FUNDAMENTALS UPDATED ACTUAL
Exam Questions and CORRECT Answers
Information security - CORRECT ANSWER state of the well-being of information and
infrastructure in which the possibility of theft, tampering, or disruption of information and
services is kept low or tolerable.
security policy - CORRECT ANSWER specification of how objects in a security domain are
allowed to interact.
Confidentiality - CORRECT ANSWER assurance that the information is accessible only to
authorized people. Confidentiality breaches may occur due to improper data handling or a
hacking attempt.
integrity - CORRECT ANSWER The trustworthiness of data or resources in the prevention of
improper and unauthorized changes - the assurance that information is sufficiently accurate for
its purpose.
checksum - CORRECT ANSWER which is a number produced by a mathematical function to
verify that a given block of data is not changed,
access control - CORRECT ANSWER which ensures that only authorized people can update,
add to, or delete data.
Availability - CORRECT ANSWER assurance that the systems responsible for delivering,
storing, and processing information are accessible when required by authorized users.
Authenticity - CORRECT ANSWER The characteristic of communication, documents, or any
data that ensures the quality of being genuine or uncorrupted. The major role of authentication is
to confirm that a user is authentic.
, Non-repudiation - CORRECT ANSWER A guarantee that the sender of a message cannot
later deny having sent the message and that the recipient cannot deny having received the
message. Individuals and organizations use digital signatures to ensure non-repudiation.
Functionality - CORRECT ANSWER The set of features provided by the system.
Usability - CORRECT ANSWER : The GUI components were used to design the system for
ease of use.
Security - CORRECT ANSWER The restrictions imposed on accessing the components of the
system
motive - CORRECT ANSWER originates from the notion that a target system stores or
processes something valuable, which leads to the threat of an attack on the system
goal - CORRECT ANSWER may be to disrupt the target's organization's business operations,
to steal valuable information for the sake of curiosity, or even to enact revenge.
Passive Attacks - CORRECT ANSWER The intercepting and monitoring of network traffic
and data flow on the target network and not tampering with the data
reconnaissance - CORRECT ANSWER the initial phase where attackers gather information
about a target system, network, or organization, on network activities
sniffers - CORRECT ANSWER tools to intercept and analyze data network traffic
Active Attacks - CORRECT ANSWER Tamper with the data in transit or disrupt
communication or services between the systems to bypass or break into secured systems.