keys or locks? - ANSWER unauthorized individuals wait for
controlled doors to open and walk in behind those authorized.
1
, In a public key infrastructure (PKI), a registration authority: - ANSWER verifies
information supplied by the subject requesting certificate
In transport mode, the use of the Encapsulating Security Payload (ESP) protocol is
advantageous ove the Authentication Header (AH) protocol because it provides: -
ANSWER confidentially
Two factor authentication can be circumvented through which of the following attacks -
ANSWER man in the middle
An IS auditor reviewing wireless network security determines that the Dynamic Host
Configuration Protocol (DHCP) is disabled at all wireless access points. This practice: -
ANSWER reduces the risk of unauthorized access to the network
In a public key infrastructure (PKI), which of the following may be relied upon to prove that
an online transaction was authorized by a specific customer? -
ANSWER nonrepudiation
The responsibility for authorizing access to application data should be with the: -
ANSWER data owner
The purpose of a deadman door controlling access to a computer facility is PRIMARY to: -
ANSWER prevent piggybacking
An IS auditor selects a server for a penetration test that will be carried out by a technical
specialist. Which of the following is MOST important? - ANSWER Permission from the
data owner of the server
A technical lead who was working on a major project has left the organization. The project
manager reports suspicious system activities on one of the servers that is accessible to the
2