ISOL 531 ACCESS CONTROL MIDTERM EXAM FALL SEMESTER 2024 APPROVED QUESTIONS AND ANSWERS EXAM A+ GRADE
UNIVERSITY OF THE CUMBERLANDS ISOL 531 ACCESS CONTROL MIDTERM EXAM FALL SEMESTER 2024 APPROVED QUESTIONS AND ANSWERS EXAM A+ GRADE QUESTION 1 1. There are three principal components of any access control scenario: policies, subjects, and . tools procedu res objects access QUESTION 2 1. In the private sector, the most common systems use a token or challenge-response device coupled with a username and password. multilayered access control control asset value smart card QUESTION 3 1. Users are not the only subjects in access control systems. Technological resources may also serve as subjects. A(n) can be a subject when it attempts to access other resources on the same computer or over the network. applicati on system process network QUESTION 4 1. are disgruntled employees who can pose a major threat to information security in the forms of theft, sabotage, vandalism, and more. Tiger teams Rogue Internal Operatives Black-hat hackers Malicious hackers QUESTION 5 1. There are three types of subjects when it comes to access control for a specific resource: authorized, unauthorized, and . unknown authenticat ed objects unauthentic ated QUESTION 6 1. ensures that information is available to authorized users when they need it. Least privilege Information integrity Information availability Information confidentiality QUESTION 7 1. is the level of information an individual is authorized to access. Clearance Confidential information Controlled unclassified information (CUI) Mandatory declassification QUESTION 8 1. There are three elements of security in the Workstation Domain: virus scanning, , and host firewall. access control security administrators operating system patching workstation QUESTION 9 1. With respect to typical corporate security classification schemes, sensitive information is often not released outside the company except under the terms of a formal . classification scheme declassification nondisclosure agreement mandatory declassification review QUESTION 10 1. A summary of the system under analysis, a list of information to be collected, and a description of how the information will be collected are all components of . access control California Identity Theft Statute PIA DMCA QUESTION 11 1. is a method of scrambling data for security purposes that was published in 1974. It has since been broken and is no longer considered highly secure. Shadow password Data Encryption Standard (DES) encryption Hash salt NTLM hash QUESTION 12 1. Which of the following is a description of SOX Title VIII, Corporate and Criminal Fraud Accountability? Defines the conditions under which the Securities and Exchange Commission (SEC) has the authority to censure or bar securities professionals from practice. Establishes standards that require external auditors to be completely independent from the firms they audit, which limits conflicts of interest. Describes enhanced reporting procedures required for financial transactions. Also requires internal controls that ensure that financial reports and disclosures are accurate. Imposes documentation retention requirements on companies and auditors. It also describes specific criminal penalties for manipulation, destruction, or alteration of financial records. QUESTION 13 1. There are three main categories of objects to be protected by access controls: information, technology, and . applications processes physical location networks QUESTION 14 1. There are two primary types of biometric authentication systems: physical and . mnemonic physiologi cal psychologi cal behavioral QUESTION 15 1. What term is used to describe a method of organizing sensitive information into various access levels? confidential information secret information automatic classification classification scheme QUESTION 16 1. According to the typical corporate security classification scheme, information, if disclosed, could cause serious damage to the firm. sensitive public internal highly sensitive QUESTION 17 1. is an authentication system in which two conditions must be met in order for access to be granted. If one condition is met but not the other, access is denied. Input control Separation of responsibilities Discretionary access control (DAC) Output control QUESTION 18 1. Information ensures that data has not been modified without authorization. availability confidentia lity integrity ability QUESTION 19 1. There are penalties for disclosing medical/patient information in violation of the Health Insurance Portability and Accountability Act (HIPAA). When such information is disclosed with willful negligence in a situation that is corrected, the penalty is per violation. $1,000 $10,000 $50,000
Written for
- Institution
-
University Of The Cumberlands
- Course
-
ISOL 531
Document information
- Uploaded on
- February 3, 2024
- Number of pages
- 20
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
- isol 531
- isol 531 access control
- isol531 access control
- isol531access control
-
university of the cumberlands isol 531
-
isol 531 access control midterm exam fall semester