IS3220 CHAPTER 6 Flashcards
Less rigorous than training or education this security training focuses on common or basic security elements that all employees must know and abide by. This is called ___?
AWARENESS
This process of making copies of data onto other storage media is called ___?
The purpose is to protect against data loss by having additional onsite or offsite copies of data that can be restored when necessary.
BACKUP
A plan to maintain the mission-critical functions of the organization in the event of a problem that threatens to take business processes offline is called ___?
The goal is to prevent the interruption of business tasks, even with a damaged environment and reduced resources.
BUSINESS CONTINUITY PLAN
A detailed and thorough review of the deployed security infrastructure compared with the organization’s security policy and any applicable laws and regulations is called ___?
COMPLIANCE AUDIT
A security stance that blocks all access to all resources until a valid authorized explicit exemption is defined is called ___?
DEFAULT DENY
A security stance that allows all access to all resources until an explicit exception is defined is called ___?
DEFAULT PERMIT
A plan to restore the mission-critical functions of the organization once they have been interrupted by an adverse event is called ___?
The goal of this is to return the business to functional operation within a limited time to prevent the failure of the organization to the incident.
DISASTER RECOVERY PLAN
The third and highest level of obtaining security knowledge that leads to career advancement is called ___?
This is broad and not necessarily focused on specific job tasks or assignments. More rigorous than awareness or training.
EDUCATION
A form of security protection that protects individual files by scrambling the contents in such a way as to render them unusable by unauthorized third parties is called ___?
FILE ENCRYPTION
A collection of multiple honey pots in a network for the purposes of luring and trapping hackers is called ___?
HONEYNET
A predefined procedure to react to security breaches to limit damage, contain the spread of malicious content, stop compromise of information, and promptly restore the environment to a normal state. This is called ___?
INCIDENT RESPONSE PLAN
The state or condition of an asset or process vitally important to the long-term existence and stability of an organization is called ___?
If this element is interrupted or removed, it often results in the failure of the organization.
MISSION-CRITICAL
Specialized host used to place an attacker into a system where the intruder cannot do any harm is called ___?
PADDED CELL
The guideline that all users should be granted only the minimum level of access and permission required to perform their assigned job tasks and responsibilities is called ___?
PRINCIPLE OF LEAST PRIVILEGE
A security guideline, procedure, or recommendation manual is called ___?
SECURITY TECHNICAL IMPLEMENTATION GUIDES (STIGS)
An administrative rule whereby no single individual possesses sufficient rights to perform certain actions is called ___?
Achieved by dividing administrative level tasks and powers among compartmentalized administrators.
SEPARATION OF DUTIES
The use of only a single element of validation or verification to prove the identity of a subject and considered much weaker than multi-factor authentication is called ___?
SINGLE-FACTOR AUTHENTICATION
The second level of knowledge distribution offered by an organization to educate users about job task focused security concerns is called ___?
More rigorous than awareness: less rigorous than education.
TRAINING
A dedicated microchip found on some motherboards that host and protect the encryption key for whole hard drive encryption is called ___?
TRUSTED PLATFORM MODULE (TPM)
A form of investigation that aims at checking whether or not a target system is subject to attack based on a database of test, scripts, and simulated exploits is called ___?
VULNERABILITY SCANNING
The process of encrypting an entire hard drive rather than just individual files is called ___?
In most cases, this provides better security against unauthorized access than file encryption, because it encrypts temporary directories and slack space.
