Solved Solutions 2026 Updated.
Confidentiality - Answer Assurance that the information is
accessible **only to those authorized to have access**
Authenticity - Answer **Trustworthiness of data or
resources** in terms of preventing improper and unauthorized changes
Information Security - Answer Information security is defined as "a state of well-being of
information and infrastructure in which the possibility of theft, tampering, and disruption of
information and services is kept low or tolerable." It relies on five major elements:
confidentiality, integrity, availability, authenticity, and non-repudiation.
Availability - Answer Assurance that the systems are
**accessible when required** by the
authorized users.
Integrity - Answer Characteristic of a document,
communication or any data that ensures the
**quality of being genuine**
Non-repudiation - Answer **Guarantee** that the sender of a message cannot
later deny having sent the message and that the
recipient cannot deny having received the message
What is the CIA triad? - Answer Confidentiality, integrity, and availability are together
referred to as the CIA triad.
Information as Business asset - Answer An information asset can be defined as a
piece of information identified as important to an organization.
What does an information asset include? - Answer Information assets may include trade
secrets, patent information, a simple idea for improvement in the way an organization conducts
its business, a new technique, management concept, employee/personnel information, or any
other information that if leaked can negatively affect the organization's business environment.
,What are important characteristics of an organization's information asset? - Answer It is
recognized to be of value to the organization. ▪ It is considered as an asset to the organization. ▪
It is difficult to replace the information without cost, skills, time, and resources. ▪ It is a part of
the organization's corporate identity. ▪ The data classified as information asset is confidential
and proprietary. ▪ It plays a significant role in the organization's business. ▪ It is any organized
documentation that motivates the organization to achieve its goals.▪ It is maintained by people
working in a consistent and cooperative manner. ▪ It can be a part of the enterprise application
or a unique application. ▪ The loss of information affects the investment of organization in
different business activities.
Defense-n-depth - Answer Defense-in-depth is a security strategy in which several protection
layers are placed throughout an information system
What does defense-n-depth do? - Answer Defense-in-depth helps to prevent direct attacks
against an information system and its data because a break in one layer only leads the attacker
to the next layer.
Information Security Policies - Answer Security policies are the foundation of the security
infrastructure that defines the basic security requirements and rules to be implemented in
order to protect and secure an organization's information systems
What two things does information security policies prevent? - Answer 1.Prevent
unauthorized modifications of the data
2.Prevent wastage of company's computing resources
What two things does information security policies protect? - Answer 1.Protect confidential,
proprietary information from theft, misuse, unauthorized disclosure
2.Protect an organization's computing resources
What does information security policies maintain? - Answer Maintain an outline for the
management and administration of network security
What does information security policies manage? - Answer Manage legal liabilities arising
from employees or third parties
What two types of security policies are there? - Answer There are two types of security
policies: technical security and administrative security policies.
Technical security policy - Answer Technical security policies describe the configuration of the
technology for convenient use
,Administrative security policy - Answer Administrative security policies address how all
persons should behave.
Information security systems in an organization might require more attention in what terms of
security? - Answer ▪ Encryption mechanisms ▪ Access control devices ▪ Authentication
systems ▪ Firewalls ▪ Antivirus systems ▪ Websites ▪ Gateways ▪ Routers and switches
High-level management - Answer In an organization the high-level management is
responsible for the implementation of the organization's security policies. High-level officers
involved in the implementation of the policies include the following: ▪ Director of Information
Security ▪ Chief Security Officer
Promiscuous Policy - Answer No restrictions on usage of system resources
Permissive Policy - Answer Policy begins wide open and only known dangerous
services/attacks or behaviors are blocked. It should be updated regularly to be effective
Prudent Policy - Answer It provides maximum security while allowing known but necessary
dangers.
It blocks all services and only safe/ necessary services are enabled individually; everything is
logged.
Paranoid Policy - Answer It forbids everything, no internet connection, or severely limited
internet usage.
Access Control Policy - Answer It defines the resources being protected and the rules that
control access to them.
Remote-Access Policy - Answer It defines who can have remote access, and defines access
medium and remote access security controls.
Firewall-Management Policy - Answer It defines access, management, and monitoring of
firewalls in the organization.
Network-Connection Policy - Answer It defines who can install new resources on the
network, approve the installation of new devices, document network changes, etc.
Passwords Policy - Answer It provides guidelines for using strong password protection on
organization's resources.
, User-Account Policy - Answer It defines the account creation process, and authority, rights,
and responsibilities of user accounts.
Information-Protection Policy - Answer It defines the sensitivity levels of information, who
may have access, how it is stored and transmitted, and how it should be deleted from storage
media.
Special-Access Policy - Answer This policy defines the terms and conditions of granting
special access to system resources.
Email Security Policy - Answer It is created to govern the proper usage of corporate email.
Acceptable-Use Policy - Answer It defines the acceptable use of system resources.
Motives, Goals, and Objectives of Information Security Attacks - Answer A motive originates
out of the notion that the target system stores or processes something valuable and this leads
to threat of an attack on the system. Attackers try various tools and attack techniques to exploit
vulnerabilities in a computer system or security policy and controls to achieve their motives
Attacks = ? - Answer Motive (Goal) + Method + Vulnerability
Motives behind information security attacks - Answer ▪ Disrupting business continuity ▪
Performing information theft ▪ Manipulating data ▪ Creating fear and chaos by disrupting critical
infrastructures
▪ Bringing financial loss to the target ▪ Propagating religious or political beliefs
▪ Achieving the state's military objectives
▪ Damaging reputation of the target ▪ Taking revenge ▪ Demanding ransom ▪
Fun/thrill/exploration
Cloud Computing Threats - Answer Cloud computing is an on-demand delivery of IT
capabilities where sensitive data of organizations and their clients is stored. Flaws in one client's
application cloud allow attackers to access other client's data.
Advanced Persistent Threats (APT) - Answer APT is an attack that is focused on stealing
information from the victim machine without the user being aware of it.
Viruses and Worms - Answer Viruses and worms are the most prevalent networking threat
that are capable of infecting a network within seconds