Video Quizzes (Fundamental of ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Information Security) exam with ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
correct answers ||\\||\\
You want to ensure that data is secure from prying eyes,
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
so you implement encryption and logical access control
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
measures. Which of the three CIA Triad principles are you ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
implementing?
Confidentiallity
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
__________ is used to prevent an entity from denying an ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
action took place. ||\\||\\ ||\\||\\
Non-Repudiation
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
Which of the following is NOT an example of something
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
you know when discussing authentication?
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Keystroke
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
,Which of the following is NOT a best practices general ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
password rule discussed in this section of the course? ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Passwords should be shared ||\\||\\ ||\\||\\ ||\\||\\
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
You've been asked by your IT manager to perform an audit ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
review of access records for a specific server to see who
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
has logged into the server in the last hour. In regards to
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
the AAA, which of the AAA concepts applies to your
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
manager's request? ||\\||\\
Accounting
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
What are we referring to when we're talking about the
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
prudent man rule? ||\\||\\ ||\\||\\
Due Care ||\\||\\
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
The basic risk assessment equation in risk management is:
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Risk assessment score = Impact x Probability
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
, A ____________ is anything that can exploit a
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
vulnerability, intentionally or accidentally, and obtain, ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
damage, or destroy an asset. ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Threat
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
Quantitative risk assessments are more subjective than ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
qualitative risk assessments. ||\\||\\ ||\\||\\
False
After performing a risk assessment associated with
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
moving your customer data into the cloud with a local ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
cloud-based service provider, your risk management ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
team, in conjunction with your CIO has determined the
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
most appropriate risk response category would be to
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
purchase insurance. What type of risk response is this? ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Transference
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
The company you work for currently uses free anti-virus
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
software that isn't effective. The CEO has asked you, the IT ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
manager, to identify a cost-effective paid anti-virus
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
solution. You're performing a quantitative risk assessment ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Information Security) exam with ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
correct answers ||\\||\\
You want to ensure that data is secure from prying eyes,
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
so you implement encryption and logical access control
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
measures. Which of the three CIA Triad principles are you ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
implementing?
Confidentiallity
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
__________ is used to prevent an entity from denying an ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
action took place. ||\\||\\ ||\\||\\
Non-Repudiation
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
Which of the following is NOT an example of something
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
you know when discussing authentication?
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Keystroke
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
,Which of the following is NOT a best practices general ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
password rule discussed in this section of the course? ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Passwords should be shared ||\\||\\ ||\\||\\ ||\\||\\
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
You've been asked by your IT manager to perform an audit ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
review of access records for a specific server to see who
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
has logged into the server in the last hour. In regards to
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
the AAA, which of the AAA concepts applies to your
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
manager's request? ||\\||\\
Accounting
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
What are we referring to when we're talking about the
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
prudent man rule? ||\\||\\ ||\\||\\
Due Care ||\\||\\
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
The basic risk assessment equation in risk management is:
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Risk assessment score = Impact x Probability
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
2 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
, A ____________ is anything that can exploit a
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
vulnerability, intentionally or accidentally, and obtain, ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
damage, or destroy an asset. ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Threat
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
Quantitative risk assessments are more subjective than ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
qualitative risk assessments. ||\\||\\ ||\\||\\
False
After performing a risk assessment associated with
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
moving your customer data into the cloud with a local ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
cloud-based service provider, your risk management ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
team, in conjunction with your CIO has determined the
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
most appropriate risk response category would be to
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
purchase insurance. What type of risk response is this? ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
Transference
3 multiple choice options
||\\||\\ ||\\||\\ ||\\||\\
The company you work for currently uses free anti-virus
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
software that isn't effective. The CEO has asked you, the IT ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
manager, to identify a cost-effective paid anti-virus
||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\
solution. You're performing a quantitative risk assessment ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\ ||\\||\\