Correct Detailed Answers Already Graded A+
1. Tim's organization recently recieved a contract to conduct sponsored research
as a government contractor. What law now likely applies to the information
system involved in this contract?
A. FISMA
B. PCI DSS
C. HIPAA
D. GISRA - CORRECT ANSWER-A. FISMA
2. Chris is advising travelers from his organization who will be visiting many
different countries overseas. He is concerned about compliiance with export
control laws. Which of the following technologies is most likely to trigger these
regulations?
A. Memory chips
B. Office productivity applications
C. Hard drives
D. Encryption software - CORRECT ANSWER-D. Encryption software
,3. Bobbi is investigating a security incident and discovers that an attacker began
with a normal user account but managed to exploit a system vulnerability to
provide that account with administrative rights. What type of attack took place
under the STRIDE model?
A. Spoofing
B. Repudiation
C. Tampering
D. Elevation of privilege - CORRECT ANSWER-A. D. Elevation of privilege
4. You are completing your business continuity planning effort and have decided
that you wish to accept one of the risks. What should you do next?
A. Implement new security control to reduce the risk level.
B. Design a disaster recovery plan.
C. Repeat the business impact assessment.
D. Document your decision-making process. - CORRECT ANSWER-D. Document
your decision-making process.
5. Which one of the following control categories does not accurately describe a
fence around a facility?
A. Physical
B. Detective
,C. Deterrent
D. Preventive - CORRECT ANSWER-B. Detective
6. Tony is developing a business continuity plan and is having difficulty prioritizing
resources because of the difficulty of combining information about tangible and
intangible assets. What would be the most effective risk assessment approach for
him to use?
A. Quantitative risk assessment
B. Qualitative risk assessment
C. Neither quantitative nor qualitative risk assessment
D. Combination of quantitative and qualitative risk assessment - CORRECT
ANSWER-D. Combination of quantitative and qualitative risk assessment
7. What law provides intellectual property proctection to the holders of trade
secrets?
A. Copyright Law
B. Lanham Act
C. Glass-Steagall Act
D. Economic Espionage Act - CORRECT ANSWER-D. Economic Espionage Act
, 8. Which one of the following principles imposes a standard of care upon an
individual that is broad and equivalent to what one would expect from a
resonable person uder the circumstances?
A. Due diligence
B. Separation of duties
C. Due care
D. Least privilege - CORRECT ANSWER-C. Due care
9. Darcy is designing a fault tolerant system and wants to implement RAID-5 for
her system. What is the minimum number of physical hard disks she can use to
build this system?
A. One
B. Two
C. Three
D. Five - CORRECT ANSWER-C. Three
10. Which one of the following is an example of an administrative control?
A. Intrusion detection system
B. Security awareness training
C. Firewalls