C. Presentation
D. Network
Item number 168
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following statements about IPsec is true?
Options:
A. IPsec perform authentication but does not encrypt packets.
B. IPsec performs encryption but does not support authentication.
C. IPsec supports both encryption and authentication.
D. IPsec does not support either encryption or authentication.
Item number 169
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following protocols encapsulates an IP packet within another
packet and then encrypts the result?
Options:
A. SSL
B. IPsec
C. HTTPS
D. SET
Item number 170
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following are the two basic modes in which IPsec can operate?
Options:
A. Encrypted and encapsulated
B. Open and secure
C. Transport and tunnel
D. Authenticated and clear text
Item number 171
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following ensures that messages arrive intact and unaltered?
Options:
A. Sender authentication
B. Message integrity
C. Message confidentiality
D. Message availability
Item number 172
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following ensures that messages originate from their advertised
source?
Options:
A. Sender authentication
B. Message integrity
C. Message confidentiality
D. Message availability
Item number 173
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: Which of the following IPsec component adds an attribute field to IP
datagrams?
Options:
A. IP
B. AH
C. ESP
D. SA
Item number 174
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: IPsec authentication header provides which of the following?
Options:
A. Connectionless data integrity
B. Data authentication
C. Protection against replay attacks
D. All the above
Item number 175
Chapter 12: Telecommunications, Network, and Internet Security
Section: IPSec
Item type: Multiple Choice
Question: IPSec authentication header supports all the following except?
Options:
A. Connectionless data integrity
B. Data confidentiality
C. Data authentication
D. Protection against replay attacks
Item number 176
Chapter 12: Telecommunications, Network, and Internet Security
Section: Applied VPNs
Item type: Multiple Choice
Question: Which of the following statements about SSL VPNs is true?
Options:
A. It requires no end user software to set up and use.
B. Connections originate from an Internet accessible URL.
C. When authenticated users have access to the corporate network as if they are
physically connected to it.
D. All the above.
Item number 177
Chapter 12: Telecommunications, Network, and Internet Security
Section: Applied VPNs
Item type: Multiple Choice
Question: VPNs use which of the following protocols to provide encrypted secure
connection?
Options:
A. SSL and TCP
B. IPsec and TCP
C. IPsec and SSL
D. SMTP and TCP
Item number 178
Chapter 1: Why Study Information Security?
Section: Information Security Careers Meet the Need of Business
Item type: Multiple Choice
Question: Which of the following best describes the job duties of security
administrators?
Options:
A. They create security policies.
B. They design secure systems.
C. They check if employees comply with security policies.
D. They ensure appropriate separation of duties exists to prevent abuse of privilege.
Item number 179
Chapter 1: Why Study Information Security?
Section: Information Security Careers Meet the Need of Business
Item type: Multiple Choice
Question: Security testers are also called which of the following?
Options:
A. White hat hackers
B. Gray hat hackers
C. Black hat hackers
D. Script kiddies
Item number 180
Chapter 1: Why Study Information Security?
Section: Information Security Careers Meet the Need of Business
Item type: Multiple Choice
Question: Which of the following best describes the job duties of security architects?
Options:
A. They create security policies.
B. They design and implement secure networks.
C. They check if employees comply with security policies.
D. They ensure appropriate separation of duties exists to prevent abuse of privilege.
Item number 181
Chapter 1: Why Study Information Security?
Section: Information Security Careers Meet the Need of Business
Item type: Multiple Choice
Question: Which of the following best describes the job duties of compliance officers?
Options:
A. They create security policies.
B. They design and implement secure networks.
C. They check if employees comply with security policies.
D. They ensure appropriate separation of duties exists to prevent abuse of privilege.
Item number 182
Chapter 2: Information Security Principles of Success
Section: Principle 2: The Three Security Goals Are Confidentiality, Integrity, and
Availability
Item type: Multiple Choice
Question: Which of the following are the three goals of the security triad?
Options:
A. Confidentiality, integrity, authorization
B. Confidentiality, authorization, availability
C. Confidentiality, nonrepudiation, integrity
D. Confidentiality, integrity, availability
Item number 183
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding OSI model and the TCP Protocol stack is a key area of which
of the following CBK domain?
Options:
A. Access control
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Telecommunications and network security
Item number 184
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding how to develop and implement security policies and standards
is a key area of which of the following CBK domain?
