Chapter 14 – Ongoing Security Management
TRUE/FALSE
1. Network protection is something you should implement initially and then only make changes if there is
a serious security breach.
2. One of the events you should continually monitor is logins.
3. In centralized data collection, data from sensors go to security managers at each corporate office.
4. Most IDPSs use random ports to transfer security data, thereby making it difficult for attackers to
exploit.
5. Change management should be used before making changes to firewall or IDPS rules that affect users.
6. Security auditing is the process of documenting countermeasures put in place due to attacks on the
network.
7. An operational audit looks for accounts that have weak or blank passwords.
8. Nonrepudiation is the use of encryption methods to ensure the confidentiality of data.
9. An IDPS must have enough memory to maintain connection state information.
10. Since system intrusions take place over a very short period of time, there is no need to maintain IDPS
log data for more than a few hours.
MULTIPLE CHOICE
1. Which of the following is NOT typically an aspect of a security event management program?