• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 53 pages
Exam (elaborations)

Comprehensive Information Security Fundamentals EXAM STUDY GUIDE 2026/2027 COMPLETE QUESTIONS WITH 100% VERIFIED CORRECT ANSWERS // A++ Graded

Document preview thumbnail
Preview 4 out of 53 pages

Comprehensive Information Security Fundamentals EXAM STUDY GUIDE 2026/2027 COMPLETE QUESTIONS WITH 100%VERIFIED CORRECT ANSWERS // A++ Graded A badge or token is considered what type of authentication? - ANSWER Something you have A password or PIN is considered what type of authentication? - ANSWER Something you know The set of methods we use to establish a claim of identity as being true is called ______. - ANSWER Authentication A fingerprint is considered what type of authentication? - ANSWER Something you are What type of authentication can prevent a man-in-the-middle attack? - ANSWER Mutual The biometric characteristic that measures how well a factor resists change over time and with advancing age is called __________ - ANSWER Permanence What dictates that we should only allow the bare minimum of access, as needed? - ANSWER Principle of least privilege Access controls are policies or procedures used to control access to certain items. - ANSWER True What does FISMA require from federal agencies? - ANSWER To develop, document, and implement an agency-wide information security program. What are the key components of the FISMA framework? - ANSWER Standards for categorizing information, minimum security requirements, guidance for selecting and assessing security controls, and security authorization. What is the General Data Protection Regulation (GDPR)? - ANSWER A stringent privacy and security law enacted by the European Union that applies to organizations targeting or collecting data related to EU individuals. What are the seven data protection principles outlined in the GDPR? - ANSWER Lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability. What does the Data Protection Act 2018 (DPA) regulate? - ANSWER The processing of personal data in the UK, updating the Data Protection Act 1998. What rights does the DPA confer to data subjects? - ANSWER Rights to obtain information about data processing and to require rectification of inaccurate personal data. What is cyberlaw? - ANSWER Laws that deal with protecting the Internet and online communication technologies, covering topics like privacy and jurisdiction. Why have cyber laws become prominent? - ANSWER Due to the increase in Internet usage worldwide. What are the potential consequences of violating cyber laws? - ANSWER Punishments ranging from fines to imprisonment. What does the term 'technological protection measures' refer to in the context of the DMCA? - ANSWER Measures employed by copyright owners to protect their works from unauthorized access or use. What is the significance of the accountability principle in GDPR? - ANSWER The data controller is responsible for demonstrating compliance with all GDPR principles. What is meant by 'data minimization' under GDPR? - ANSWER Collecting and processing only as much data as necessary for specified purposes. What does 'integrity and confidentiality' mean in the context of GDPR? - ANSWER Ensuring appropriate security measures are in place to protect personal data. What is the role of the Information Commissioner in the DPA? - ANSWER To monitor and enforce compliance with data protection provisions. What does the term 'ephemeral recordings' refer to in Title IV of the DMCA? - ANSWER Temporary recordings made for specific purposes that are exempt from certain copyright restrictions. What is the purpose of the Vessel Hull Design Protection Act (VHDPA)? - ANSWER To protect the original designs of hulls of vessels up to 200 feet in length. What is the impact of GDPR on organizations outside the EU? - ANSWER It imposes obligations on organizations anywhere that target or collect data related to individuals in the EU. What is implemented through the use of access controls? - ANSWER Authorization Which answer best describes the authorization component of access control? - ANSWER Authorization is the process of determining who is approved for access and what resources they are approved for. A client-side attack that involves the attacker placing an invisible layer over something on a website that the user would normally click on, in order to execute a command differing from what the user thinks they are performing, is known as ___________. - ANSWER Clickjacking What type of access control can prevent the confused deputy problem? - ANSWER Capability-based security A user who creates a network share and sets permissions on that share is employing which model of access control? - ANSWER Discretionary access control A VPN connection that is set to time out after 24 hours is demonstrating which model of access control? - ANSWER Attribute-based access control Confidential Services Inc. is a military-support branch consisting of 1,400 computers with Internet access and 250 servers. All employees are required to have security clearances. From the options listed below, what access control model would be most appropriate for this organization? - ANSWER Mandatory access control What is information security? - ANSWER Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. Using the concept of defense in depth we can protect ourselves against someone using a USB flash drive to remove confidential data from an office space within our building. - ANSWER True Select the example(s) of identity verification. (Choose all that apply.) - ANSWER SSN Passport Birth certificate Multifactor authentication is the use of more than one authentication method to access an information system. - ANSWER True Which password below would meet complexity standards? - ANSWER !Q@S#z6ge7Uks1lw3 What is accountability comprised of? - ANSWER Authorization Authentication Identification Access What document do courts require for admissibility of records? - ANSWER Chain of custody An employee is charged with fraud, and the company can prove in court that there are email transactions showing that the employee completed these using a digital signature. What term is being described? - ANSWER Nonrepudiation What is auditing? - ANSWER The primary means to ensure accountability through technical means What are the two common forms of assessments performed on networks? (Choose all that apply.) - ANSWER Penetration test Vulnerability assessment _______ provides us with the means to trace activities in our environment back to their source. - ANSWER Accountability Nessus is an example of a(n) _______________ tool. - ANSWER Vulnerability scanning A surveillance video log contains a record, including the exact date and time, of an individual gaining access to his company's office building after hours. He denies that he was there during that time, but the existence of the video log proves otherwise. What benefit of accountability does this example demonstrate? - ANSWER Non repudiation What process ensures compliance with applicable laws, policies, and other bodies of administrative control, and detects misuse? - ANSWER Auditing Your organization's network was recently the target of an attack. Fortunately, the new system you installed took action and refused traffic from the source before you even had a chance to respond. What system did you install? - ANSWER An intrusion prevention system The act of scrambling plain text into cyphertext is known as ________. - ANSWER encryption A strong hash function is designed so that a message cannot be forged that will result in the same hash as a legitimate message. - ANSWER True An encryption cipher that uses the same key to encrypt and decrypt is called a/an ______. - ANSWER asymmetric key Hashes provide confidentiality and integrity. - ANSWER False An algorithm used for cryptographic purposes is known as a _______. - ANSWER cipher __________ corroborates the identity of an entity, whether it is the sender, the sender's computer, some device, or some information. - ANSWER Authentication The science of breaking through encryption is known as _____. - ANSWER Cryptanalysis Hashes provide _______, but not _______. - ANSWER Integrity, confidentiality Shovels and Shingles is a small construction company consisting of 12 computers that have Internet access. The company is concerned that a wily, computer-savvy competitor will send e-mail messages pretending to be from Shovels and Shingles to its customers, in an attempt to gather customer information. What encryption solution best prevents a competitor from successfully impersonating the company? - ANSWER: Digital signatures Backordered Parts is a defense contractor that builds communications parts for the military. The employees use mostly Web-based applications for parts design and information sharing. Due to the sensitive nature of the business, Backordered Parts would like to implement a solution that secures all browser connections to the Web servers. What encryption solution best meets this company's needs? - ANSWER Elliptic Curve Cryptography (ECC) We are somewhat limited in our ability to protect which type of data? - ANSWER Data in use A cybersecurity professional must be proficient with all current laws, both state and federal, that may apply to the organization he or she works with. - ANSWER False FISMA refers to ____. - ANSWER Federal Information Security Management Act of 2002 and Federal Information Security Modernization Act of 2014 Which statement below is true about a company operating in the United States today? - ANSWER International computing laws must be considered if any customer resides outside the U.S. PII is personally identifiable information. This data must always _____. - ANSWER be monitored for compliance ______ ensures the protection of information, operations, and assets in federal government. - ANSWER FISMA ______ protects the privacy of students and their parents. - ANSWER FERPA ______ sets limits on the use and disclosure of patient information and grants individuals rights over their own health records. - ANSWER HIPAA ______ regulates the financial practice and governance of corporations. - ANSWER SOX

