IST 305 CH. 8 QUESTIONS AND VERIFIED ANSWERS
By causing other people's computers to become "zombie" pcs following a master
computer. - Answers - Hackers create a botnet by
Recovery-oriented computing - Answers - The development and use of methods to
make computer systems resume their activities more quickly after mishaps is called
Issue patches - Answers - How do software vendors correct flaws in their software after
it has been distributed?
Only those viruses already known when the software is written. - Answers - Most
antivirus software is effective against
SSL, TLS, and S-HTTP. - Answers - Currently, the protocols used for secure
information transfer over the Internet are
Unified Threat Management - Answers - Comprehensive security management
products, with tools for firewalls, vpns, intrusion detection systems, and more, are called
________ systems.
SQL injection attacks - Answers - Which of the following does not pose a security threat
to wireless networks?
-broadcasted ssids
-scannability of radio frequency bands
-SQL injection attacks
-geographic range of wireless signals
Symmetric Key Encryption - Answers - In which method of encryption is a single
encryption key sent to the receiver so both sender and receiver share the same key?
Deep packet inspection - Answers - In controlling network traffic to minimize slow-
downs, a technology called ________ is used to examine data files and sort low-priority
data from high-priority data.
True (one shared and one private) - Answers - T/F: Public key encryption uses two
keys.
Bogus wireless network access points that look legitimate to users. - Answers - Evil
twins are
Can be classified as input controls, processing controls, and output controls. - Answers
- Application controls
, Fault-tolerant computer systems. - Answers - For 100% availability, online transaction
processing requires
Communication lines - Answers - Sniffing is a security challenge that is most likely to
occur in which of the following points of a corporate network?
False - Answers - T/F: An acceptable use policy defines the acceptable level of access
to information assets for different users.
"security" - Answers - ________ refers to policies, procedures, and technical measures
used to prevent unauthorized access, alternation, theft, or physical damage to
information systems.
True - Answers - T/F: SSL is a protocol used to establish a secure connection between
two computers.
True - Answers - T/F: NAT conceals the IP addresses of the organization's internal host
computers to deter sniffer programs.
Malware - Answers - Malicious software programs referred to as ________ include a
variety of threats such as computer viruses, worms, and Trojan horses.
Outlines medical security and privacy rules. - Answers - The HIPAA Act of 1997
True - Answers - T/F: Biometric authentication is the use of physical characteristics
such as retinal images to provide identification.
Mssps - Answers - Smaller firms may outsource some or many security functions to
Employees - Answers - You have been hired as a security consultant for a law firm.
Which of the following constitutes the greatest source of security threats to the firm?
True - Answers - T/F: One form of spoofing involves forging the return address on an e-
mail so that the e-mail message appears to come from someone other than the sender.
Trojan Horse - Answers - In 2004, ICQ users were enticed by a sales message from a
supposed anti-virus vendor. On the vendor's site, a small program called Mitglieder was
downloaded to the user's machine. The program enabled outsiders to infiltrate the
user's machine. What type of malware is this an example of?
False - Answers - T/F: dos attacks are used to destroy information and access restricted
areas of a company's information system.
Secure socket filtering - Answers - Which of the following is not one of the main firewall
screening techniques?
By causing other people's computers to become "zombie" pcs following a master
computer. - Answers - Hackers create a botnet by
Recovery-oriented computing - Answers - The development and use of methods to
make computer systems resume their activities more quickly after mishaps is called
Issue patches - Answers - How do software vendors correct flaws in their software after
it has been distributed?
Only those viruses already known when the software is written. - Answers - Most
antivirus software is effective against
SSL, TLS, and S-HTTP. - Answers - Currently, the protocols used for secure
information transfer over the Internet are
Unified Threat Management - Answers - Comprehensive security management
products, with tools for firewalls, vpns, intrusion detection systems, and more, are called
________ systems.
SQL injection attacks - Answers - Which of the following does not pose a security threat
to wireless networks?
-broadcasted ssids
-scannability of radio frequency bands
-SQL injection attacks
-geographic range of wireless signals
Symmetric Key Encryption - Answers - In which method of encryption is a single
encryption key sent to the receiver so both sender and receiver share the same key?
Deep packet inspection - Answers - In controlling network traffic to minimize slow-
downs, a technology called ________ is used to examine data files and sort low-priority
data from high-priority data.
True (one shared and one private) - Answers - T/F: Public key encryption uses two
keys.
Bogus wireless network access points that look legitimate to users. - Answers - Evil
twins are
Can be classified as input controls, processing controls, and output controls. - Answers
- Application controls
, Fault-tolerant computer systems. - Answers - For 100% availability, online transaction
processing requires
Communication lines - Answers - Sniffing is a security challenge that is most likely to
occur in which of the following points of a corporate network?
False - Answers - T/F: An acceptable use policy defines the acceptable level of access
to information assets for different users.
"security" - Answers - ________ refers to policies, procedures, and technical measures
used to prevent unauthorized access, alternation, theft, or physical damage to
information systems.
True - Answers - T/F: SSL is a protocol used to establish a secure connection between
two computers.
True - Answers - T/F: NAT conceals the IP addresses of the organization's internal host
computers to deter sniffer programs.
Malware - Answers - Malicious software programs referred to as ________ include a
variety of threats such as computer viruses, worms, and Trojan horses.
Outlines medical security and privacy rules. - Answers - The HIPAA Act of 1997
True - Answers - T/F: Biometric authentication is the use of physical characteristics
such as retinal images to provide identification.
Mssps - Answers - Smaller firms may outsource some or many security functions to
Employees - Answers - You have been hired as a security consultant for a law firm.
Which of the following constitutes the greatest source of security threats to the firm?
True - Answers - T/F: One form of spoofing involves forging the return address on an e-
mail so that the e-mail message appears to come from someone other than the sender.
Trojan Horse - Answers - In 2004, ICQ users were enticed by a sales message from a
supposed anti-virus vendor. On the vendor's site, a small program called Mitglieder was
downloaded to the user's machine. The program enabled outsiders to infiltrate the
user's machine. What type of malware is this an example of?
False - Answers - T/F: dos attacks are used to destroy information and access restricted
areas of a company's information system.
Secure socket filtering - Answers - Which of the following is not one of the main firewall
screening techniques?