Accounting Information Systems, 11e (Bodnar/Hopwood)
Chapter 6 Information Systems Security
1) An information security system has the basic elements of any information system: hardware,
software, databases, procedures, and reports.
2) The objective of the first phase of the security system life cycle is to design risk control
measures such as various security measures and contingency plans.
3) One of the duties of the CSO is to present reports to the board of directors for approval.
4) The CSO should report directly to the president of the organization.
5) Using the qualitative approach to risk assessment, each loss exposure is computed as the
product of the cost of an individual loss times the likelihood of its occurrence.
6) An information security threat is a potential exploitation of a vulnerability.
7) Computer security and information security mean the same thing.
8) Information security is broader in concept than computer security and deals with all
information, not just computerized information.
9) Information security management system is an internal control process and manages risk.
10) The ERM process is part of the information security management system.
11) ISO 27000 family of standards defines standards for building, operating, and maintaining
ISMSs.
12) ISO27001 includes 132 general security controls, organized under 11 topics and further
broken down into over 5000 detailed controls.
13) Passive threats include information systems fraud and computer sabotage.
14) System faults represent component equipment failures such as disk failures and power
outages.
15) All hackers are malicious.
16) White hat hackers legitimately probe systems for weaknesses in order to help with security
control procedures.
17) Black hat hackers formally probe systems for legitimate purposes in order to help with
security control procedures.
18) Social engineering is a form of manipulation of people in order to trick them into divulging
privileged information.
19) Pretexting and phishing are forms of social engineering.
20) Malware is short for malicious hardware that compromises the security of the victim’s
computer.
21) Malware can be hidden in email, downloaded software, disk or Web browser.
22) Hacker methods include social engineering, direct observation, electronic interception, and
exploits.
23) Direct observation includes shoulder surfing and piggybacking.
24) Direct observation includes shoulder surfing and dumpster diving.
25) In general, vulnerabilities arise from improperly installed or configured software and from
unforeseen defects or deficiencies in the software.
26) Three major groups of individuals that may attack information systems include information
personnel, users, and employees.
27) Three major groups of individuals that may attack information systems include information
personnel, users, and hackers.
28) Virtualization involves running multiple operating systems, or multiple copies of the same
operating system, all on the same machine.
29) Using cloud-based services and data storage is referred to as cloud computing.
30) Business continuity planning and disaster recovery, in general, mean the same thing.
31) In the health insurance sector, the Gramm-Leach-Bliley Act, requires federal agencies that
oversee the health insurance sector to implement regulatory standards aimed at protecting the
security of critical information resources.
32) GASB statement #34 requires utility companies to maintain business continuity plans.
33) Criminal Code 301.2(1) makes it a federal crime in the United States to knowingly and with
intent fraudulently gain unauthorized access to data stored in financial institution computers.
34) Intruders who attack information systems for fun and challenge are known as hackers.
35) Input manipulation is the least-used method in most cases of computer fraud.
36) A serious business problem today is the theft of data.
37) A trapdoor is a portion of a computer program that, upon detecting an intruder, “traps” the
intruder by activating a firewall to prevent unauthorized access to critical data.
38) Logic bombs are dormant pieces of code placed in programs for activation at a later date by a
specific event.
39) A worm is any type of Trojan that silently spreads from one computer to another over a
network, without the intervention of any individual or server.
40) Implementing security measures and contingency plans help to control computer information
threats.
41) In a denial of service attack, an intruder is denied access to an organization’s Web site after
the intruder attempts to break through its firewalls and proxy server countermeasures.
42) In most organizations, accounting, computing, and data processing are all organized under
the controller.
43) Employees should be laid off or terminated with the greatest care because terminated
employees account for a significant portion of all sabotage incidents.
44) With today’s excellent computer security software, it is no longer necessary to physically
separate unauthorized individuals from computer resources.
45) Software should not be installed on any computer without prior approval of security.
46) System-access controls prevent unauthorized individuals from physically accessing computer
resources.
47) The ideal password should consist of easy-to-remember names such as banana, kitty, IBM,
password, or Friday.
48) No password system is of much value unless the passwords themselves are protected.
49) A program kept in a locked file is one which can be run but not looked at (i.e., code) or
altered in anyway.
50) Fault tolerance can be applied at any of three levels: input, processing, or output.
51) An incremental backup backs up all files whose archive bit is set to 0 before termination of
the session.
52) The problem with Web server attacks is that the Web server is essentially an extension of the
operating system.
53) Studies have shown that 45% of all disasters are due to human error.
54) Escalation procedures state the conditions under which a disaster should be declared, who
should declare it, and whom that person should notify when executing the declaration.
