Quiz 6
A ______ is a network of hijacked computers (often referred to as zombies).
botnet
Man in the middle attacks are used to ______.
attack public key encryption systems
John the hacker discovers a vulnerability in a microsoft software. Microsoft releases a
patch 24 hours after the vulnerability is discovered. A hack that occurs between the time
the vulnerability was discovered and the time the patch was released is referred to as a
_____.
zero-day attack
Computers that are part of a botnet and are controlled by a bot herder are referred to as
zombies.
The call to tech support was fairly routine. A first-time computer user had purchased a
brand new PC two months ago and it was now operating much more slowly and sluggishly
than it had at first. Had he been accessing the Internet? Yes. Had he installed any “free”
software? Yes. The problem is likely to be a(an)
virus.
Gaining control of someone else’s computer to carry out illicit activities without the
owner’s knowledge is known as
hijacking.
A set of unauthorized computer instructions in an otherwise properly functioning program
is known as a
Trojan horse
A ________ is similar to a ________, except that it is a program rather than a code
segment hidden in a host program.
worm; virus
Illegally obtaining and using confidential information about a person for economic gain is
known as
identity theft
The unauthorized use of special system programs to bypass regular system controls and
perform illegal act is called
superzapping
Quiz 7
___ make sure transactions are processed correctly
Application controls
______ make sure an organization’s control environment is stable and well managed
General controls
Independent checks on performance to insure transactions are processed accurately include
all of the following except
archiving of all financial records
A ________ is created to guide and oversee systems development and acquisition
steering committee
A(n) ________ helps employees act ethically by setting limits beyond which an employee
must not pass
boundary system
Go-Go Corporation, a publicly traded company, has three brothers who serve as President,
Vice President of Finance and CEO. This situation
increases the risk associated with an audit
Which of the following is an independent check on performance
The General Manager compares budgeted amounts with expenditure records from all
departments
Duplicate checking of calculations is an example of a ________ control, and procedures to
resubmit rejected transactions is an example of a ________ control
detective; corrective
The definition of the lines of authority and responsibility and the overall framework for
planning, directing, and controlling is laid out by the
organizational structure
What is not a corrective control procedure
Deter problems before they arise
Quiz 8
An example of a Preventive control is:
training
In the time-based model of security (P>D+C):
NOT Decreases in P heighten security
I think it’s:
Increases in P or decreases in D and C heighten security.
An example of a Corrective control is:
patch management
Which of the following preventive controls are necessary to provide adequate security for
social engineering threats?
Awareness training
This is used to identify rogue modems (or by hackers to identify targets).
War dialing
In recent years, many of the attacks carried out by hackers have relied on this type of
vulnerability in computer software.
Buffer overflow
A well-known hacker started his own computer security consulting business shortly after
being released from prison. Many companies pay him to attempt to gain unauthorized
access to their network. If he is successful, he offers advice as to how to design and
implement better controls. What is the name of the testing for which the hacker is being
paid?
Penetration test
The most common input-related vulnerability is
buffer overflow attack.
This protocol specifies the structure of packets sent over the internet and the route to get
them to the proper destination.
Internet protocol
Information technology managers are often in a bind when a new exploit is discovered in
the wild. They can respond by updating the affected software or hardware with new code
provided by the manufacturer, which runs the risk that a flaw in the update will break the
system. Or they can wait until the new code has been extensively tested, but that runs the
risk that they will be compromised by the exploit during the testing period. Dealing with
these issues is referred to as
patch management.
Which of the following statements regarding COBIT is false?
COBIT is not sufficiently detailed to comply with SOX requirements.
In which of the COBIT domains would the activity “Define a strategic plan” reside?
Plan and Organize
In which of the COBIT domains would the activity “Ensure system security” reside?
Deliver and Support
This is an authorized attempt by an internal audit team or an external security consultant to
attempt to break into the organization’s information system.
Penetration test
When new employees are hired by Folding Squid Technologies, they are assigned user
names and passwords and provided with laptop computers that have an integrated
fingerprint reader. In order to log in, the user’s fingerprint must be recognized by the
reader. This is an example of a(an)
biometric device.
Which of the following preventive controls are necessary to provide adequate security for
social engineering threats?
Awareness training
Meaningful Discussions is a social networking site that boasts over a million registered
users and a quarterly membership growth rate in the double digits. As a consequence, the
size of the information technology department has been growing very rapidly, with many
new hires. Each employee is provided with a name badge with a photo and embedded
computer chip that is used to gain entry to the facility. This is an example of a(an)
NOT authorization control.
Answer is:
authentication control.
Restricting access of users to specific portions of the system as well as specific tasks, is
authorization.
The Trust Services Framework reliability principle that states that users must be able to
enter, update, and retrieve data during agreed-upon times is known as