Computer Security - Exam 1 Review
questions with answers
NIST |Definition |of |Computer |Security |- |correct |answers✔✔Measures |and |controls
|that |ensure |confidentiality, |integrity, |and |availability |of |information |system |assets,
|including |hardware, |software, |firmware, |and |information |being |processed, |stored,
|and |communicated.
NIST |CIA |Definition |of |Confidentiality |- |correct |answers✔✔Preserving |authorized
|restrictions |on |information |access |and |disclosure, |including |means |for |protecting
|personal |privacy |and |proprietary |information. |A |loss |of |confidentiality |is |the
|unauthorized |disclosure |of |information.
NIST |CIA |Definition |of |Integrity |- |correct |answers✔✔Guarding |against |improper
|information |modification |or |destruction, |ensuring |information |nonrepudiation |and
|authenticity. |A |loss |of |integrity |is |the |unauthorized |modification |or |destruction |of
|information.
NIST |CIA |Definition |of |Availability |- |correct |answers✔✔Ensuring |timely |and |reliable
|access |to |and |use |of |information. |A |loss |of |availability |is |disrupting |access |to |or
|use |of |information |or |an |information |system.
Definition |of |Privacy |in |Context |of |CIA |- |correct |answers✔✔Lies |under
|confidentiality. |Assures |that |individuals |control |or |influence |what |information
|related |to |them |may |be |collected |and |stored |and |by |whom |and |to |whom |that
|information |may |be |disclosed.
NIST |CIA |Definition |of |Authenticity |- |correct |answers✔✔The |property |of |being
|genuine |and |being |able |to |be |verified |and |trusted; |confidence |in |the |validity |of |a
|transmission, |a |message, |or |message |originator.
-This |means |verifying |that |users |are |who |they |say |they |are |and |that |each |input
|arriving |at |the |system |came |from |a |trusted |source.
, Low |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be |expected
|to |have |a |limited |adverse |effect |on |organizational |operations, |organizational |assets,
|or |individuals
Moderate |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be
|expected |to |have |a |serious |adverse |effect |on |organizational |operations,
|organizational |assets, |or |individuals
High |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be |expected
|to |have |a |severe |or |catastrophic |adverse |effect |on |organizational |operations,
|organizational |assets, |or |individuals
Definition |of |an |asset |in |computer |security |context |- |correct |answers✔✔A |major
|application, |general |support |system, |high-impact |program, |physical |plant, |mission-
critical |system, |personnel, |equipment, |or |a |logically |related |group |of |systems.
Examples |of |Computer |System |Assets |- |correct |answers✔✔-Hardware: |Computer
|systems |and |other |data |processing, |data |storage, |and |data |communications |devices.
-Software: |Including |the |operating |system, |system |utilities, |and |applications.
-Data: |Including |files |and |databases |and |security-related |data, |such |as |password
|files.
-Communication |facilities |and |networks: |Local |and |wide |area |network
|communication |links, |bridges, |routers, |and |so |on.
Computer |security |definition |of |an |Adversary |- |correct |answers✔✔Individual, |group,
|organization, |or |government |that |conducts |or |has |the |intent |to |conduct |harmful
|activities. |Also |known |as |a |"threat |agent".
Computer |security |definition |of |an |Attack |- |correct |answers✔✔Any |kind |of |malicious
|activity |that |attempts |to |collect, |disrupt, |deny, |degrade, |or |destroy |information
|system |resources |or |the |information |itself. |An |attack |is |a |threat |carried |out |(threat
|action) |and, |if |successful, |leads |to |an |undesirable |violation |of |security |or |threat
|consequence
questions with answers
NIST |Definition |of |Computer |Security |- |correct |answers✔✔Measures |and |controls
|that |ensure |confidentiality, |integrity, |and |availability |of |information |system |assets,
|including |hardware, |software, |firmware, |and |information |being |processed, |stored,
|and |communicated.
NIST |CIA |Definition |of |Confidentiality |- |correct |answers✔✔Preserving |authorized
|restrictions |on |information |access |and |disclosure, |including |means |for |protecting
|personal |privacy |and |proprietary |information. |A |loss |of |confidentiality |is |the
|unauthorized |disclosure |of |information.
NIST |CIA |Definition |of |Integrity |- |correct |answers✔✔Guarding |against |improper
|information |modification |or |destruction, |ensuring |information |nonrepudiation |and
|authenticity. |A |loss |of |integrity |is |the |unauthorized |modification |or |destruction |of
|information.
NIST |CIA |Definition |of |Availability |- |correct |answers✔✔Ensuring |timely |and |reliable
|access |to |and |use |of |information. |A |loss |of |availability |is |disrupting |access |to |or
|use |of |information |or |an |information |system.
Definition |of |Privacy |in |Context |of |CIA |- |correct |answers✔✔Lies |under
|confidentiality. |Assures |that |individuals |control |or |influence |what |information
|related |to |them |may |be |collected |and |stored |and |by |whom |and |to |whom |that
|information |may |be |disclosed.
NIST |CIA |Definition |of |Authenticity |- |correct |answers✔✔The |property |of |being
|genuine |and |being |able |to |be |verified |and |trusted; |confidence |in |the |validity |of |a
|transmission, |a |message, |or |message |originator.
-This |means |verifying |that |users |are |who |they |say |they |are |and |that |each |input
|arriving |at |the |system |came |from |a |trusted |source.
, Low |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be |expected
|to |have |a |limited |adverse |effect |on |organizational |operations, |organizational |assets,
|or |individuals
Moderate |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be
|expected |to |have |a |serious |adverse |effect |on |organizational |operations,
|organizational |assets, |or |individuals
High |level |of |security |breach |impact |- |correct |answers✔✔The |loss |could |be |expected
|to |have |a |severe |or |catastrophic |adverse |effect |on |organizational |operations,
|organizational |assets, |or |individuals
Definition |of |an |asset |in |computer |security |context |- |correct |answers✔✔A |major
|application, |general |support |system, |high-impact |program, |physical |plant, |mission-
critical |system, |personnel, |equipment, |or |a |logically |related |group |of |systems.
Examples |of |Computer |System |Assets |- |correct |answers✔✔-Hardware: |Computer
|systems |and |other |data |processing, |data |storage, |and |data |communications |devices.
-Software: |Including |the |operating |system, |system |utilities, |and |applications.
-Data: |Including |files |and |databases |and |security-related |data, |such |as |password
|files.
-Communication |facilities |and |networks: |Local |and |wide |area |network
|communication |links, |bridges, |routers, |and |so |on.
Computer |security |definition |of |an |Adversary |- |correct |answers✔✔Individual, |group,
|organization, |or |government |that |conducts |or |has |the |intent |to |conduct |harmful
|activities. |Also |known |as |a |"threat |agent".
Computer |security |definition |of |an |Attack |- |correct |answers✔✔Any |kind |of |malicious
|activity |that |attempts |to |collect, |disrupt, |deny, |degrade, |or |destroy |information
|system |resources |or |the |information |itself. |An |attack |is |a |threat |carried |out |(threat
|action) |and, |if |successful, |leads |to |an |undesirable |violation |of |security |or |threat
|consequence