Skip to main content

Information Security Test Preparation - 496 Verified Questions

Page 1


Information Security Test Preparation

Course Introduction

Information Security explores the principles, technologies, and practices used to protect digital information from unauthorized access, disruption, or destruction. The course covers foundational concepts such as confidentiality, integrity, availability, and threats to information systems, including malware, social engineering, and network attacks. Students learn about encryption methods, authentication processes, security policies, risk management strategies, and legal and ethical aspects of information security. Hands-on exercises and case studies help illustrate how organizations defend against cyber threats and maintain secure computing environments.

Recommended Textbook Guide to Firewalls and VPNs 3rd Edition by Michael E. Whitman

Available Study Resources on Quizplus

10 Chapters

496 Verified Questions

496 Flashcards

Source URL: https://quizplus.com/study-set/2181

Page 2

Chapter 1: Introduction to Information Security

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43454

Sample Questions

Q1) What is the role of the chief information security officer (CISO)?

Answer: The chief information security officer (CISO) is the individual primarily responsible for the assessment, management, and implementation of information security in the organization.The CISO may also be referred to as the manager for IT security, the security administrator, information security officer (ISO), chief security officer (CSO), or by a similar title.The CISO usually reports directly to the CIO, although in larger organizations it is not uncommon for one or more layers of management to exist between the two.

Q2) ____ means that information is free from mistakes or errors.

A) Accuracy

B) Availability

C) Confidentiality

D) Integrity

Answer: A

Q3) The most common Intellectual Property breach is ____________________.

Answer: software piracy

Q4) A(n) ____________________ is an application error that occurs when more data is sent to a buffer than it can handle.

Answer: buffer overflow

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Security Policies and Standards

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43455

Sample Questions

Q1) Policies are put in place to support the organization's mission, vision, and strategic planning.

A)True

B)False

Answer: True

Q2) Attack profiles should include scenarios depicting a typical attack, with details on the method, the indicators, and the broad consequences of the attack.

A)True

B)False

Answer: True

Q3) Within a SETA program, ____ is only available to some of the organization's employees.

A) security-related trinkets

B) security education

C) security training

D) security awareness programs

Answer: B

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Authenticating Users

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43456

Sample Questions

Q1) ____ authentication is most commonly set up as a form of auditing and occurs when a system records the activities of each user and writes details about each activity to a log file.

A) Local

B) Discretionary

C) Centralized

D) Decentralized

Answer: C

Q2) Some firewalls use authentication to give employees access to common resources.

A)True

B)False

Answer: True

Q3) IEEE 802.1x is one of the fastest growing standards being used in enterprise networks today.

A)True

B)False

Answer: True

Q4) In ____________________-based access controls, access is granted based on a set of rules specified by the central authority.

Answer: rule

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Introduction to Firewalls

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43457

Sample Questions

Q1) Mobile devices such as laptops, PDAs, and smartphones blur the perimeter boundary.

A)True

B)False

Q2) Segment of the DMZ where additional authentication and authorization controls are put into place to provide services that are not available to the general public.

A)PAT and NAT

B)bastion host

C)application proxy

D)extranet

E)header

F)perimeter

G)data

H)port

I)packet filtering

Q3) A packet-filtering firewall installed on a TCP/IP-based network typically functions at the TCP level.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above.

Page 6

Chapter 5: Packet Filtering

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43458

Sample Questions

Q1) How does a packet filter process IP header criteria?

Q2) List and describe the types of hardware devices and software programs that perform packet filtering.

Q3) Using TCP or UDP port numbers can help you filter a wide variety of information, including SMTP and POP e-mail messages, NetBIOS sessions, ____, and Network News Transfer Protocol (NNTP) newsgroup sessions.

A) DNS requests

B) ICMP messages

C) stateful transfers

D) Trojan horses

Q4) A(n) ____________________ is hardware or software that blocks or allows transmission of information packets based on criteria such as port, IP address, and protocol.

Q5) It is good practice to block ____ access to all internal servers from the public networks.

