Mod 01 CSIA 105 Exam Questions With
Correct Answers
In |relation |to |security |and |convenience, |what |does |inversely |proportional |mean?
Means |that |when |security |increases |(from |low |to |high |on |the |horizontal |x-axis), |convenience |
decreases |(from |high |to |low |on |the |vertical |y-axis).
What |are |the |2 |fundamental |security |concepts?
Confidentiality, |Integrity, |and |Availability |(CIA) |&
Authentication, |Authorization, |Accounting |(AAA)
What |3 |basic |security |protections |must |be |extended |over |the |information?
Confidentiality
Integrity
Availibility
Within |the |information |security |managerial |and |technical |personnel, |list |the |4 |generally |
recognized |types |of |security |positions.
1. |Chief |Information |Security |Officer |(CISO)
2. |Security |Manager
3. |Security |Administrator
4. |Security |Technician
List |the |4 |broad |categories |of |security |controls.
1. |Managerial
2. |Operational
3. |Technical
4. |Physical
Two |Rights |& |A |Wrong
1. |Integrity |ensures |that |only |authorized |parties |can |view |information.
2. |The |relationship |between |security |and |convenience |is |inversely |proportional: |as |security |is |
, increased, |convenience |is |decreased.
3. |A |deterrent |control |is |designed |to |discourage |an |attack |from |taking |place.
1. |Integrity |ensures |that |only |authorized |parties |can |view |information.
Explanation: |Confidentiality |ensures |that |only |authorized |parties |can |view |information.
Financial |cybercrime |can |be |divided |into |what |three |categories?
1. |Individual |users.
2. |Enterprises.
3. |Governments.
List |the |3 |attributes |of |threat |actors.
1. |Level |of |Sophistication/Capability
2. |Resources/Funding
3. |Internal/External
Two |Rights |& |A |Wrong
1. |Nation-state |actors |are |responsible |for |the |class |of |attacks |called |Advanced |Persistent |
Threats.
2. |A |usual |motivation |for |organized |crime |is |service |disruption.
3. |Hacktivists |are |motivated |by |philosophical/political |beliefs.
2. |A |usual |motivation |for |organized |crime |is |service |disruption.
Explanation: |A |usual |motivation |for |organized |crime |is |financial |gain.
What |are |the |3 |categories |of |mainstream |attack |surfaces?
Software
Hardware
Networks
List |the |3 |mainstream |attack |software |surfaces.
Vulnerable |software
File-based |software
Image-based |software
List |the |3 |mainstream |attack |hardware |surfaces.
Unsupported |systems |and |applications
Removable |devices
Correct Answers
In |relation |to |security |and |convenience, |what |does |inversely |proportional |mean?
Means |that |when |security |increases |(from |low |to |high |on |the |horizontal |x-axis), |convenience |
decreases |(from |high |to |low |on |the |vertical |y-axis).
What |are |the |2 |fundamental |security |concepts?
Confidentiality, |Integrity, |and |Availability |(CIA) |&
Authentication, |Authorization, |Accounting |(AAA)
What |3 |basic |security |protections |must |be |extended |over |the |information?
Confidentiality
Integrity
Availibility
Within |the |information |security |managerial |and |technical |personnel, |list |the |4 |generally |
recognized |types |of |security |positions.
1. |Chief |Information |Security |Officer |(CISO)
2. |Security |Manager
3. |Security |Administrator
4. |Security |Technician
List |the |4 |broad |categories |of |security |controls.
1. |Managerial
2. |Operational
3. |Technical
4. |Physical
Two |Rights |& |A |Wrong
1. |Integrity |ensures |that |only |authorized |parties |can |view |information.
2. |The |relationship |between |security |and |convenience |is |inversely |proportional: |as |security |is |
, increased, |convenience |is |decreased.
3. |A |deterrent |control |is |designed |to |discourage |an |attack |from |taking |place.
1. |Integrity |ensures |that |only |authorized |parties |can |view |information.
Explanation: |Confidentiality |ensures |that |only |authorized |parties |can |view |information.
Financial |cybercrime |can |be |divided |into |what |three |categories?
1. |Individual |users.
2. |Enterprises.
3. |Governments.
List |the |3 |attributes |of |threat |actors.
1. |Level |of |Sophistication/Capability
2. |Resources/Funding
3. |Internal/External
Two |Rights |& |A |Wrong
1. |Nation-state |actors |are |responsible |for |the |class |of |attacks |called |Advanced |Persistent |
Threats.
2. |A |usual |motivation |for |organized |crime |is |service |disruption.
3. |Hacktivists |are |motivated |by |philosophical/political |beliefs.
2. |A |usual |motivation |for |organized |crime |is |service |disruption.
Explanation: |A |usual |motivation |for |organized |crime |is |financial |gain.
What |are |the |3 |categories |of |mainstream |attack |surfaces?
Software
Hardware
Networks
List |the |3 |mainstream |attack |software |surfaces.
Vulnerable |software
File-based |software
Image-based |software
List |the |3 |mainstream |attack |hardware |surfaces.
Unsupported |systems |and |applications
Removable |devices