Exam Questions and CORRECT Answers
security - CORRECT ANSWER✔✔- The degree of protection against criminal activity,
danger, damage, and/or loss
information security - CORRECT ANSWER✔✔- Protecting organization's information
resources from unauthorized access, use, disclosure, disruption, modification, or destruction
threat - CORRECT ANSWER✔✔- any danger to which a system may be exposed
exposure - CORRECT ANSWER✔✔- the harm, loss or damage that can result if a threat
compromises that resource
vulnerability - CORRECT ANSWER✔✔- the possibility that the system will suffer harm by
a threat
unintentional threats to IS - CORRECT ANSWER✔✔- - human errors
- social engineering
human errors - CORRECT ANSWER✔✔- higher level employees + greater access = greater
threat
human error areas - CORRECT ANSWER✔✔- - human resources
- information systems
- contract labor, consultants, janitors, and guards
social engineering - CORRECT ANSWER✔✔- attack where perpetrator uses social skills to
trick or manipulate employees for confidential information
,espionage - CORRECT ANSWER✔✔- individual attempts to gain illegal access to
organizational information
information extortion - CORRECT ANSWER✔✔- attacker demands money for
- not stealing info
- giving back info
- not to disclose stolen info
sabotage - CORRECT ANSWER✔✔- intruder maliciously alters a web page by inserting or
substituting provocative and frequently offending data
theft - CORRECT ANSWER✔✔- smaller equipment are easier to steal
larger storage means more information lost
dumpster diving - CORRECT ANSWER✔✔- going through trash to find discarded info
identity theft - CORRECT ANSWER✔✔- pretending to be someone else to access financial
info or to frame a person of a crime
phishing - CORRECT ANSWER✔✔- impersonating a trusted organization in an electronic
communication
intellectual property - CORRECT ANSWER✔✔- property created by individuals or
coroporations
trade secret - CORRECT ANSWER✔✔- company secret, not public info
,patent - CORRECT ANSWER✔✔- protect an invention or process for 20 years
copyright - CORRECT ANSWER✔✔- protects ownership of the property for the life of the
creator
user action - CORRECT ANSWER✔✔- - virus
- worm
- phishing attack
- spear phishing attack
without user action - CORRECT ANSWER✔✔- - denial of service
- distrubuted DoS attack
attack by programmers - CORRECT ANSWER✔✔- - trojan horse
- back door
- logic bomb
virus - CORRECT ANSWER✔✔- attack by a host computer
worm - CORRECT ANSWER✔✔- can spread by itself
spear phishing - CORRECT ANSWER✔✔- phishing attack on a specific target
denial of service (DoS) - CORRECT ANSWER✔✔- bombarding and crashing a target
computer with bogus requests
distributed dos attack - CORRECT ANSWER✔✔- use to hacked computers to perform dos
attack
, trojan horse - CORRECT ANSWER✔✔- disguised as an innocent program
back door - CORRECT ANSWER✔✔- allows unauthorized access to the program or
system, bypassing security measures
logic bomb - CORRECT ANSWER✔✔- dormant until activated at a certain date and time
alien software - CORRECT ANSWER✔✔- programs installed on a computer without user's
consent or knowledge
alien software - CORRECT ANSWER✔✔- - adware
- spyware
- spamware
- cookies
adware - CORRECT ANSWER✔✔- display pop-up advertisements on computer screens
spyware - CORRECT ANSWER✔✔- collects personal information about users without their
consent
spamware - CORRECT ANSWER✔✔- creates a launchpad for sending out spam emails
cookies - CORRECT ANSWER✔✔- small files stored on a computer containing information
about visited websites
scada (supervisor control and data acquisition) - CORRECT ANSWER✔✔- systems control
chemical, physical, or transport processes
cyberterrorism - CORRECT ANSWER✔✔- attack via the internet to use a target's computer
systems to cause physical, real world harm