Stateful inspection firewalls Right Ans - grant a broader range of access for
authorized users & activities
TCP wrapper Right Ans - application that can serve as a basic firewall by
restricting access to ports and resources based on user or system IDs
ARP Right Ans - (Address Resolution Protocol) resolves IP addresses to
MAC addresses
OSI layers Right Ans - Application, Presentation, Session, Transport,
Network, Data Link, Physical (All Presidents Since Truman Never Did Pot)
OSI layer 7 Right Ans - application
OSI layer 6 Right Ans - presentation
OSI layer 5 Right Ans - session
OSI layer 4 Right Ans - transport
OSI layer 3 Right Ans - network
OSI layer 2 Right Ans - data link
OSI layer 1 Right Ans - physical
IEEE 802.5 Right Ans - token ring
IEEE 802.11 Right Ans - wireless ethernet, wifi
fail secure system Right Ans - preserves state before a crash to prevent
firther damage
DAC Right Ans - discretionary access control
DAC disadvantage Right Ans - owners decide access levels
, issue with passwords Right Ans - nonrepudiable
SOX Right Ans - requires execs to review financial reports (enron)
corrective controls Right Ans - reduce the effect of an attack
administrative investigations Right Ans - are internal and examine
operational and policy issues
chain of custody preservation requires Right Ans - circumstance and name
of evidence collector
user Right Ans - accesses data & objects
owner Right Ans - liable for data protection
custodian Right Ans - classifies & protects data
nonrepudiation Right Ans - prevents a subject from claiming not to have
sent a message, performed an action, or not to have been the cause of an event
layering Right Ans - multiple controls in a series
data hiding Right Ans - preventing data from being known
change control Right Ans - mechanism to manage change. involves logging,
auditing, & monitoring
strategic plan Right Ans - long term directions & stable
tactical plan Right Ans - midterm plan with more details
operational plan Right Ans - short term, highly detailed
third party governance Right Ans - security oversight for third parties
ALE Right Ans - annualized loss expectancy
SLE Right Ans - single loss expectancy