

Information Security
Final Exam
Course Introduction
This course offers a comprehensive overview of the principles and practices of information security, focusing on the protection of digital assets in modern organizational environments. Students will explore key concepts such as confidentiality, integrity, and availability, while examining risks, threats, vulnerabilities, and the frameworks used to counter them. Topics include cryptography, authentication, access control, secure communication, malware analysis, risk management, and legal and ethical considerations in cybersecurity. Practical case studies and hands-on exercises will enable students to understand and implement fundamental security strategies, preparing them to address both technical and organizational challenges in maintaining secure information systems.
Recommended Textbook
Computer Security Principles and Practice 3rd Edition by William Stallings
Available Study Resources on Quizplus 24 Chapters
1076 Verified Questions
1076 Flashcards
Source URL: https://quizplus.com/study-set/3981

Page 2

Chapter 1: Computer Systems Overview
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79973
Sample Questions
Q1) A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.
A)attack
B)adversary
C)countermeasure
D)protocol
Answer: C
Q2) The OSI security architecture focuses on security attacks,__________,and services.
Answer: mechanisms
Q3) __________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.
A)Traffic padding
B)Traffic control
C)Traffic routing
D)Traffic integrity
Answer: A
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Cryptographic Tools
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79962
Sample Questions
Q1) The __________ is a pair of keys that have been selected so that if one is used for encryption,the other is used for decryption.
Answer: public and private key
Q2) A _________ is a hardware device that sits between servers and storage systems and encrypts all data going from the server to the storage system and decrypts data going in the opposite direction.
Answer: back-end appliance
Q3) __________ is provided by means of a co-processor board embedded in the tape drive and tape library hardware.
Answer: library-based tape encryption
Q4) A __________ stream is one that is unpredictable without knowledge of the input key and which has an apparently random character.
Answer: pseudorandom
Q5) In July 1998 the __________ announced that it had broken a DES encryption using a special purpose "DES cracker" machine.
Answer: Electronic Frontier Foundation (EFF)
Q6) Public-key encryption was first publicly proposed by __________ in 1976. Answer: Diffie and Hellman
To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: User Authentication
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79956
Sample Questions
Q1) Depending on the application,user authentication on a biometric system involves either verification or identification.
A)True
B)False
Answer: True
Q2) User authentication is a procedure that allows communicating parties to verify that the contents of a received message have not been altered and that the source is authentic.
A)True
B)False Answer: False
Q3) Objects that a user possesses for the purpose of user authentication are called Answer: tokens
Q4) A smart card contains an entire microprocessor.
A)True
B)False Answer: True
Q5) A host generated random number is often called a __________. Answer: nonce
To view all questions and flashcards with answers, click on the resource link above. Page 5
Chapter 4: Access Control
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79955
Sample Questions
Q1) Any program that is owned by,and SetUID to,the "superuser" potentially grants unrestricted access to the system to any user executing that program.
A)True
B)False
Q2) __________ controls access based on comparing security labels with security clearances.
A)MAC
B)DAC
C)RBAC
D)MBAC
Q3) A constraint is a defined relationship among roles or a condition related to roles.
A)True
B)False
Q4) __________ is verification that the credentials of a user or other system entity are valid.
A)Adequacy
B)Authentication
C)Authorization
D)Audit

Page 6
To view all questions and flashcards with answers, click on the resource link above.

Chapter 5: Database and Cloud Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79954
Sample Questions
Q1) In a relational database rows are referred to as _________.
A)relations
B)attributes
C)views
D)tuples
Q2) In relational database parlance,the basic building block is a __________,which is a flat table.
A)attribute
B)tuple
C)primary key
D)relation
Q3) _________ is a model for enabling ubiquitous,convenient,on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.
Q4) In a relational database columns are referred to as _________.
Q5) In a ___________ administration a small number of privileged users may grant and revoke access rights.
Q6) The __________ cloud infrastructure is operated solely for an organization.
Page 7
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Malicious Software
Available Study Resources on Quizplus for this Chatper
44 Verified Questions
44 Flashcards
Source URL: https://quizplus.com/quiz/79953
Sample Questions
Q1) A bot propagates itself and activates itself,whereas a worm is initially controlled from some central facility.
A)True
B)False
Q2) A __________ is when a user views a Web
Q3) A __________ virus is explicitly designed to hide itself from detection by anti-virus software.
Q4) __________ are used to send large volumes of unwanted e-mail.
A)Rootkits
B)Spammer programs
C)Downloaders
D)Auto-rooter
Q5) Developed by IBM and refined by Symantec,the __________ provides a malware detection system that will automatically capture,analyze,add detection and shielding,or remove new malware and pass information about it to client systems so the malware can be detected before it is allowed to run elsewhere.
Q6) Keyware captures keystrokes on a compromised system.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 8
Q7) A __________ is a collection of bots capable of acting in a coordinated manner.

Chapter 7: Denial-Of-Service Attacks
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79952
Sample Questions
Q1) A characteristic of reflection attacks is the lack of _______ traffic.
A)backscatter
B)network
C)three-way
D)botnet
Q2) When a DoS attack is detected,the first step is to _______.
A)identify the attack
B)analyze the response
C)design blocking filters
D)shut down the network
Q3) ______ attempts to monopolize all of the available request handling threads on the Web server by sending HTTP requests that never complete.
A)HTTP
B)Reflection attacks
C)SYN flooding
D)Slowloris
Q4) A _______ flood refers to an attack that bombards Web servers with HTTP requests.
Q5) Requests and _______ are the two different types of SIP messages.
Q6) The standard protocol used for call setup in VoIP is the ________ Protocol.
To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Intrusion Detection
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79951
Sample Questions
Q1) _________ are either individuals or members of a larger group of outsider attackers who are motivated by social or political causes.
A)State-sponsored organizations
B)Activists
C)Cyber criminals
D)Others
Q2) Intrusion detection is based on the assumption that the behavior of the intruder differs from that of a legitimate user in ways that can be quantified.
A)True
B)False
Q3) Signature-based approaches attempt to define normal,or expected, behavior,whereas anomaly approaches attempt to define proper behavior.
A)True
B)False
Q4) The __________ is the human with overall responsibility for setting the security policy of the organization,and,thus,for decisions about deploying and configuring the IDS.
Q5) Anomaly detection is effective against misfeasors.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Firewalls and Intrusion Prevention Systems
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79950
Sample Questions
Q1) A ________ uses encryption and authentication in the lower protocol layers to provide a secure connection through an otherwise insecure network,typically the Internet.
Q2) An intruder transmitting packets from the outside with a source IP address field containing an address of an internal host is known as IP address _________.
Q3) Typically the systems in the _________ require or foster external connectivity such as a corporate Web site,an e-mail server,or a DNS server.
A)DMZ
B)IP protocol field
C)boundary firewall
D)VPN
Q4) Snort Inline enables Snort to function as an intrusion prevention capability.
A)True
B)False
Q5) _________ matching scans incoming packets for specific byte sequences (the signature)stored in a database of known attacks.
Q6) Snort Inline adds three new rule types: drop,reject,and _________.
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Buffer Overflow
Available Study Resources on Quizplus for this Chatper
44 Verified Questions
44 Flashcards
Source URL: https://quizplus.com/quiz/79972
Sample Questions
Q1) In 2003 the _________ exploited a buffer overflow in Microsoft SQL Server 2000.
A)Slammer worm
B)Morris Internet Worm
C)Sasser worm
D)Code Red worm
Q2) Buffer overflow exploits are no longer a major source of concern to security practitioners.
A)True
B)False
Q3) The function of ________ was to transfer control to a user command-line interpreter,which gave access to any program available on the system with the privileges of the attacked program.
A)shellcode
B)stacking
C)no-execute
D)memory management
Q4) Shellcode is not specific to a particular processor architecture.
A)True
B)False
Q5) Data is simply an array of _________ .
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Software Security
Available Study Resources on Quizplus for this Chatper
43 Verified Questions
43 Flashcards
Source URL: https://quizplus.com/quiz/79971
Sample Questions
Q1) Defensive programming requires a changed mindset to traditional programming practices.
A)True
B)False
Q2) Security flaws occur as a consequence of sufficient checking and validation of data and error codes in programs.
A)True
B)False
Q3) Without suitable synchronization of accesses it is possible that values may be corrupted,or changes lost,due to over-lapping access,use,and replacement of shared values.
A)True
B)False
Q4) Defensive programming is sometimes referred to as _________.
A)variable programming
B)secure programming
C)interpretive programming
D)chroot programming
Q5) _________ attacks are most commonly seen in scripted Web applications.
Page 13
Q6) Program input data may be broadly classified as textual or ______.
To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Operating System Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79970
Sample Questions
Q1) A very common configuration fault seen with Web and file transfer servers is for all the files supplied by the service to be owned by the same "user" account that the server executes as.
A)True
B)False
Q2) ______ is a reactive control that can only inform you about bad things that have already happened.
Q3) Passwords installed by default are secure and do not need to be changed.
A)True
B)False
Q4) The following steps should be used to secure an operating system:
A)test the security of the basic operating system
B)remove unnecessary services
C)install and patch the operating system
D)all of the above
Q5) Configuration information in Windows systems is centralized in the _______,which forms a database of keys and values.
Q6) The final step in the process of initially securing the base operating system is
To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Trusted Computing and Multilevel Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79969
Sample Questions
Q1) The _________ Model was developed for commercial applications in which conflicts of interest can arise.
A)Biba
B)Clark-Wilson Integrity
C)Bell-Lapadula
D)Chinese Wall
Q2) The Common Criteria for Information Technology and Security Evaluation are ISO standards for specifying security requirements and defining evaluation criteria.
A)True
B)False
Q3) __________ data are data that may be derived from corporate data but that cannot be used to discover the corporation's identity.
A)Reference
B)Trust
C)Sanitized
D)MAC
Q4) Functionality is the security features provided by a product.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: It Security Management and Risk Assessment
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79968
Sample Questions
Q1) The advantages of the _________ risk assessment approach are that it provides the most detailed examination of the security risks of an organization's IT system and produces strong justification for expenditure on the controls proposed.
Q2) __________ ensures that critical assets are sufficiently protected in a cost-effective manner.
A)IT control
B)IT security management
C)IT discipline
D)IT risk implementations
Q3) The four approaches to identifying and mitigating risks to an organization's IT infrastructure are: baseline approach,detailed risk analysis,combined approach,and __________ approach.
Q4) ________ specification indicates the impact on the organization should the particular threat in question actually eventuate.
A)Risk
B)Consequence
C)Threat
D)Likelihood
Q5) Not proceeding with the activity or system that creates the risk is _________.
To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: It Security Controls,plans,and Procedures
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79967
Sample Questions
Q1) The _________ controls focus on the response to a security breach,by warning of violations or attempted violations of security policies or the identified exploit of a vulnerability and by providing means to restore the resulting lost computing resources.
Q2) The objective of the ________ control category is to avoid breaches of any law,statutory,regulatory,or contractual obligations,and of any security requirements.
A)access
B)asset management
C)compliance
D)business continuity management
Q3) The implementation phase comprises not only the direct implementation of the controls,but also the associated training and general security awareness programs for the organization.
A)True
B)False
Q4) The _______ plan documents what needs to be done for each selected control,along with the personnel responsible,and the resources and time frame to be used.
Q5) A _________ on an organization's IT systems identifies areas needing treatment.
To view all questions and flashcards with answers, click on the resource link above. Page 17

