Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 11 pages
Exam (elaborations)

Principles of Information Security 7th Edition by Whitman and Mattord

Document preview thumbnail
Preview 2 out of 11 pages

Principles of Information Security 7th Edition by Whitman and Mattord

Content preview

TEST BANK For Principles of Information Security 7th
Edition by Whitman and Mattord



Which of the following acts is also widely known as the Gramm-Leach-Bliley Act? -
ANSWER: Financial Services Modernization Act

_________ assigns a status level to employees to designate the maximum level of
classified data they may access. - ANSWER: security clearance scheme

____ is any technology that aids in gathering information about a person or
organization without their knowledge. - ANSWER: Spyware

__________ law regulates the structure and administration of government agencies
and their relationships with citizens, employees, and other governments. - ANSWER:
Public

Complete loss of power for a moment is known as a ____. - ANSWER: fault

The goals of information security governance include all but which of the following?

1) Regulatory compliance by using information security knowledge and
infrastructure to support minimum standards of due care

2) Strategic alignment of information security with business strategy to support
organizational objectives


3) Risk management by executing appropriate measures to manage and mitigate
threats to information resources


4) Performance measurement by measuring, monitoring, and reporting information
security governance metrics to ensure that organizational objectives are achieved -
ANSWER: Regulatory compliance by using information security knowledge and
infrastructure to support minimum standards of due care

The _________ control strategy that attempts to eliminate or reduce any remaining
uncontrolled risk through the application of additional controls and safeguards. -
ANSWER: defense

A single loss ____________________ is the calculation of the value associated with
the most likely loss from an attack. - ANSWER: expectancy

, The Health Insurance Portability and Accountability Act Of 1996, also known as the
__________ Act, protects the confidentiality and security of health care data by
establishing and enforcing standards and by standardizing electronic data
interchange. - ANSWER: Kennedy-Kessebaum

__________ is an estimate of how many times per year you expect a specific type of
attack to occur. - ANSWER: ARO

Incident ____________________ is the process of examining a potential incident, or
incident candidate, and determining whether or not that candidate constitutes an
actual incident. - ANSWER: classification

As frustrating as viruses and worms are, perhaps more time and money is spent on
resolving virus ____________________. - ANSWER: hoaxes

A(n) ________ plan is a plan for the organization's intended strategic efforts over the
next several years. - ANSWER: tactical

__________ is a strategy for the protection of information assets that uses multiple
layers and different types of controls (managerial, operational, and technical) to
provide optimal protection. - ANSWER: Defense in depth

________often function as standards or procedures to be used when configuring or
maintaining systems. - ANSWER: SysSPs

The SETA program is a control measure designed to reduce the instances of
__________ security breaches by employees. - ANSWER: accidental

A methodology for the design and implementation of an information system that is a
formal development strategy is referred to as a __________. - ANSWER: systems
development life cycle

__________ was the first operating system to integrate security as its core functions.
- ANSWER: MULTICS

A computer is the __________ of an attack when it is used to conduct an attack
against another computer. - ANSWER: subject

The transfer of large batches of data to an off-site facility, usually through leased
lines or services, is called ____. - ANSWER: electronic vaulting

The ________is based on and directly supports the mission, vision, and direction of
the organization and sets the strategic direction, scope, and tone for all security
efforts. - ANSWER: EISP (Enterprise Information Security Policy)

Connected book
 image
Michael E. Whitman, Herbert J. Mattord Principles of Information Security
Edition: 2021 ISBN: 9780357506431 Edition: Unknown

Document information

Uploaded on
September 6, 2024
Number of pages
11
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$18.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
3
Followers
0
Items
1282
Last sold
10 months ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions