CHAPTER 11— CYBERCRIME AND IT SECURITY MULTIPLE CHOICE 1. Identify a true statement about the bring your own device (BYOD) business policy. a. It can improve employee productivity. b. It can provide data security. c. It creates a bug-free environment. d. It enhances employee interaction. ANS: A RATIONALE: Bring your own device (BYOD) is a business policy that permits, and in some cases encourages, employees to use their own mobile devices to access company computing resources and applications, including email, corporate databases, the corporate intranet, and the Internet. Proponents of BYOD say it improves employee productivity by allowing workers to use devices with which they are already familiar—while also helping to create an image of a company as a flexible and progressive employer. 2. Which of the following is a drawback of the bring your own device (BYOD) business policy? a. It affects the productivity of the employees of a company. b. It inhibits the privacy of the employees of a company. c. It exposes a company’s data to malware. d. It creates the image of a company as not being flexible. ANS: C RATIONALE: Most companies have found they cannot entirely prevent employees from using their own devices to perform work functions. However, this practice raises many potential security issues as it is highly likely that such devices are also used for nonwork activity (browsing Web sites, blogging, shopping, visiting social networks, etc.) that exposes them to malware much more frequently than a device used strictly for business purposes. 3. In computing, a(n) _____ is an attack on an information system that takes advantage of a particular system vulnerability. a. exit door b. glitch c. bot d. exploit ANS: D RATIONALE: In computing, an exploit is an attack on an information system that takes advantage of a particular system vulnerability. Often this attack is due to poor system design or implementation. Once the vulnerability is discovered, software developers create and issue a “fix,” or patch, to eliminate the problem. 4. Which of the following is created and issued by software engineers to remove a system vulnerability?