Chapter 16: Physical and Infrastructure Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79966
Sample Questions
Q1) For information systems,the role of logical security is to protect the physical assets that support the storage and processing of information.
A)True
B)False
Q2) _______ facilities include electrical power,communication services,and environmental controls such as heat and humidity.
A)Supporting
B)Information
C)Physical
D)All of the above
Q3) Physical security threats are organized into three categories: environmental threats,human-caused threats,and _________ threats.
Q4) The most essential element of recovery from physical security breaches is ____.
Q5) A restricted area within close proximity of a security interest has a classification of ______.
A)exclusion
B)controlled
C)limited
D)unrestricted
To view all questions and flashcards with answers, click on the resource link above. Page 18

Chapter 17: Human Resources Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79965
Sample Questions
Q1) A(n)________ is any file or object found on a system that might be involved in probing or attacking systems and networks or that is being used to defeat security measures.
Q2) Security awareness,training,and education programs may be needed to comply with regulations and contractual obligations.
A)True
B)False
Q3) Network and host __________ monitor and analyze network and host activity and usually compare this information with a collection of attack signatures to identify potential security incidents.
Q4) Any action that threatens one or more of the classic security services of confidentiality,integrity,availability,accountability,authenticity,and reliability in a system constitutes a(n)________.
Q5) ________ need training on the development of risk management goals,means of measurement,and the need to lead by example in the area of security awareness.
A)Executives
B)Analysts
C)Managers
D)Trainers
To view all questions and flashcards with answers, click on the resource link above. Page 19

Chapter 18: Security Auditing
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79964
Sample Questions
Q1) The _________ is logic embedded into the software of the system that monitors system activity and detects security-related events that it has been configured to detect.
A)event discriminator
B)audit analyzer
C)archive
D)alarm processor
Q2) Windows allows the system user to enable auditing in _______ different categories.
A)five
B)seven
C)nine
D)eleven
Q3) _________ identifies the level of auditing,enumerates the types of auditable events,and identifies the minimum set of audit-related information provided.
A)Event selection
B)Data generation
C)Automatic response
D)Audit analysis
To view all questions and flashcards with answers, click on the resource link above.
Page 20

