118) Which of the following causes of disasters occurs less than any other cause?
A) Natural disasters
B) Human errors
C) Deliberate actions
D) Passive threats
119) A disaster recovery plan should include
A) a list of priorities for recovery.
B) an evaluation of a company’s needs in the event of a disaster.
C) a set of recovery strategies and procedures.
D) All of these answers are correct.
120) One recovery strategy in the event of a disaster is an alternative processing arrangement. An
arrangement between two companies in which each company agrees to help the other if the need
arises is a(n)
A) commercial vendor arrangement.
B) computer service bureau agreement.
C) shared contingency arrangement.
D) alternate site center.
121) A company which specializes in processing the data of other companies, but not its own, is
a(n)
A) computer service bureau.
B) commercial vendor of disaster services.
C) emergency response center.
D) flying-start site.
122) The possibility of losing employees to a disaster should be addressed in
A) a salvage plan.
B) an alternative processing arrangement.
C) the personnel replacement plan.
D) the personnel relocation plan.
123) One recovery strategy in the event of a disaster is an alternative processing arrangement
using a backup site. A site which contains the wiring for computers and also having the
equipment is a
A) cold site.
B) hot site.
C) flying-start site.
D) service bureau.
124) Which of the following is an ideal password?
A) ABC123
B) DOG&bone
C) sky&CAT
D) 2s&Ytc8x
125) If users are permitted to choose their own passwords, the best procedure is to
A) forbid users from choosing certain “easy-to-guess” passwords.
B) forbid users to change their passwords later.
C) allow users to choose passwords they can easily remember.
D) allow users to choose the appropriate expiration date for their passwords.
126) A flying-start site
A) is the most commonly adopted option for companies with disaster recovery plans.
B) usually cannot be made operational within 24 hours.
C) involves mirroring of transactions at the primary site, followed by transmission of data to the
backup site.
D) is arranged through a service bureau.
127) After a planning committee has been appointed and the support of senior management has
been obtained, the first step in designing a disaster recovery plan is
A) determining what computer-related resources are critical.
B) naming an emergency response team.
C) finding a suitable alternative processing site to use in an emergency.
D) listing the company’s recovery priorities.
128) Sandra Johnson is her company’s chief security officer. She is interested in obtaining fault
tolerance at the direct-access storage device level. Which of the following methods would be of
most interest to her?
A) Rollback processing
B) Disk mirroring
C) Consensus-based protocols
D) Database shadowing
129) The best way to test the integrity of a computer system is to
A) review all system output thoroughly.
B) review all system input thoroughly.
C) sample the system’s actual transactions.
D) process hypothetical transactions through the system.
130) To detect unauthorized direct changes to master files, the auditor traces these changes back
to the underlying
A) transaction files.
B) source documents.
C) hypothetical transactions.
D) control account balances.
131) A type of processing that writes a transaction to disk only if it has been completed
successfully is
A) rollback processing.
B) disk mirroring.
C) fault-tolerant processing.
D) read-after-write checking.
132) The most basic security procedure in system-access controls is the
A) sign-countersign system.
B) identification of the user’s ID, time, and date of each entry.
C) user’s responsibility to protect his or her password.
D) system’s assignment of the user ID and password.
133) Jennifer Nguyen is interested in archiving several data files. She should
A) use a full backup for each file.
B) use an incremental backup for each file.
C) store the data files on media suitable for long-term storage.
D) use a differential backup for each file and restore each file.
134) The ________ makes it a federal felony for anyone other than law enforcement or
intelligence officers to pretext phone records.
A) Computer Fraud and Abuse Act of 1986
B) Telephone Records and Privacy Protection Act of 2006
C) Gramm-Leach-Bliley Act
D) Health Insurance Portability and Accountability Act
135) The three objectives of information security include
A) confidentiality, integrity, and availability.
B) protection, responsibility, and continuity.
C) confidentiality, protection, and continuity.
