UPDATED Exam Questions and
CORRECT Answers
Chapter 2: Secure Information Systems - CORRECT ANSWER -
Bring your own device (BYOD) - CORRECT ANSWER - - business policy permitting,
and in some cases encouraging, employees to use their own mobile devices to access company
computing resources and applications
- raises security conrcerns
exploit - CORRECT ANSWER - - an attack on an IS that takes advantage of a particular
system vulnerability
-software devs must fix the issue once the exploit is discovered
zero-day attack - CORRECT ANSWER - - an attack that takes place before the security
community becomes aware of and fixes a vulnerability
- very rare
attack vector - CORRECT ANSWER - - allows perpetrators to gain unauthorized access to
a device or a network and to initiate a cyberattack
ransomeware - CORRECT ANSWER - - malware that stops you from using your
computer or accessing its data until certain demands are met
distributed denial-of-service (DDoS) attack - CORRECT ANSWER - - when a malicious
hacker takes over computers via the internet to flood a target site
, botnet - CORRECT ANSWER - - a large group of such computers, which are controlled
from one or more remote locations by hackers, without the knowledge or consent
data breach - CORRECT ANSWER - - unintended release of sensitive data or the access
of sensitive data by unauthorized individuals
cyberespionage - CORRECT ANSWER - - deployment of malware that secretly steals
data in the computer systems of orgs
cyberterrorism - CORRECT ANSWER - - intimidation of govt or civilian population by
using information technology to disable critical national infrastructure to achieve political,
religious, or ideological goals
Department of Homeland Security (DHS) - CORRECT ANSWER - - a large federal
agency with more than 240,000 employees and a budget of almost $65 billion
- goal is to provide for a "safer, more secure America"
U.S. Computer Emergency Readiness Team (US-CERT) - CORRECT ANSWER --
(partnership between the DHS and the public and private sectors)
- goal is to provide timely handling of security incidents as well as conducting improved analysis
of such incidents
Consequences of Successful Cyberattacks - CORRECT ANSWER - 1) direct impact -
value of assets (cash, inventory) stolen or damaged
2) business disruption - organizations aren't able to operate effectively for a duration
3) recovery cost
4) legal consequences
5) reputation damage
CIA security triad - CORRECT ANSWER - - confidentiality, integrity, and availability