HUGE ITN 267 FINAL EXAM QUESTIONS
WITH CORRECT ANSWERS
___________________________ must be in place for securing | | | | | | |
networks, facilities, and systems or groups of IT systems. They are
| | | | | | | | | | |
intended for technologies or system components that are a part of the
| | | | | | | | | | | |
larger information security program. - CORRECT ANSWER✔✔-
| | | | | |
Subordinate Plans |
The term cyberwar specifically refers to conflicts between nations and
| | | | | | | | | |
their militaries. This is the main distinction between cyberwar and other
| | | | | | | | | |
types of information system attacks that are reported in the news
| | | | | | | | | | | |
media. (T or F) - CORRECT ANSWER✔✔-True
| | | | | |
__________________ restrict the transmission of certain types of | | | | | | | |
information to non-U.S. citizens or non-permanent residents who are
| | | | | | | | |
located in the United States. - CORRECT ANSWER✔✔-Export control
| | | | | | | | |
regulations
Which of the following are types of export control regulations? -
| | | | | | | | | | |
CORRECT ANSWER✔✔-ITAR & EAR | | |
,One of the most important parts of a FISMA information security
| | | | | | | | | | |
program is that agencies test and evaluate it. FISMA requires each
| | | | | | | | | | |
agency to perform "periodic testing and evaluation of the effectiveness
| | | | | | | | | |
of information security policies, procedures, and practices." Agencies
| | | | | | | |
must test every IT system—no matter the risk level— at least once a
| | | | | | | | | | | | |
year (T or F) - CORRECT ANSWER✔✔-True
| | | | | |
NIST created a FISMA Implementation Project to help it meet its FISMA
| | | | | | | | | | | |
duties. The project helped it create FISMA-related standards and
| | | | | | | | |
guidelines in a timely manner. The project had two phases. In the first
| | | | | | | | | | | | |
phase, NIST developed standards and guidelines to help agencies meet
| | | | | | | | | |
basic FISMA requirements. The documents developed in this phase
| | | | | | | | |
helped agencies create their information security programs. (T or F) -
| | | | | | | | | | |
CORRECT ANSWER✔✔-True |
An inspector general (IG) is an official who reviews the actions of a
| | | | | | | | | | | | |
federal agency. An IG examines the agency's activities to make sure that
| | | | | | | | | | | |
it's operating efficiently and following good governance practices. (T or
| | | | | | | | | |
F) - CORRECT ANSWER✔✔-True
| | |
Each agency must report yearly to the OMB on its FISMA compliance
| | | | | | | | | | | |
activities. An agency also must send a copy of their yearly report to each
| | | | | | | | | | | | |
of these agencies with the exception of: - CORRECT ANSWER✔✔-
| | | | | | | | | |
Senate Committee on Foreign Relations
| | | |
,Congress created the _____________ in response to the September 11,
| | | | | | | | | |
2001, terrorist attacks. - CORRECT ANSWER✔✔-FISMA
| | | | |
FISMA requires the Department of Commerce to create information
| | | | | | | | |
security standards and guidelines. To which of the following
| | | | | | | | |
organizations did the Department of Commerce delegate this
| | | | | | | |
responsibility? - CORRECT ANSWER✔✔-NIST | | |
Which of the following items is not part of the in "SP 800-37, Revision 1,
| | | | | | | | | | | | | | |
Guide for Applying the Risk Management Framework to Federal
| | | | | | | | |
Information Systems: A Security Life Cycle Approach" that NIST uses to
| | | | | | | | | | |
create a risk management framework (RMF) approach to FISMA
| | | | | | | | |
compliance? - CORRECT ANSWER✔✔-Monitor security controls only
| | | | | | |
when necessary
|
The __________________________enforces trade sanctions and
| | | | |
embargoes. - CORRECT ANSWER✔✔-OFAC | | |
Which of the following statements best captures the role and
| | | | | | | | | |
responsibility of NIST? - CORRECT ANSWER✔✔-NIST creates the
| | | | | | | |
standards and guidelines for non-national security systems to help
| | | | | | | | |
agencies meet their FISMA obligations.