D) responsibility, integrity, and availability.
136) The information security management system life cycle includes analysis, design,
implementation, and
A) operation, evaluation, and management.
B) operation, evaluation, and control.
C) operation, management, and continuity.
D) operation, control, and continuity.
137) Guidelines and standards that are important to Information Security Management Systems
include all the following except
A) COSO.
B) COBIT.
C) ERM.
D) ISO 27000 series.
138) The ISO series number that defines a code of best practices for ISMSs is
A) 27000.
B) 27001.
C) 27002.
D) 27003.
139) The ISO series numbers that define implementation, measuring performance, and risk
management for ISMSs include
A) 27000-27002.
B) 27003-27005.
C) 27006-27008.
D) 27001-27008.
140) Hackers can be categorized as white, black, or ________ hat hackers.
A) gray
B) green
C) top
D) None of these answers is correct.
141) Hacker methods include all of the following except
A) social engineering.
B) direct observation.
C) electronic interception.
D) continuity prevention.
142) Examples of social engineering include
A) pretexting and phishing.
B) pretexting and direct observation.
C) phishing and direct observation.
D) pretexting, phishing, and direct observation.
143) Viruses and denial of service attacks are examples of
A) electronic interception.
B) spyware.
C) malware.
D) exploits.
144) The ________ makes it a federal crime, with a mandatory prison sentence, to pretext any
kind of information that relates to a relationship between a consumer and a financial institution.
A) Computer Fraud and Abuse Act of 1986
B) Telephone Records and Privacy Protection Act of 2006
C) Gramm-Leach-Bliley Act
D) Health Insurance Portability and Accountability Act
145) When a hacker takes advantage of a vulnerability to access the software, hardware, or data
in an unauthorized manner a(n) ________ has occurred.
A) exploit
B) vector
C) exposure
D) virtualization
146) In general, ________ arise from improperly installed or configured software and from
unforeseen defects or deficiencies in the software.
A) exploits
B) virtualizations
C) vulnerabilities
D) exposures
147) Sabotage is a(n) ________ threat.
A) active
B) passive
C) direct
D) second layer
148) Input ________ is an example of a system attack method.
A) vector
B) manipulation
C) hacking
D) buffer
149) ________ involves running multiple operating systems, or multiple copies of the same
operating system, all on the same machine.
A) Hypervisor
B) Business continuity planning
C) Virtualization
D) Subscriber Identity Module (SIM)
150) All software and data is stored by the SaaS provider in the
A) hypervisor.
B) cloud.
C) stars.
D) grid.
151) ________ computing involves clusters of interlinked computers that share common
workloads.
A) Grid
B) Cloud
C) Networked
D) Malware
152) Which of the following forms of social engineering involves impersonation?
A) Contexting
B) Phishing
C) Hypervising
D) Pretexting
153) Botnets are normally used for which of the following?
A) Grid computing
B) Denial of service attacks
C) Continuity planning
D) Cloud computing
154) Adware is a type of
A) virus.
B) logic bomb.
C) spyware.
D) Trojan horse.
155) On the local workstation, cloud computing
A) complicates security considerations.
B) simplifies security considerations.
C) is not involved with security considerations.
D) affects security minimally but still must be considered under ISO 27000.
156) In the following, which source of information security frameworks or standards targets
managers rather than IP professionals?
A) COSO
B) ISMS
C) COBIT
D) ISO
157) Presented below is a list of terms relating to accounting information systems, followed by
definitions of those terms.
Required: Match the letter next to each definition with the appropriate term. Each answer will be
used only once.
________ 1. Biometric hardware authentication
________ 2. Archive bit
________ 3. Trapdoor
________ 4. Consensus-based protocol
________ 5. Hacker
________ 6. Fault tolerance
________ 7. Locked files
________ 8. Service bureau
________ 9. System fault
A. The concept that if one part of the computer fails, a redundant part is available to take over
B. This generally cannot be prevented by appropriate wall shielding
C. Systems that automatically identify individuals based on their fingerprints, hand sizes, retina
patterns, voice patterns, and other personal features
D. This type of system requires an odd number of processors
E. A program can be run but not looked at or altered
F. A company that provides data processing services to other companies for a fee
G. A type of intruder or attacker
H. A portion of the computer program that allows someone to access a system while bypassing
normal security procedures
I. This would include hard disk crashes, power failures, or printer jams
J. Commonly used in backup systems to indicate whether a file has been altered
158) Presented below is a list of terms relating to accounting information systems, followed by
definitions of those terms.
Required: Match the letter next to each definition with the appropriate term. Each answer will be
used only once.
________ 1. Database shadowing
________ 2. Logic bomb
________ 3. Information security system
________ 4. Risk management
________ 5. File-access controls
________ 6. Site-access controls
________ 7. Piracy
________ 8. Incremental backup
________ 9. Piggybacking
________ 10. Risk-seeking perpetrator
A. Prevents unauthorized access to both data and program controls
B. A duplicate of all transactions is automatically recorded
C. All files whose archive bit is set to 1 are backed up
D. One who will take risks “just because,” without significant monetary gain
E. A dormant piece of code placed in a computer program for later activation by a later event
F. The copying and distributing of copyrighted software or files without permission
G. The process of assessing and controlling computer system risks
H. The interception of legitimate information and substitution of fraudulent information in its
place
I. The subsystem of the organization that controls these risks
J. These separate unauthorized individuals from computer resources
159) Your company has been rapidly growing and increasing in profitability for the past five
years. Suddenly, a new, smaller company has appeared, and it seems to have an uncanny ability
to win away your previously loyal customers. You know that the owner of the new company is
your company’s former employee. You suspect the former employee has continued to access
your databases.
Required:
a. Identify and briefly discuss the method that the former employee is likely using to access the
system.
b. Recommend three controls your company could employ to address this problem.
160) You’ve been hired as the chief security officer of your company. Before long, you learn that
one of the operators has been making changes to the accounts receivable database. Upon this
discovery, the employee is immediately terminated.
Required:
List three procedures that you should implement to prevent this problem from happening in the
future.
161) You are the chief security officer for the Astra Corporation. You have decided that the risk
of viruses is too great to allow employees to install and run games on the company’s computer
system.
Required:
a. What types of controls are required, and what is the objective of the required controls?
b. List three procedures that you can implement to guard against the unauthorized installation of
software (and the inadvertent installation of viruses) on company computers.
162) New Millennium Company is concerned about the security of its information system. It
hosts a company Web site that is accessible through the Internet. Certain employees can access
New Millennium’s private network through the Internet as well. Employees can also access the
Internet through the private network. The chief security officer for the company is worried about
hackers and intruder attacks on both its Web site as well as the private network.
Required:
a. What Internet-related vulnerabilities may be present in New Millennium’s information system?
b. What procedures or steps might be implemented to strengthen system security?
163) Describe the similarities and differences between a quantitative and a qualitative approach
to computer risk assessment.
164) Give four factors that are important to a company’s control environment in the area of
computer security, and illustrate each with an example.
165) When devising its disaster recovery plan, a company should have a detailed set of recovery
strategies and procedures. What are five considerations that should be covered by the company’s
recovery strategies and procedures?
166) Discuss how U.S. law has addressed the issue of information systems fraud.
167) Discuss the information security system life cycle.
168) The main group of international standards for information security is ISO/IEC 27000 series
published by the International Organization for Standardization (ISO). ISO/IEC 27002 addresses
over 5,000 controls categorized under 12 categories. Discuss 10 of the 12 categories that should
be used as a general guide by any company considering information security.
169) COBIT is a framework that defines a set, or code, of best practices. Discuss the 4 domains
within the COBIT standard.
170) Describe the security advantage of virtualization.