Cyber Security Chapter 8 Quiz
LATEST QUESTIONS AND
VERIFIED CORRECT
ANSWERS GRADED A+
A breach occurs in a company that processes credit card information. Which industry specific
law governs credit card data protection? - CORRECT ANSWER-PCI DSS
A company has had several incidents involving users downloading unauthorized software, using
unauthorized websites, and using personal USB devices. The CIO wants to put in place a scheme
to manage the user threats. What three things might be put in place to manage the threats?
(Choose three.) - CORRECT ANSWER-Provide security awareness training, Disable CD and USB
access, Use content filtering.
A company is attempting to lower the cost in deploying commercial software and is considering
a cloud based service. Which cloud based service would be best to host the software? -
CORRECT ANSWER-SaaS
A consultant is hired to make recommendations on managing device threats in a company.
What are three general recommendations that can be made? (Choose three.) - CORRECT
ANSWER-Enable screen lockout, Disable administrative rights for users, Enable automated
antivirus scans.
, A school administrator is concerned with the disclosure of student information due to a breach.
Under which act is student information protected? - CORRECT ANSWER-FERPA
A security professional is asked to perform an analysis of the current state of a company
network. What tool would the security professional use to scan the network only for security
risks? - CORRECT ANSWER-vulnerability scanner
An auditor is asked to assess the LAN of a company for potential threats. What are three
potential threats the auditor may point out? (Choose three.) - CORRECT ANSWER-a
misconfigured firewall, unauthorized port scanning and network probing, unlocked access to
network equipment
An organization has implemented a private cloud infrastructure. The security administrator is
asked to secure the infrastructure from potential threats. What three tactics can be
implemented to protect the private cloud? (Choose three.) - CORRECT ANSWER-Disable ping,
probing, and port scanning, Test inbound and outbound traffic, Update devices with security
fixes and patches.
As a security professional, there is a possibility to have access to sensitive data and assets. What
is one item a security professional should understand in order to make informed ethical
decisions? - CORRECT ANSWER-laws governing the data
As part of HR policy in a company, an individual may opt-out of having information shared with
any third party other than the employer. Which law protects the privacy of personal shared
information? - CORRECT ANSWER-GLBA
If a person knowingly accesses a government computer without permission, what federal act
laws would the person be subject to? - CORRECT ANSWER-CFAA
Unauthorized visitors have entered a company office and are walking around the building. What
two measures can be implemented to prevent unauthorized visitor access to the building?
LATEST QUESTIONS AND
VERIFIED CORRECT
ANSWERS GRADED A+
A breach occurs in a company that processes credit card information. Which industry specific
law governs credit card data protection? - CORRECT ANSWER-PCI DSS
A company has had several incidents involving users downloading unauthorized software, using
unauthorized websites, and using personal USB devices. The CIO wants to put in place a scheme
to manage the user threats. What three things might be put in place to manage the threats?
(Choose three.) - CORRECT ANSWER-Provide security awareness training, Disable CD and USB
access, Use content filtering.
A company is attempting to lower the cost in deploying commercial software and is considering
a cloud based service. Which cloud based service would be best to host the software? -
CORRECT ANSWER-SaaS
A consultant is hired to make recommendations on managing device threats in a company.
What are three general recommendations that can be made? (Choose three.) - CORRECT
ANSWER-Enable screen lockout, Disable administrative rights for users, Enable automated
antivirus scans.
, A school administrator is concerned with the disclosure of student information due to a breach.
Under which act is student information protected? - CORRECT ANSWER-FERPA
A security professional is asked to perform an analysis of the current state of a company
network. What tool would the security professional use to scan the network only for security
risks? - CORRECT ANSWER-vulnerability scanner
An auditor is asked to assess the LAN of a company for potential threats. What are three
potential threats the auditor may point out? (Choose three.) - CORRECT ANSWER-a
misconfigured firewall, unauthorized port scanning and network probing, unlocked access to
network equipment
An organization has implemented a private cloud infrastructure. The security administrator is
asked to secure the infrastructure from potential threats. What three tactics can be
implemented to protect the private cloud? (Choose three.) - CORRECT ANSWER-Disable ping,
probing, and port scanning, Test inbound and outbound traffic, Update devices with security
fixes and patches.
As a security professional, there is a possibility to have access to sensitive data and assets. What
is one item a security professional should understand in order to make informed ethical
decisions? - CORRECT ANSWER-laws governing the data
As part of HR policy in a company, an individual may opt-out of having information shared with
any third party other than the employer. Which law protects the privacy of personal shared
information? - CORRECT ANSWER-GLBA
If a person knowingly accesses a government computer without permission, what federal act
laws would the person be subject to? - CORRECT ANSWER-CFAA
Unauthorized visitors have entered a company office and are walking around the building. What
two measures can be implemented to prevent unauthorized visitor access to the building?