Guide – Practice Questions & Verified
Answers
Prepare for your exams with confidence using this comprehensive and well-organized study
guide. This resource is designed to help students understand key concepts, strengthen their
knowledge, and improve exam performance through carefully structured practice questions
and detailed explanations.
The document includes exam-style questions that closely reflect the format and difficulty of
real assessments, helping students become familiar with the types of questions they may
encounter. Each question is accompanied by accurate answers and clear explanations,
allowing you to fully understand the reasoning behind the correct responses.
What This Study Guide Offers
✔ Practice questions based on important and commonly tested topics
✔ Verified answers with clear, easy-to-follow explanations
✔ Well-structured formatting for efficient studying and revision
✔ Coverage of key course concepts and learning objectives
✔ A reliable resource for strengthening understanding and exam readiness
Why This Resource Is Useful
This study guide is designed to support students who want to review effectively, identify
knowledge gaps, and improve their test-taking skills. By practicing with exam-style questions
and reviewing detailed explanations, students can reinforce their understanding and build
confidence before their exams.
Ideal For
• Final exam preparation
• Midterm review
• Regular revision sessions
• Improving understanding of difficult topics
• Enhancing overall academic performance
,Whether you are studying weeks in advance or reviewing shortly before an exam, this guide
provides structured practice and clear explanations to help you prepare effectively and
perform at your best.
A valuable study resource for students who want to prepare smarter and succeed in their
exams.
Concepts
CIA (Diagram)
DAD - NEGATIVE - (disclosure alteration and destruction)
Confidentiality - prevent unauthorized disclosure, need to know, and least privilege. assurance
that information is not disclosed to unauthorized programs, users, processes, encryption, logical
and physical access control,
Integrity - no unauthorized modifications, consistent data, protecting data or a resource from
being altered in an unauthorized fashion
Availability - reliable and timely, accessible, fault tolerance and recovery procedures, WHEN
NEEDED
IAAA - requirements for accountability
Identification - user claims identity, used for user access control
Authentication - testing of evidence of users identity
Accountability - determine actions to an individual person
Authorization - rights and permissions granted
Privacy - level of confidentiality and privacy protections
Risk
Not possible to get rid of all risk.
Get risk to acceptable/tolerable level
Baselines - minimum standards
ISO 27005 - risk management framework
Budget - if not constrained go for the $$$
Responsibilities of the ISO
Written Products - ensure they are done
CIRT - implement and operate
Security Awareness - provide leadership
,Communicate - risk to higher management
Report to as high a level as possible
Security is everyone's responsibility
Control Frameworks
Consistent - approach & application
Measurable - way to determine progress
Standardized - all the same
Comprehension - examine everything
Modular - to help in review and adaptive. Layered, abstraction
Due Care Which means when a company did all that it could have reasonably done to try and
prevent security breach / compromise / disaster, and took the necessary steps required as
countermeasures / controls (safeguards). The benefit of "due care" can be seen as the
difference between the damage with or without "due care" safeguards in place. AKA doing
something about the threats, Failing to perform periodic security audits can result in the
perception that due care is not being maintained
Due Diligence means that the company properly investigated all of its possibly weaknesses and
vulnerabilities AKA understanding the threats
Intellectual property laws
Patent - grants ownership of an invention and provides enforcement for owner to exclude
others from practicing the invention. After 20 years the idea is open source of application
Copyright protects the expression of ideas but not necessarily the idea itself ex. Poem, song
@70 years after author dies
Trade Secret - something that is propriety to a company and important for its survival and
profitability (like formula of Coke or Pepsi) DON'T REGISTER - no application
Trademarks - words, names, product shape, symbol, color or a combination used to identify
products and distinguish them from competitor products (McDonald's M) @10 years
Wassenaar Arrangement (WA) - Dual use goods & trade, International cryptographic
agreement, prevent destabilizing
Computer Crimes - loss, image, penalties
, Regulations
SOX, Sarbanes Oxley, 2002 after ENRON and World Online debacle Independent review by
external accountants.
Section 302: CEO's CFO's can be sent to jail when information they sign is incorrect. CEO SIGN
Section 404 is the about internal controls assessment: describing logical controls over
accounting files; good auditing and information security.
Corporate Officer Liability
Executives are now held liable if the organization they represent is not compliant with the law.
Negligence occurs if there is a failure to implement recommended precautions, if there is no
contingency/disaster recovery plan, failure to conduct appropriate background checks, failure to
institute appropriate information security measures, failure to follow policy or local laws and
regulations.
COSO - framework to work with Sarbanes-Oxley 404 compliance
European laws: TREADWAY COMMISSION
Need for information security to protect the individual.
Privacy is the keyword here! Only use information of individuals for what it was gathered for
(remember ITSEC, the European version of TCSEC that came from the USA/Orange Book, come
together in Common Criteria, but there still is some overlap)
• strong in anti-spam and legitimate marketing
• Directs public directories to be subjected to tight controls
• Takes an OPT-IN approach to unsolicited commercial electronic communications
• User may refuse cookies to be stored and user must be provided with information
• Member states in the EU can make own laws e.g.
retention of data
COBIT - examines the effectiveness, efficiency, confidentiality, integrity, availability, compliance,
and reliability of high level control objectives. Having controls, GRC heavy auditing, metrics,
regulated industry
Data Breaches
Incident - an event that has potential to do harm