A) HTTP

B) Telnet

C) Simple Mail Transport Protocol

D) DNS

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Firewall Configuration and Administration

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43459

Sample Questions

Q1) Password you need to enter to make your screen saver vanish so you can return to your desktop and resume working.

A)boot-up password

B)firewall rules

C)bastion host

D)screen saver password

E)restrictive

F)IP forwarding

G)permissive

H)supervisor password

I)caching

Q2) Many companies use the Internet to enable a(n) ____________________ that connects internal hosts with specific clients in other organizations.

Q3) A critical ____________________ is defined as a software- or hardware-related item that is indispensable to the operation of a device or program.

Q4) What is an intrusion detection and prevention system?

Q5) Describe best practices for adding software updates and patches.

Q6) Describe the need for firewall scalability.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Working With Proxy Servers and Application-Level Firewalls

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43460

Sample Questions

Q1) A network must have one or more proxy servers available for each ____ proxied on the network.

A) packet filter

B) network connection

C) service protocol

D) client computer

Q2) Microsoft ____________________ is a complex, full-featured firewall that includes stateful packet filtering as well as proxy services, NAT, and intrusion detection.

Q3) Configured so that they are totally invisible to end users.

A)dual-homed host

B)URL redirection

C)nontransparent proxies

D)log files

E)parameters

F)SOCKS

G)WinGate

H)proxy servers

I)transparent proxies

Q4) How can a proxy server be used for e-mail protection?

Page 9

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Implementing the Bastion Host

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43461

Sample Questions

Q1) Speed up the retrieval and storage of stored data.

A)instruction cache

B)log files

C)translation lookaside buffer

D)data cache

E)Demilitarized Zone

F)bastion host

G)UNIX

H)processor speed

I)syslog daemon

Q2) When selcting a bastion host operating system, the most important consideration is

A) Choose UNIX/LINUX only

B) Choose Windows only

C) Choose the OS you're most familiar with

D) Choose the OS that is the most cost effective

Q3) ____________________ occurs when a company physically hosts its server(s) in a data center that is managed by a third party.

Q4) What type of processor speed is best for a bastion host?

Q5) Why is it a good idea to disable user accounts on the bastion host?

Page 10

To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Encryption - The Foundation for the Virtual

Private

Network

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/43462

Sample Questions

Q1) One of the most popular public key cryptosystems is a proprietary model named

A) Triple DES

B) Rijndael

C) Rivest-Shamir-Aldeman (RSA)

D) certificate authority (CA)

Q2) ____ was developed by Netscape in 1994 to provide security for online electronic commerce transactions.

A) Secure Hypertext Transfer Protocol (SHTTP)

B) Secure Shell (SSH)

C) Secure Sockets Layer (SSL)

D) Secure Electronic Transactions (SET)

Q3) AES has been the federally approved standard for nonclassified data since 2002.

A)True

B)False

Q4) Describe some of the common protocols used to secure e-mail.

Q5) Describe asymmetric encryption.

Q7) What is a timing attack? Page 11

Q6) Describe some of the challenges that organizations face when it comes to cryptographic controls.

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Setting up a Virtual Private Network

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43463

Sample Questions

Q1) L2TP uses ____ rather than MPPE to encrypt data sent over PPP.

A) SSL

B) SSH

C) IPSec

D) IKE

Q2) The host encrypts traffic when it is generated; the data part of packets is encrypted, but not the headers.

A)encapsulation

B)tunnel

C)client-to-site

D)transport mode

E)gateway

F)private leased lines

G)tunnel mode

H)site-to-site

I)Point-to-Point Tunneling Protocol

Q3) Describe the features of IP encapsulation provided by a VPN.

Q4) What should be specified in a VPN security policy?

Q5) What are VPN endpoints?

Q6) Describe the drawbacks of VPNs.

To view all questions and flashcards with answers, click on the resource link above. Page 13

Turn static files into dynamic content formats.

Create a flipbook
Information Security Test Preparation - 496 Verified Questions by Quizplus - Issuu