CORPORATE COMPUTER SECURITY
UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS COMPLETE STUDY
GUIDE
●● Threat environment
Answer: the types of attackers and attacks companies face
●● Security goals
Answer: Confidentiality, Integrity, Availability (CIA)
●● Confidentiality
Answer: Means that people cannot read sensitive information, either
while it is on a computer or while it is traveling across a network.
●● Integrity
Answer: Means that attackers cannot change or destroy information,
either while it is on a computer or while it is traveling across a network.
Or, at least, if information is changed or destroyed, then the receiver can
detect the change or restore destroyed data.
●● Availability
,Answer: Means that people who are authorized to use information are
not prevented from doing so
●● Compromises
Answer: Successful attacks, incidents, breaches
●● Countermeasures
Answer: tools used to thwart attacks, also called safeguards, protections,
and controls
●● Types of countermeasures
Answer: preventative, detective, corrective
●● When a threat succeeds in causing harm to a business, this is a(n)
________.
Answer: incident,breach, or compromise
●● the goal of countermeasures is to:
Answer: keep business processes on track for meeting their business
goals despite the presence of threats and actual compromises
●● Tools used to thwart attacks are called:
Answer: countermeasures, safeguards, or controls
, ●● Employees and ex-employees are dangerous for four reasons:
Answer: 1. They usually have an extensive knowledge of systems.
2. They often have the credentials needed to access sensitive parts of the
systems.
3. They know corporate control mechanisms and so often know how to
avoid detection.
4. Companies tend to trust their employees.
●● The greatest employee threats are:
Answer: IT and especially IT security professionals.
●● Employee Sabotage
Answer: Destruction of hardware, software, or data
Plant time bomb or logic bomb on computer
●● Employee hacking
Answer: Intentionally accessing a computer resource without
authorization or in excess of authorization. Authorization is the key.
●● Employee financial threat
Answer: Misappropriation of assets or theft of money
UPDATED ACTUAL QUESTIONS AND
CORRECT ANSWERS COMPLETE STUDY
GUIDE
●● Threat environment
Answer: the types of attackers and attacks companies face
●● Security goals
Answer: Confidentiality, Integrity, Availability (CIA)
●● Confidentiality
Answer: Means that people cannot read sensitive information, either
while it is on a computer or while it is traveling across a network.
●● Integrity
Answer: Means that attackers cannot change or destroy information,
either while it is on a computer or while it is traveling across a network.
Or, at least, if information is changed or destroyed, then the receiver can
detect the change or restore destroyed data.
●● Availability
,Answer: Means that people who are authorized to use information are
not prevented from doing so
●● Compromises
Answer: Successful attacks, incidents, breaches
●● Countermeasures
Answer: tools used to thwart attacks, also called safeguards, protections,
and controls
●● Types of countermeasures
Answer: preventative, detective, corrective
●● When a threat succeeds in causing harm to a business, this is a(n)
________.
Answer: incident,breach, or compromise
●● the goal of countermeasures is to:
Answer: keep business processes on track for meeting their business
goals despite the presence of threats and actual compromises
●● Tools used to thwart attacks are called:
Answer: countermeasures, safeguards, or controls
, ●● Employees and ex-employees are dangerous for four reasons:
Answer: 1. They usually have an extensive knowledge of systems.
2. They often have the credentials needed to access sensitive parts of the
systems.
3. They know corporate control mechanisms and so often know how to
avoid detection.
4. Companies tend to trust their employees.
●● The greatest employee threats are:
Answer: IT and especially IT security professionals.
●● Employee Sabotage
Answer: Destruction of hardware, software, or data
Plant time bomb or logic bomb on computer
●● Employee hacking
Answer: Intentionally accessing a computer resource without
authorization or in excess of authorization. Authorization is the key.
●● Employee financial threat
Answer: Misappropriation of assets or theft of money