D. The problems associated with this risk analysis are the unreliability and
inaccuracy of the data.
Item number 44
Chapter 4: Governance and Risk Management
Section: Quantitative Risk Analysis
Item type: Multiple Choice
Question: How is annualized loss expectancy computed?
Options:
A. The probability of an event occurring multiplied by the likely loss it would incur
B. The probability of an event occurring multiplied by the existing vulnerabilities
C. The probability of an event occurring divided by the existing threats
D. The probability of an event occurring divided by the existing controls
Item number 45
Chapter 4: Governance and Risk Management
Section: Qualitative Risk Analysis
Item type: Multiple Choice
Question: Which of the following best describes recovery controls?
Options:
A. Reduce the likelihood of a deliberate attack.
B. Restore lost computer resources or capabilities.
C. Reduce the effect of an attack.
D. Discover attack and trigger preventive or corrective controls.
Item number 46
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements best describes data hiding?
Options:
A. Mechanism used to ensure that information available at one processing level is
not available at another level.
B. A process operation that is divided into layers by function.
C. The process of segmenting the memory into protected segments.
D. A design objective in which each process has its own address space.
Item number 47
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements best describes layering?
Options:
A. Mechanism used to ensure that information available at one processing level is
not available at another level
B. A process operation that is divided into layers by function
C. The process of segmenting the memory into protected segments
D. A design objective in which each process has its own address space
Item number 48
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Magnetic tape is an example of which of the following?
Options:
A. Primary storage
B. Virtual memory
C. Sequential storage
D. Volatile memory
Item number 49
Chapter 5: Security Architecture and Design
Section: Confidentiality and Integrity Models
Item type: Multiple Choice
Question: Which of the following statements about the Biba integrity model is true?
Options:
A. It is an integrity model.
B. It is an availability model.
C. It simplifies analysis of covert channels.
D. It uses read-up, write down approach.
Item number 50
Chapter 5: Security Architecture and Design
Section: Confidentiality and Integrity Models
Item type: Multiple Choice
Question: Which of the following statements best describes the Biba integrity model?
Options:
A. Subjects can read objects at a lower level but cannot write to objects at a higher
level.
B. Subjects can’t read objects at a lower level but can write to objects at a higher
level.
C. Subjects can read objects at a lower level and can write to objects at a higher
level.
D. Subjects can’t read objects at a lower level and can’t write to objects at a higher
level.
Item number 51
Chapter 5: Security Architecture and Design
Section: The Federal Criteria for Information Technology Security
Item type: Multiple Choice
Question: Which of the following security evaluation criteria was developed jointly by
NIST and NSA?
Options:
A. The Federal Criteria for Information Technology Security
B. The Trusted Computer System Evaluation Criteria
C. The Information Technology Security Evaluation Criteria
D. The Common Criteria
Item number 52
Chapter 5: Security Architecture and Design
Section: The Common Criteria
Item type: Multiple Choice
Question: Which of the following statements about the Common Criteria is true?
Options:
A. It’s referred to as The Orange Book.
B. It was jointly developed by NIST and NSA.
C. It’s an international standard that provides a common language and structure to
define IT security requirements.
D. It is a European-developed criterion of security standards.
Item number 53
Chapter 5: Security Architecture and Design
Section: Evaluation Assurance Levels
Item type: Multiple Choice
Question: How many evaluation assurance levels are part of the Common Criteria?
Options:
A. Four
B. Five
C. Six
D. Seven
Item number 54
Chapter 5: Security Architecture and Design
Section: Rings of Trust
Item type: Multiple Choice
Question: Which of the following statements about rings of trust on a standalone system
is true?
Options:
A. Outer rings contain a higher level of security.
B. Inner rings contain a lower level of security.
C. Systems requiring a higher level of security are placed in the inner rings.
D. Systems requiring a higher level of security are placed in the outer rings.
Item number 55
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following is a process that defines a specific set of permissible
values for an object and operations for that object?
Options:
A. Layering
B. Abstraction
C. Data hiding
D. Hardware segmentation
Item number 56
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements best describe multitasking?
Options:
A. Running two or more programs at a time
B. Running two or more tasks at a time
C. Running two tasks one after another
D. Running two programs one after another
Item number 57
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Running two or more programs simultaneously is called which of the
following?
Options:
A. Multitasking
B. Multiprocessing
C. Multithreading
D. Multiprogramming
Item number 58
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements best describes primary storage?
Options:
A. Stores data on a page/swap file on a disk
B. The computer main memory that is volatile and directly addressable by the CPU
C. Nonvolatile storage format that can store data, applications, and system code
D. Computer memory that is accessed sequentially
Item number 59
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements best describes secondary storage?
