BCOR 330 EXAM 3 - 4 QUESTIONS & ANSWERS
How do job descriptions safeguard information systems from threats? - Answers -By
restricting information access under a need-to-know basis
Which of the following is an example of a human error? - Answers -Something going
wrong because of installation.
Data loss is the principal cost of __________. - Answers -computer crime
Computer criminals can launch __________ attacks in which a malicious hacker floods
a web server with bogus service requests that then tie up the server, so that it cannot
service legitimate requests. - Answers -denial of service
Which of the following refers to an organization-wide function that is in charge of
developing data policies and enforcing data standards? - Answers -Data administration
Which of the following occurs when an intruder uses another site's Internet Protocol
address to masquerade as that other site? - Answers -IP spoofing
A __________ is an opportunity for a person or organization to gain access to individual
or organizational assets. - Answers -vulnerability
Which of the following describes white-hat hacking? - Answers -Involves the task of
finding security flaws in your network and financial applications
A(n) __________ is a sophisticated, possibly long-running, computer hack that is
perpetrated by large, well-funded organizations such as governments. - Answers -
Advanced Persistent Threat (APT)
Which of the following involves the task of finding security flaws in your network and
financial applications? - Answers -White-hat hacking
__________ protect databases and other organizational data. - Answers -Data
safeguards
Which of the following is something senior management can do to impact all levels of
the organization and clearly state the company's position on data from all sources—
customers, vendors, partners, and employees? - Answers -Establish an organizational
security policy.
__________ refers to the ability to know that a person is who he or she claims to be. -
Answers -Authentication
, A __________ is some measure that individuals or organizations take to block access
to the assets. - Answers -Safeguard
Which of the following best describes a threat? - Answers -A person or organization
that seeks to obtain or alter data or other assets illegally
Which of the following is true about faulty service? - Answers -Faulty service includes
problems that result because of incorrect system operation
You buy a new office computer system online and use your credit card to pay the cost,
which requires your credit card data to be transmitted over the Internet to complete the
order.
The scenario above best describes which of the following? - Answers -A vulnerability
Which of the following is NOT a recommended personal security safeguard? - Answers
-Creating a password that is easy to remember and easy to figure out
Which of the following is a similar technique to pretexting that obtains unauthorized data
via email? - Answers -Phishing
Tulips Retail-Comm Inc., a retail company, has formed a new team to manage the
company's online retail business. This team creates a website through which users can
place orders for a wide variety of products. The team accidentally lists the products
available for online purchase from an outdated database. This results in customers
placing orders for products that are no longer available in the company's inventories.
Which type of security loss is being illustrated in this scenario? - Answers -Incorrect
data modification
Which of the following is a way to prevent a hacker from using a brute force attack? -
Answers -Create multiple, strong passwords
Computer criminals use denial-of-service attacks on information systems to
__________. - Answers -prevent legitimate users from using the system's resources
Which of the following is the part of a security plan that stipulates what an employee
should do when a security problem occurs? - Answers -Incident response plan
Which of the following is NOT recommended as part of an incident response plan? -
Answers -Dealing with problems as they come up
What are the parts of an incident response plan? - Answers --Practicing incidence
response
-Identifying critical personnel and their off -hours contact information
How do job descriptions safeguard information systems from threats? - Answers -By
restricting information access under a need-to-know basis
Which of the following is an example of a human error? - Answers -Something going
wrong because of installation.
Data loss is the principal cost of __________. - Answers -computer crime
Computer criminals can launch __________ attacks in which a malicious hacker floods
a web server with bogus service requests that then tie up the server, so that it cannot
service legitimate requests. - Answers -denial of service
Which of the following refers to an organization-wide function that is in charge of
developing data policies and enforcing data standards? - Answers -Data administration
Which of the following occurs when an intruder uses another site's Internet Protocol
address to masquerade as that other site? - Answers -IP spoofing
A __________ is an opportunity for a person or organization to gain access to individual
or organizational assets. - Answers -vulnerability
Which of the following describes white-hat hacking? - Answers -Involves the task of
finding security flaws in your network and financial applications
A(n) __________ is a sophisticated, possibly long-running, computer hack that is
perpetrated by large, well-funded organizations such as governments. - Answers -
Advanced Persistent Threat (APT)
Which of the following involves the task of finding security flaws in your network and
financial applications? - Answers -White-hat hacking
__________ protect databases and other organizational data. - Answers -Data
safeguards
Which of the following is something senior management can do to impact all levels of
the organization and clearly state the company's position on data from all sources—
customers, vendors, partners, and employees? - Answers -Establish an organizational
security policy.
__________ refers to the ability to know that a person is who he or she claims to be. -
Answers -Authentication
, A __________ is some measure that individuals or organizations take to block access
to the assets. - Answers -Safeguard
Which of the following best describes a threat? - Answers -A person or organization
that seeks to obtain or alter data or other assets illegally
Which of the following is true about faulty service? - Answers -Faulty service includes
problems that result because of incorrect system operation
You buy a new office computer system online and use your credit card to pay the cost,
which requires your credit card data to be transmitted over the Internet to complete the
order.
The scenario above best describes which of the following? - Answers -A vulnerability
Which of the following is NOT a recommended personal security safeguard? - Answers
-Creating a password that is easy to remember and easy to figure out
Which of the following is a similar technique to pretexting that obtains unauthorized data
via email? - Answers -Phishing
Tulips Retail-Comm Inc., a retail company, has formed a new team to manage the
company's online retail business. This team creates a website through which users can
place orders for a wide variety of products. The team accidentally lists the products
available for online purchase from an outdated database. This results in customers
placing orders for products that are no longer available in the company's inventories.
Which type of security loss is being illustrated in this scenario? - Answers -Incorrect
data modification
Which of the following is a way to prevent a hacker from using a brute force attack? -
Answers -Create multiple, strong passwords
Computer criminals use denial-of-service attacks on information systems to
__________. - Answers -prevent legitimate users from using the system's resources
Which of the following is the part of a security plan that stipulates what an employee
should do when a security problem occurs? - Answers -Incident response plan
Which of the following is NOT recommended as part of an incident response plan? -
Answers -Dealing with problems as they come up
What are the parts of an incident response plan? - Answers --Practicing incidence
response
-Identifying critical personnel and their off -hours contact information