TEST BANK
Computer Security Principles and Practice, 5th edition
by William Stallings,Lawrie Brown
ST
U
D
YL
AB
, Table of content
1.Overview
2.Cryptographic Tools
3.User Authentication
4.Access Control
5.Database and Data Center Security
6.Malicious Software
7.Denial-of-Service Attacs
8.Intrusion Detection
9.Firewalls and Intrusion Prevention Systems
ST
10.Buffer Overflow
11.Software Security
12.Operating Systems Security
13.Cloud and IoT Security
U
14.IT Security Management and Risk Assessment
15.IT Security Controls, plans, and Procedures
D
16.Physical and Infrastructure Security
17.Human Resources Security
YL
18.Security Auiditing
19.Legal and Ethical Aspects
20.Symmetric Encryption and Message Confidentiality
21.Public-Key Cryptography and Message Authentication
AB
22.Internet Security Protocols and Standards
23.Internet Authentication Applications
24.Wireless Network Security
, UYTREW
Chapter 1 – Computer Systems Overview All Chapters
TRUE/FALSE QUESTIONS: All Answers
T F 1. Threats are attacks carried out.
T F 2. Computer security is protection of the integrity, availability, and
confidentiality of information system resources.
T F 3. Data integrity assures that information and programs are changed only
in a specified and authorized manner.
T F 4. Availability assures that systems works promptly and service is not
ST
denied to authorized users.
T F 5. The “A” in the CIA triad stands for “authenticity”.
T F 6. The more critical a component or service, the higher the level of
availability required.
U
T F 7. Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
D
T F 8. Security mechanisms typically do not involve more than one particular
algorithm or protocol.
YL
T F 9. Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
T F 10. In the context of security our concern is with the vulnerabilities of
system resources.
AB
T F 11. Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
T F 12. Contingency planning is a functional area that primarily requires
computer security technical measures.
T F 13. X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
T F 14. The first step in devising security services and mechanisms is to
develop a security policy.
T F 15. Assurance is the process of examining a computer product or system
with respect to certain criteria.
jhgfdsa
, UYTREW
MULTIPLE CHOICE QUESTIONS:
1. assures that individuals control or influence what information related
to them may be collected and stored and by whom and to whom that information
may be disclosed.
A. Availability B. System Integrity
C. Privacy D. Data Integrity
2. assures that a system performs its intended function in an unimpaired
manner, free from deliberate or inadvertent unauthorized manipulation of the
system.
ST
A. System Integrity B. Data Integrity
C. Availability D. Confidentiality
3. A loss of is the unauthorized disclosure of information.
A. confidentiality B. integrity
U
C. authenticity D. availability
4. A level breach of security could be expected to have a severe or
catastrophic adverse effect on organizational operations, organizational assets, or
D
individuals.
A. low B. normal
YL
C. moderate D. high
5. A flaw or weakness in a system’s design, implementation, or operation and
management that could be exploited to violate the system’s security policy is
a(n) .
AB
A. countermeasure B. vulnerability
C. adversary D. risk
6. An assault on system security that derives from an intelligent act that is a
deliberate attempt to evade security services and violate the security policy of a
system is a(n) .
A. risk B. asset
C. attack D. vulnerability
jhgfdsa
Computer Security Principles and Practice, 5th edition
by William Stallings,Lawrie Brown
ST
U
D
YL
AB
, Table of content
1.Overview
2.Cryptographic Tools
3.User Authentication
4.Access Control
5.Database and Data Center Security
6.Malicious Software
7.Denial-of-Service Attacs
8.Intrusion Detection
9.Firewalls and Intrusion Prevention Systems
ST
10.Buffer Overflow
11.Software Security
12.Operating Systems Security
13.Cloud and IoT Security
U
14.IT Security Management and Risk Assessment
15.IT Security Controls, plans, and Procedures
D
16.Physical and Infrastructure Security
17.Human Resources Security
YL
18.Security Auiditing
19.Legal and Ethical Aspects
20.Symmetric Encryption and Message Confidentiality
21.Public-Key Cryptography and Message Authentication
AB
22.Internet Security Protocols and Standards
23.Internet Authentication Applications
24.Wireless Network Security
, UYTREW
Chapter 1 – Computer Systems Overview All Chapters
TRUE/FALSE QUESTIONS: All Answers
T F 1. Threats are attacks carried out.
T F 2. Computer security is protection of the integrity, availability, and
confidentiality of information system resources.
T F 3. Data integrity assures that information and programs are changed only
in a specified and authorized manner.
T F 4. Availability assures that systems works promptly and service is not
ST
denied to authorized users.
T F 5. The “A” in the CIA triad stands for “authenticity”.
T F 6. The more critical a component or service, the higher the level of
availability required.
U
T F 7. Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
D
T F 8. Security mechanisms typically do not involve more than one particular
algorithm or protocol.
YL
T F 9. Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
T F 10. In the context of security our concern is with the vulnerabilities of
system resources.
AB
T F 11. Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
T F 12. Contingency planning is a functional area that primarily requires
computer security technical measures.
T F 13. X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
T F 14. The first step in devising security services and mechanisms is to
develop a security policy.
T F 15. Assurance is the process of examining a computer product or system
with respect to certain criteria.
jhgfdsa
, UYTREW
MULTIPLE CHOICE QUESTIONS:
1. assures that individuals control or influence what information related
to them may be collected and stored and by whom and to whom that information
may be disclosed.
A. Availability B. System Integrity
C. Privacy D. Data Integrity
2. assures that a system performs its intended function in an unimpaired
manner, free from deliberate or inadvertent unauthorized manipulation of the
system.
ST
A. System Integrity B. Data Integrity
C. Availability D. Confidentiality
3. A loss of is the unauthorized disclosure of information.
A. confidentiality B. integrity
U
C. authenticity D. availability
4. A level breach of security could be expected to have a severe or
catastrophic adverse effect on organizational operations, organizational assets, or
D
individuals.
A. low B. normal
YL
C. moderate D. high
5. A flaw or weakness in a system’s design, implementation, or operation and
management that could be exploited to violate the system’s security policy is
a(n) .
AB
A. countermeasure B. vulnerability
C. adversary D. risk
6. An assault on system security that derives from an intelligent act that is a
deliberate attempt to evade security services and violate the security policy of a
system is a(n) .
A. risk B. asset
C. attack D. vulnerability
jhgfdsa