100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4.2 TrustPilot
logo-home
Examen

ITN 262 MIDTERM EXAM REPORTED QUESTIONS WITH CORRECT DETAILED ANSWERS

Puntuación
-
Vendido
-
Páginas
5
Grado
A+
Subido en
18-07-2025
Escrito en
2024/2025

ITN 262 MIDTERM EXAM REPORTED QUESTIONS WITH CORRECT DETAILED ANSWERS

Institución
ITN 262
Grado
ITN 262









Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
ITN 262
Grado
ITN 262

Información del documento

Subido en
18 de julio de 2025
Número de páginas
5
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

ITN 262 MIDTERM EXAM
REPORTED QUESTIONS WITH
CORRECT DETAILED ANSWERS

Which of the following yields a more specific set of attacks tied to our particular threat
agents? - Answer-Attack matrix

Which of the following produces a risk to an asset? - Answer-A threat agent and an
attack the agent can perform

Which of the following are threat agents? - Answer--Cracker
-Phone phreak
-Script kiddy
-Black-hat hacker

True or False? Modus operandi applies only to criminal organizations. - Answer-False

Which of the following types of threat agents is most typically associated with
masquerade attacks? - Answer-Identity thieves

Which threat agent is most often associated with denial of service attacks? - Answer-
Natural threats

Impact x Likelihood = ______________ - Answer-Relative Significance of Risk

Typical retail businesses expect a _____ rate of loss due to theft, damages, and other
causes. - Answer-3 percent

True or False? Once we have filled in the attack likelihoods and impacts, we compute
the significance by multiplying these values together. - Answer-True

We are estimating the impact of an individual attack. Which of the following has the
greatest estimated impact? - Answer-An attack with a $100 loss that could happen once
a week

We draft the __________ requirements to address the risks we identified. - Answer-
security

True or False? To analyze a risk, we review it against the threat agents behind the risk.
- Answer-True

, By default ,most systems only record the most ______ events. - Answer-significant

What does AUP stand for? - Answer-Acceptable Use Policy

Cyber vulnerabilities became a public issue in the __________ as new internet users
struggled to understand the technology's risks. - Answer-1990s

True or False? Victims can protect themselves against zero-day attacks. - Answer-False

True or False? A zero-day vulnerability is one that has been reported to the software's
vendor and the general public. - Answer-False

Which of the following describes the effect of the Digital Millennium Copyright Act
(DMCA) on the investigation and publication of security flaws in commercial equipment?
- Answer-It restricts the publication of techniques to reverse-engineer copy protection
schemes.

Which of the following most often forbids people from performing trial-and-error attacks
on computer systems? - Answer-Acceptable use policies

Section 1.6.2 outlines a procedure for disclosing security vulnerabilities in a commercial
device or product. Assume that we have discovered a vulnerability in a commercial
product. The vendor has not acknowledged our initial vulnerability report or
communicated with us in any other way. They have not announced the vulnerability to
the public. We wish to warn the public of the vulnerability as soon as is ethically
defensible. Given the procedure in Section 1.6.2, which of the following is the best
course of action? - Answer-After 30 days, announce that the vulnerability exists, and
describe how to reduce a system's risk of attack through that vulnerability.

Given the vulnerability disclosure procedure in Section 1.6.2 and the story of Michael
Lynn's presentation of a Cisco router vulnerability at Black Hat 2005, which of the
following most accurately describes Lynn's action? - Answer-Lynn acted ethically
because the vulnerability had already been reported and patched, and he did not
describe how to exploit the vulnerability.

A person skilled in attacking computer systems, who uses those skills as a security
expert to help protect systems, is a: - Answer-white-hat hacker

When disclosing a security vulnerability in a system or software, the manufacturer
should avoid: - Answer-including enough detail to allow an attacker to exploit the
vulnerability.

A risk assessment involves which of the following? - Answer--Identifying risks
-Prioritizing risks
$14.49
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada


Documento también disponible en un lote

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
victoryguide stuvia
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
22
Miembro desde
1 año
Número de seguidores
1
Documentos
2757
Última venta
6 días hace

3.7

7 reseñas

5
4
4
0
3
1
2
1
1
1

Recientemente visto por ti

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes