CMIT 320 FINAL EXAM 2024
ANSWER ALL QUESTIONS IN THIS SECTION
QUESTION 1
Your company has long maintained an email server, but it's insecure and
unreliable. As a solution, you're considering outsourcing email to an external
company that provides secure cloud-based email services. What risk management
strategy are you employing? - ANSWERS-risk transference
QUESTION 2
Which of the following risk management practices or concepts is designed to test
the variability in testing processes? - ANSWERS-measurement systems analysis
QUESTION 3
Which of the following is the port scanner that you can use for network mapping
and service enumeration? - ANSWERS-nmap
QUESTION 4
What type of cryptography is most commonly used for secure password storage? -
ANSWERS-hashing
END OF
PAGE 1
, CMIT 320 FINAL EXAM 2024
QUESTION 5
Steps of complete risk assessment - ANSWERS-1. Identify assets at risk
2. Conduct a threat assessment
3. Analyze business impact
4. Evaluate threat probability
5. Prioritize risks
6. Create a mitigation strategy
QUESTION 6
What access control model was popularized by military usage? - ANSWERS-
Mandatory
QUESTION 7
A security program alerts you of a failed login attempt to a secure system. On
investigation, you learn the system's regular user accidentally had caps lock turned
on. What kind of alert was it? - ANSWERS-false positive
END OF
PAGE 2
, CMIT 320 FINAL EXAM 2024
QUESTION 8
Three applications were developed in-house to work together on a complex task.
After a month of continuous execution, it is discovered that one of the applications
frequently requests that shared memory be allocated for a procedure that all three
applications must contribute to.
Once the procedure is complete, the requesting applications fail to release the
memory, and neither of the two other applications requires that the memory remain
allocated nor do they take responsibility for releasing it. What type of vulnerability
has the requesting application introduced? - ANSWERS-memory leak
Memory leaks occur when an application allocates memory but fails to release it
when it's done using the space.
QUESTION 9
You want to test an application to make sure it doesn't behave insecurely when it
receives non-standard input. What technique should you use? - ANSWERS-
fuzzing
QUESTION 10
Which of the following is a difference between load balancing and clustering? -
ANSWERS-Clustering tends to use tighter integration between redundant systems.
END OF
PAGE 3
, CMIT 320 FINAL EXAM 2024
QUESTION 11
Which of the following is an accurate characteristic of virtual private networks
(VPNs) or their features? - ANSWERS-VPNs offer secure communications over
wired and wireless networks alike.
QUESTION 12
In terms of time, how does a differential backup plan tend to differ from an
incremental backup plan? - ANSWERS-It's slower to create backups, but quicker
to restore data.
QUESTION 13
Which of the following are examples of password policies which were once
against conventional wisdom, but are now recommended by NIST to reduce the
likelihood of users forgetting their passwords or needing to write them down to
remember them? - ANSWERS-Do not require passwords to be changed on a
regular basis.
Do not require users to create complex passwords.
END OF
PAGE 4
ANSWER ALL QUESTIONS IN THIS SECTION
QUESTION 1
Your company has long maintained an email server, but it's insecure and
unreliable. As a solution, you're considering outsourcing email to an external
company that provides secure cloud-based email services. What risk management
strategy are you employing? - ANSWERS-risk transference
QUESTION 2
Which of the following risk management practices or concepts is designed to test
the variability in testing processes? - ANSWERS-measurement systems analysis
QUESTION 3
Which of the following is the port scanner that you can use for network mapping
and service enumeration? - ANSWERS-nmap
QUESTION 4
What type of cryptography is most commonly used for secure password storage? -
ANSWERS-hashing
END OF
PAGE 1
, CMIT 320 FINAL EXAM 2024
QUESTION 5
Steps of complete risk assessment - ANSWERS-1. Identify assets at risk
2. Conduct a threat assessment
3. Analyze business impact
4. Evaluate threat probability
5. Prioritize risks
6. Create a mitigation strategy
QUESTION 6
What access control model was popularized by military usage? - ANSWERS-
Mandatory
QUESTION 7
A security program alerts you of a failed login attempt to a secure system. On
investigation, you learn the system's regular user accidentally had caps lock turned
on. What kind of alert was it? - ANSWERS-false positive
END OF
PAGE 2
, CMIT 320 FINAL EXAM 2024
QUESTION 8
Three applications were developed in-house to work together on a complex task.
After a month of continuous execution, it is discovered that one of the applications
frequently requests that shared memory be allocated for a procedure that all three
applications must contribute to.
Once the procedure is complete, the requesting applications fail to release the
memory, and neither of the two other applications requires that the memory remain
allocated nor do they take responsibility for releasing it. What type of vulnerability
has the requesting application introduced? - ANSWERS-memory leak
Memory leaks occur when an application allocates memory but fails to release it
when it's done using the space.
QUESTION 9
You want to test an application to make sure it doesn't behave insecurely when it
receives non-standard input. What technique should you use? - ANSWERS-
fuzzing
QUESTION 10
Which of the following is a difference between load balancing and clustering? -
ANSWERS-Clustering tends to use tighter integration between redundant systems.
END OF
PAGE 3
, CMIT 320 FINAL EXAM 2024
QUESTION 11
Which of the following is an accurate characteristic of virtual private networks
(VPNs) or their features? - ANSWERS-VPNs offer secure communications over
wired and wireless networks alike.
QUESTION 12
In terms of time, how does a differential backup plan tend to differ from an
incremental backup plan? - ANSWERS-It's slower to create backups, but quicker
to restore data.
QUESTION 13
Which of the following are examples of password policies which were once
against conventional wisdom, but are now recommended by NIST to reduce the
likelihood of users forgetting their passwords or needing to write them down to
remember them? - ANSWERS-Do not require passwords to be changed on a
regular basis.
Do not require users to create complex passwords.
END OF
PAGE 4