ISA 301 Midterm Exam #Questions with correct answers
Is the internet a public or private network? - ✔✔Public
What enables communications? - ✔✔Networks
What are the two points of attack? - ✔✔data packets and the devices that
connect to the network
When assessing threats, what are the two perspectives? - ✔✔1) there is no real
threat, we are fine
2) all hackers are experts and out to break into my network (paranoid)
What kinds of companies have the most security implemented? - ✔✔consumer
focused companies who cannot afford to have a security/data breech
Types of attacks - ✔✔intrusion, blocking, malware
What does it mean to hack into a system? - ✔✔gain unauthorized access to the
network
blocking - ✔✔trying to shut the network down or overwhelm the system so that
the legitimate users cannot access the server
ex. Denial of Service
,malware - ✔✔some type of software (virus, worm, etc.) that is installed in a
network
provides a point of attack by creating a back door or collecting confidential
information
ex. "You won $1000!"
Types of intrusion attacks - ✔✔cracking, social engineering, war-dialing/war
driving, malware
cracking - ✔✔trying to figure out a password through brute force
social engineering - ✔✔people try to convince you to give up information
ex. casual conversations, phishing
war-dialing - ✔✔computer calling phone numbers and trying to find an available
computer and try to gain entry into the system
war driving - ✔✔driving around trying to find open wifi networks
What makes worms different than viruses? - ✔✔worms don't require any human
intervention; they are self-replicating
, trojan horse - ✔✔a program that appears desirable but actually contains
something harmful
spyware - ✔✔a special class of adware that collects data about the user and
transmits it over the Internet without the user's knowledge or permission
ex. cookies (monitors activities) or key loggers (keystrokes)
cookies - ✔✔originally designed for website improvement, but also are
sometimes installed with a bad intent
types of blocking attacks - ✔✔Denial of Service
Denial of Service - ✔✔floods system by sending too many requests from infected
devices with the intent of "shutting down" a server, which makes it inaccessible
for legitimate users
takes advantage of the limits of a system
Why is it bad for a server to get shut down? - ✔✔information and services cannot
be provided/accessed
Threat Assessment Characteristics - ✔✔1) attractiveness of system (is it a big deal
to gain access)
2) nature of information on the system (newborn baby information is valuable
because of its longevity)
Is the internet a public or private network? - ✔✔Public
What enables communications? - ✔✔Networks
What are the two points of attack? - ✔✔data packets and the devices that
connect to the network
When assessing threats, what are the two perspectives? - ✔✔1) there is no real
threat, we are fine
2) all hackers are experts and out to break into my network (paranoid)
What kinds of companies have the most security implemented? - ✔✔consumer
focused companies who cannot afford to have a security/data breech
Types of attacks - ✔✔intrusion, blocking, malware
What does it mean to hack into a system? - ✔✔gain unauthorized access to the
network
blocking - ✔✔trying to shut the network down or overwhelm the system so that
the legitimate users cannot access the server
ex. Denial of Service
,malware - ✔✔some type of software (virus, worm, etc.) that is installed in a
network
provides a point of attack by creating a back door or collecting confidential
information
ex. "You won $1000!"
Types of intrusion attacks - ✔✔cracking, social engineering, war-dialing/war
driving, malware
cracking - ✔✔trying to figure out a password through brute force
social engineering - ✔✔people try to convince you to give up information
ex. casual conversations, phishing
war-dialing - ✔✔computer calling phone numbers and trying to find an available
computer and try to gain entry into the system
war driving - ✔✔driving around trying to find open wifi networks
What makes worms different than viruses? - ✔✔worms don't require any human
intervention; they are self-replicating
, trojan horse - ✔✔a program that appears desirable but actually contains
something harmful
spyware - ✔✔a special class of adware that collects data about the user and
transmits it over the Internet without the user's knowledge or permission
ex. cookies (monitors activities) or key loggers (keystrokes)
cookies - ✔✔originally designed for website improvement, but also are
sometimes installed with a bad intent
types of blocking attacks - ✔✔Denial of Service
Denial of Service - ✔✔floods system by sending too many requests from infected
devices with the intent of "shutting down" a server, which makes it inaccessible
for legitimate users
takes advantage of the limits of a system
Why is it bad for a server to get shut down? - ✔✔information and services cannot
be provided/accessed
Threat Assessment Characteristics - ✔✔1) attractiveness of system (is it a big deal
to gain access)
2) nature of information on the system (newborn baby information is valuable
because of its longevity)