MISY 5325 COMPREHENSIVE BUSINESS
TECHNOLOGY REVIEW SHEET FULL
SOLUTIONS
●● A __________ grants the authority to perform an action on a system.
A __________ grants access to a resource.
Answer: right, permission
●● A business continuity plan (BCP) is an example of a(n):
Answer: security plan
●● A hacker wants to launch an attack on an organization. The hacker
uses a tool to capture data sent over the network in cleartext, hoping to
gather information that will help make the attack successful. What tool
is the hacker using?
Answer: a packet analyzer
●● A threat is any activity that represents a possible danger, which
includes any circumstances or events with the potential to cause an
adverse impact on all of the following, except:
Answer: assessments
,●● A(n) ____________ assessment attempts to identify vulnerabilities
that can be exploited.
Answer: exploit
●● An access control such as a firewall or intrusion prevention system
cannot protect against which of the following?
Answer: Social engineering
●● Another term for data range and reasonableness checks is:
Answer: input validation
●● Background checks, software testing, and awareness training are all
categories of:
Answer: procedural controls.
●● Bill is a security professional. He is in a meeting with co-workers
and describes a system that will make web sessions more secure. He
says when a user connects to the web server and starts a secure session,
the server sends a certificate to the user. The certificate includes a public
key. The user can encrypt data with the public key and send it to the
server. Because the server holds the private key, it can decrypt the data.
Because no other entity has the private key, no one else can decrypt the
data. What is Bill describing?
Answer: Public key infrastructure (PKI)
, ●● Bonding is a type of __________ that covers against losses by theft,
fraud, or dishonesty.
Answer: Insurance
●● Complete the equation for the relationship between risk,
vulnerabilities, and threats: Risk equals:
Answer: Vulnerability × Threat .
●● Functionality testing is primarily used with:
Answer: Software Development
●● Ideally, when should you perform threat modeling?
Answer: Before writing an application or deploying a system
●● In a SQL injection attack, an attacker can:
Answer: read sections of a database or a whole database without
authorization.
●● Piggybacking is also known as:
Answer: Tailgating
●● Primary considerations for assessing threats based on historical data
in your local area are __________ and ___________.
TECHNOLOGY REVIEW SHEET FULL
SOLUTIONS
●● A __________ grants the authority to perform an action on a system.
A __________ grants access to a resource.
Answer: right, permission
●● A business continuity plan (BCP) is an example of a(n):
Answer: security plan
●● A hacker wants to launch an attack on an organization. The hacker
uses a tool to capture data sent over the network in cleartext, hoping to
gather information that will help make the attack successful. What tool
is the hacker using?
Answer: a packet analyzer
●● A threat is any activity that represents a possible danger, which
includes any circumstances or events with the potential to cause an
adverse impact on all of the following, except:
Answer: assessments
,●● A(n) ____________ assessment attempts to identify vulnerabilities
that can be exploited.
Answer: exploit
●● An access control such as a firewall or intrusion prevention system
cannot protect against which of the following?
Answer: Social engineering
●● Another term for data range and reasonableness checks is:
Answer: input validation
●● Background checks, software testing, and awareness training are all
categories of:
Answer: procedural controls.
●● Bill is a security professional. He is in a meeting with co-workers
and describes a system that will make web sessions more secure. He
says when a user connects to the web server and starts a secure session,
the server sends a certificate to the user. The certificate includes a public
key. The user can encrypt data with the public key and send it to the
server. Because the server holds the private key, it can decrypt the data.
Because no other entity has the private key, no one else can decrypt the
data. What is Bill describing?
Answer: Public key infrastructure (PKI)
, ●● Bonding is a type of __________ that covers against losses by theft,
fraud, or dishonesty.
Answer: Insurance
●● Complete the equation for the relationship between risk,
vulnerabilities, and threats: Risk equals:
Answer: Vulnerability × Threat .
●● Functionality testing is primarily used with:
Answer: Software Development
●● Ideally, when should you perform threat modeling?
Answer: Before writing an application or deploying a system
●● In a SQL injection attack, an attacker can:
Answer: read sections of a database or a whole database without
authorization.
●● Piggybacking is also known as:
Answer: Tailgating
●● Primary considerations for assessing threats based on historical data
in your local area are __________ and ___________.