Content preview

Comprehensive Information Security Fundamentals EXAM
STUDY GUIDE 2026/2027 COMPLETE QUESTIONS
WITH 100%VERIFIED CORRECT ANSWERS // A++
Graded


A badge or token is considered what type of authentication? - ANSWER
Something you have


A password or PIN is considered what type of authentication? - ANSWER
Something you know


The set of methods we use to establish a claim of identity as being true is
called ______. - ANSWER Authentication


A fingerprint is considered what type of authentication? - ANSWER
Something you are


What type of authentication can prevent a man-in-the-middle attack? -
ANSWER Mutual


The biometric characteristic that measures how well a factor resists change
over time and with advancing age is called __________ - ANSWER

,Permanence


What dictates that we should only allow the bare minimum of access, as
needed? - ANSWER Principle of least privilege


Access controls are policies or procedures used to control access to certain
items. - ANSWER True
What does FISMA require from federal agencies? - ANSWER To develop,
document, and implement an agency-wide information security program.


What are the key components of the FISMA framework? - ANSWER
Standards for categorizing information, minimum security requirements,
guidance for selecting and assessing security controls, and security
authorization.


What is the General Data Protection Regulation (GDPR)? - ANSWER A
stringent privacy and security law enacted by the European Union that
applies to organizations targeting or collecting data related to EU individuals.


What are the seven data protection principles outlined in the GDPR? -
ANSWER Lawfulness, fairness, and transparency; purpose limitation; data
minimization; accuracy; storage limitation; integrity and confidentiality;
accountability.


What does the Data Protection Act 2018 (DPA) regulate? - ANSWER The
processing of personal data in the UK, updating the Data Protection Act

,1998.


What rights does the DPA confer to data subjects? - ANSWER Rights to
obtain information about data processing and to require rectification of
inaccurate personal data.


What is cyberlaw? - ANSWER Laws that deal with protecting the Internet
and online communication technologies, covering topics like privacy and
jurisdiction.


Why have cyber laws become prominent? - ANSWER Due to the increase
in Internet usage worldwide.


What are the potential consequences of violating cyber laws? - ANSWER
Punishments ranging from fines to imprisonment.


What does the term 'technological protection measures' refer to in the
context of the DMCA? - ANSWER Measures employed by copyright
owners to protect their works from unauthorized access or use.


What is the significance of the accountability principle in GDPR? -
ANSWER The data controller is responsible for demonstrating compliance
with all GDPR principles.


What is meant by 'data minimization' under GDPR? - ANSWER Collecting

, and processing only as much data as necessary for specified purposes.


What does 'integrity and confidentiality' mean in the context of GDPR? -
ANSWER Ensuring appropriate security measures are in place to protect
personal data.


What is the role of the Information Commissioner in the DPA? - ANSWER
To monitor and enforce compliance with data protection provisions.


What does the term 'ephemeral recordings' refer to in Title IV of the
DMCA? - ANSWER Temporary recordings made for specific purposes that
are exempt from certain copyright restrictions.


What is the purpose of the Vessel Hull Design Protection Act (VHDPA)? -
ANSWER To protect the original designs of hulls of vessels up to 200 feet in
length.


What is the impact of GDPR on organizations outside the EU? - ANSWER
It imposes obligations on organizations anywhere that target or collect data
related to individuals in the EU.


What is implemented through the use of access controls? - ANSWER
Authorization


Which answer best describes the authorization component of access control?

Document information

Uploaded on
September 23, 2026
Number of pages
53
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$20.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
59
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions