Electronic Commerce 2012, 7e (Turban) Chapter 9 E-Commerce Security and Fraud
Protection 9.1 True/False Question: Seattles Northwest Hospital and Medical Center was
attacked by malware that was able to enter their network through a Windows flaw. Answer:
Question: A cyberwar occurs when computers are set up to attack other computers in the
same or other organizations. Answer:
Question: Computer security refers to the protection of data, networks, computer
programs, computer power, and other elements of computerized information systems.
Answer:
Question: Fraud is aimed mostly against organizations. Answer:
Question: Data leaks were the most important EC security management concern for 2011.
Answer:
Question: The CyberCop Portal analyzes and combats cyberthreats and vulnerabilities.
Answer:
Question: Protection of the U.S. computer networks is in the hands of the Department of
the Interior (DOI). Answer:
Question: The Internet, or more specifically the Internet and network protocols, was never
intended for use by untrusted users or components. Answer:
Question: The Internet was designed for maximum efficiency and security by providing for
error checking to ensure that the message was sent and received correctly, user
authentication, and access control. Answer:
Question: An IP address uniquely identifies each computer connected to a network or the
Internet. Answer:
Question: There is a clear shift in the nature of the operation of computer criminals from
the desire for fame to the desire for financial gain. Answer:
Question: Exposure is the estimated cost, loss, or damage that can result if a threat exploits
a vulnerability. Answer:
Question: A cyberwarrior is a person who intentionally carries out crimes over the Internet.
Answer:
Question: Social engineering refers to criminals tricking unsuspecting people into giving
them information or access that they should not have. Answer:
Question: Key logs provide the means to reconstruct what specific actions have occurred
and may help EC security investigators identify the person or program that performed
unauthorized actions. Answer:
Question: Validation is the assurance that online customers or trading partners cannot
falsely deny their purchase or transaction. Answer:
Question: Detection measures are actions that will make criminals abandon their idea of
attacking a specific system. Answer:
Question: Phishing is an example of a technical attack. Answer:
Question: Spam and spyware are the most frequently used technical security attack
methods used by cybercriminals. Answer:
Question: A macro virus or macro worm is executed when the application object that
contains the macro is opened or a particular procedure is executed. Answer:
Question: Network viruses can enter through unprotected ports and compromise the whole
network. Answer:
Question: Girlfriend Trojans come to life when computer owners visit one of a number of
online banking or e-commerce sites. Answer:
Question: Malvertising is fake online advertising designed to trick you into downloading
malicious software onto your computer. Answer:
Question: Access control is a mechanism that determines who can legitimately use a
network resource. Answer:
Question: Biometric systems are authentication systems that identify a person by
measurement of a biological characteristic, such as fingerprints, iris patterns, facial
features, or voice. Answer:
Question: A digital envelope is the combination of the encrypted original message and the
digital signature, using the recipients public key. Answer:
Question: An intrusion detection system uses the public Internet to carry information but
remains private by using encryption, authentication, and access control to verify the
identity of anyone using the network. Answer:
Question: A honeypot is a production system that looks like it does real work, but acts as a
decoy and is watched to study how network intrusions occur. Answer:
Question: General controls are intended to protect specific applications. Answer:
Question: Splogs are software applications that have some degree of reactivity, autonomy,
and adaptability. An agent is able to adapt itself based on changes occurring in its
environment. Answer:
Question: Risk aversion is an approach oriented toward prevention and seeks to minimize
the chance of avoidable disasters. Answer:
Question: Ninety-three percent of companies that suffer a significant data loss go out of
business within 5 years. Answer:
Question: The success of an EC security strategy and program depends on the commitment
and involvement of senior management. Answer:
Question: Acceptable use policies (AUP) inform users of their responsibilities when a
cyberattack or network intrusion has occurred. Answer:
Question: Due care in EC are those actions that a company is reasonably expected to take
based on the risks affecting its business and online transactions. Answer:
Question: Protecting information and information systems from unauthorized access, use,
disclosure, disruption, modification, perusal, inspection, recording, or destruction best
defines A) information security. B) security audit. C) anti-virus protection. D) incident
management. Answer:
Question: The ________ translates or converts domain names to their IP addresses. A) IPS
B) DOS C) VPN D) DNS Answer:
Question: ________ refers to the e-markets for stolen information. A) Internet
underground economy B) Denial of service C) Cybercriminal D) Virtual private network
Answer:
Question: ________ systems are highly useful for both law enforcement and for law
breaking, for example, by providing a means to obtain passwords or encryption keys and
thus bypassing other security measures. A) Biometric B) Keystroke logging C) Access
control D) Intrusion detection Answer:
Question: ________ is a crimeware technique used to steal the identity of target companies
to get the identities of their customers. A) Spamming B) Pretexting C) Social engineering
D) Phishing Answer:
Question: A plan that keeps the business running after a disaster occurs best defines A)
security audit specifications. B) business continuity plan. C) vulnerability assessment plan.
D) project initiation plan. Answer:
Question: The estimated cost, loss, or damage that can result if a threat exploits a
vulnerability best describes A) total cost of ownership. B) present value of risk. C)
exposure. D) risk feasibility assessment. Answer:
Question: A generic term for malicious software is A) NOS. B) ad-aware. C) spynet. D)
malware. Answer:
Question: The probability that a vulnerability will be known and used best describes A)
risk. B) feasibility. C) security fault. D) splog point. Answer:
Question: A type of nontechnical attack that uses some ruse to trick users into revealing
information or performing an action that compromises a computer or network best
describes A) splog. B) social engineering. C) viral email. D) identity theft. Answer:
Question: Computers infected with malware that are under the control of a spammer,
hacker, or other criminal best describes A) fraud servers. B) electronic defenders. C)
zombies. D) cyber warriors. Answer:
Question: Unintentional threats include each of the following except A) human errors. B)
environmental hazards. C) computer system malfunctions. D) identity theft. Answer:
Question: Someone who gains unauthorized access to a computer system best describes a
A) hacker. B) network technician. C) cyberwarrior. D) cyberseeker. Answer:
Question: A malicious hacker who may represent a serious problem for a corporation best
describes a A) cyberspy. B) cracker. C) web surfer. D) Internet commando. Answer:
Question: According to Sullivan (2011), vulnerabilities in IT and EC systems include each
of the following except A) poor application security. B) weak boundary security. C) lack
of environmental support. D) unencrypted communications. Answer:
Question: According to Sullivan (2011), the vulnerabilities in Business IT and EC systems
include each of the following organizational weaknesses except A) end-user training and
security awareness. B) lax security with mobile devices. C) inappropriate use of business
computers and network services. D) closed systems not reacting quickly enough to security
breaches. Answer:
Question: The process of determining what the authenticated entity is allowed to access
and what operations it is allowed to perform is known as A) integrity. B) availability. C)
authorization. D) nonrepudiation. Answer:
Question: The process of verifying the real identity of an individual, computer, computer
program, or EC website best defines A) vulnerability assessment. B) security audit. C)
authentication. D) authorization. Answer:
Question: The assurance that an online customer or trading partner cannot falsely deny
their purchase or transaction is referred to as A) integrity. B) availability. C) authentication.
D) nonrepudiation. Answer:
Question: The protection of information systems against unauthorized access to or
modification of information that is stored, processed, or being sent over a network is
referred to as A) information assurance. B) data integrity. C) information integrity. D)
human firewall. Answer:
Question: A strategy that views EC security as the process of preventing and detecting
unauthorized use of the organizations brand, identity, website, e-mail, information, or other
asset and attempts to defraud the organization, its customers, and employees best describes
A) feasibility assessment. B) EC security strategy. C) information systems security plan.
D) disaster recovery plan. Answer:
Question: A program that appears to have a useful function but that contains a hidden
function that presents a security risk best defines A) virus. B) worm. C) Trojan horse. D)
botnet. Answer:
Question: A software program that runs independently, consuming the resources of its host
in order to maintain itself, that is capable of propagating a complete working version of
itself onto another machine best describes A) splog. B) tidal wave. C) Trojan horse. D)
worm. Answer:
Question: An attack on a website in which an attacker uses specialized software to send a
flood of data packets to the target computer with the aim of overloading its resources best
describes A) cyberraid. B) denial-of-service attack. C) cyberhijacking. D) botnet
infestation. Answer:
Question: Creating a rogue copy of a popular website that shows contents similar to the
original to a Web crawler. Once there, an unsuspecting user is redirected to malicious
websites. This description is indicative of A) electronic splogging. B) cyberworming. C)
page hijacking. D) spamming. Answer:
Question: A botnet is a A) collection of a few hundred hijacked Internet computers that
have been set up to forward traffic, including spam and viruses, to other computers on the
Internet. B) piece of software code that inserts itself into a host or operating system to
launch DoS attacks. C) piece of code in a worm that spreads rapidly and exploits some
known vulnerability. D) coordinated network of computers that can scan and compromise
other computers and launch DoS attacks. Answer:
Question: Software that gathers user information over an Internet connection without the
users knowledge best defines A) spyware. B) Trojan horse. C) zombie. D) search engine
spam. Answer:
Question: A page that uses techniques that deliberately subvert a search engines algorithms
to artificially inflate the pages ranking best describes A) Trojan page. B) spam site. C)
zombie. D) search engine imposter. Answer:
Question: The success and security of EC can be measured by A) encryption, functionality,
and privacy. B) quality, reliability, and speed. C) authentication, authorization, and
nonrepudiation. D) confidentiality, integrity, and availability. Answer:
Question: Which of the following refers to the assurance of data privacy and accuracy? A)
integrity B) availability C) confidentiality D) security Answer:
Question: Which of the following refers to the assurance that access to data, the website, or
other EC data service is timely, available, reliable, and restricted to authorized users? A)
spontaneity B) confidentiality C) integrity D) availability Answer:
Question: Which of the following refers to the process of identifying, quantifying, and
prioritizing the vulnerabilities in a system? A) vulnerability assessment B) feasibility
assessment C) initial security report D) certification audit Answer:
Question: A method of evaluating the security of a computer system or a network by
simulating an attack from a malicious source best describes A) vulnerability assessment.
B) penetration test. C) security breach. D) cyber audit. Answer:
Question: Each of the following is a characteristic of access control except A) access
control determines which persons, programs, or machines can legitimately use a network
resource and which resources he, she, or it can use. B) access control lists (ACLs) define
users rights, such as what they are allowed to read, view, write, print, copy, delete, execute,
modify, or move. C) all resources need to be considered together to identify the rights of
users or categories of users. D) after a user has been identified, the user must be
authenticated. Answer:
Question: Fingerprint scanners, facial recognition systems, and voice recognition are
examples of ________ that recognize a person by some physical trait. A) biometric
systems B) human firewalls C) intrusion detection systems D) access control lists Answer:
Question: The mathematical formula used to encrypt the plaintext into the ciphertext, and
vice versa best defines A) key space. B) encryption algorithm. C) locking algorithm. D)
public key infrastructure. Answer:
Question: The large number of possible key values created by the algorithm to use when
transforming the message best describes A) determinate. B) encryption code. C) encryption
lock. D) key space. Answer:
Question: Security functions or characteristics of digital signatures include all of the
following except A) a digital signature is the electronic equivalent of a personal signature,
which can be forged. B) digital signatures are based on public keys for authenticating the
identity of the sender of a message or document. C) digital signatures ensure that the
original content of an electronic message or document is unchanged. D) digital signatures
are portable. Answer:
Question: A summary of a message converted into a string of digits after the hash has been
applied best describes A) reference rate. B) message digest. C) digital certificate. D) key
code. Answer:
Question: A mathematical computation that is applied to a message, using a private key to
encrypt the message, best defines A) locking code. B) Sharpe ratio. C) hash. D) standard
deviation. Answer:
Question: Advantages of virtual private networks include each of the following except A)
they are less expensive than private leased lines because they use the public Internet to
carry information. B) they ensure the confidentiality and integrity of the data transmitted
over the Internet without requiring encryption. C) they can reduce communication costs
dramatically because VPN equipment is cheaper than other remote solutions. D) remote
users can use broadband connections rather than make long distance calls to access an
organizations private network. Answer:
Question: A method used to ensure confidentiality and integrity of data transmitted over
the Internet by encrypting data packets, sending them in packets across the Internet, and
decrypting them at the destination address best defines A) data wrapping. B) message
envelope. C) protocol tunneling. D) Trojan horse. Answer:
Question: An EC security strategy and program begins with A) the commitment and
involvement of executive management. B) layers of hardware and software defenses. C)
information security policies and training. D) secure design of EC applications. Answer:
Question: An exercise that determines the impact of losing the support of an EC resource
to an organization and establishes the escalation of that loss over time, identifies the
minimum resources needed to recover, and prioritizes the recovery of processes and
supporting systems best describes A) business continuity plan. B) business impact analysis.
C) vulnerability assessment. D) computer security incident management. Answer:
Question: The key reasons why EC criminals cannot be stopped include each of the
following except A) sophisticated hackers use browsers to crack into Web sites. B) strong
EC security makes online shopping inconvenient and demanding on customers. C) there is
a lack of cooperation from credit card issuers and foreign ISPs. D) online shoppers do not
take necessary precautions to avoid becoming a victim. Answer:
Question: Briefly describe nonrepudiation and its importance for EC and electronic
transactions. Answer:
Question: Briefly describe the CIA security triad. Answer:
Question: Define biometric system. Identify four common biometrics. Answer:
Question: Define encryption. Identify five major benefits of encryption. Answer:
Question: Why does the success of an EC security strategy and program depend on the
commitment and involvement of executive management? Answer: