GIANT ITN 267 FINAL EXAM QUESTIONS
WITH CORRECT ANSWERS
Congress created the _____________ in response to the September 11,
| | | | | | | | | |
2001, terrorist attacks. - CORRECT ANSWER✔✔-Federal Information
| | | | | | |
Security Management Act (FISMA) | | |
Under the Privacy Act, a record is any information about a person that
| | | | | | | | | | | | |
an agency maintains. It includes a person's educational, financial,
| | | | | | | | |
medical, and criminal history information. The act requires agencies to
| | | | | | | | | |
keep accurate and complete records. It also states that an agency should
| | | | | | | | | | |
store only the data that it needs to conduct business. It shouldn't store
| | | | | | | | | | | | | |
any extra or unnecessary data. - CORRECT ANSWER✔✔-True
| | | | | | |
One of the most important parts of a FISMA information security
| | | | | | | | | | |
program is that agencies test and evaluate it. FISMA requires each
| | | | | | | | | | |
agency to perform "periodic testing and evaluation of the effectiveness
| | | | | | | | | |
of information security policies, procedures, and practices." Agencies
| | | | | | | |
must test every IT system—no matter the risk level— at least once a
| | | | | | | | | | | | |
year. - CORRECT ANSWER✔✔-False
| | |
According Washington State's data disposal law, if an entity's failure to
| | | | | | | | | | |
comply with the law was intentional, then the law allows the court to
| | | | | | | | | | | | |
,award "double" damages, which are twice the amount of the actual
| | | | | | | | | | |
damages incurred. - CORRECT ANSWER✔✔-False
| | | |
Georgia's notification law is unique because it applies to information
| | | | | | | | | |
brokers, which are entities that sell personal data to other entities, as
| | | | | | | | | | | |
well as government agencies. - CORRECT ANSWER✔✔-False
| | | | | |
The OMB breach notification memo required federal agencies to do the
| | | | | | | | | | |
following: 1) review and reduce the volume of personally identifiable
| | | | | | | | | |
information that they store; 2) maintain the use of SSNs as a personal
| | | | | | | | | | | | |
identifier; and 3) develop policies and procedures for individuals who
| | | | | | | | | |
are authorized to access personally identifiable information. - CORRECT
| | | | | | | | |
ANSWER✔✔-False
The ______________________ was created by Congress to protect data
| | | | | | | |
collected by the government. - CORRECT ANSWER✔✔-Privacy Act of
| | | | | | | | | |
1974
Which of the following statements best captures the difference
| | | | | | | | |
between civil law and criminal law? - CORRECT ANSWER✔✔-In civil law,
| | | | | | | | | | |
a defendant isn't sent to jail as a punishment. Instead, civil law imposes
| | | | | | | | | | | | |
fines.
,Though it is not a law, businesses that wish to accept credit cards for
| | | | | | | | | | | | | |
payment must follow the PCI DSS, which is enforced by major credit
| | | | | | | | | | | |
companies like Visa and MasterCard. - CORRECT ANSWER✔✔-True
| | | | | | |
NIST created a FISMA Implementation Project to help it meet its FISMA
| | | | | | | | | | | |
duties. The project helped it create FISMA-related standards and
| | | | | | | | |
guidelines in a timely manner. The project had two phases. In the first
| | | | | | | | | | | | |
phase, NIST developed standards and guidelines to help agencies meet
| | | | | | | | | |
basic FISMA requirements. The documents developed in this phase
| | | | | | | | |
helped agencies create their information security programs. - CORRECT
| | | | | | | | |
ANSWER✔✔-True
Which of the following statements summarizes why a breach
| | | | | | | | |
notification is hard for entities? - CORRECT ANSWER✔✔-States have
| | | | | | | | |
different laws about what constitutes a breach.
| | | | | |
According to California law, entities don't need to give notice of a breach
| | | | | | | | | | | |
if the personal information in their computer system was encrypted;
| | | | | | | | | | |
thus, they are granted safe harbor. - CORRECT ANSWER✔✔-True
| | | | | | | |
The ________________ enforces trade sanctions and embargoes and
| | | | | | | |
prohibits trade with certain people in other countries. - CORRECT
| | | | | | | | | |
ANSWER✔✔-Office of Foreign Assets Control (OFAC) | | | | |
, Congress can create laws in areas where the________________ allows
| | | | | | | | |
it. - CORRECT ANSWER✔✔-U.S. Constitution
| | | |
Under FISMA, the government must have a federal incident response
| | | | | | | | | |
(IR) center. The OMB is responsible for this. Under FISMA, the IR center
| | | | | | | | | | | | |
must: 1) give technical support to agencies about information security
| | | | | | | | | |
incidents; 2) share information about security incidents; 3) protect
| | | | | | | | |
agencies from learning about current and potential threats and
| | | | | | | | |
vulnerabilities; and 4) consult with NIST and agencies with national | | | | | | | | | |
security systems about information security incidents. - CORRECT
| | | | | | | |
ANSWER✔✔-False
The rules stated in the Gramm-Leach-Bliley Act (GLBA) require that
| | | | | | | | | |
entities engaged in certain kinds of financial transactions need to follow
| | | | | | | | | | |
privacy and information security rules that are designed to protect
| | | | | | | | | |
customers' personal information. - CORRECT ANSWER✔✔-True
| | | | |
What is considered to be personal information by most states? -
| | | | | | | | | | |
CORRECT ANSWER✔✔-both A and B | | | |
Which of the following is included in a law's legislative history? -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-any materials generated in the course of
| | | | | | | |
creating legislation; this includes committee reports, hearings, and
| | | | | | | |
transcripts of debate and reports issued by legislatures
