TEST BANK
Computer Security Fundamentals, 5th edition
by William Easttom
ST
U
D
YL
AB
, Table of content
Chapter 1: Introduction to computer security
Chapter 2: Networks and the internet
Chapter 3: Cyber stalking, fraud, and abuse
Chapter 4: Denial of service attacks
Chapter 5: Malware
Chapter 6: Techniques used by hackers
Chapter 7: Industrial espionage in cyberspace
Chapter 8: Encryption
ST
Chapter 9: Computer security technology
Chapter 10: Security policies
Chapter 11: Network scanning and vulnerability scanning
Chapter 12: Cyber terrorism and information warfare
U
Chapter 13: Cyber detective
Chapter 14: Introduction to forensics
D
Chapter 15: Cybersecurity engineering
YL
AB
, lkjhgfds
All Chapters Included
Computer Security Fundamentals 5e
Chapter 1 Introduction to Computer Security
True / False All Answers Included
1. The Domain Name System is what translates human-readable domain names into IP
addresses that computers and routers understand.
True
2. The type of hacking that involves breaking into telephone systems is called sneaking.
False—This type of hacking is called phreaking.
3. The technique for breaching a system’s security by exploiting human nature rather than
technology is war-driving.
ST
False—This describes social engineering.
4. Malware is a generic term for software that has a malicious purpose.
True
5. Software that lays dormant until some specific condition is met is a Trojan horse.
U
False—This describes a logic bomb. Usually, the condition that is met is a date
and time.
6. Someone who breaks into a system legally to assess security deficiencies is a
D
penetration tester.
True
7. Auditing is the process to determine if a user’s credentials are authorized to access a
YL
network resource.
False—This describes authentication. Auditing is the process of reviewing logs,
records, and procedures.
8. Confidentiality, integrity, and availability are three pillars of security, called the CIA
AB
triangle.
True
9. The Health Insurance Portability and Accountability Act of 1996 requires government
agencies to identify sensitive systems, conduct computer security training, and develop
computer security plans.
False—This describes the Computer Security Act of 1987.
10. The SANS Institute website is a vast repository of security-related documentation.
True
Multiple Choice
uytrew
, lkjhgfds
1. Which type of hacking is designed to prevent legitimate access to a computer system?
a. Denial of service
b. Web attack
c. Session hijacking
d. DNS poisoning
Answer A.
2. Your company is instituting a new security awareness program. You are responsible
for educating end users on a variety of threats, including social engineering. Which of the
following best defines social engineering?
a. Illegal copying of software
b. Gathering information from discarded manuals and printouts
c. Using people skills to obtain proprietary information
ST
d. Destruction or alteration of data
Answer C.
3. Which type of hacking occurs when the attacker monitors an authenticated session
between the client and the server and takes over that session?
U
a. Denial of service
b. Web attack
c. Session hijacking
d. DNS poisoning
D
Answer C.
YL
4. Someone who finds a flaw in a system and reports that flaw to the vendor of the
system is a .
a. White hat hacker
b. Black hat hacker
c. Gray hat hacker
d. Red hat hacker
AB
Answer A.
5. Someone who gains access to a system and causes harm is a ?
a. White hat hacker
b. Black hat hacker
c. Gray hat hacker
d. Red hat hacker
Answer B.
6. A black hat hacker is also called a .
uytrew
Computer Security Fundamentals, 5th edition
by William Easttom
ST
U
D
YL
AB
, Table of content
Chapter 1: Introduction to computer security
Chapter 2: Networks and the internet
Chapter 3: Cyber stalking, fraud, and abuse
Chapter 4: Denial of service attacks
Chapter 5: Malware
Chapter 6: Techniques used by hackers
Chapter 7: Industrial espionage in cyberspace
Chapter 8: Encryption
ST
Chapter 9: Computer security technology
Chapter 10: Security policies
Chapter 11: Network scanning and vulnerability scanning
Chapter 12: Cyber terrorism and information warfare
U
Chapter 13: Cyber detective
Chapter 14: Introduction to forensics
D
Chapter 15: Cybersecurity engineering
YL
AB
, lkjhgfds
All Chapters Included
Computer Security Fundamentals 5e
Chapter 1 Introduction to Computer Security
True / False All Answers Included
1. The Domain Name System is what translates human-readable domain names into IP
addresses that computers and routers understand.
True
2. The type of hacking that involves breaking into telephone systems is called sneaking.
False—This type of hacking is called phreaking.
3. The technique for breaching a system’s security by exploiting human nature rather than
technology is war-driving.
ST
False—This describes social engineering.
4. Malware is a generic term for software that has a malicious purpose.
True
5. Software that lays dormant until some specific condition is met is a Trojan horse.
U
False—This describes a logic bomb. Usually, the condition that is met is a date
and time.
6. Someone who breaks into a system legally to assess security deficiencies is a
D
penetration tester.
True
7. Auditing is the process to determine if a user’s credentials are authorized to access a
YL
network resource.
False—This describes authentication. Auditing is the process of reviewing logs,
records, and procedures.
8. Confidentiality, integrity, and availability are three pillars of security, called the CIA
AB
triangle.
True
9. The Health Insurance Portability and Accountability Act of 1996 requires government
agencies to identify sensitive systems, conduct computer security training, and develop
computer security plans.
False—This describes the Computer Security Act of 1987.
10. The SANS Institute website is a vast repository of security-related documentation.
True
Multiple Choice
uytrew
, lkjhgfds
1. Which type of hacking is designed to prevent legitimate access to a computer system?
a. Denial of service
b. Web attack
c. Session hijacking
d. DNS poisoning
Answer A.
2. Your company is instituting a new security awareness program. You are responsible
for educating end users on a variety of threats, including social engineering. Which of the
following best defines social engineering?
a. Illegal copying of software
b. Gathering information from discarded manuals and printouts
c. Using people skills to obtain proprietary information
ST
d. Destruction or alteration of data
Answer C.
3. Which type of hacking occurs when the attacker monitors an authenticated session
between the client and the server and takes over that session?
U
a. Denial of service
b. Web attack
c. Session hijacking
d. DNS poisoning
D
Answer C.
YL
4. Someone who finds a flaw in a system and reports that flaw to the vendor of the
system is a .
a. White hat hacker
b. Black hat hacker
c. Gray hat hacker
d. Red hat hacker
AB
Answer A.
5. Someone who gains access to a system and causes harm is a ?
a. White hat hacker
b. Black hat hacker
c. Gray hat hacker
d. Red hat hacker
Answer B.
6. A black hat hacker is also called a .
uytrew