| | | |
Under FISMA, the government must have a federal incident response
| | | | | | | | | |
(IR) center. The OMB is responsible for this. Under FISMA, the IR center
| | | | | | | | | | | | |
, must: 1) give technical support to agencies about information security
| | | | | | | | | |
incidents; 2) share information about security incidents; 3) protect
| | | | | | | | |
agencies from learning about current and potential threats and
| | | | | | | | |
vulnerabilities; and 4) consult with NIST and agencies with national | | | | | | | | | |
security systems about information security incidents. (T or F) -
| | | | | | | | | |
CORRECT ANSWER✔✔-False |
From 2006 to 2012, the number of incidents reported by federal
| | | | | | | | | | |
agencies to the USCERT increased by 782 percent. (T or F) - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-True
There's a growing trend in states such as California and North Carolina
| | | | | | | | | | | |
to specify the types of information that should be included in a breach
| | | | | | | | | | | | |
notice. Such content should be sure to fit the following criteria: describe
| | | | | | | | | | |
the incident in general terms; describe the type of personal information
| | | | | | | | | | |
that was involved in the breach; describe how the entity is going to
| | | | | | | | | | | | | |
protect the personal information from additional unauthorized access;
| | | | | | | |
and advise the person being notified to review his or her account
| | | | | | | | | | | |
statements and purchase access to his/her credit report from a
| | | | | | | | | |
recommended list of vendors. (T or F) - CORRECT ANSWER✔✔-False | | | | | | | | |
What was the first state to have a breach notification law? - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-California
WITH CORRECT ANSWERS
___________________________ must be in place for securing | | | | | | |
networks, facilities, and systems or groups of IT systems. They are
| | | | | | | | | | |
intended for technologies or system components that are a part of the
| | | | | | | | | | | |
larger information security program. - CORRECT ANSWER✔✔-
| | | | | |
Subordinate Plans |
The term cyberwar specifically refers to conflicts between nations and
| | | | | | | | | |
their militaries. This is the main distinction between cyberwar and other
| | | | | | | | | |
types of information system attacks that are reported in the news
| | | | | | | | | | | |
media. (T or F) - CORRECT ANSWER✔✔-True
| | | | | |
__________________ restrict the transmission of certain types of | | | | | | | |
information to non-U.S. citizens or non-permanent residents who are
| | | | | | | | |
located in the United States. - CORRECT ANSWER✔✔-Export control
| | | | | | | | |
regulations
Which of the following are types of export control regulations? -
| | | | | | | | | | |
CORRECT ANSWER✔✔-ITAR & EAR | | |
,One of the most important parts of a FISMA information security
| | | | | | | | | | |
program is that agencies test and evaluate it. FISMA requires each
| | | | | | | | | | |
agency to perform "periodic testing and evaluation of the effectiveness
| | | | | | | | | |
of information security policies, procedures, and practices." Agencies
| | | | | | | |
must test every IT system—no matter the risk level— at least once a
| | | | | | | | | | | | |
year (T or F) - CORRECT ANSWER✔✔-True
| | | | | |
NIST created a FISMA Implementation Project to help it meet its FISMA
| | | | | | | | | | | |
duties. The project helped it create FISMA-related standards and
| | | | | | | | |
guidelines in a timely manner. The project had two phases. In the first
| | | | | | | | | | | | |
phase, NIST developed standards and guidelines to help agencies meet
| | | | | | | | | |
basic FISMA requirements. The documents developed in this phase
| | | | | | | | |
helped agencies create their information security programs. (T or F) -
| | | | | | | | | | |
CORRECT ANSWER✔✔-True |
An inspector general (IG) is an official who reviews the actions of a
| | | | | | | | | | | | |
federal agency. An IG examines the agency's activities to make sure that
| | | | | | | | | | | |
it's operating efficiently and following good governance practices. (T or
| | | | | | | | | |
F) - CORRECT ANSWER✔✔-True
| | |
Each agency must report yearly to the OMB on its FISMA compliance
| | | | | | | | | | | |
activities. An agency also must send a copy of their yearly report to each
| | | | | | | | | | | | |
of these agencies with the exception of: - CORRECT ANSWER✔✔-
| | | | | | | | | |
Senate Committee on Foreign Relations
| | | |
,Congress created the _____________ in response to the September 11,
| | | | | | | | | |
2001, terrorist attacks. - CORRECT ANSWER✔✔-FISMA
| | | | |
FISMA requires the Department of Commerce to create information
| | | | | | | | |
security standards and guidelines. To which of the following
| | | | | | | | |
organizations did the Department of Commerce delegate this
| | | | | | | |
responsibility? - CORRECT ANSWER✔✔-NIST | | |
Which of the following items is not part of the in "SP 800-37, Revision 1,
| | | | | | | | | | | | | | |
Guide for Applying the Risk Management Framework to Federal
| | | | | | | | |
Information Systems: A Security Life Cycle Approach" that NIST uses to
| | | | | | | | | | |
create a risk management framework (RMF) approach to FISMA
| | | | | | | | |
compliance? - CORRECT ANSWER✔✔-Monitor security controls only
| | | | | | |
when necessary
|
The __________________________enforces trade sanctions and
| | | | |
embargoes. - CORRECT ANSWER✔✔-OFAC | | |
Which of the following statements best captures the role and
| | | | | | | | | |
responsibility of NIST? - CORRECT ANSWER✔✔-NIST creates the
| | | | | | | |
standards and guidelines for non-national security systems to help
| | | | | | | | |
agencies meet their FISMA obligations.
| | | |
Under FISMA, the government must have a federal incident response
| | | | | | | | | |
(IR) center. The OMB is responsible for this. Under FISMA, the IR center
| | | | | | | | | | | | |
, must: 1) give technical support to agencies about information security
| | | | | | | | | |
incidents; 2) share information about security incidents; 3) protect
| | | | | | | | |
agencies from learning about current and potential threats and
| | | | | | | | |
vulnerabilities; and 4) consult with NIST and agencies with national | | | | | | | | | |
security systems about information security incidents. (T or F) -
| | | | | | | | | |
CORRECT ANSWER✔✔-False |
From 2006 to 2012, the number of incidents reported by federal
| | | | | | | | | | |
agencies to the USCERT increased by 782 percent. (T or F) - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-True
There's a growing trend in states such as California and North Carolina
| | | | | | | | | | | |
to specify the types of information that should be included in a breach
| | | | | | | | | | | | |
notice. Such content should be sure to fit the following criteria: describe
| | | | | | | | | | |
the incident in general terms; describe the type of personal information
| | | | | | | | | | |
that was involved in the breach; describe how the entity is going to
| | | | | | | | | | | | | |
protect the personal information from additional unauthorized access;
| | | | | | | |
and advise the person being notified to review his or her account
| | | | | | | | | | | |
statements and purchase access to his/her credit report from a
| | | | | | | | | |
recommended list of vendors. (T or F) - CORRECT ANSWER✔✔-False | | | | | | | | |
What was the first state to have a breach notification law? - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-California