| | | | | | |
WITH CORRECT ANSWERS
Congress created the _____________ in response to the September 11,
| | | | | | | | | |
2001, terrorist attacks. - CORRECT ANSWER✔✔-Federal Information
| | | | | | |
Security Management Act (FISMA) | | |
Under the Privacy Act, a record is any information about a person that
| | | | | | | | | | | | |
an agency maintains. It includes a person's educational, financial,
| | | | | | | | |
medical, and criminal history information. The act requires agencies to
| | | | | | | | | |
keep accurate and complete records. It also states that an agency should
| | | | | | | | | | |
store only the data that it needs to conduct business. It shouldn't store
| | | | | | | | | | | | | |
any extra or unnecessary data. - CORRECT ANSWER✔✔-True
| | | | | | |
One of the most important parts of a FISMA information security
| | | | | | | | | | |
program is that agencies test and evaluate it. FISMA requires each
| | | | | | | | | | |
agency to perform "periodic testing and evaluation of the effectiveness
| | | | | | | | | |
of information security policies, procedures, and practices." Agencies
| | | | | | | |
must test every IT system—no matter the risk level— at least once a
| | | | | | | | | | | | |
year. - CORRECT ANSWER✔✔-False
| | |
According Washington State's data disposal law, if an entity's failure to
| | | | | | | | | | |
comply with the law was intentional, then the law allows the court to
| | | | | | | | | | | | |
,award "double" damages, which are twice the amount of the actual
| | | | | | | | | | |
damages incurred. - CORRECT ANSWER✔✔-False
| | | |
Georgia's notification law is unique because it applies to information
| | | | | | | | | |
brokers, which are entities that sell personal data to other entities, as
| | | | | | | | | | | |
well as government agencies. - CORRECT ANSWER✔✔-False
| | | | | |
The OMB breach notification memo required federal agencies to do the
| | | | | | | | | | |
following: 1) review and reduce the volume of personally identifiable
| | | | | | | | | |
information that they store; 2) maintain the use of SSNs as a personal
| | | | | | | | | | | | |
identifier; and 3) develop policies and procedures for individuals who
| | | | | | | | | |
are authorized to access personally identifiable information. - CORRECT
| | | | | | | | |
ANSWER✔✔-False
The ______________________ was created by Congress to protect data
| | | | | | | |
collected by the government. - CORRECT ANSWER✔✔-Privacy Act of
| | | | | | | | | |
1974
Which of the following statements best captures the difference
| | | | | | | | |
between civil law and criminal law? - CORRECT ANSWER✔✔-In civil law,
| | | | | | | | | | |
a defendant isn't sent to jail as a punishment. Instead, civil law imposes
| | | | | | | | | | | | |
fines.
,Though it is not a law, businesses that wish to accept credit cards for
| | | | | | | | | | | | | |
payment must follow the PCI DSS, which is enforced by major credit
| | | | | | | | | | | |
companies like Visa and MasterCard. - CORRECT ANSWER✔✔-True
| | | | | | |
NIST created a FISMA Implementation Project to help it meet its FISMA
| | | | | | | | | | | |
duties. The project helped it create FISMA-related standards and
| | | | | | | | |
guidelines in a timely manner. The project had two phases. In the first
| | | | | | | | | | | | |
phase, NIST developed standards and guidelines to help agencies meet
| | | | | | | | | |
basic FISMA requirements. The documents developed in this phase
| | | | | | | | |
helped agencies create their information security programs. - CORRECT
| | | | | | | | |
ANSWER✔✔-True
Which of the following statements summarizes why a breach
| | | | | | | | |
notification is hard for entities? - CORRECT ANSWER✔✔-States have
| | | | | | | | |
different laws about what constitutes a breach.
| | | | | |
According to California law, entities don't need to give notice of a breach
| | | | | | | | | | | |
if the personal information in their computer system was encrypted;
| | | | | | | | | | |
thus, they are granted safe harbor. - CORRECT ANSWER✔✔-True
| | | | | | | |
The ________________ enforces trade sanctions and embargoes and
| | | | | | | |
prohibits trade with certain people in other countries. - CORRECT
| | | | | | | | | |
ANSWER✔✔-Office of Foreign Assets Control (OFAC) | | | | |
, Congress can create laws in areas where the________________ allows
| | | | | | | | |
it. - CORRECT ANSWER✔✔-U.S. Constitution
| | | |
Under FISMA, the government must have a federal incident response
| | | | | | | | | |
(IR) center. The OMB is responsible for this. Under FISMA, the IR center
| | | | | | | | | | | | |
must: 1) give technical support to agencies about information security
| | | | | | | | | |
incidents; 2) share information about security incidents; 3) protect
| | | | | | | | |
agencies from learning about current and potential threats and
| | | | | | | | |
vulnerabilities; and 4) consult with NIST and agencies with national | | | | | | | | | |
security systems about information security incidents. - CORRECT
| | | | | | | |
ANSWER✔✔-False
The rules stated in the Gramm-Leach-Bliley Act (GLBA) require that
| | | | | | | | | |
entities engaged in certain kinds of financial transactions need to follow
| | | | | | | | | | |
privacy and information security rules that are designed to protect
| | | | | | | | | |
customers' personal information. - CORRECT ANSWER✔✔-True
| | | | |
What is considered to be personal information by most states? -
| | | | | | | | | | |
CORRECT ANSWER✔✔-both A and B | | | |
Which of the following is included in a law's legislative history? -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-any materials generated in the course of
| | | | | | | |
creating legislation; this includes committee reports, hearings, and
| | | | | | | |
transcripts of debate and reports issued by legislatures
| | | | | | |