WHOLE HARD DRIVE ENCRYPTION
- All of the following are examples of network security management best practices EXCEPT:
- Write a security policy
- Obtain senior management endorsement
- Filter Internet connectivity
- Provide fast response time to customers
- Implement defense-in-depth
Provide fast response time to customers
- All of the following are examples of network security management best practices EXCEPT:
- Avoid remote access
- Purchase equipment from a single vendor
- Use whole heard drive encryption
- Implement IPSec
- Harden internal and border devices
Purchase equipment from a single vendor
- All the following are examples of network security management best practices EXCEPT:
- Use multi-factor authentication
- Backup
- Have a business continuity plan
- Prioritize
- Spend each year’s budget in full
Spend each year’s budget in full
- A firewall host that fails and reverts to a state where all communication between the Internet and the DMZ is cut off displays a type of defense known as:
- Default permit
- Explicit deny
- Fail-close
- Egress filtering
- Security through obscurity
Fail-close
- The purpose of physical security access control is to:
- Grant access to external entities
- Prevent external attacks from coming through the firewall
- Provide teachable scenarios for training
- Limit interaction between people and devices
- Protect against authorized communications over external devices
Protect against authorized communications over external devices
- A complete and comprehensive security approach needs to address or perform two main functions, the first is to secure assets and the second is:
- Watch for violation attempts
- Prevent downtime
- Verify identity
- control access to resources
- Design the infrastructure based on the organization’s mission
Watch for violation attempts
- Incident response is the planned reaction to negative situations or events. Which of the following is NOT a common step or phase in an incident response?
- Containment
- Recovery
- Eradication
- Detection
- Assessment
Assessment
- All of the following are elements of an effective network security installation EXCEPT:
- Backup
- Recovery
- Eradication
- Detection
- Assessment
Assessment
- The task of compartmentalization is focused on as siting with what overarching security concern?
- Limiting damage caused by intruders
- Filtering traffic based on volume
- Controlling access based on location
- Supporting transactions through utilization
- Assess security
Limiting damage caused by intruders
- Which of the following types of security components are important to install on all hosts?
- Firewall
- Antivirus
- Whole hard drive encryption
- Spyware defense
- All the above
Firewall
Antivirus
Whole hard drive encryption
Spyware defense
- What is the only protection against data loss?
- Integrity checking
- Encryption
- Traffic filtering
- Backup and recovery
- Auditing
Backup and recovery
- All the following are common mistakes or security problems that should be addressed in awareness training EXCEPT:
- Opening email attachments from unknown sources
- Using resources from other subnets of which the host is not a member
- Installing unapproved software on work computers
- Failing to make backups of personal data
- Walking awry from a computer while still logged in
Using resources from other subnets of which the host is not a member
- The best network security management tools include all of the following EXCEPT:
- Complete inventory of equipment
- Written security policy
- Expensive commercial products
- Logical organization map
- Change documentation
Expensive commercial products
- The purpose of a security checklist is:
- To keep an inventory of equipment
- To create shopping list for replacement parts
- To ensure that all security elements are still effective
- To complete the security documentation for the organization
- To assess the completeness of the infrastructure
To ensure that all security elements are still effective
- Which of the following is NOT a potential hazard when installing patches or updates?
- Resetting configuration back to factory defaults
- Reducing security
- Bricking the device
- Installing untested code
- Improving resiliency against exploits
Improving resiliency against exploits
- Which of the following is a true statement in regards to compliance auditing?
- Compliance auditing is a legally mandated task for every organization
- Compliance auditing ensures that all best practices are followed
- Compliance auditing creates a security policy
- Compliance auditing is an optional function for the financial and medical industries
- Compliance auditing verifies that industry specific regulations and laws are followed
Compliance auditing verifies that industry specific regulations and laws are followed
- Which of the following is not typically considered a form of network security assessment in terms of how well existing security stands up to current threats?
- Configuration scan
- Compliance
- Vulnerability assessment
- Ethical hacking
- Penetration testing
Compliance
- Which of the following cannot be performed adequately using an automated tool?
- Checking for current patches
- Confirming configuration settings
- Vulnerability assessment
- Scanning for known weaknesses
- Ethical hacking
Ethical hacking
- What is the key factor that determines how valuable and relevant a vulnerability assessment’s report is?
- Timeliness of the database
- Whether the product is open sourced
- The platform hosting the scanning engine
- The time of day the scan is performed
- The available bandwidth on the network
Timeliness of the database
- What is the primary purpose of a post-mortem assessment review?
- Reducing costs
- Adding new tools and resources
- Placing blame on an individual
- Learning from mistakes
- Extending the length of time consumed by a task
Learning from mistakes
The procedure of watching for the release of new updates from vendors is called ___?
This includes testing the patches, obtain approval, then overseeing the deployment and implementation of updates across the production environment.
PATCH MANAGEMENT