Options:
A. Information security governance and risk management
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Operations security
Item number 185
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding access control attacks is a key area of which of the following
CBK domain?
Options:
A. Access control
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Telecommunications and network security
Item number 186
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding how to apply security in all stages of the SDLC is a key area
of which of the following CBK domains?
Options:
A. Information security governance and risk management
B. Software development security
C. Business continuity and disaster recovery planning
D. Operations security
Item number 187
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding asymmetric and symmetric encryption protocols is a key area
of which of the following CBK domain?
Options:
A. Cryptography
B. Security architecture and design
C. Access control
D. Operations security
Item number 188
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding security models and software and system vulnerabilities and
threats are key areas of which of the following CBK domains?
Options:
A. Information security governance and risk management
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Operations security
Item number 189
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Creating a business impact analysis is key area of which of the following CBK
domains?
Options:
A. Information security governance and risk management
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Operations security
Item number 190
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Managing incident response is a key area of which of the following CBK
domains?
Options:
A. Information security governance and risk management
B. Security architecture and design
C. Business continuity and disaster recovery planning
D. Operations security
Item number 191
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Personnel privacy and safety is a key area of which of the following CBK
domains?
Options:
A. Physical (environmental) security
B. Security architecture and design
C. Legal regulations, investigations, and compliance
D. Operations security
Item number 192
Chapter 3: Certification Programs and the Common Body of Knowledge
Section: The Information Security Common Body of Knowledge
Item type: Multiple Choice
Question: Understanding professional ethics is a key area of which of the following CBK
domains?
Options:
A. Physical (environmental) security
B. Security architecture and design
C. Legal regulations, investigations, and compliance
D. Operations security
Item number 193
Chapter 4: Governance and Risk Management
Section: Regulations
Item type: Multiple Choice
Question: Which of the following regulations protects the privacy of medical records?
Options:
A. PCI DSS
B. HIPAA
C. SOX
D. GBLA
Item number 194
Chapter 4: Governance and Risk Management
Section: Issue – Specific Policies
Item type: Multiple Choice
Question: Email acceptable use and Internet acceptable use are considered which of
the following?
Options:
A. System-specific policies
B. Issue-specific policies
C. Programme-framework policies
D. Programme-level policies
Item number 195
Chapter 4: Governance and Risk Management
Section: Who Is Responsible for Security?
Item type: Multiple Choice
Question: Which of the following best describes the responsibilities of custodians of
information resources?
Options:
A. Establish and maintain security and risk management programmes for
information resources.
B. Direct policies and procedures designed to protect information resources.
C. Provide technical facilities, data processing, and other support services to
owners and users of information resources.
D. Provide technical support for security of information resources.
Item number 196
Chapter 4: Governance and Risk Management
Section: Who Is Responsible for Security?
Item type: Multiple Choice
Question: Which of the following best describes the responsibilities of the chief
information security officer?
Options:
A. Establish and maintain security and risk management programmes for
information resources.
B. Direct policies and procedures designed to protect information resources.
C. Provide technical facilities, data processing , and other support services to
owners and users of information resources.
D. Provide technical support for security of information resources.
Item number 197
Chapter 11: Cryptography
Section: Digesting Data
Item type: Multiple Choice
Question: MD5 and SHA-1 are examples of which of the following?
Options:
A. Communication protocols
B. Hashing algorithms
C. Encryption algorithms
D. Transport protocols
Item number 198
Chapter 11: Cryptography
Section: Digital Certificates
Item type: Multiple Choice
Question: Which of the following is the standard used for digital certificates?
Options:
A. X.500
B. X.509
C. SHA-1
D. MD5
Item number 199
Chapter 11: Cryptography
Section: Digital Certificates
Item type: Multiple Choice
Question: Which of the following best describes X.509?
Options:
A. Public key infrastructure
B. Standard used for digital certificates
C. Database of revoked certificate
D. Database of existing hash values
Item number 200
Chapter 11: Cryptography
Section: The Secure Electronic Transactions Protocol
Item type: Multiple Choice
Question: Which of the following protocols was designed to address most of the
consumer demands for privacy when using a credit card online?
Options:
A. TSL
B. PGP
C. SET
D. S/MIME