ISTM 410 EXAM 3 UPDATED QUESTIONS AND CORRECT
ANSWERS
Question:
1. NIST Cybersecu-rity Framework
Answer:
Identify, Protect, Detect, Respond, Recover; gives leaders and managers a good place to start to think
about how to create the necessary plans to protect their organizations in the event of a cyber incident
Question:
2. Information se-curity strategy
Answer:
based on such IT principles as protecting the confidentiality of customer informa-tion, strict
compliance with regulations, and maintaining a security baseline that is above the industry
benchmark
Question:
3. Information se-curity infrastruc-ture
Answer:
involves selecting and configuring the right tools; common objectives are to achieve consistency in
protection, economies of scale, and synergy among the components
Question:
4. Who is responsi-ble for informa-tion security in-frastructure deci-sions?
Answer:
corporate IT
Question:
5. Information se-curity policy
Answer:
provide guidelines for the organization's activities, both technical and organiza-tional, to increase
cyber resilience; they broadly define the scope of and overall expectations for the company's
information security program
Question:
6. Cybersecurity culture
Answer:
Creating the understanding that good cybersecurity practices are important to the success of the
business
Question:
7. information se-curity invest-ments
Answer:
decisions about the appropriate level of investment
Question:
8. Who should make decisions regarding infor-mation security investments?
,Answer:
Both business leaders and IT
Question:
9. What compa-ny suffered the largest breach of all time?
Answer:
Yahoo
Question:
10. Breaches
Answer:
when unauthorized actors gain access to systems, passwords, data, or other assets
Question:
11. T/F: 80% of breaches are conducted by stealing a pass-word
Answer:
True
Question:
12. How many mega-breaches were there in 2017?
Answer:
16
Question:
13. Poulsen's law
Answer:
information is secure when it costs more to get it than it's worth
Question:
14. Duties of chief in-formation securi-ty officer (CISO)
Answer:
keep abreast of new threats that emerge and manage the policies and education necessary to reduce
risk
Question:
15. Two categories of security infra-structure tools
Answer:
1. those that provide protection from access by undesired intruders
2. those that provide protection for storage and transmission
Question:
16. T/F: Some se-curity specialists claim that pass-words are obso-lete and should be discontin-ued
because of their vulnerabili-ties and the false sense of securi-ty created when users think a password
is all they need to be secure
Answer:
True
, Question:
17. three types of factors that are popular to use for MFA
Answer:
1. Knowledge—something a user knows (e.g., password, challenge ques-
tion/answer)
2. Ownership—something the user has (e.g., cellphone, token, smartcard)
3. Biometric—something the user is (e.g., fingerprint, retinal scan)
Question:
18. T/F: Online mer-chants do not tend to make MFA a require-ment for their customers, per-haps
due to fear of making site ac-cess less conve-nient
Answer:
True
Question:
19. T/F: Although they can be help-ful, what grey hat hackers do is nevertheless ille-gal.
Answer:
True
Question:
20. Culture
Answer:
the values, beliefs, and attitudes held by members of the organization
Question:
21. T/F: a simple, annual training course is just not enough to change behav-iors
Answer:
True
Question:
22. Awareness
Answer:
let users know that security is a complex but important issue and that there are consequences when
policies are not followed
Question:
23. Education
Answer:
provides frameworks, reveals concepts, and builds understanding
Question:
24. Training
Answer:
covers procedures to follow and practice in following them
Question:
25. Spoofing
ANSWERS
Question:
1. NIST Cybersecu-rity Framework
Answer:
Identify, Protect, Detect, Respond, Recover; gives leaders and managers a good place to start to think
about how to create the necessary plans to protect their organizations in the event of a cyber incident
Question:
2. Information se-curity strategy
Answer:
based on such IT principles as protecting the confidentiality of customer informa-tion, strict
compliance with regulations, and maintaining a security baseline that is above the industry
benchmark
Question:
3. Information se-curity infrastruc-ture
Answer:
involves selecting and configuring the right tools; common objectives are to achieve consistency in
protection, economies of scale, and synergy among the components
Question:
4. Who is responsi-ble for informa-tion security in-frastructure deci-sions?
Answer:
corporate IT
Question:
5. Information se-curity policy
Answer:
provide guidelines for the organization's activities, both technical and organiza-tional, to increase
cyber resilience; they broadly define the scope of and overall expectations for the company's
information security program
Question:
6. Cybersecurity culture
Answer:
Creating the understanding that good cybersecurity practices are important to the success of the
business
Question:
7. information se-curity invest-ments
Answer:
decisions about the appropriate level of investment
Question:
8. Who should make decisions regarding infor-mation security investments?
,Answer:
Both business leaders and IT
Question:
9. What compa-ny suffered the largest breach of all time?
Answer:
Yahoo
Question:
10. Breaches
Answer:
when unauthorized actors gain access to systems, passwords, data, or other assets
Question:
11. T/F: 80% of breaches are conducted by stealing a pass-word
Answer:
True
Question:
12. How many mega-breaches were there in 2017?
Answer:
16
Question:
13. Poulsen's law
Answer:
information is secure when it costs more to get it than it's worth
Question:
14. Duties of chief in-formation securi-ty officer (CISO)
Answer:
keep abreast of new threats that emerge and manage the policies and education necessary to reduce
risk
Question:
15. Two categories of security infra-structure tools
Answer:
1. those that provide protection from access by undesired intruders
2. those that provide protection for storage and transmission
Question:
16. T/F: Some se-curity specialists claim that pass-words are obso-lete and should be discontin-ued
because of their vulnerabili-ties and the false sense of securi-ty created when users think a password
is all they need to be secure
Answer:
True
, Question:
17. three types of factors that are popular to use for MFA
Answer:
1. Knowledge—something a user knows (e.g., password, challenge ques-
tion/answer)
2. Ownership—something the user has (e.g., cellphone, token, smartcard)
3. Biometric—something the user is (e.g., fingerprint, retinal scan)
Question:
18. T/F: Online mer-chants do not tend to make MFA a require-ment for their customers, per-haps
due to fear of making site ac-cess less conve-nient
Answer:
True
Question:
19. T/F: Although they can be help-ful, what grey hat hackers do is nevertheless ille-gal.
Answer:
True
Question:
20. Culture
Answer:
the values, beliefs, and attitudes held by members of the organization
Question:
21. T/F: a simple, annual training course is just not enough to change behav-iors
Answer:
True
Question:
22. Awareness
Answer:
let users know that security is a complex but important issue and that there are consequences when
policies are not followed
Question:
23. Education
Answer:
provides frameworks, reveals concepts, and builds understanding
Question:
24. Training
Answer:
covers procedures to follow and practice in following them
Question:
25. Spoofing