Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 2 fuera de 11 páginas
Examen

Principles of Information Security 7th Edition by Whitman and Mattord

Document preview thumbnail
Vista previa 2 fuera de 11 páginas

Principles of Information Security 7th Edition by Whitman and Mattord

Vista previa del contenido

TEST BANK For Principles of Information Security 7th
Edition by Whitman and Mattord



Which of the following acts is also widely known as the Gramm-Leach-Bliley Act? -
ANSWER: Financial Services Modernization Act

_________ assigns a status level to employees to designate the maximum level of
classified data they may access. - ANSWER: security clearance scheme

____ is any technology that aids in gathering information about a person or
organization without their knowledge. - ANSWER: Spyware

__________ law regulates the structure and administration of government agencies
and their relationships with citizens, employees, and other governments. - ANSWER:
Public

Complete loss of power for a moment is known as a ____. - ANSWER: fault

The goals of information security governance include all but which of the following?

1) Regulatory compliance by using information security knowledge and
infrastructure to support minimum standards of due care

2) Strategic alignment of information security with business strategy to support
organizational objectives


3) Risk management by executing appropriate measures to manage and mitigate
threats to information resources


4) Performance measurement by measuring, monitoring, and reporting information
security governance metrics to ensure that organizational objectives are achieved -
ANSWER: Regulatory compliance by using information security knowledge and
infrastructure to support minimum standards of due care

The _________ control strategy that attempts to eliminate or reduce any remaining
uncontrolled risk through the application of additional controls and safeguards. -
ANSWER: defense

A single loss ____________________ is the calculation of the value associated with
the most likely loss from an attack. - ANSWER: expectancy

, The Health Insurance Portability and Accountability Act Of 1996, also known as the
__________ Act, protects the confidentiality and security of health care data by
establishing and enforcing standards and by standardizing electronic data
interchange. - ANSWER: Kennedy-Kessebaum

__________ is an estimate of how many times per year you expect a specific type of
attack to occur. - ANSWER: ARO

Incident ____________________ is the process of examining a potential incident, or
incident candidate, and determining whether or not that candidate constitutes an
actual incident. - ANSWER: classification

As frustrating as viruses and worms are, perhaps more time and money is spent on
resolving virus ____________________. - ANSWER: hoaxes

A(n) ________ plan is a plan for the organization's intended strategic efforts over the
next several years. - ANSWER: tactical

__________ is a strategy for the protection of information assets that uses multiple
layers and different types of controls (managerial, operational, and technical) to
provide optimal protection. - ANSWER: Defense in depth

________often function as standards or procedures to be used when configuring or
maintaining systems. - ANSWER: SysSPs

The SETA program is a control measure designed to reduce the instances of
__________ security breaches by employees. - ANSWER: accidental

A methodology for the design and implementation of an information system that is a
formal development strategy is referred to as a __________. - ANSWER: systems
development life cycle

__________ was the first operating system to integrate security as its core functions.
- ANSWER: MULTICS

A computer is the __________ of an attack when it is used to conduct an attack
against another computer. - ANSWER: subject

The transfer of large batches of data to an off-site facility, usually through leased
lines or services, is called ____. - ANSWER: electronic vaulting

The ________is based on and directly supports the mission, vision, and direction of
the organization and sets the strategic direction, scope, and tone for all security
efforts. - ANSWER: EISP (Enterprise Information Security Policy)

Libro relacionado
 image
Michael E. Whitman, Herbert J. Mattord Principles of Information Security
Edición: 2021 ISBN: 9780357506431 Edición: Desconocido

Información del documento

Subido en
6 de septiembre de 2024
Número de páginas
11
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$18.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
3
Seguidores
0
Artículos
1282
Última venta
10 meses hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes