100) The most important personnel policy and practice regarding information systems security is
that
A) there should be adequate supervision of personnel at all times.
B) employees should be required to rotate jobs.
C) the duties of computer users and computer systems personnel should be segregated.
D) employees should be required to take vacations.
101) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. The second step behind the layered approach to access
control is to
A) prevent unauthorized access to both data and program files.
B) physically separate unauthorized individuals from computer resources.
C) classify all data and equipment according to their importance and vulnerability.
D) keep unauthorized users from using the system.
102) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. Withholding administrative rights from individual PC users
is an example of a
A) file access control.
B) system access control.
C) site access control.
D) None of these answers are correct.
103) The primary way to prevent active threats concerning fraud and sabotage is to implement
successive layers of access controls. Such an approach involves erecting multiple layers of
controls that separate the would-be perpetrator from his or her potential targets. One file-access
control system that will prevent unauthorized access is (are)
A) a password management system.
B) biometric hardware authentication.
C) locked files.
D) a firewall.