Chapter 3: Computer and Internet Crime
53. A is defined as an exploit that takes place before the security community or software developer knows about
the vulnerability or has been able to repair it.
a. logic bomb b. DDoS attack
c. zero-day attack d. rootkit
54. is the act of fraudulently using email to try to get the recipient to reveal personal data.
a. Pharming b. Phishing
c. Spamdexing d. Flyposting
55. is the sending of fraudulent emails to an organization’s employees designed to look like they came from high-
level executives from within the organization.
a. Spamdexing b. Vishing
c. Smishing d. Spear-phishing
56. are poorly trained and inadequately managed employees who mean well but have the potential to cause much
damage.
a. Whistleblowers b. Negligent insiders
c. Malicious insiders d. Industrial spies
57. A(n) works by using the Internet to relay communications; it maintains privacy through security procedures
and tunneling protocols, which encrypt data at the sending end and decrypt it at the receiving end.
a. firewall b. social network
c. intrusion detection device d. virtual private network
58. Before the IT security group can begin an eradication effort, it must .
a. seek permission of the firm’s legal counsel b. collect and log all possible criminal evidence from the system
c. consider the potential for negative publicity d. develop an estimate for the monetary damage caused
59. Technically, a(n) is a piece of programming code, usually disguised as something else, that causes a computer
to behave in an unexpected and usually undesirable manner.
a. virus b. operating system
c. zombie d. CAPTCHA