Latest Update 2026 | Exam Prep
1. Describe how industry compliance differs from regulatory compliance in
information security.
Both types of compliance are the same and serve identical purposes.
Regulatory compliance is only applicable to financial institutions, while
industry compliance applies to all sectors.
Industry compliance is voluntary, whereas regulatory compliance is
always mandatory.
Industry compliance refers to standards set by industry groups,
while regulatory compliance is mandated by government laws.
2. Explain how authentication contributes to the overall security of information
systems.
Authentication is used to create backups of critical data.
Authentication ensures that only authorized users can access
sensitive information, thus protecting against unauthorized access.
Authentication encrypts data to prevent interception during
transmission.
Authentication monitors network traffic for suspicious activities.
3. A new web server has been provisioned at a third party hosting provider for
processing credit card transactions. The security administrator runs the
netstat command on the server and notices that ports 80, 443, and 3389 are
in a 'listening' state. No other ports are open. Which of the following services
should be disabled to ensure secure communications?
TELNET
, HTTPS
RDP
HTTP
4. What are the three main types of factors used in multifactor authentication?
Something you know, something you have, something you are
Username, password, security question
Password, PIN, biometric data
Email, phone number, security token
5. If a healthcare organization fails to comply with HIPAA regulations, what
potential consequence might it face?
Enhanced data availability
Legal penalties and fines
Increased patient satisfaction
Improved employee morale
6. Describe the role of Port 80 in web communication.
Port 80 is used for remote server management.
Port 80 is used for file transfer between computers.
Port 80 is used for secure email transmission.
Port 80 is used for HTTP traffic, which facilitates the transfer of web
pages and resources over the internet.
,7. Describe how the origins of cryptography have influenced modern security
practices.
Modern security practices are entirely independent of historical
cryptographic methods.
The origins of cryptography, rooted in ancient methods of encoding
messages, have led to the development of complex algorithms and
protocols that ensure secure communication today.
Cryptography originated solely from military needs and has no
relevance to modern security.
The origins of cryptography are irrelevant to current technology.
8. List the five stages of the Operations Security Process.
Detection, Response, Recovery, Mitigation, and Reporting
Planning, Execution, Monitoring, Evaluation, and Closure
Identification, Analysis, Control, Monitoring, and Review
Assessment, Implementation, Verification, Maintenance, and
Reporting
9. What is the purpose of Pretty Good Privacy (PGP)?
Securing DNS packets
Encrypting and digitally signing emails and files
Performing key stretching
Creating digital signatures
10. Cryptography is defined as:
Sensitive information sent over networks that needs to be secured
, Verified authority to view information, such as a password or key
The act of stealing personal information online
The practice of encoding information so only authorized people
can read it
11. What is the primary purpose of counterintelligence in cybersecurity?
To analyze trends in cyber threats
To collect intelligence on employees
To gather intelligence on competitors
To protect against espionage and intelligence collection by
adversaries
12. The quality or state of having ownership or control of some object or item.
Information is said to be in possession if one obtains it, independent of
format or other characteristic. While a breach of confidentiality always
results in a breach of possession, a breach of possession does not always
result in a breach of confidentiality.
Accuracy
Confidentiality
Possession
Utility
13. Describe the primary purpose of MD5 in information security.
MD5 is used to create a hash value for data integrity verification.
MD5 is a protocol for secure data transmission.
MD5 encrypts data to ensure confidentiality.