Computer Security Principles and Practice, 5th Edition by William Stallings Lawrie
Brown
Chapter 1-24 Answers are at the End of Last Chapter
Chapter 1 – Overview
TRUE/FALSE zQUESTIONS:
T F 1. z Threats zare zattacks zcarried zout.
T F 2. z Computer zsecurity zis zprotection zof zthe zintegrity, zavailability, zand
zconfidentiality zof zinformation zsystem zresources.
T F 3. z Data zintegrity zassures zthat zinformation zand zprograms zare zchanged
zonly zin za zspecified zand zauthorized zmanner.
T F 4. z Availability zassures zthat zsystems zworks zpromptly zand zservice zis znot
zdenied zto zauthorized zusers.
T F 5. z The z―A‖ zin zthe zCIA ztriad zstands zfor z―authenticity‖.
T F 6. z The zmore zcritical za zcomponent zor zservice, zthe zhigher zthe zlevel zof
zavailability zrequired.
T F 7. z Computer zsecurity zis zessentially za zbattle zof zwits zbetween za
zperpetrator zwho ztries zto zfind zholes zand zthe zadministrator zwho ztries zto
zclose zthem.
T F 8. z Security zmechanisms ztypically zdo znot zinvolve zmore zthan zone
zparticular zalgorithm zor zprotocol.
T F 9. z Many zsecurity zadministrators zview zstrong zsecurity zas zan zimpediment
zto zefficient zand zuser-friendly zoperation zof zan zinformation zsystem.
T F 10. z In zthe zcontext zof zsecurity zour zconcern zis zwith zthe zvulnerabilities zof
zsystem zresources.
T F 11. z Hardware zis zthe zmost zvulnerable zto zattack zand zthe zleast zsusceptible
zto zautomated zcontrols.
T F 12. z Contingency zplanning zis za zfunctional zarea zthat zprimarily zrequires
zcomputer zsecurity ztechnical zmeasures.
T F 13. z An zattack zsurface zconsists zof zthe zreachable zand zexploitable
zvulnerabilities zin za zsystem.
Copyright © 2024, 2018, 2015 by Pearson Education, Inc. or its affiliates.
,T F 14. z The zfirst zstep zin zdevising zsecurity zservices zand zmechanisms zis
zto zdevelop za zsecurity zpolicy.
T F15. z Assurance zis zthe zprocess zof zexamining za zcomputer zproduct zor
zsystem zwith zrespect zto zcertain zcriteria.
MULTIPLE zCHOICE zQUESTIONS:
1. assures zthat zindividuals zcontrol zor zinfluence zwhat zinformation
zrelated zto zthem zmay zbe zcollected zand zstored zand zby zwhom zand zto zwhom zthat
zinformation zmay zbe zdisclosed.
A. Availability B. z System zIntegrity
C. z Privacy D. z Data zIntegrity
2. assures zthat za zsystem zperforms zits zintended zfunction zin zan
zunimpaired zmanner, zfree zfrom zdeliberate zor zinadvertent zunauthorized
zmanipulation zof zthe zsystem.
A. System zIntegrity B. z Data zIntegrity
C. z Availability D. z Confidentiality
3. A zloss zof is zthe zunauthorized zdisclosure zof zinformation.
A. confidentiality B. z integrity
C. z authenticity D. z availability
4. A z level zbreach zof zsecurity zcould zbe zexpected zto zhave za zsevere zor
zcatastrophic zadverse zeffect zon zorganizational zoperations, zorganizational zassets,
zor zindividuals.
A. low B. z normal
C. zmoderate D. z high
5. A zflaw zor zweakness zin za zsystem’s zdesign, zimplementation, zor zoperation
zand zmanagement zthat zcould zbe zexploited zto zviolate zthe zsystem’s zsecurity
zpolicy zis za(n) z .
A. countermeasure B. zvulnerability
C. z adversary D. z risk
6. An zassault zon zsystem zsecurity zthat zderives zfrom zan zintelligent zact zthat zis za
zdeliberate zattempt zto zevade zsecurity zservices zand zviolate zthe zsecurity zpolicy
zof za zsystem zis za(n) z .
A. risk B. z asset
C. z attack D. z vulnerability
Copyright © 2024, 2018, 2015 by Pearson Education, Inc. or its affiliates.
