security OAEXAM 2 VERSIONS TESTBANK
AND LATEST UPDATED
"Modification - Correct Answer Attacks involve tampering with our asset. Such attacks might
primarily be considered an integrity attack, but could also be an availability attack."
"Fabrication - Correct Answer Attacks involve generating data, processes, communications, or
other similar activities with a system. Attacks primarily affect integrity but can be considered
an availability attack."
"Risk - Correct Answer The likelihood that a threat will occur. There must be a threat and
vulnerability"
"Threat - Correct Answer Any event being man-made, natural or environmental that could
damage the assets"
"Vulnerabilities - Correct Answer Weakness that a threat event or the threat can take
advantage of"
"Impact - Correct Answer taking into account the assets cost"
"Controls - Correct Answer The ways we protect assets. Physical, technical/ logical, and
administrative"
"Physical controls - Correct Answer Controls are physical items that protect assets. Think of
locks, doors, guards and fences"
"Technical/ logical controls - Correct Answer Controls are devices and software that protect
assets. Think of firewalls, av, ids, and ips"
"Administrative controls - Correct Answer Controls are the policies that organizations create
for governance. Ex: email policies"
"risk mamagement - Correct Answer A constant process as assets are purchased, used and
retired. The general steps are 1- identify assets
2- identify threats
,3- assess vulnerabilities
4- assess risk
5- mitigating risks"
"Identify assets - Correct Answer First and most important part or risk management.
Identifying and categorizing the assets we are protecting"
"Identify threats - Correct Answer Once we have our critical assets we can identify the
threats that might effect them"
"Assess Vulnerabilities - Correct Answer Look at potential threats. any given asset may have
thousand or millions of threats that could impact it, but only a small fraction of the threats
will be relevant"
"Assess risks - Correct Answer Once we have identified the threats and vulnerabilities for a
given asset we can access the overall risk"
"Mitigating risks - Correct Answer Putting measures in place to help ensure that a given type
of threat is accounted for"
"Incident response - Correct Answer Response to when risk management practices have
failed and have cause an inconvenience to a disastrous event"
"Incident response cycle - Correct Answer 1 preparation
2- detection and analysis
3- containment
4- eradication
5- recovery
6- post incident activity"
"Preparation phase - Correct Answer The preparation phase consists of all of the activities
that we can preform in advance of the incident itself in order to better enable us to handle it"
"Detection and analysis phase - Correct Answer Where the action begins to happen. We will
detect the occurrence of an issue and decide whether or not it is actually an incident so that
we can respond"
"Containment phase - Correct Answer Taking steps to ensure that the situation does not
cause any more damage than it already has, or to at least lessen any ongoing harm."
, "Eradication phase - Correct Answer We will attempt to remove the effects of the issue from
our environment"
"Recovery phase - Correct Answer Recover to a better state that we were prior to the incident
or perhaps prior to when the issue started if we did not detect it immediately"
"Post incident activity phase - Correct Answer We attempt to determine specifically what
happened, why it happened, and what we can do to keep it from happening again."
"Defense in depth - Correct Answer Layering of security controls is more effective and secure
than relying on a single control"
"Identity - Correct Answer Who or what we claim to be ( username)"
"Authentication - Correct Answer The act of proving who or what we claim to be (password)"
"Identity verification - Correct Answer The half step between identity and authentication
(showing two forms of Id)"
"single-factor authentication - Correct Answer Involves the use of simply one of the three
available factors solely in order to carry out the authentication process being requested"
"Dual-factor authentication - Correct Answer An authentication method that includes
multiple methods for a single authentication transaction. Often referred to as "something you
have and something you know," when the factors include a device such as a smart card and a
secret such as a password or PIN."
"Multi-factor authentication - Correct Answer Use of several authentication techniques
together, such as passwords and security tokens."
"mutual authentication - Correct Answer The process where the session is authenticated on
both ends and just one end . Prevents man in the middle attacks"
"man-in-the-middle attack - Correct Answer a hacker placing himself between a client and a
host to intercept communications between them"
"brute force attack - Correct Answer the password cracker tries every possible combination
of characters to guess the password"