CITM 820 FINAL UPDATED QUESTIONS AND CORRECT
ANSWERS
Question:
1. __________ is a term used that refers to the means of delivering a key to two parties that wish to
exchange data without allowing others to see the key.
Answer:
Key distribution technique
Question:
2. A ________ is a key used between entities for the purpose of distributing session keys.
Answer:
permanent key
Question:
3. Security controls are defined by which of the fol-lowing standards?
Answer:
NIST SP 800-53
Question:
4. A ___________ attack involves trying all possible keys
Answer:
Brute-force
Question:
5. In order to manage security, the international standards organization (ISO) has revised and
con-solidated a number of security standards into the ISO _________ series
Answer:
27000
Question:
6. The physical threats can be organized into envi-ronmental, technical and _____ threats.
Answer:
Human-caused
Question:
7. Which of the following categories is classified as the greatest risk level
Answer:
E
Question:
8. Cryptographic systems are generically classified by _________.
Answer:
The type of operations used for transforming plaintext to cipher-text The number of keys used The
way in which the plaintext is processed All of the above None of the above
, Question:
9. SHA-1 produces a hash value of __________ bits.
Answer:
160
Question:
10. Computer media such as flexible disks and mag-netic tapes may be damaged with a temperature
level exceeding _____ Celsius degrees.
Answer:
38
Question:
11. There are three classes of security controls: Tech-nical controls, Management controls, and
______ controls.
Answer:
Operational
Question:
12. What is the port number of HTTPS?
Answer:
443
Question:
13. This security standard provides guidelines for in-formation security management in an
organiza-tion and contains a list of best practice security controls.
Answer:
27002
Question:
14. Audit and Accountability are part of which of the following classes of security controls?
Answer:
Technical
Question:
15. Three elements of IS security as discussed in this module: logical, physical and _____ security.
Answer:
Premises
Question:
16. _____ mode is typically used for a general-pur-pose block-oriented transmission and is useful for
high-speed requirements. It is deployed with applications such as ATM and IPsec.
Answer:
CTR
Question:
17. Which of the following options is related to the second step of a risk assessment analysis?
ANSWERS
Question:
1. __________ is a term used that refers to the means of delivering a key to two parties that wish to
exchange data without allowing others to see the key.
Answer:
Key distribution technique
Question:
2. A ________ is a key used between entities for the purpose of distributing session keys.
Answer:
permanent key
Question:
3. Security controls are defined by which of the fol-lowing standards?
Answer:
NIST SP 800-53
Question:
4. A ___________ attack involves trying all possible keys
Answer:
Brute-force
Question:
5. In order to manage security, the international standards organization (ISO) has revised and
con-solidated a number of security standards into the ISO _________ series
Answer:
27000
Question:
6. The physical threats can be organized into envi-ronmental, technical and _____ threats.
Answer:
Human-caused
Question:
7. Which of the following categories is classified as the greatest risk level
Answer:
E
Question:
8. Cryptographic systems are generically classified by _________.
Answer:
The type of operations used for transforming plaintext to cipher-text The number of keys used The
way in which the plaintext is processed All of the above None of the above
, Question:
9. SHA-1 produces a hash value of __________ bits.
Answer:
160
Question:
10. Computer media such as flexible disks and mag-netic tapes may be damaged with a temperature
level exceeding _____ Celsius degrees.
Answer:
38
Question:
11. There are three classes of security controls: Tech-nical controls, Management controls, and
______ controls.
Answer:
Operational
Question:
12. What is the port number of HTTPS?
Answer:
443
Question:
13. This security standard provides guidelines for in-formation security management in an
organiza-tion and contains a list of best practice security controls.
Answer:
27002
Question:
14. Audit and Accountability are part of which of the following classes of security controls?
Answer:
Technical
Question:
15. Three elements of IS security as discussed in this module: logical, physical and _____ security.
Answer:
Premises
Question:
16. _____ mode is typically used for a general-pur-pose block-oriented transmission and is useful for
high-speed requirements. It is deployed with applications such as ATM and IPsec.
Answer:
CTR
Question:
17. Which of the following options is related to the second step of a risk assessment analysis?