WGU C725 Information Security and Assurance, Final Exam Questions and Answers Latest
WGU C725 Information Security and Assurance, Final Exam Questions and Answers Latest . A job title: Have access to information resources in accordance with the owner-defined controls and access rules.: Ans- Users 2. One purpose of a security awareness program is to modify which of the following? A. Employees' attitudes and behaviors B. Management's approach C. Attitudes of employees toward sensitive data D. Corporate attitudes about safeguarding data: Ans- A. Employees' attitudes and behaviors Explanation: Because people are the weakest link in any security-related process, it's crucial that a security program address user education, awareness, and training on policies and procedures that affect them. 2 / 14 3. The totality of protection mechanisms within a computer system, including hardware, firmware, and software. It consists of one or more components that together enforce a unified security policy over a product or system: Trusted Computing Base (TCB) 4. A software model that mediates all access from any subject (user or other device) to any object (resource, data, and so forth); it cannot be bypassed.It mediates accesses to objects by subjects. In principle, it should be: Complete, to mediate every access Isolated from modification by other system entities (objects and processes) Verifiable, doing only what it's programmed to do and not being susceptible to circumvention by malicious acts or programmer error: reference monitor a.k.a. abstract machine 5. Implementation of a reference monitor for a specific hardware base, such as Sun Solaris, Red Hat Linux, or Mac OS X.: security kernel 3 / 14 The TCB, reference monitor, and security kernel are essential for military- and 4 / 14 government-grade information technology (IT) security to prevent unauthorized access or threats to the integrity of programs, operating systems, or data. 6. T or F In "The ring of trust" Trust in a system moves from the outside to the inside in a unidirectional mode.: True 7. T or F Multics was the first operating system to provide a hierarchical file system: - True 8. Which of the following terms best defines the sum of protection mechanisms inside the computer, including hardware, firmware, and software? A . Trusted system B .Security kernel C. Trusted computing base D. Security perimeter: C. Trusted computing base Explanation: The Trusted Computing Base (TCB) is the totality of protection mechanisms within 5 / 14 a computer system, including hardware, firmware, and software. 9. A TCB practice in which a design objective in which each process has its own distinct address space for its application code and data. Such a design makes it possible to prevent each process from accessing another process's data. This prevents data or information leakage and prevents modification of the data while in memory.: Process isolation 10. A TCB practice in which a process (program) have no more privilege than what it really needs to perform its functions. Any modules that require supervisor or root access (that is, complete system privileges) are embedded in the operating system kernel. The kernel handles all requests for system resources and mediates the access from external modules to privileged modules when required.: The principle of least privilege 11. A TCB practice in which specifically relates to the segmentation of memory into protected segments. The kernel allocates the required amount of memory for the process to load its application code, its process data, and its application data. The system prevents user processes from accessing another process's allocated memory. It also prevents user processes from accessing system memory.: Hardware segmentation 6 / 14 12. A TCB practice in which process operation that is divided into layers by function. Each layer deals with a specific activity. The lower (outer) layers perform basic tasks, whereas the higher (inner) layers perform more complex or protected tasks.: Layering 13. A TCB practice in which a process that defines a specific set of permissiblevalues for an object and the operations that are permissible on that object. This involves ignoring or separating implementation details to concentrate on what is important to maintain security.: Abstraction 14. A TCB practice in which a mechanism used to ensure that information available at one processing level is not available in another, regardless of whether it is higher or lower. It is also a concept in the object-oriented programming (OOP) technique when information is encapsulated within an object and can be directly manipulated only by the services provided within the object.: Data hiding a.k.a. information hiding 15. A TCB practice in which parts of a computer system that retain a physical state (information) for some interval of time, possibly even after electrical power to the computer is removed.: Information storage 16. A type of information storage in which it is the computer's main memory 7 / 14 that is directly addressable by the central processing unit (CPU). Primary storage is a volatile storage medium, meaning that the contents of the physicalmemory are lost when the power is removed.: Primary storage a.k.a. (RAM) Random Access Memory 17. A type of information storage in which it is a nonvolatile storage format that can store application and system code plus data when the system is not in use.Examples of this type of storage are disk drives or other persistent data storage mechanisms (including Flash [USB] drives, memory sticks, and tapes).: Secondary storage 18. A type of information storage in which refers to a definite storage location for a program in memory and direct access to a peripheral device. This is common with database management systems that control how storage is used outside the operating system's control.: Real memory 19. A type of information storage in which it extends the volume of primary storage by using secondary storage to hold the memory contents. In this way, the operating system can run programs larger than the available physical memory. This memory (memory contents stored on disk) is swapped in and out of primary memory when needed for processing.: Virtual memory 8 / 14 20. A type of information storage in which it is the computer's primary working and storage area. It is addressable directly by the CPU and stores application or system code in addition to data.: Random memory 21. A type of information storage in which it is computer memory that is accessed sequentially. An example of this is magnetic tape.: Sequential storage 22. A type of information storage in which it experiences a complete loss of any stored information when the power is removed.: Volatile memory 23. T or F Closed systems are proprietary in nature.: True They use specific operating systems and hardware to perform the task and generallylack standard interfaces to allow connection to other systems. The user is generally limited in the applications and programming languages available. 24. An is based on accepted standards and employs standard interfaces to allow connections between different systems. It promotes interoperability and gives the user full access to the total system capability.- : open system 9 / 14 25. A technique used by a system that is capable of running two or more tasks in a concurrent performance or interleaved execution.: Multitasking 26. permits the interleaved execution of two or more programs on a processor.: multiprogramming system 27. provides for simultaneous execution of two or more programs by a processor (CPU). This can alternatively be done through parallel processing of a single program by two or more processors in a multiprocessor system that all have common access to main storage.: Multiprocessing 28. Any device that stores the status or state of something at a given time that can operate based on inputs to change the stored status and/or cause an action or output to take place. The importance of this is that the machine has distinct states that it remembers. In Multics, for example, a state was associated with each ring of trust. Each computer's data register also stores a state. The read-only memory from which a boot (computer start-up) program is loaded stores a state. In fact, the boot program is an initial state. The operatingsystem is itself a state, and each application that it runs begins with some initial state that can change as it handles input.
Written for
- Institution
- WGU C725 Information Security and Assurance
- Module
- WGU C725 Information Security and Assurance
Document information
- Uploaded on
- September 13, 2023
- Number of pages
- 31
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers
Subjects
-
wgu c725
-
latest updated
-
2023
-
2024
-
graded
-
wgu c725 information security and assurance
-
information security and assurance
-
wgu c725 final exam questions and answers
Also available in package deal