,7. A(n) z is zan zaction, zdevice, zprocedure, zor ztechnique zthat zreduces za
zthreat, za zvulnerability, zor zan zattack zby zeliminating zor zpreventing zit, zby
zminimizing zthe zharm zit zcan zcause, zor zby zdiscovering zand zreporting zit zso zthat
zcorrect zaction zcan zbe ztaken.
A. attack B. z countermeasure
C. z adversary D. z protocol
8. A(n) z is zan zattempt zto zlearn zor zmake zuse zof zinformation zfrom zthe
zsystem zthat zdoes znot zaffect zsystem zresources.
A. passive zattack B. zinside zattack
C. z outside zattack D. z active zattack
9. Masquerade, zfalsification, zand zrepudiation zare zthreat zactions zthat zcause
threat zconsequences.
A. unauthorized zdisclosure B. z deception
C. z disruption D. z usurpation
10. zA zthreat zaction zin zwhich zsensitive zdata zare zdirectly zreleased zto zan
zunauthorized zentity zis z .
A. corruption B. z disruption
C. z intrusion D. z exposure
11. zAn zexample zof z is zan zattempt zby zan zunauthorized zuser zto zgain
zaccess zto za zsystem zby zposing zas zan zauthorized zuser.
A. masquerade B. z interception
C. z repudiation D. z inference
12. zThe z prevents zor zinhibits zthe znormal zuse zor zmanagement
zof zcommunications zfacilities.
A. passive zattack B. z traffic zencryption
C. z denial zof zservice D. z masquerade
13. zA z is zany zaction zthat zcompromises zthe zsecurity zof zinformation
zowned zby zan zorganization.
A. security zmechanism B. z security zattack
C. z security zpolicy D. z security zservice
Copyright © 2024, 2018, 2015 by Pearson Education, Inc. or its affiliates.
, 14. zThe zassurance zthat zdata zreceived zare zexactly zas zsent zby zan
zauthorized zentity zis z.
A. authentication B. z data zconfidentiality
C. z access zcontrol D. z data zintegrity
15. z is zthe zinsertion zof zbits zinto zgaps zin za zdata zstream zto zfrustrate
traffic zanalysis zattempts.
z
A. Traffic zpadding B. z Traffic zrouting
C. z Traffic zcontrol D. z Traffic zintegrity
SHORT zANSWER zQUESTIONS:
1. is zthe zprotection zafforded zto zan zautomated zinformation zsystem zin zorder
zto zattain zthe zapplicable zobjectives zof zpreserving zthe zintegrity, zavailability, zand
zconfidentiality zof zinformation zsystem zresources.
2. Confidentiality, zIntegrity, zand zAvailability zform zwhat zis zoften zreferred zto zas zthe z .
3. A zloss zof z is zthe zdisruption zof zaccess zto zor zuse zof zinformation zor
zan zinformation zsystem.
4. Patient zallergy zinformation zis zan zexample zof zan zasset zwith za zhigh zrequirement zfor
.
5. A(n) z is za zthreat zthat zis zcarried zout zand, zif zsuccessful, zleads zto zan
zundesirable zviolation zof zsecurity, zor zthreat zconsequence.
6. A(n) z is zany zmeans ztaken zto zdeal zwith za zsecurity zattack.
7. Misappropriation zand zmisuse zare zattacks zthat zresult zin z threat zconsequences.
8. The zassets zof za zcomputer zsystem zcan zbe zcategorized zas zhardware,
zsoftware, zcommunication zlines zand znetworks, zand z .
9. Release zof zmessage zcontents zand ztraffic zanalysis zare ztwo ztypes zof z attacks.
10. Replay, zmasquerade, zmodification zof zmessages, zand zdenial zof zservice zare zexample zof
attacks.
11. Establishing, zmaintaining, zand zimplementing zplans zfor zemergency zresponse,
zbackup zoperations, zand zpost zdisaster zrecovery zfor zorganizational zinformation zsystems
zto zensure zthe zavailability zof zcritical zinformation zresources zand zcontinuity zof
zoperations zin zemergency zsituations zis za z plan.
12. A(n) z assessment zis zperiodically zassessing zthe zrisk zto
zorganizational zoperations, zorganizational zassets, zand zindividuals, zresulting zfrom
zthe zoperation zof
Copyright © 2024, 2018, 2015 by Pearson Education, Inc. or its affiliates.