Options:
A. Stores data on a page/swap file on a disk
B. The computer main memory that is volatile and directly addressable by the CPU
C. Nonvolatile storage format that can store data, applications, and system code
D. Computer memory that is accessed sequentially
Item number 60
Chapter 5: Security Architecture and Design
Section: Protection Mechanisms in a TCB
Item type: Multiple Choice
Question: Which of the following statements about primary storage is true?
Options:
A. Primary storage is the same as virtual memory.
B. Primary storage is volatile.
C. Primary storage is a storage format that can store data and application when the
system in not in use.
D. Primary storage is memory that is access sequentially.
Item number 61
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Overview of the Business Continuity Plan and Disaster Recovery Plan
Item type: Multiple Choice
Question: Which of the following best describes business impact analysis?
Options:
A. Evaluates risks to the organization and prioritizes the systems that will be used
for recovery
B. Describes the critical processes, procedures, and personnel that must be
protected in an event of an emergency
C. Describes the exact steps and procedures that should be followed to recover
critical business systems in the event of a disaster
D. Determines the cost of continuous operation and the value of each service
Item number 62
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Using Alternate Sites
Item type: Multiple Choice
Question: A cold site provides which of the following?
Options:
A. Hardware systems
B. Software systems
C. Power and air conditioning systems
D. The servers
Item number 63
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Using Alternate Sites
Item type: Multiple Choice
Question: Which of the following alternate sites provides all the services needed to
continue running the business without interruption?
Options:
A. Cold site
B. Warm site
C. Hot site
D. Mobile site
Item number 64
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Testing the DRP
Item type: Multiple Choice
Question: Which of the following statements about full interruption tests is true?
Options:
A. It is considered a true/false test.
B. It is a passive type of test.
C. During the test key personnel performs a dry run of the emergency.
D. Backup processing occurs in parallel with production services that never stop.
Item number 65
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Testing the DRP
Item type: Multiple Choice
Question: Which of the following statements about checklists testing is true?
Options:
A. It is considered a true/false test.
B. It is a passive type of test.
C. During the test key personnel performs a dry run of the emergency.
D. Members of the key business units meet to trace their steps through the plan.
Item number 66
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Testing the DRP
Item type: Multiple Choice
Question: Which of the following DRP tests is typically done as the first step toward a
more comprehensive testing?
Options:
A. Simulations
B. Walk-throughs
C. Full interruption
D. Parallel testing
E. Checklists
Item number 67
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Testing the DRP
Item type: Multiple Choice
Question: Which of the following statements best describes the walk-through test of the
DRP?
Options:
A. Members of key departments perform a dry run of the emergency.
B. Members of key departments trace their steps through the plan checking for
omissions and inaccuracies.
C. Members of key departments check off the tasks for which they are responsible.
D. Backup processing run simultaneously with the production services.
E. Production systems are stopped to evaluate how backup systems perform.
Item number 68
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Testing the DRP
Item type: Multiple Choice
Question: Which of the following statements best describes a full-interruption test of the
DRP?
Options:
A. Members of key departments perform a dry run of the emergency.
B. Members of key departments trace their steps through the plan checking for
omissions and inaccuracies.
C. Members of key departments check off the tasks for which they are responsible.
D. Backup processing run simultaneously with the production services.
E. Production systems are stopped to evaluate how backup systems perform.
Item number 69
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Making Additional Arrangements
Item type: Multiple Choice
Question: Which of the following provides backup processing at a remote location?
Options:
A. Cold sites
B. Service bureaus
C. Mobile sites
D. Warm sites
Item number 70
Chapter 6: Business Continuity Planning and Disaster Recovery Planning
Section: Testing the DRP
Item type: Multiple Choice
Question: Which of the following statements best describes a simulation test of the
DRP?
Options:
A. Members of key departments perform a dry run of the emergency.
B. Members of key departments trace their steps through the plan checking for
omissions and inaccuracies.
C. Members of key departments check off the tasks for which they are responsible.
D. Backup processing run simultaneously with the production services.
E. Production systems are stopped to evaluate how backup systems perform.
Item number 71
Chapter 7: Law, Investigations, and Ethics
Section: Patent Law
Item type: Multiple Choice
Question: How long is a patent good for in the United States?
Options:
A. 5 years
B. 7 years
C. 10 years
D. 17 years
Item number 72
Chapter 7: Law, Investigations, and Ethics
Section: How Cybercriminals Commit Crimes
Item type: Multiple Choice
Question: Which of the following attacks attempts to prevent legitimate users from
accessing resources?