Chapter 19: Legal and Ethical Aspects
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79963
Sample Questions
Q1) The success of cybercriminals,and the relative lack of success of law enforcement,influence the behavior of _______.
A)cyber thieves
B)cybercrime victims
C)cybercrime acts
D)cyber detectives
Q2) No cybercriminal databases exist that can point investigators to likely suspects.
A)True
B)False
Q3) A ______ handles the financial transaction for issuing the digital license to the consumer and pays royalty fees to the content provider and distribution fees to the distributor accordingly.
Q4) The purpose of the privacy functions is to provide a user protection against discovery and misuse of identity by other users.
A)True
B)False
Q5) The ___________ Act places restrictions on online organizations in the collection of data from children under the age of 13.
To view all questions and flashcards with answers, click on the resource link above. Page 21

Chapter 20: Symmetric Encryption and Message
Confidentiality
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79961
Sample Questions
Q1) The ciphertext-only attack is the easiest to defend against. A)True
B)False
Q2) Key distribution can be achieved for two parties A and B by a third party selecting the key and physically delivering it to A and B.
A)True
B)False
Q3) An encryption scheme is _________ if the cost of breaking the cipher exceeds the value of the encrypted information and/or the time required to break the cipher exceeds the useful lifetime of the information.
Q4) The most powerful,and most common,approach to countering the threats to network security is ________.
Q5) The most widely used encryption scheme is based on the _________ adopted in 1977 by the National Bureau of Standards.
A)AES
B)3DES
C)CES
D)DES
To view all questions and flashcards with answers, click on the resource link above. Page 22

Chapter 21: Public-Key Cryptography and Message
Authentication
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79960
Sample Questions
Q1) The Diffie-Hellman algorithm depends for its effectiveness on the difficulty of computing discrete logarithms.
A)True
B)False
Q2) The operations performed during a round consist of circular shifts,and primitive Boolean functions based on DSS,MD5,SHA,and RSA.
A)True
B)False
Q3) A __________ type of attack exploits properties of the RSA algorithm.
A)timing
B)brute-force
C)chosen ciphertext
D)mathematical
Q4) The evaluation criteria for the new hash function are: security,_______,and algorithm and implementation characteristics.
Q5) Unlike RSA,DSS cannot be used for encryption or key exchange.
A)True
B)False
Q7) One of the simplest hash functions is the ________ of every block. Page 23
Q6) NIST has published FIPS PUB 186,which is known as the ___________.
To view all questions and flashcards with answers, click on the resource link above.
Page 24

Chapter 22: Internet Security Protocols and Standards
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79959
Sample Questions
Q1) The recipient of a message can decrypt the signature using DSS and the sender's public DSS key.
A)True
B)False
Q2) The ______ is responsible for transferring the message from the MHS to the MS.
A)MDA
B)MS
C)MUA
D)MSA
Q3) Recipients without S/MIME capability can view the message content, although they cannot verify the signature.
A)True
B)False
Q4) The default algorithms used for encrypting S/MIME messages are the triple DES and a public-key scheme known as _______.
Q5) Most browsers come equipped with SSL and most Web servers have implemented the protocol.
A)True
B)False
Q6) The _________ is used to convey SSL-related alerts to the peer entity.
Page 25
To view all questions and flashcards with answers, click on the resource link above.

Chapter 23: Internet Authentication Applications
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79958
Sample Questions
Q1) _______ is the process in which a CA issues a certificate for a user's public key and returns that certificate to the user's client system and/or posts that certificate in a repository.
A)Certification
B)Registration
C)Initialization
D)Authorization
Q2) An obvious security risk is that of impersonation.
A)True
B)False
Q3) _______ is movement of data in a business process.
A)Provisioning
B)Workflow automation
C)Revocation
D)Initialization
Q4) ______ is the set of hardware,software,people,policies,and procedures needed to create,manage,store,distribute,and revoke digital certificates based on asymmetric cryptography.
Q5) ________ allows end entities to restore their encryption/decryption key pair from an authorized key backup facility.
26
To view all questions and flashcards with answers, click on the resource link above.

Chapter 24: Wireless Network Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79957
Sample Questions
Q1) The fields preceding the MSDU field are referred to as the _________.
Q2) A(n)__________ is any entity that has station functionality and provides access to the distribution system via the wireless medium for associated stations.
A)ESS
B)access point
C)distribution system
D)MPDU
Q3) The purpose of the discovery phase is for an STA and an AP to recognize each other,agree on a set of security capabilities,and establish an association for future communication using those security capabilities.
A)True
B)False
Q4) The specification of a protocol,along with the chosen key length,is known as a ___. A)distribution set
B)open system
C)cipher suite
D)realm
Q5) At the top level of the group key hierarchy is the ___________.
To view all questions and flashcards with answers, click on the resource link above. Page 27