(VERIFIED ANSWERS) ALREADY GRADED A+
What measures the average amount of time between failures for a particular system?
A. Uptime
B. Recovery time objective (RTO)
C. Mean time to failure (MTTF)
D. Mean time to repair (MTTR)
C. Mean time to failure (MTTF)
Taylor is a security professional working for a retail company. She is revising the company's
policies and procedures to meet Payment Card Industry Data Security Standard (PCI DSS)
objectives. One change she has made is to require the use of antivirus software on all systems
commonly affected by malware and to keep them regularly updated. Which PCI DSS control
objective is she attempting to meet?
A. Build and maintain a secure network
B. Protect cardholder data
C. Maintain a vulnerability management program
D. Implement strong access control measures
C. Maintain a vulnerability management program
Alan withdraws cash from an ATM belonging to Bank X that is coming from his account with
Bank Y. What is Alan's relationship with Bank X?
A. Consumer
B. Covered entity
C. Customer
D. Nonaffiliated third party
A. Consumer
Alan withdraws cash from an ATM belonging to Bank X that is coming from his account with
Bank Y. What is Alan's relationship with Bank Y?
A. Customer
B. Covered entity
C. Nonaffiliated third party
D. Consumer
A. Customer
Under the Federal Information Security Management Act (FISMA) of 2002, which of the
following broadens the scope of FISMA beyond a federal agency and is important because IT
systems and functions are often outsourced?
,A. An agency must protect the IT systems that support its operations even if another agency or
contractor owns the IT systems.
B. The Office of Management and Budget (OMB) is responsible for FISMA compliance.
C. FISMA requires each federal agency to create an agency-wide information security program.
D. Agencies must test and evaluate the security program at least annually and test IT systems
with greater risk more often.
A. An agency must protect the IT systems that support its operations even if another agency or
contractor owns the IT systems.
Erin is a system administrator for a U.S. federal government agency. What law contains guidance
on how she may operate a federal information system?
A. Gramm-Leach-Bliley Act (GLBA)
B. Family Educational Rights and Privacy Act (FERPA)
C. Federal Information Security Management Act (FISMA)
D. Sarbanes-Oxley Act (SOX)
C. Federal Information Security Management Act (FISMA)
Alison retrieved data from a company database containing personal information on customers.
When she looks at the Social Security number (SSN) field, she sees values that look like this:
"XXX-XX-9142." What has happened to these records?
A. Masking
B. Encryption
C. Hashing
D. Truncation
A. Masking
Remote access security controls help to ensure that the user connecting to an organization's
network is who the user claims to be. A username is commonly used for _______, whereas a
biometric scan could be used for _______.
A. identification, authentication
B. authorization, accountability
C. identification, authorization
D. authentication, authorization
A. identification, authentication
A brute-force password attack and the theft of a mobile worker's laptop are risks most likely
found in which domain of a typical IT infrastructure?
A. Local Area Network (LAN) Domain
B. Workstation Domain
C. Remote Access Domain
D. User Domain
C. Remote Access Domain
,In which domain of a typical IT infrastructure is the first layer of defense for a layered security
strategy?
A. Workstation Domain
B. Local Area Network (LAN) Domain
C. User Domain
D. System/Application Domain
C. User Domain
Rachel is investigating an information security incident that took place at the high school where
she works. She suspects that students may have broken into the student records system and
altered their grades. If that is correct, which one of the tenets of information security did this
attack violate?
A. Integrity
B. Nonrepudiation
C. Confidentiality
D. Availability
A. Integrity
Which network device is designed to block network connections that are identified as potentially
malicious?
A. Intrusion detection system (IDS)
B. Intrusion prevention system (IPS)
C. Router
D. Web server
B. Intrusion prevention system (IPS)
Which security control is most helpful in protecting against eavesdropping on wide area network
(WAN) transmissions?
A. Deploying an intrusion detection system/intrusion prevention system (IDS/IPS)
B. Applying filters on exterior Internet Protocol (IP) stateful firewalls
C. Encrypting transmissions with virtual private networks (VPNs)
D. Blocking Transmission Control Protocol (TCP) synchronize (SYN) open connections
C. Encrypting transmissions with virtual private networks (VPNs)
What is a U.S. federal government classification level that applies to information that would
cause serious damage to national security if it were disclosed?
A. Top secret
B. Confidential
C. Secret
D. Private
C. Secret
, What is a primary risk to the Workstation Domain, the Local Area Network (LAN) Domain, and
the System/Application Domain?
A. Unauthorized network probing and port scanning
B. Unauthorized access to systems
C. Downtime of IT systems for an extended period after a disaster
D. Mobile worker token or other authentication stolen
B. Unauthorized access to systems
Which term describes the level of exposure to some event that has an effect on an asset, usually
the likelihood that something bad will happen to an asset?
A. Threat
B. Countermeasure
C. Risk
D. Vulnerability
C. Risk
Which compliance obligation includes security requirements that apply specifically to the
European Union?
A. Gramm-Leach-Bliley Act (GLBA)
B. Health Insurance Portability and Accountability Act (HIPAA)
C. General Data Protection Regulation (GDPR)
D. Federal Information Security Management Act (FISMA)
C. General Data Protection Regulation (GDPR)
In Mobile IP, what term describes a device that would like to communicate with a mobile node
(MN)?
A. Correspondent node (CN)
B. Foreign agent (FA)
C. Home agent (HA)
D. Care of address (COA)
A. Correspondent node (CN)
Which of the following enables businesses to transform themselves into an Internet of Things
(IoT) service offering?
A. Store-and-forward communications
B. Remote sensoring
C. Real-time tracking and monitoring
D. Anything as a Service (AaaS) delivery model
D. Anything as a Service (AaaS) delivery model
Which of the following is an example of a business-to-consumer (B2C) application of the
Internet of Things (IoT)?
A. Video conferencing