ACCURATE QUESTIONS WITH CORRECT
DETAILED SOLUTIONS ||
100% GUARANTEED PASS
<NEWEST VERSION>
1. accounting - ANSWER ✔ to create and preserve a record of who accessed
the enterprise network, what resources they accessed, and when they
disconnected from the network
2. agentless software - ANSWER ✔ software in which no additional
processes are required to run in the background
3. applications - ANSWER ✔ software programs
4. attack surface (threat vector) - ANSWER ✔ digital platform that threat
actors for their exploits
5. attributions of actors - ANSWER ✔ characteristic features of the different
groups of threat actors
6. authentication - ANSWER ✔ act of verifying that credentials are authentic
and not fabricated
7. authentication, authorization, and accounting (AAA) - ANSWER ✔
providing framework to control access to computer resources
8. authorization - ANSWER ✔ granting permission to take an action
,9. In what kind of attack can attackers make use of hundreds of thousands of
computers under their control in an attack against a single server or
network? - ANSWER ✔ distributed
10.Which term below is frequently used to describe the tasks of securing
information that is in a digital format? - ANSWER ✔ information security
11.Which of the three protections ensures that only authorized parties can view
information? - ANSWER ✔ Confidentiality
12.Select below the information protection item that ensures that information is
correct and that no unauthorized person or malicious software has altered
that data. - ANSWER ✔ Integrity
13.The security protection item that ensures that the individual is who they
claim to be (the authentic or genuine person) and not an imposter is known
as? - ANSWER ✔ Authentication
14.In information security, what constitutes a loss? - ANSWER ✔ all of the
above
15.In information security, an example of a threat agent can be - ANSWER ✔
All of the above
16.What type of theft involves stealing another person's personal information,
such as a Social Security number, and then using the information to
impersonate the victim, generally for financial gain? - ANSWER ✔
Identity theft
17.Under which law are health care enterprises required to guard protected
health information and implement policies and procedures whether it be in
paper or electronic format? - ANSWER ✔ HIPAA
18.Select below the term that is used to describe individuals who want to attack
computers yet lack the knowledge of computers and networks needed to do
so: - ANSWER ✔ Script kiddies
,19.What term below is used to describe a means of gathering information for an
attack by relying on the weaknesses of individuals? - ANSWER ✔ Social
engineering
20.The two types of malware that require user intervention to spread are: -
ANSWER ✔ Viruses and trojans
21.Select below the type of malware that appears to have a legitimate use, but
actually contains or does something malicious: - ANSWER ✔ TROJAN
22.What type of malware consists of a set of software tools used by an attacker
to hide the actions or presence of other types of malicious software, such as
Trojans, viruses, or worms? - ANSWER ✔ rootkit
23.Federal agencies are required to name a senior official in charge of
information security. What title is normally given to these individuals?
A. Chief information officer (CIO)
B. Chief technology officer (CTO)
C. Chief information security officer (CISO)
D. Chief financial officer (CFO) - ANSWER ✔ C. Chief information
security officer (CISO)
24.What federal government agency is charged with the responsibility of
creating information security standards and guidelines for use within the
federal government and more broadly across industries?
A. National Security Administration (NSA)
B. National Institute of Standards and Technology (NIST)
C. Department of Defense (DoD)
D. Federal Communications Commission (FCC) - ANSWER ✔ B.
National Institute of Standards and Technology (NIST)
25.Howard is leading a project to commission a new information system that
will be used by a federal government agency. He is working with senior
officials to document and accept the risk of operation prior to allowing use.
What step of the risk management framework is Howard completing?
A. Implement security controls in IT systems.
B. Assess security controls for effectiveness.
C. Authorize the IT system for processing.
, D. Continuously monitor security controls. - ANSWER ✔ C. Authorize
the IT system for processing.
26.Joe is the CEO of a company that handles medical billing for several
regional hospital systems. How would Joe's company be classified under the
Health Insurance Portability and Accountability Act (HIPAA)?
A. Covered entity as a health plan
B. Covered entity as a health care clearinghouse
C. Covered entity as a provider
D. Business associate of a covered entity - ANSWER ✔ D. Business
associate of a covered entity
27.Under the Health Insurance Portability and Accountability Act (HIPAA)
Security Rule, what type of safeguards must be implemented by all covered
entities, regardless of the circumstances?
A. Addressable
B. Standard
C. Security
D. Required - ANSWER ✔ D. Required
28.Bobbi recently discovered that an email program used within her health care
practice was sending sensitive medical information to patients without using
encryption. She immediately corrected the problem because it violated the
company's security policy and standard rules. What level of the Health
Insurance Portability and Accountability Act (HIPAA) violation likely took
place?
A. Tier A
B. Tier B
C. Tier C
D. Tier D - ANSWER ✔ A. Tier A
29.Which of the following agencies is NOT involved in the Gramm-Leach-
Bliley Act (GLBA) oversight process?
A. Securities and Exchange Commission (SEC)
B. Federal Trade Commission (FTC)
C. Federal Deposit Insurance Corporation (FDIC)
D. Federal Communications Commission (FCC) - ANSWER ✔ D.
Federal Communications Commission (FCC)