Skip to main content

Information Security Final Exam - 1076 Verified Questions

Page 1


Information Security

Final Exam

Course Introduction

This course offers a comprehensive overview of the principles and practices of information security, focusing on the protection of digital assets in modern organizational environments. Students will explore key concepts such as confidentiality, integrity, and availability, while examining risks, threats, vulnerabilities, and the frameworks used to counter them. Topics include cryptography, authentication, access control, secure communication, malware analysis, risk management, and legal and ethical considerations in cybersecurity. Practical case studies and hands-on exercises will enable students to understand and implement fundamental security strategies, preparing them to address both technical and organizational challenges in maintaining secure information systems.

Recommended Textbook

Computer Security Principles and Practice 3rd Edition by William Stallings

Available Study Resources on Quizplus 24 Chapters

1076 Verified Questions

1076 Flashcards

Source URL: https://quizplus.com/study-set/3981

Page 2

Chapter 1: Computer Systems Overview

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79973

Sample Questions

Q1) A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.

A)attack

B)adversary

C)countermeasure

D)protocol

Answer: C

Q2) The OSI security architecture focuses on security attacks,__________,and services.

Answer: mechanisms

Q3) __________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

A)Traffic padding

B)Traffic control

C)Traffic routing

D)Traffic integrity

Answer: A

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Cryptographic Tools

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79962

Sample Questions

Q1) The __________ is a pair of keys that have been selected so that if one is used for encryption,the other is used for decryption.

Answer: public and private key

Q2) A _________ is a hardware device that sits between servers and storage systems and encrypts all data going from the server to the storage system and decrypts data going in the opposite direction.

Answer: back-end appliance

Q3) __________ is provided by means of a co-processor board embedded in the tape drive and tape library hardware.

Answer: library-based tape encryption

Q4) A __________ stream is one that is unpredictable without knowledge of the input key and which has an apparently random character.

Answer: pseudorandom

Q5) In July 1998 the __________ announced that it had broken a DES encryption using a special purpose "DES cracker" machine.

Answer: Electronic Frontier Foundation (EFF)

Q6) Public-key encryption was first publicly proposed by __________ in 1976. Answer: Diffie and Hellman

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: User Authentication

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79956

Sample Questions

Q1) Depending on the application,user authentication on a biometric system involves either verification or identification.

A)True

B)False

Answer: True

Q2) User authentication is a procedure that allows communicating parties to verify that the contents of a received message have not been altered and that the source is authentic.

A)True

B)False Answer: False

Q3) Objects that a user possesses for the purpose of user authentication are called Answer: tokens

Q4) A smart card contains an entire microprocessor.

A)True

B)False Answer: True

Q5) A host generated random number is often called a __________. Answer: nonce

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Access Control

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79955

Sample Questions

Q1) Any program that is owned by,and SetUID to,the "superuser" potentially grants unrestricted access to the system to any user executing that program.

A)True

B)False

Q2) __________ controls access based on comparing security labels with security clearances.

A)MAC

B)DAC

C)RBAC

D)MBAC

Q3) A constraint is a defined relationship among roles or a condition related to roles.

A)True

B)False

Q4) __________ is verification that the credentials of a user or other system entity are valid.

A)Adequacy

B)Authentication

C)Authorization

D)Audit

Page 6

To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Database and Cloud Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79954

Sample Questions

Q1) In a relational database rows are referred to as _________.

A)relations

B)attributes

C)views

D)tuples

Q2) In relational database parlance,the basic building block is a __________,which is a flat table.

A)attribute

B)tuple

C)primary key

D)relation

Q3) _________ is a model for enabling ubiquitous,convenient,on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Q4) In a relational database columns are referred to as _________.

Q5) In a ___________ administration a small number of privileged users may grant and revoke access rights.

Q6) The __________ cloud infrastructure is operated solely for an organization.

Page 7

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Malicious Software

Available Study Resources on Quizplus for this Chatper

44 Verified Questions

44 Flashcards

Source URL: https://quizplus.com/quiz/79953

Sample Questions

Q1) A bot propagates itself and activates itself,whereas a worm is initially controlled from some central facility.

A)True

B)False

Q2) A __________ is when a user views a Web

Q3) A __________ virus is explicitly designed to hide itself from detection by anti-virus software.

Q4) __________ are used to send large volumes of unwanted e-mail.

A)Rootkits

B)Spammer programs

C)Downloaders

D)Auto-rooter

Q5) Developed by IBM and refined by Symantec,the __________ provides a malware detection system that will automatically capture,analyze,add detection and shielding,or remove new malware and pass information about it to client systems so the malware can be detected before it is allowed to run elsewhere.

Q6) Keyware captures keystrokes on a compromised system.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 8

Q7) A __________ is a collection of bots capable of acting in a coordinated manner.

Chapter 7: Denial-Of-Service Attacks

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79952

Sample Questions

Q1) A characteristic of reflection attacks is the lack of _______ traffic.

A)backscatter

B)network

C)three-way

D)botnet

Q2) When a DoS attack is detected,the first step is to _______.

A)identify the attack

B)analyze the response

C)design blocking filters

D)shut down the network

Q3) ______ attempts to monopolize all of the available request handling threads on the Web server by sending HTTP requests that never complete.

A)HTTP

B)Reflection attacks

C)SYN flooding

D)Slowloris

Q4) A _______ flood refers to an attack that bombards Web servers with HTTP requests.

Q5) Requests and _______ are the two different types of SIP messages.

Q6) The standard protocol used for call setup in VoIP is the ________ Protocol.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Intrusion Detection

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79951

Sample Questions

Q1) _________ are either individuals or members of a larger group of outsider attackers who are motivated by social or political causes.

A)State-sponsored organizations

B)Activists

C)Cyber criminals

D)Others

Q2) Intrusion detection is based on the assumption that the behavior of the intruder differs from that of a legitimate user in ways that can be quantified.

A)True

B)False

Q3) Signature-based approaches attempt to define normal,or expected, behavior,whereas anomaly approaches attempt to define proper behavior.

A)True

B)False

Q4) The __________ is the human with overall responsibility for setting the security policy of the organization,and,thus,for decisions about deploying and configuring the IDS.

Q5) Anomaly detection is effective against misfeasors.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Firewalls and Intrusion Prevention Systems

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79950

Sample Questions

Q1) A ________ uses encryption and authentication in the lower protocol layers to provide a secure connection through an otherwise insecure network,typically the Internet.

Q2) An intruder transmitting packets from the outside with a source IP address field containing an address of an internal host is known as IP address _________.

Q3) Typically the systems in the _________ require or foster external connectivity such as a corporate Web site,an e-mail server,or a DNS server.

A)DMZ

B)IP protocol field

C)boundary firewall

D)VPN

Q4) Snort Inline enables Snort to function as an intrusion prevention capability.

A)True

B)False

Q5) _________ matching scans incoming packets for specific byte sequences (the signature)stored in a database of known attacks.

Q6) Snort Inline adds three new rule types: drop,reject,and _________.

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Buffer Overflow

Available Study Resources on Quizplus for this Chatper

44 Verified Questions

44 Flashcards

Source URL: https://quizplus.com/quiz/79972

Sample Questions

Q1) In 2003 the _________ exploited a buffer overflow in Microsoft SQL Server 2000.

A)Slammer worm

B)Morris Internet Worm

C)Sasser worm

D)Code Red worm

Q2) Buffer overflow exploits are no longer a major source of concern to security practitioners.

A)True

B)False

Q3) The function of ________ was to transfer control to a user command-line interpreter,which gave access to any program available on the system with the privileges of the attacked program.

A)shellcode

B)stacking

C)no-execute

D)memory management

Q4) Shellcode is not specific to a particular processor architecture.

A)True

B)False

Q5) Data is simply an array of _________ .

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Software Security

Available Study Resources on Quizplus for this Chatper

43 Verified Questions

43 Flashcards

Source URL: https://quizplus.com/quiz/79971

Sample Questions

Q1) Defensive programming requires a changed mindset to traditional programming practices.

A)True

B)False

Q2) Security flaws occur as a consequence of sufficient checking and validation of data and error codes in programs.

A)True

B)False

Q3) Without suitable synchronization of accesses it is possible that values may be corrupted,or changes lost,due to over-lapping access,use,and replacement of shared values.

A)True

B)False

Q4) Defensive programming is sometimes referred to as _________.

A)variable programming

B)secure programming

C)interpretive programming

D)chroot programming

Q5) _________ attacks are most commonly seen in scripted Web applications.

Page 13

Q6) Program input data may be broadly classified as textual or ______.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Operating System Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79970

Sample Questions

Q1) A very common configuration fault seen with Web and file transfer servers is for all the files supplied by the service to be owned by the same "user" account that the server executes as.

A)True

B)False

Q2) ______ is a reactive control that can only inform you about bad things that have already happened.

Q3) Passwords installed by default are secure and do not need to be changed.

A)True

B)False

Q4) The following steps should be used to secure an operating system:

A)test the security of the basic operating system

B)remove unnecessary services

C)install and patch the operating system

D)all of the above

Q5) Configuration information in Windows systems is centralized in the _______,which forms a database of keys and values.

Q6) The final step in the process of initially securing the base operating system is

To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Trusted Computing and Multilevel Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79969

Sample Questions

Q1) The _________ Model was developed for commercial applications in which conflicts of interest can arise.

A)Biba

B)Clark-Wilson Integrity

C)Bell-Lapadula

D)Chinese Wall

Q2) The Common Criteria for Information Technology and Security Evaluation are ISO standards for specifying security requirements and defining evaluation criteria.

A)True

B)False

Q3) __________ data are data that may be derived from corporate data but that cannot be used to discover the corporation's identity.

A)Reference

B)Trust

C)Sanitized

D)MAC

Q4) Functionality is the security features provided by a product.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: It Security Management and Risk Assessment

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79968

Sample Questions

Q1) The advantages of the _________ risk assessment approach are that it provides the most detailed examination of the security risks of an organization's IT system and produces strong justification for expenditure on the controls proposed.

Q2) __________ ensures that critical assets are sufficiently protected in a cost-effective manner.

A)IT control

B)IT security management

C)IT discipline

D)IT risk implementations

Q3) The four approaches to identifying and mitigating risks to an organization's IT infrastructure are: baseline approach,detailed risk analysis,combined approach,and __________ approach.

Q4) ________ specification indicates the impact on the organization should the particular threat in question actually eventuate.

A)Risk

B)Consequence

C)Threat

D)Likelihood

Q5) Not proceeding with the activity or system that creates the risk is _________.

To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: It Security Controls,plans,and Procedures

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79967

Sample Questions

Q1) The _________ controls focus on the response to a security breach,by warning of violations or attempted violations of security policies or the identified exploit of a vulnerability and by providing means to restore the resulting lost computing resources.

Q2) The objective of the ________ control category is to avoid breaches of any law,statutory,regulatory,or contractual obligations,and of any security requirements.

A)access

B)asset management

C)compliance

D)business continuity management

Q3) The implementation phase comprises not only the direct implementation of the controls,but also the associated training and general security awareness programs for the organization.

A)True

B)False

Q4) The _______ plan documents what needs to be done for each selected control,along with the personnel responsible,and the resources and time frame to be used.

Q5) A _________ on an organization's IT systems identifies areas needing treatment.

To view all questions and flashcards with answers, click on the resource link above. Page 17

Chapter 16: Physical and Infrastructure Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79966

Sample Questions

Q1) For information systems,the role of logical security is to protect the physical assets that support the storage and processing of information.

A)True

B)False

Q2) _______ facilities include electrical power,communication services,and environmental controls such as heat and humidity.

A)Supporting

B)Information

C)Physical

D)All of the above

Q3) Physical security threats are organized into three categories: environmental threats,human-caused threats,and _________ threats.

Q4) The most essential element of recovery from physical security breaches is ____.

Q5) A restricted area within close proximity of a security interest has a classification of ______.

A)exclusion

B)controlled

C)limited

D)unrestricted

To view all questions and flashcards with answers, click on the resource link above. Page 18

Chapter 17: Human Resources Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79965

Sample Questions

Q1) A(n)________ is any file or object found on a system that might be involved in probing or attacking systems and networks or that is being used to defeat security measures.

Q2) Security awareness,training,and education programs may be needed to comply with regulations and contractual obligations.

A)True

B)False

Q3) Network and host __________ monitor and analyze network and host activity and usually compare this information with a collection of attack signatures to identify potential security incidents.

Q4) Any action that threatens one or more of the classic security services of confidentiality,integrity,availability,accountability,authenticity,and reliability in a system constitutes a(n)________.

Q5) ________ need training on the development of risk management goals,means of measurement,and the need to lead by example in the area of security awareness.

A)Executives

B)Analysts

C)Managers

D)Trainers

To view all questions and flashcards with answers, click on the resource link above. Page 19

Chapter 18: Security Auditing

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79964

Sample Questions

Q1) The _________ is logic embedded into the software of the system that monitors system activity and detects security-related events that it has been configured to detect.

A)event discriminator

B)audit analyzer

C)archive

D)alarm processor

Q2) Windows allows the system user to enable auditing in _______ different categories.

A)five

B)seven

C)nine

D)eleven

Q3) _________ identifies the level of auditing,enumerates the types of auditable events,and identifies the minimum set of audit-related information provided.

A)Event selection

B)Data generation

C)Automatic response

D)Audit analysis

To view all questions and flashcards with answers, click on the resource link above.

Page 20

Chapter 19: Legal and Ethical Aspects

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79963

Sample Questions

Q1) The success of cybercriminals,and the relative lack of success of law enforcement,influence the behavior of _______.

A)cyber thieves

B)cybercrime victims

C)cybercrime acts

D)cyber detectives

Q2) No cybercriminal databases exist that can point investigators to likely suspects.

