C795 Chapter 19 Questions
1. Devin is revising the policies and procedures used by his organization to conduct
investigations
and would like to include a definition of computer crime. Which one of the following
definitions
would best meet his needs?
A. Any attack specifically listed in your security policy
B. Any illegal attack that compromises a protected computer
C. Any violation of a law or regulation that involves a computer
D. Failure to practice due diligence in computer security - answerC. Any violation of a
law or regulation that involves a computer
2.What is the main purpose of a military and intelligence attack?
A. To attack the availability of military systems
B. To obtain secret and restricted information from military or law enforcement sources
C. To utilize military or intelligence agency systems to attack other, nonmilitary sites
D. To compromise military systems for use in attacks against other systems - answerB.
To obtain secret and restricted information from military or law enforcement sources
3. Which of the following is not a canon of the (ISC)2 Code of Ethics?
A. Protect your colleagues.
B. Provide diligent and competent service to principals.
C. Advance and protect the profession.
D. Protect society. - answerA. Protect your colleagues.
4. Which of the following are examples of financially motivated attacks? (Choose all that
apply.)
A. Accessing services that you have not purchased
B. Disclosing confidential personal employee information
C. Transferring funds from an unapproved source into your account
D. Selling a botnet for use in a DDoS attack - answerA. Accessing services that you
have not purchased
C. Transferring funds from an unapproved source into your account
D. Selling a botnet for use in a DDoS attack
5. Which one of the following attacker actions is most indicative of a terrorist attack?
A. Altering sensitive trade secret documents
B. Damaging the ability to communicate and respond to a physical attack
C. Stealing unclassified information
D. Transferring funds to other countries - answerB. Damaging the ability to
communicate and respond to a physical attack
, 6. Which of the following would not be a primary goal of a grudge attack?
A. Disclosing embarrassing personal information
B. Launching a virus on an organization's system
C. Sending inappropriate email with a spoofed origination address of the victim
organization
D. Using automated tools to scan the organization's systems for vulnerable ports -
answerD. Using automated tools to scan the organization's systems for vulnerable ports
7. What are the primary reasons attackers engage in thrill attacks? (Choose all that
apply.)
A. Bragging rights
B. Money from the sale of stolen documents
C. Pride of conquering a secure system
D. Retaliation against a person or organization - answerA. Bragging rights
C. Pride of conquering a secure system
8. What is the most important rule to follow when collecting evidence?
A. Do not turn off a computer until you photograph the screen.
B. List all people present while collecting evidence.
C. Avoid the modification of evidence during the collection process.
D. Transfer all equipment to a secure storage location. - answerC. Avoid the
modification of evidence during the collection process.
9. What would be a valid argument for not immediately removing power from a machine
when an
incident is discovered?
A. All of the damage has been done. Turning the machine off would not stop additional
damage.
B. There is no other system that can replace this one if it is turned off.
C. Too many users are logged in and using the system.
D. Valuable evidence in memory will be lost. - answerD. Valuable evidence in memory
will be lost.
10. What type of evidence refers to written documents that are brought into court to
prove a fact?
A. Best evidence
B. Parol evidence
C. Documentary evidence
D. Testimonial evidence - answerC. Documentary evidence
Best evidence rule states that when a document is used as evidence in
a court proceeding, the original document must be introduced.
Parol evidence rule states that when an agreement between parties is put into written
form, the written document is assumed to contain all the terms of the agreement, and no
verbal agreements may modify the written agreement.
Testimonial evidence is evidence consisting of the testimony of a witness, either
verbal testimony in court or written testimony in a recorded deposition.
1. Devin is revising the policies and procedures used by his organization to conduct
investigations
and would like to include a definition of computer crime. Which one of the following
definitions
would best meet his needs?
A. Any attack specifically listed in your security policy
B. Any illegal attack that compromises a protected computer
C. Any violation of a law or regulation that involves a computer
D. Failure to practice due diligence in computer security - answerC. Any violation of a
law or regulation that involves a computer
2.What is the main purpose of a military and intelligence attack?
A. To attack the availability of military systems
B. To obtain secret and restricted information from military or law enforcement sources
C. To utilize military or intelligence agency systems to attack other, nonmilitary sites
D. To compromise military systems for use in attacks against other systems - answerB.
To obtain secret and restricted information from military or law enforcement sources
3. Which of the following is not a canon of the (ISC)2 Code of Ethics?
A. Protect your colleagues.
B. Provide diligent and competent service to principals.
C. Advance and protect the profession.
D. Protect society. - answerA. Protect your colleagues.
4. Which of the following are examples of financially motivated attacks? (Choose all that
apply.)
A. Accessing services that you have not purchased
B. Disclosing confidential personal employee information
C. Transferring funds from an unapproved source into your account
D. Selling a botnet for use in a DDoS attack - answerA. Accessing services that you
have not purchased
C. Transferring funds from an unapproved source into your account
D. Selling a botnet for use in a DDoS attack
5. Which one of the following attacker actions is most indicative of a terrorist attack?
A. Altering sensitive trade secret documents
B. Damaging the ability to communicate and respond to a physical attack
C. Stealing unclassified information
D. Transferring funds to other countries - answerB. Damaging the ability to
communicate and respond to a physical attack
, 6. Which of the following would not be a primary goal of a grudge attack?
A. Disclosing embarrassing personal information
B. Launching a virus on an organization's system
C. Sending inappropriate email with a spoofed origination address of the victim
organization
D. Using automated tools to scan the organization's systems for vulnerable ports -
answerD. Using automated tools to scan the organization's systems for vulnerable ports
7. What are the primary reasons attackers engage in thrill attacks? (Choose all that
apply.)
A. Bragging rights
B. Money from the sale of stolen documents
C. Pride of conquering a secure system
D. Retaliation against a person or organization - answerA. Bragging rights
C. Pride of conquering a secure system
8. What is the most important rule to follow when collecting evidence?
A. Do not turn off a computer until you photograph the screen.
B. List all people present while collecting evidence.
C. Avoid the modification of evidence during the collection process.
D. Transfer all equipment to a secure storage location. - answerC. Avoid the
modification of evidence during the collection process.
9. What would be a valid argument for not immediately removing power from a machine
when an
incident is discovered?
A. All of the damage has been done. Turning the machine off would not stop additional
damage.
B. There is no other system that can replace this one if it is turned off.
C. Too many users are logged in and using the system.
D. Valuable evidence in memory will be lost. - answerD. Valuable evidence in memory
will be lost.
10. What type of evidence refers to written documents that are brought into court to
prove a fact?
A. Best evidence
B. Parol evidence
C. Documentary evidence
D. Testimonial evidence - answerC. Documentary evidence
Best evidence rule states that when a document is used as evidence in
a court proceeding, the original document must be introduced.
Parol evidence rule states that when an agreement between parties is put into written
form, the written document is assumed to contain all the terms of the agreement, and no
verbal agreements may modify the written agreement.
Testimonial evidence is evidence consisting of the testimony of a witness, either
verbal testimony in court or written testimony in a recorded deposition.