MIS 301 Exam QUESTIONS AND
ANSWERS
Methods of Protection - ANSWER>>Safe login procedure
Firewalls
Fingerprint identification
Scanning the eyes/face
Voice recognition
Firewall - ANSWER>>Software programs (sometimes hardware) that
confirm the login/password match and then allow a person access to
the system
More complex than typing in the right information
Firewall will mostly block logins from unlikely locations
Pretexting - ANSWER>>Someone pretends to be someone who they
really aren't
Phishing - ANSWER>>Someone pretending to be someone they aren't
with intention to gain information
Spoofing - ANSWER>>a technique intruders use to make their
network or internet transmission appear legitimate to a victim
computer or network
IP spoofing
Email spoofing
Skimmers - ANSWER>>Devices installed onto machines in an effort to
steal credit/debit card
,Packet (Drive-by) sniffers - ANSWER>>Monitor and intercept wireless
Internet traffic
This happens when a person goes into a business with open WiFi and
the person has software on the computer that allows them to access
(see) what all the other people on the free WiFi are looking at or
accessing
faulty service - ANSWER>>problems that result because of incorrect
system operation
Incorrect data modification occurs when... - ANSWER>>Corporate
procedures are incorrectly designed or not followed
Increasing customer's discount or incorrectly modifying employee's
salary
Placing incorrect data on company Web site; prices of items, sales
amounts, store hours, employee names/titles
Improper internal controls on systems
Who has access to a specific area of the system
System errors
Faculty recovery actions after a disaster
Usurpation - ANSWER>>Occurs when computer criminals invade a
computer system & replace legitimate systems with their own
Try to spy, steal, & manipulate data, or achieve their own purpose
Denial of service (DoS) - ANSWER>>Attack that makes the
website/app not respond in an appropriate manner
Single computer → single application
Distributed Denial of service (DDoS) - ANSWER>>An attack that uses
many computers to perform a DoS attack
, Multiple bots → single application
Types of DDoS - ANSWER>>Volumetric - flooded with a bunch of
bandwidth (connection/server overloaded)
Protocol - infected computer will send spoofs, unresponsive due to
requests
Application - passes firewall, sends a bunch of requests, overloads
servers
Loss of Infrastructure - ANSWER>>Human accidents
Theft and terrorist events
Disgruntled or terminated employee
Natural disasters
Advanced Persistent Threat (APT)
Sophisticated, possibly long-running computer hack perpetrated by
large, well-funded organizations
How to Protect Against A Loss of Data/Infrastructure -
ANSWER>>Take security seriously
Create strong passwords
Use multiple passwords
Send no valuable data via email or IM
Use https at trusted, reputable vendors
Remove high-value assets from computers
Clear browsing history, temporary files, and cookies
Regularly update antivirus software
ANSWERS
Methods of Protection - ANSWER>>Safe login procedure
Firewalls
Fingerprint identification
Scanning the eyes/face
Voice recognition
Firewall - ANSWER>>Software programs (sometimes hardware) that
confirm the login/password match and then allow a person access to
the system
More complex than typing in the right information
Firewall will mostly block logins from unlikely locations
Pretexting - ANSWER>>Someone pretends to be someone who they
really aren't
Phishing - ANSWER>>Someone pretending to be someone they aren't
with intention to gain information
Spoofing - ANSWER>>a technique intruders use to make their
network or internet transmission appear legitimate to a victim
computer or network
IP spoofing
Email spoofing
Skimmers - ANSWER>>Devices installed onto machines in an effort to
steal credit/debit card
,Packet (Drive-by) sniffers - ANSWER>>Monitor and intercept wireless
Internet traffic
This happens when a person goes into a business with open WiFi and
the person has software on the computer that allows them to access
(see) what all the other people on the free WiFi are looking at or
accessing
faulty service - ANSWER>>problems that result because of incorrect
system operation
Incorrect data modification occurs when... - ANSWER>>Corporate
procedures are incorrectly designed or not followed
Increasing customer's discount or incorrectly modifying employee's
salary
Placing incorrect data on company Web site; prices of items, sales
amounts, store hours, employee names/titles
Improper internal controls on systems
Who has access to a specific area of the system
System errors
Faculty recovery actions after a disaster
Usurpation - ANSWER>>Occurs when computer criminals invade a
computer system & replace legitimate systems with their own
Try to spy, steal, & manipulate data, or achieve their own purpose
Denial of service (DoS) - ANSWER>>Attack that makes the
website/app not respond in an appropriate manner
Single computer → single application
Distributed Denial of service (DDoS) - ANSWER>>An attack that uses
many computers to perform a DoS attack
, Multiple bots → single application
Types of DDoS - ANSWER>>Volumetric - flooded with a bunch of
bandwidth (connection/server overloaded)
Protocol - infected computer will send spoofs, unresponsive due to
requests
Application - passes firewall, sends a bunch of requests, overloads
servers
Loss of Infrastructure - ANSWER>>Human accidents
Theft and terrorist events
Disgruntled or terminated employee
Natural disasters
Advanced Persistent Threat (APT)
Sophisticated, possibly long-running computer hack perpetrated by
large, well-funded organizations
How to Protect Against A Loss of Data/Infrastructure -
ANSWER>>Take security seriously
Create strong passwords
Use multiple passwords
Send no valuable data via email or IM
Use https at trusted, reputable vendors
Remove high-value assets from computers
Clear browsing history, temporary files, and cookies
Regularly update antivirus software