CITM 820 FINAL UPDATED QUESTIONS AND
CORRECT ANSWERS
Question:
1. __________ is a term used that refers to the means of delivering a key to two parties that wish to
exchange data without allowing others to see the key.
Answer:
Key distribution technique
Question:
2. A ________ is a key used between entities for the purpose of distributing session keys.
Answer:
permanent key
Question:
3. Security controls are defined by which of the following standards?
Answer:
NIST SP 800-53
Question:
4. A ___________ attack involves trying all possible keys
Answer:
Brute-force
Question:
5. In order to manage security, the international standards organization (ISO) has revised and consolidated
a number of security standards into the ISO _________ series
Answer:
27000
Question:
6. The physical threats can be organized into environmental, technical and _____ threats.
Answer:
Human-caused
Question:
7. Which of the following categories is classified as the greatest risk level
Answer:
E
Question:
8. Cryptographic systems are generically classified by _________.
Answer:
The type of operations used for transforming plaintext to ciphertext The number of keys used The way in
which the plaintext is processed All of the above None of the above
, Question:
9. SHA-1 produces a hash value of __________ bits.
Answer:
160
Question:
10. Computer media such as flexible disks and magnetic tapes may be damaged with a temperature level
exceeding _____ Celsius degrees.
Answer:
38
Question:
11. There are three classes of security controls: Technical controls, Management controls, and ______
controls.
Answer:
Operational
Question:
12. What is the port number of HTTPS?
Answer:
443
Question:
13. This security standard provides guidelines for information security management in an organization and
contains a list of best practice security controls.
Answer:
27002
Question:
14. Audit and Accountability are part of which of the following classes of security controls?
Answer:
Technical
Question:
15. Three elements of IS security as discussed in this module: logical, physical and _____ security.
Answer:
Premises
Question:
16. _____ mode is typically used for a general-purpose block-oriented transmission and is useful for
high-speed requirements. It is deployed with applications such as ATM and IPsec.
Answer:
CTR
Question:
17. Which of the following options is related to the second step of a risk assessment analysis?
CORRECT ANSWERS
Question:
1. __________ is a term used that refers to the means of delivering a key to two parties that wish to
exchange data without allowing others to see the key.
Answer:
Key distribution technique
Question:
2. A ________ is a key used between entities for the purpose of distributing session keys.
Answer:
permanent key
Question:
3. Security controls are defined by which of the following standards?
Answer:
NIST SP 800-53
Question:
4. A ___________ attack involves trying all possible keys
Answer:
Brute-force
Question:
5. In order to manage security, the international standards organization (ISO) has revised and consolidated
a number of security standards into the ISO _________ series
Answer:
27000
Question:
6. The physical threats can be organized into environmental, technical and _____ threats.
Answer:
Human-caused
Question:
7. Which of the following categories is classified as the greatest risk level
Answer:
E
Question:
8. Cryptographic systems are generically classified by _________.
Answer:
The type of operations used for transforming plaintext to ciphertext The number of keys used The way in
which the plaintext is processed All of the above None of the above
, Question:
9. SHA-1 produces a hash value of __________ bits.
Answer:
160
Question:
10. Computer media such as flexible disks and magnetic tapes may be damaged with a temperature level
exceeding _____ Celsius degrees.
Answer:
38
Question:
11. There are three classes of security controls: Technical controls, Management controls, and ______
controls.
Answer:
Operational
Question:
12. What is the port number of HTTPS?
Answer:
443
Question:
13. This security standard provides guidelines for information security management in an organization and
contains a list of best practice security controls.
Answer:
27002
Question:
14. Audit and Accountability are part of which of the following classes of security controls?
Answer:
Technical
Question:
15. Three elements of IS security as discussed in this module: logical, physical and _____ security.
Answer:
Premises
Question:
16. _____ mode is typically used for a general-purpose block-oriented transmission and is useful for
high-speed requirements. It is deployed with applications such as ATM and IPsec.
Answer:
CTR
Question:
17. Which of the following options is related to the second step of a risk assessment analysis?