Fundamentals of Information Security
with verified solutions
Controls that protect the systems, networks, and environments that process,
transmit, and store our data are called _______. - ANSWERLogical Controls
During what phase of the incident response process do we determine what
happened, why it happened, and what we can do to keep it from happening
again? - ANSWERPost-Incident Activity
Something that has the potential to cause harm to our assets is known as a(n)
________. - ANSWERThreat
What is the first and arguably one of the most important steps of the risk
management process? - ANSWERIdentify assess
The Fabrication attack type most commonly affects which principle(s) of the
CIA triad? - ANSWERIntegrity and Availability
The Interception attack type most commonly affects which principle(s) of the
CIA triad? - ANSWERConfidentiality
A badge or token is considered what type of authentication? -
ANSWERSomething you have
,A password or PIN is considered what type of authentication? -
ANSWERSomething you know
The set of methods we use to establish a claim of identity as being true is
called ______. - ANSWERAuthentication
A fingerprint is considered what type of authentication? - ANSWERSomething
you are
What type of authentication can prevent a man-in-the-middle attack? -
ANSWERMutual
The biometric characteristic that measures how well a factor resists change
over time and with advancing age is called __________ -
ANSWERPermanence
What dictates that we should only allow the bare minimum of access, as
needed? - ANSWERPrinciple of least privilege
Access controls are policies or procedures used to control access to certain
items. - ANSWERTrue
What is implemented through the use of access controls? -
ANSWERAuthorization
Which ANSWER best describes the authorization component of access
control? - ANSWERAuthorization is the process of determining who is
approved for access and what resources they are approved for.
,A client-side attack that involves the attacker placing an invisible layer over
something on a website that the user would normally click on, in order to
execute a command differing from what the user thinks they are performing,
is known as ___________. - ANSWERClickjacking
What type of access control can prevent the confused deputy problem? -
ANSWERCapability-based security
A user who creates a network share and sets permissions on that share is
employing which model of access control? - ANSWERDiscretionary access
control
A VPN connection that is set to time out after 24 hours is demonstrating
which model of access control? - ANSWERAttribute-based access control
Confidential Services Inc. is a military-support branch consisting of 1,400
computers with Internet access and 250 servers. All employees are required
to have security clearances. From the options listed below, what access
control model would be most appropriate for this organization? -
ANSWERMandatory access control
What is information security? - ANSWERProtecting information and
information systems from unauthorized access, use, disclosure, disruption,
modification, or destruction.
Using the concept of defense in depth we can protect ourselves against
someone using a USB flash drive to remove confidential data from an office
space within our building. - ANSWERTrue
, Select the example(s) of identity verification. (Choose all that apply.) -
ANSWERSSN
Passport
Birth certificate
Multifactor authentication is the use of more than one authentication
method to access an information system. - ANSWERTrue
Which password below would meet complexity standards? -
ANSWER!Q@S#z6ge7Uks1lw3
What is accountability comprised of? - ANSWERAuthorization
Authentication
Identification
Access
What document do courts require for admissibility of records? -
ANSWERChain of custody
with verified solutions
Controls that protect the systems, networks, and environments that process,
transmit, and store our data are called _______. - ANSWERLogical Controls
During what phase of the incident response process do we determine what
happened, why it happened, and what we can do to keep it from happening
again? - ANSWERPost-Incident Activity
Something that has the potential to cause harm to our assets is known as a(n)
________. - ANSWERThreat
What is the first and arguably one of the most important steps of the risk
management process? - ANSWERIdentify assess
The Fabrication attack type most commonly affects which principle(s) of the
CIA triad? - ANSWERIntegrity and Availability
The Interception attack type most commonly affects which principle(s) of the
CIA triad? - ANSWERConfidentiality
A badge or token is considered what type of authentication? -
ANSWERSomething you have
,A password or PIN is considered what type of authentication? -
ANSWERSomething you know
The set of methods we use to establish a claim of identity as being true is
called ______. - ANSWERAuthentication
A fingerprint is considered what type of authentication? - ANSWERSomething
you are
What type of authentication can prevent a man-in-the-middle attack? -
ANSWERMutual
The biometric characteristic that measures how well a factor resists change
over time and with advancing age is called __________ -
ANSWERPermanence
What dictates that we should only allow the bare minimum of access, as
needed? - ANSWERPrinciple of least privilege
Access controls are policies or procedures used to control access to certain
items. - ANSWERTrue
What is implemented through the use of access controls? -
ANSWERAuthorization
Which ANSWER best describes the authorization component of access
control? - ANSWERAuthorization is the process of determining who is
approved for access and what resources they are approved for.
,A client-side attack that involves the attacker placing an invisible layer over
something on a website that the user would normally click on, in order to
execute a command differing from what the user thinks they are performing,
is known as ___________. - ANSWERClickjacking
What type of access control can prevent the confused deputy problem? -
ANSWERCapability-based security
A user who creates a network share and sets permissions on that share is
employing which model of access control? - ANSWERDiscretionary access
control
A VPN connection that is set to time out after 24 hours is demonstrating
which model of access control? - ANSWERAttribute-based access control
Confidential Services Inc. is a military-support branch consisting of 1,400
computers with Internet access and 250 servers. All employees are required
to have security clearances. From the options listed below, what access
control model would be most appropriate for this organization? -
ANSWERMandatory access control
What is information security? - ANSWERProtecting information and
information systems from unauthorized access, use, disclosure, disruption,
modification, or destruction.
Using the concept of defense in depth we can protect ourselves against
someone using a USB flash drive to remove confidential data from an office
space within our building. - ANSWERTrue
, Select the example(s) of identity verification. (Choose all that apply.) -
ANSWERSSN
Passport
Birth certificate
Multifactor authentication is the use of more than one authentication
method to access an information system. - ANSWERTrue
Which password below would meet complexity standards? -
ANSWER!Q@S#z6ge7Uks1lw3
What is accountability comprised of? - ANSWERAuthorization
Authentication
Identification
Access
What document do courts require for admissibility of records? -
ANSWERChain of custody