55) The information security management system is an organizational ________ ________
________ that controls special risks associated with computer-based information systems.
56) The method of risk assessment for computer systems where system vulnerabilities and
threats are listed and subjectively ranked is known as the ________ approach.
57) The Treadway Commission has linked ________ ________ to computer crime.
58) The most sophisticated type of wire tapping is called ________.
59) The least common method used to commit computer fraud is ________ ________.
60) A defrauder may use ________ to cover up ________.
61) In computer environments, ________ control is especially important as there is often a
tendency to either overspend or spend on the wrong things.
62) ________ authentication systems identify individuals based on their fingerprints, hand sizes,
retina patterns, or voice patterns.
63) The distribution of ________ should be controlled by a formal, secure delivery system.
64) A security system where the user enters an identification number and the system responds
with a sign (i.e., code word) is known as a(n) ________ system.
65) ________ can be digitally signed in the same way that electronic messages are signed to
authenticate the identity of the source of the program.
66) Backing up files is not the same thing as ________ them.
67) A weakness in the ________ system is also likely to create a related weakness in ________
server security.
68) The best security ________ will not help if the system ________ do not enforce the policies.
69) An alternate site that contains the wiring, equipment, and very up-to-date back-up data and
software is a(n) ________ site.
70) The three objectives of information security are ________, ________, and ________.
71) Information security management system is an internal control process and manages
________.
72) Information security management system is part of the larger ________ risk management
process.
73) Instead of using the terms systems analysis, design, implementation, operation, evaluation,
and control, ISO 27001 uses the terms ________, ________, ________, and ________.
74) ________ ________ involves manipulating victims in order to trick them into divulging
privileged information.
75) ________ is a form of social engineering in which one impersonates another typically in a
phone call or electronic communication.
76) ________ is a form of social engineering which is aimed directly at tricking victims into
giving information, money, or other valuable assets to perpetrators.
77) ________ ________ includes unnoticed intruders, wiretrappers, piggybackers, impersonating
intruders, and eavesdroppers.
78) A(n) ________ cell phone is an exact and illegitimate copy of another cell phone, including a
copy of the internal SIM in order to intercept text and voice messages.
79) In general, ________ arise from improperly installed or configured software and from
unforeseen defects or deficiencies in the software.
80) ________ is the best defense against electronic interception.
81) Most financial institutions use ________ ________ layer encryption to communicate with
their clients through Web browsers.
82) ________ involves running multiple operating systems or multiple copies of the same
operating system on the same machine.
83) In virtualization, the individual operating system instances run under the control of a “master
program” called a(n) ________.
84) Within the health-care sector the ________ ________ Portability and Accountability Act
requires that health-care providers, insurance companies, and payment clearinghouses adopt
standardized processes for electronic payments and claims.
85) GASB statement number ________ requires utility companies to maintain business
continuity plans.
86) A significant benefit of the quantitative approach to risk assessment is that
A) often the most likely threat to occur is not the one with the largest exposure.
B) the relevant cost of the loss’s occurrence is an estimate.
C) the likelihood of a given failure requires predicting the future.
D) the approach estimates the costs and benefits to the perpetrators of attacks.
87) When the qualitative approach to risk assessment is used, costs might be estimated using
A) replacement costs.
B) service denial costs.
C) business interruption costs.
D) All of these answers are correct.
88) An extremely risk-seeking perpetrator
A) will offer his or her services to the “highest bidder.”
B) will take very large risks for a small reward.
C) is almost always a terminated employee of the organization he or she attacks.
D) will take small risks for small rewards.
89) A weakness in an information security system is
A) a threat.
B) computer sabotage.
C) a vulnerability.
D) a system fault.
90) Information security is an international problem. Which countries below have set criminal
penalties of up to 10 years for fraudulent use of computer services or the intentional changing of
a data processing record with the intent of enrichment?
A) Canada and Finland
B) Switzerland and Canada
C) Denmark and Finland
D) France and Germany
91) Which group of people listed below would not pose a high degree of threat to an
organization’s information system?
A) Systems personnel
B) Users
C) Intruders
D) External auditors
92) Which individual listed below is placed in a position of great trust, normally having access to
security secrets, files and programs?
A) Systems supervisor
B) Programmer
C) Computer maintenance person
D) Data control clerk
93) An intruder who intercepts legitimate information and replaces it with fraudulent information
is known as a
A) hacker.
B) wiretapper.
C) piggybacker.
D) spy.
94) The method used in most cases of computer fraud is
A) program alteration.
B) input manipulation.
C) data theft.
D) sabotage.