A)True

B)False

Q3) A ______ handles the financial transaction for issuing the digital license to the consumer and pays royalty fees to the content provider and distribution fees to the distributor accordingly.

Q4) The purpose of the privacy functions is to provide a user protection against discovery and misuse of identity by other users.

A)True

B)False

Q5) The ___________ Act places restrictions on online organizations in the collection of data from children under the age of 13.

To view all questions and flashcards with answers, click on the resource link above. Page 21

Chapter 20: Symmetric Encryption and Message

Confidentiality

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79961

Sample Questions

Q1) The ciphertext-only attack is the easiest to defend against. A)True

B)False

Q2) Key distribution can be achieved for two parties A and B by a third party selecting the key and physically delivering it to A and B.

A)True

B)False

Q3) An encryption scheme is _________ if the cost of breaking the cipher exceeds the value of the encrypted information and/or the time required to break the cipher exceeds the useful lifetime of the information.

Q4) The most powerful,and most common,approach to countering the threats to network security is ________.

Q5) The most widely used encryption scheme is based on the _________ adopted in 1977 by the National Bureau of Standards.

A)AES

B)3DES

C)CES

D)DES

To view all questions and flashcards with answers, click on the resource link above. Page 22

Chapter 21: Public-Key Cryptography and Message

Authentication

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79960

Sample Questions

Q1) The Diffie-Hellman algorithm depends for its effectiveness on the difficulty of computing discrete logarithms.

A)True

B)False

Q2) The operations performed during a round consist of circular shifts,and primitive Boolean functions based on DSS,MD5,SHA,and RSA.

A)True

B)False

Q3) A __________ type of attack exploits properties of the RSA algorithm.

A)timing

B)brute-force

C)chosen ciphertext

D)mathematical

Q4) The evaluation criteria for the new hash function are: security,_______,and algorithm and implementation characteristics.

Q5) Unlike RSA,DSS cannot be used for encryption or key exchange.

A)True

B)False

Q7) One of the simplest hash functions is the ________ of every block. Page 23

Q6) NIST has published FIPS PUB 186,which is known as the ___________.

To view all questions and flashcards with answers, click on the resource link above.

Page 24

Chapter 22: Internet Security Protocols and Standards

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79959

Sample Questions

Q1) The recipient of a message can decrypt the signature using DSS and the sender's public DSS key.

A)True

B)False

Q2) The ______ is responsible for transferring the message from the MHS to the MS.

A)MDA

B)MS

C)MUA

D)MSA

Q3) Recipients without S/MIME capability can view the message content, although they cannot verify the signature.

A)True

B)False

Q4) The default algorithms used for encrypting S/MIME messages are the triple DES and a public-key scheme known as _______.

Q5) Most browsers come equipped with SSL and most Web servers have implemented the protocol.

A)True

B)False

Q6) The _________ is used to convey SSL-related alerts to the peer entity.

Page 25

To view all questions and flashcards with answers, click on the resource link above.

Chapter 23: Internet Authentication Applications

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79958

Sample Questions

Q1) _______ is the process in which a CA issues a certificate for a user's public key and returns that certificate to the user's client system and/or posts that certificate in a repository.

A)Certification

B)Registration

C)Initialization

D)Authorization

Q2) An obvious security risk is that of impersonation.

A)True

B)False

Q3) _______ is movement of data in a business process.

A)Provisioning

B)Workflow automation

C)Revocation

D)Initialization

Q4) ______ is the set of hardware,software,people,policies,and procedures needed to create,manage,store,distribute,and revoke digital certificates based on asymmetric cryptography.

Q5) ________ allows end entities to restore their encryption/decryption key pair from an authorized key backup facility.

26

To view all questions and flashcards with answers, click on the resource link above.

Chapter 24: Wireless Network Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79957

Sample Questions

Q1) The fields preceding the MSDU field are referred to as the _________.

Q2) A(n)__________ is any entity that has station functionality and provides access to the distribution system via the wireless medium for associated stations.

A)ESS

B)access point

C)distribution system

D)MPDU

Q3) The purpose of the discovery phase is for an STA and an AP to recognize each other,agree on a set of security capabilities,and establish an association for future communication using those security capabilities.

A)True

B)False

Q4) The specification of a protocol,along with the chosen key length,is known as a ___. A)distribution set

B)open system

C)cipher suite

D)realm

Q5) At the top level of the group key hierarchy is the ___________.

To view all questions and flashcards with answers, click on the resource link above. Page 27

Turn static files into dynamic content formats.

Create a flipbook
Information Security Final Exam - 1076 Verified Questions by Quizplus - Issuu