ITN 100 Final Exam Questions And Accurate Answers
The main objective of network security = protect what? - Answer Assets, information,
data
3 Goals in providing security - Answer • Confidentiality
- Protection of data from unauthorized disclosure of customers and proprietary data
• Integrity
- Assurance that data have not been altered or destroyed
• Availability
- Providing continuous operations of hardware and software so that parties involved can
be assured of uninterrupted service
Generally, security threats could be categorized into two broad groups - Answer -
Business Continuity
Ensure that organization data and applications remain operational even in the
occurrence of disruption, destruction, or disaster
- Unauthorized access
3 Major Threats to Business Continuity - Answer - Disruption
- Disaster (Natural or artificial disasters)
- Intrusion (Types)
Amature intruders
Hackers (Security)
Professional hackers (espionage fraud etc)
Organization employees
, Network controls software
hardware
procedures that minimize threats
Types of Controls - Answer - Preventative controls
• Deter or prevent a person from taking an action or an event from happening (e.g.,
locks, passwords, backup circuits)
- Detective controls
• Detect or discover unwanted events (e.g., auditing)
• Recording events for possible evidence
- Corrective controls
• Correct an unwanted event or intrusion (e.g., restarting a network circuit)
Risk Assessment - Answer • A major step in developing a secure network
• Assigns level of risks to various threats
• Use a control spreadsheet
Assets - Answer - Hardware
- Circuits
- Network Software
- Client Software
- Organizational Data
- Mission critical applications
Threats - Answer • Virus infection is most likely event
• Intrusion
The main objective of network security = protect what? - Answer Assets, information,
data
3 Goals in providing security - Answer • Confidentiality
- Protection of data from unauthorized disclosure of customers and proprietary data
• Integrity
- Assurance that data have not been altered or destroyed
• Availability
- Providing continuous operations of hardware and software so that parties involved can
be assured of uninterrupted service
Generally, security threats could be categorized into two broad groups - Answer -
Business Continuity
Ensure that organization data and applications remain operational even in the
occurrence of disruption, destruction, or disaster
- Unauthorized access
3 Major Threats to Business Continuity - Answer - Disruption
- Disaster (Natural or artificial disasters)
- Intrusion (Types)
Amature intruders
Hackers (Security)
Professional hackers (espionage fraud etc)
Organization employees
, Network controls software
hardware
procedures that minimize threats
Types of Controls - Answer - Preventative controls
• Deter or prevent a person from taking an action or an event from happening (e.g.,
locks, passwords, backup circuits)
- Detective controls
• Detect or discover unwanted events (e.g., auditing)
• Recording events for possible evidence
- Corrective controls
• Correct an unwanted event or intrusion (e.g., restarting a network circuit)
Risk Assessment - Answer • A major step in developing a secure network
• Assigns level of risks to various threats
• Use a control spreadsheet
Assets - Answer - Hardware
- Circuits
- Network Software
- Client Software
- Organizational Data
- Mission critical applications
Threats - Answer • Virus infection is most likely event
• Intrusion