MSIS 4123 EXAM 1 | QUIZ SMART | SCORE HIGH |
GUARANTEED ACCURACY!
Which of the following produces a risk to an asset? - Answer: A threat agent and an
attack the agent can perform
Which of the following types of threat agents is most typically associated with
masquerade attacks? - Answer: Identity thieves
Different types of attacks on information are described below. Which of the descriptions
is NOT correct? - Answer: Disclosure - A program is modified to operate on the behalf
of a threat agent
Anonymous is an example of what kind of agent? - Answer: Threat
A security analyst is performing a security assessment. The analyst should not: -
Answer: take actions to mitigate a serious risk.
Which of the following is an example of security theater? - Answer: Installing a fake
video camera
True or False? A supervisory control and data acquisition (SCADA) device is a computer
that controls motors, valves, and other devices in industrial applications. - Answer: True
True or False? A zero-day vulnerability is one that has been reported to the software's
vendor and the general public. - Answer: False
Both forms of the risk management framework (RMF) illustrate a(n) _______
engineering process as a way to plan, design, and build a complicated system. -
Answer: systems
1
APPHIA - Crafted with Care and Precision for Academic Excellence.
, True or False? Victims can protect themselves against zero-day attacks. - Answer:
False
Alice has performed a security assessment for Orange State University. The resulting
assessment is treated as confidential and is not shared with Alice's coworkers. Only
specific employees are allowed to read it. Which basic security principle does this
illustrate? - Answer: Least privilege principle
Which of the following most often forbids people from performing trial-and-error attacks
on computer systems? - Answer: not (Secrecy agreements for national security
information)
In information security, CIA properties do not include: - Answer: authentication.
True or False? Once we have filled in the attack likelihoods and impacts in the risk
assessment process, we compute the significance by multiplying these values together.
- Answer: True
True or False? To analyze a risk, we review it against the threat agents behind the risk. -
Answer: True
Which of the following would be considered insider threats?* Select ALL that apply. -
Answer: Suite/room/housemates and family
Embezzlers Administrators
Maintenance crew
True or False? A vulnerability is a security measure intended to protect an asset. -
Answer: False
2
APPHIA - Crafted with Care and Precision for Academic Excellence.
GUARANTEED ACCURACY!
Which of the following produces a risk to an asset? - Answer: A threat agent and an
attack the agent can perform
Which of the following types of threat agents is most typically associated with
masquerade attacks? - Answer: Identity thieves
Different types of attacks on information are described below. Which of the descriptions
is NOT correct? - Answer: Disclosure - A program is modified to operate on the behalf
of a threat agent
Anonymous is an example of what kind of agent? - Answer: Threat
A security analyst is performing a security assessment. The analyst should not: -
Answer: take actions to mitigate a serious risk.
Which of the following is an example of security theater? - Answer: Installing a fake
video camera
True or False? A supervisory control and data acquisition (SCADA) device is a computer
that controls motors, valves, and other devices in industrial applications. - Answer: True
True or False? A zero-day vulnerability is one that has been reported to the software's
vendor and the general public. - Answer: False
Both forms of the risk management framework (RMF) illustrate a(n) _______
engineering process as a way to plan, design, and build a complicated system. -
Answer: systems
1
APPHIA - Crafted with Care and Precision for Academic Excellence.
, True or False? Victims can protect themselves against zero-day attacks. - Answer:
False
Alice has performed a security assessment for Orange State University. The resulting
assessment is treated as confidential and is not shared with Alice's coworkers. Only
specific employees are allowed to read it. Which basic security principle does this
illustrate? - Answer: Least privilege principle
Which of the following most often forbids people from performing trial-and-error attacks
on computer systems? - Answer: not (Secrecy agreements for national security
information)
In information security, CIA properties do not include: - Answer: authentication.
True or False? Once we have filled in the attack likelihoods and impacts in the risk
assessment process, we compute the significance by multiplying these values together.
- Answer: True
True or False? To analyze a risk, we review it against the threat agents behind the risk. -
Answer: True
Which of the following would be considered insider threats?* Select ALL that apply. -
Answer: Suite/room/housemates and family
Embezzlers Administrators
Maintenance crew
True or False? A vulnerability is a security measure intended to protect an asset. -
Answer: False
2
APPHIA - Crafted with Care and Precision for Academic Excellence.