95) A defrauder substitutes his own version of a company’s master file for the real one. This
method of computer fraud is known as
A) direct file alteration.
B) data theft.
C) misappropriation of information resources.
D) Answers B and C above are both correct.
96) Sometimes computer programs are used to commit acts of sabotage. A destructive program
masquerading as a legitimate one is called a
A) logic bomb.
B) worm.
C) virus.
D) Trojan horse.
97) Sometimes computer programs are used to commit acts of sabotage. A computer program
that actually grows in size as it infects more and more computers in a network is known as a
A) Trojan horse.
B) logic bomb.
C) virus.
D) worm.
98) In an information security system, security measures focus on
A) correcting the effects of threats.
B) preventing and detecting threats.
C) management philosophy and operating style.
D) the internal audit function.
99) A form of sabotage in which very large numbers of requests flood a Web server within a
short time interval is known as a
A) denial of service attack.
B) logic bomb.
C) macro virus.
D) grid overload.
100) The most important personnel policy and practice regarding information systems security is
that
A) there should be adequate supervision of personnel at all times.
B) employees should be required to rotate jobs.
C) the duties of computer users and computer systems personnel should be segregated.
D) employees should be required to take vacations.
101) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. The second step behind the layered approach to access
control is to
A) prevent unauthorized access to both data and program files.
B) physically separate unauthorized individuals from computer resources.
C) classify all data and equipment according to their importance and vulnerability.
D) keep unauthorized users from using the system.
102) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. Withholding administrative rights from individual PC users
is an example of a
A) file access control.
B) system access control.
C) site access control.
D) None of these answers are correct.
103) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. Such an approach involves erecting multiple layers of
controls that separate the would-be perpetrator from his or her potential targets. One file-access
control system that will prevent unauthorized access is (are)
A) a password management system.
B) biometric hardware authentication.
C) locked files.
D) a firewall.
104) Controls can be designed to provide a defense from both active and passive threats. An
example of a passive threat is
A) a rolling blackout.
B) a Trojan horse.
C) an unhappy employee.
D) a password which has been compromised.
105) What is an example of fault tolerance applied at the transaction level?
A) Consensus-based protocols
B) Read-after-write checks
C) Database shadowing
D) Flagging
106) Disk shadowing is an example of a fault tolerance applied at what level?
A) Network communications
B) DASD
C) Transaction
D) CPU processor
107) An example of a fault tolerance at the network communications level is
A) a watchdog processor.
B) disk mirroring.
C) rollback processing.
D) an uninterruptable power supply.
108) Since many personal computer users do not properly back up their files, a system that
centralizes the backup process is essential. A backup of all files on a given disk is known as a(n)
A) full backup.
B) differential backup.
C) incremental backup.
D) emergency backup.
109) The type of backup which avoids the problems which arise from restoring incremental
backups is a(n)
A) full backup.
B) partial backup.
C) archive restoration.
D) differential backup.
110) One Internet security problem arises from configuration problems in the area of configuring
permissions for directories. This is an example of
A) an operating system vulnerability.
B) a Web server vulnerability.
C) a private network vulnerability.
D) server program vulnerability.
111) A Trojan horse program placed on one computer with the objective of attacking another
computer is an example of which Internet security vulnerability?
A) A Web server and its configuration
B) An operating system and its configuration
C) A private network and its configuration
D) A general security procedure
112) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. However, the widespread adoption and use of the Internet
has made it impossible to completely implement which layer of the layered-access approach to
security?
A) Site-access
B) System-access
C) File-access
D) None of these answers is correct.
113) The best general security procedure is
A) to use advanced information security system software.
B) for system administrators to enforce system security policies that already exist.
C) to isolate computer facilities from the rest of the company.
D) to eliminate access privileges to all remote users.
114) General security procedures are essential in Internet security. One especially important
weakness that hackers may attempt to exploit in this area is to
A) guess at passwords.
B) rewrite computer source code.
C) alter log files to “cover their tracks.”
D) steal the hard drives of personal computers used as Web servers.
115) Which item listed below is a weakness of using a firewall for Internet security?
A) IP addresses can be spoofed.
B) Firewalls can block incoming access on computer networks.
C) Firewalls can block outgoing access on computer networks.
D) Firewalls can be set to only allow limited outgoing access to particular programs or servers.
116) Disaster risk management is concerned with
A) the prevention of disasters.
B) the layered-access approach to security.
C) contingency planning.
D) Answers A and C are both correct.
117) The first step in managing disaster risk is
A) to obtain business interruption insurance.
B) disaster prevention.
C) contingency planning.
D) to analyze and list recovery priorities.