5) Which domain covers security for the electrical transmission of data through analog or digital
transmission media?
A) Security architecture and design
B) Telecommunications
C) Application security
D) Cryptography
6) Which of the following is NOT a network access point?
A) Keyboard
B) Bridge
C) Computer
D) Router
7) Which of the following firewalls destroys suspicious messages?
A) Low-level security firewall
B) Medium-level security firewall
C) High-level security firewall
D) Proxy firewall
8) Which access control threat uses programs or devices that examine traffic on the enterprise
network?
A) Network sniffers
B) Phishing
C) Identify theft
D) Spoofing at log-on
9) The company where you work is opening offices in another state. Because the manager of the
new office is determined to keep costs down, she does not want to purchase additional firewall
software for the routers and bridges being installed behind the corporate firewall. The IT
department has asked you for help. Prepare a memo explaining the need for additional firewalls.
10) What is a honeypot and why is it used?
1) A ________ is a hardware device containing a password generator protocol that creates a new
password each time the token is used.
2) Which access control threat are programs or devices that examine traffic on the enterprise
network?
A) Password attack
B) Network sniffer
C) Identify theft
D) Spoofing at log-on
3) Which authentication method involves analyzing the user’s retina?
A) Single sign-on
B) Biometrics
C) Token device
D) Dynamic password
4) List and define five access control threats.
1) ________ controls ensure that reports and messages reach intended recipients.
2) Operations security refers to
A) Security for access to the enterprise system, including computers, networks, routers, and
databases
B) Security for telecommunications, networks, and the Internet
C) The physical security of information technology components, such as hardware and software
D) Activities and procedures required to keep information technology running securely
3) IT security management responsibility includes
A) Developing contingency plans for virus attacks
B) Input/output controls
C) Maintaining security devices and software
D) Training to all employees to inform and educate them regarding security policies and
procedures
1) Physical security frameworks are useful to provide guidance on how to secure the physical
facilities, grounds, and IT assets.
2) The physical and environmental security domain addresses
A) Activities and procedures required to keep information technology running securely
B) The physical security of information technology components, such as hardware and software
C) Security for telecommunications, networks, and the Internet
D) Security for access to the enterprise system, including computers, networks, routers, and
databases
3) Which of the following is NOT considered a deterrent to the physical access to corporate
offices?
A) GPS tracking
B) Locked doors
C) Fences
D) Cameras
4) What is the purpose of a physical security framework? Provide examples of physical security.
1) A user with specialized knowledge cannot use partial database access to gain full access to a
database.
2) ________ are tiny pieces of programming code that install themselves on an infected
computer called a Zombie.
Match the malware with the appropriate definition.
A) Code is disguised as a legitimate program, that can be downloaded and installed by users
without realizing it is malware
B) A relatively small program that infects other application software by attaching to it and
disrupting application function
C) Tiny piece(s) of programming code that install themselves on the infected computer called a
Zombie
D) Similar to a virus except it does not need a host application to function or reproduce
E) Software executes when a specified event happens within the computer
3) Viruses
Diff: 2
Objective: Q11.9 What is application security?
4) Bots
Diff: 2
Objective: Q11.9 What is application security?
5) Worms
Diff: 2
Objective: Q11.9 What is application security?
6) Logic Bomb
Diff: 2
Objective: Q11.9 What is application security?
7) Trojan horse
Diff: 2
Objective: Q11.9 What is application security?
8) What is a denial-of-service attack?
A) A hacker tracks customer transactions and steals customer payments or redirect goods to a
different shipping address.
B) A hacker uses the e-commerce client application to access the enterprise’s financial system for
fraudulent purposes.
C) A hacker overloads the enterprise’s bandwidth, effectively shutting down the Web site.
D) A hacker defaces a company’s Web site.
20
9) Which type of malware executes when a specific event happens within the computer?
A) Logic bombs
B) Bots
C) Trojan horses
D) Worms
10) The company where you work was recently the victim of a logic bomb. The company has a
policy against connecting flash drives, writable CDs/DVDs, etc. and had even had the ports and
drives for those devices removed from employees computers. The CFO does not understand how
the malware appeared within the company given these preventative measures and wonders what
other threats may already be on the network. Prepare a report on the various types of malware,
how they may gain access to the corporate network, and how the company can protect against
this type of attack.
Objective 10
1) A warm site is a commercial disaster recovery service that can be leased by an enterprise to
provide IT services in the event of a disaster that can be fully operational in a few hours.
2) A commercial disaster recovery service that provides IT services and can be fully operational
is a few hours is which type of back up facility?
A) Warm site
B) Cold site
C) Internal site
D) Hot site
3) Explain the Grandfather-Father-Son method of backing up data.
4) List and describe five types of backup facilities.
Objective 11
1) The encryption process is accomplished using an key and a algorithm. An key is a finite series
of steps to accomplish an objective. The algorithm is a value or method that converts the plain
text into cipher text.
2) Encryption is a useful tool for protecting data in transit and stored in databases.
3) Encryption is a method of converting plain text data into an unreadable form called ________.
4) The encryption method ________ uses two keys with one key used to encode and a second
related, but different, key to decode the message.
5) The encryption method ________ combines symmetric and asymmetric cryptography.
Match the encryption method with the appropriate number of keys used.
A) 3 keys
B) 4 keys
C) 2 keys
D) 1 key
6) Symmetric cryptography
Diff: 2
Objective: Q11.11 What is the cryptography?
7) Asymmetric cryptography
Diff: 2
Objective: Q11.11 What is the cryptography?
8) Digital envelope
Diff: 2
Objective: Q11.11 What is the cryptography?
9) Which key is used by an algorithm to scramble the data?
A) Transposition key
B) Primary key
C) Product key
D) Substitution key
10) Which of the following is a combination of two encryption keys?
A) Transposition key
B) Product key
C) Foreign key
D) Substitution key
11) List three encryption methods. Briefly describe how they work.
12) List and describe three types of encryption keys.
1) The IT used in an enterprise can actually create vulnerabilities to cyberattacks on its
confidential accounting data.
2) New IT security technology
A) Is usually worth the investment
B) Is less vulnerable to cyberattacks
C) May create vulnerabilities and risks to confidential data contained in the accounting system
D) Are usually reliable enough to adequately safeguard accounting data
1) COBIT provides high-level strategic guidance for meeting overall internal control objectives.
2) COSO provides a code of practice for information security management.
3) In the COBIT framework, which IT resource category consists of manual and programmed
procedures to process information?
A) Infrastructure
B) Applications
C) People
D) Information
4) Which IT process domain, as defined by COBIT, relates to IT strategy and tactics to
contribute to attaining business goals?
A) Plan and Organize (PO) Domain
B) Deliver and Support (DS) Domain
C) Acquire and Implement (AI) Domain
D) Monitor and Evaluate (ME) Domain
5) Which IT process domain, as defined by COBIT, encompasses IT operations, security, and
training?
A) Plan and Organize (PO) Domain
B) Deliver and Support (DS) Domain
C) Acquire and Implement (AI) Domain
D) Monitor and Evaluate (ME) Domain
6) Which of the following is NOT part of the information criteria as defined by COBIT?
A) Integrity
B) Scalability
C) Availability
D) Confidentiality
7) The COSO internal control component Information and Communication usually maps to
which COBIT domain for IT processes?
A) PO2 Define the information architecture
B) PO1 Define a strategic IT plan
C) PO4 Define the IT processes, organization, and relationships
D) PO9 Assess and manage IT risks
8) List and describe the IT resources categories as defined by COBIT.