Answers Graded A+
Which of the following is a correct statement about the balance c) A is for Availability, which refers to the ability of legitimate
among prevention, detection, and response (PDR)? users to access their data when needed.
d) #1 and #3, not #2
a) If preventive measures are in place, it is not necessary to e) All of the above - ANSWER -e) All of the above
have measures focused on detection and response.
b) If detection and response measures are in place, it is not
necessary to have measures devoted to prevention.
c) The greater the sensitivity and quantity of the data at issue, Which of these is not a good practice for physical security?
the more carefully the balance among these three must be
evaluated. a) Door locks, alarms, and other physical security devices are
d) Organizations have no discretion in deciding their levels of used to keep areas secure when not open for business.
security practice. - ANSWER -c) The greater the b) Unattended areas are kept secure with door locks and other
sensitivity and quantity of the data at issue, the more carefully devices whenever possible, even during business hours.
the balance among these three must be evaluated c) To preserve good customer relations, visitors are generally
allowed access to all areas of a facility unless it appears they
are doing something suspicious.
d) Access to sensitive equipment and data is controlled -- that
Which of these is not generally a good practice for telephone includes access to printers, fax machines, computers, and paper
use? files. - ANSWER -c) To preserve good customer relations,
visitors are generally allowed access to all areas of a facility
a) Whenever possible, telephone conversations involving unless it appears they are doing something suspicious.
sensitive information are conducted in non-public areas, where
they cannot be overheard.
b) When discussing confidential information on the phone, the
other person's identity is confirmed before proceeding with the Which of the following is a good security practice for portable
conversation. devices?
c) Using voicemail systems and answering machines that do
not require a password or PIN for access. a) Trying to ensure physical security, particularly for highly
d) Only names and callback numbers are left on voicemail or portable devices that are always on hand (like a smartphone).
answering machines -- or with the person that takes the b) Maximizing the quantity of sensitive information stored on
message -- if someone cannot be reached directly. - portable devices for easy access.
ANSWER -c) Using voicemail systems and answering c) Disabling all extra security features such as an access
machines that do not require a password or PIN for access. password or biometric authentication so that access is easy and
straightforward.Avoiding encrypting data stored on a portable
device.
d) Disabling any remote-locate, remote-shutdown, and remote-
Security measures are sometimes described as a combination erase capabilities because these can accidentally erase data. -
of physical, technical, and administrative (PTA) safeguards. ANSWER -a) Trying to ensure physical security,
Which of these would be considered a technical safeguard? particularly for highly portable devices that are always on hand
(like a smartphone).
a) Locked doors and other physical barriers.
b) Policies about who is granted access to what types of data.
c) Measures including device data encryption, anti-malware
software, and communications encryption. Which of the following is a good security practice for email?
d) Legal-regulatory requirements. - ANSWER -c)
Measures including device data encryption, anti-malware a) Exercising care with every email message received,
software, and communications encryption. especially email containing file attachments that may be infected
b) Accessing links in all emails regardless of the source to make
sure important information is not missed
c) Reply to all messages as quickly as possible to avoid the
Information security's goals are sometimes described by the inbox becoming too full.
letters "CIA." Which of the following is correct definition of C, I, d) Sending sensitive information in email messages or in
or A? attachments to such messages, as long as a legally binding
confidentiality notice is included. - ANSWER -a) Exercising
a) I is for Integrity, which refers to the accuracy of the data for care with every email message received, especially email
its intended use, the security-equivalent of terms like validity containing file attachments that may be infected
and reliability.
b) C is for Confidentiality, which refers to limiting data access to
appropriate persons for appropriate purposes.
1/2