Options:
A. IP spoofing attack
B. Denial-of-service attack
C. Rogue code attack
D. Social engineering attack
Item number 73
Chapter 7: Law, Investigations, and Ethics
Section: How Cybercriminals Commit Crimes
Item type: Multiple Choice
Question: Which of the following attacks installs a key logger on the victim’s system in
an attempt to collect usernames and passwords?
Options:
A. IP spoofing attack
B. Denial-of-service attack
C. Rogue code attack
D. Emanation eavesdropping attack
Item number 74
Chapter 7: Law, Investigations, and Ethics
Section: Judicial Branch of the Legal System
Item type: Multiple Choice
Question: Which of the following laws does not involve imprisonment?
Options:
A. Civil law
B. Criminal law
C. Regulatory law
D. All laws above involve imprisonment
Item number 75
Chapter 7: Law, Investigations, and Ethics
Section: Judicial Branch of the Legal System
Item type: Multiple Choice
Question: Torts are associated with which of the following laws?
Options:
A. Civil law
B. Criminal law
C. Regulatory law
D. Administrative laws
Item number 76
Chapter 7: Law, Investigations, and Ethics
Section: Types of Computer Crime
Item type: Multiple Choice
Question: Grudge attacks are most likely to be carried out by which of the following?
Options:
A. Terrorists
B. Social engineers
C. Disgruntled employees
D. External attackers
Item number 77
Chapter 7: Law, Investigations, and Ethics
Section: How Cybercriminals Commit Crimes
Item type: Multiple Choice
Question: In which of the following attacks the attacker intercepts radio frequency
signals from a wireless computer?
Options:
A. IP spoofing attack
B. Denial-of-service attack
C. Rogue code attack
D. Emanation eavesdropping attack
Item number 78
Chapter 7: Law, Investigations, and Ethics
Section: Intellectual Property Law
Item type: Multiple Choice
Question: Which of the following best describes a patent?
Options:
A. A word, name, symbol, or device that the individual intends to use commercially
and wants to distinguish from as unique
B. A company secret or sensitive information
C. Discovery or invention that is protected by law and cannot be used by others
D. A copyrighted artwork or music
Item number 79
Chapter 7: Law, Investigations, and Ethics
Section: Privacy and the Law
Item type: Multiple Choice
Question: According to the Electronic Marketplace report of the Federal Trade
Commission Fair Information Practices, which of the following is not one of the four
privacy practices companies engaged in e-commerce should observe?
Options:
A. Notice/awareness
B. Choice/consent
C. Access/participation
D. Availability/privacy
Item number 80
Chapter 7: Law, Investigations, and Ethics
Section: Computer Forensics
Item type: Multiple Choice
Question: Which of the following statements best describes computer forensics?
Options:
A. Performing penetration testing of computer systems to evaluate their security
B. Scanning computer systems for viruses and malware
C. Investigating crimes committed with computers
D. Breaking into computer systems
Item number 81
Chapter 8: Physical Security Control
Section: Providing Physical Security
Item type: Multiple Choice
Question: Smart cards are an example of which type of controls used for physical
security?
Options:
A. Administrative access controls
B. Environmental/life safety controls
C. Technical controls
D. Physical security controls
Item number 82
Chapter 8: Physical Security Control
Section: Providing Physical Security
Item type: Multiple Choice
Question: Keys and combination locks are an example of which type of controls used
for physical security?
Options:
A. Administrative access controls
B. Environmental/life safety controls
C. Technical controls
D. Physical security controls
Item number 83
Chapter 8: Physical Security Control
Section: Providing Physical Security
Item type: Multiple Choice
Question: Site selection and work area restrictions are examples of which type of
controls used for physical security?
Options:
A. Administrative access controls
B. Environmental/life safety controls
C. Technical controls
D. Physical security controls
Item number 84
Chapter 8: Physical Security Control
Section: Physical Security Control
Item type: Multiple Choice
Question: Which of the following fences is used to discourage a casual passerby?
Options:
A. Fence 3 to 4 feet high
B. Fence 6 to 7 feet high
C. Fence over 8 feet high
D. PIDAS
Item number 85
Chapter 8: Physical Security Control
Section: Environmental/Life Safety Controls
Item type: Multiple Choice
Question: Which of the following is an example of an environmental/life safety controls?
Options:
A. Smart cards
B. Fire detectors
C. Site selection
D. Biometric systems
Item number 86
Chapter 8: Physical Security Control
Section: Physical Security Control
Item type: Multiple Choice
Question: Which of the following physical security controls are enclosed areas with a
secure door on either end?
Options:
A. Fences
B. Bollards
C. Turnstiles
D. Mantraps