Exam
Name___________________________________
1. A driveby download is a technique used by hackers to enable accessing files on a wireless network.
2. Computers using cable modems to connect to the Internet are more open to penetration than those
connecting via dialup.
3. Wireless networks are vulnerable to penetration because radio frequency bands are easy to scan.
4. Mobile devices are not targeted as extensively by malware as traditional computers.
5. A Trojan horse is a software program that appears to be benign but then does something other than
expected.
6. Viruses can be spread through email.
7. Computer worms spread much more rapidly than computer viruses.
8. One form of spoofing involves forging the return address on an email so that the email message appears to
come from someone other than the sender.
9. Sniffers enable hackers to steal proprietary information from anywhere on a network, including email
messages, company files, and confidential reports.
10. DoS attacks are used to destroy information and access restricted areas of a company’s information system.
11. In a walkthrough, hackers are able to bypass security controls of a system with little opposition.
12. Zero defects cannot be achieved in larger software programs because fully testing programs that contain
thousands of choices and millions of paths would require thousands of years.
13. An acceptable use policy defines the acceptable level of access to information assets for different users.
14. Biometric authentication is the use of physical characteristics such as retinal images to provide identification.
15. Packet filtering catches most types of network attacks.
16. NAT conceals the IP addresses of the organization’s internal host computers to deter sniffer programs.
17. SSL is a protocol used to establish a secure connection between two computers.
18. Public key encryption uses two keys.
19. Highavailability computing is also referred to as fault tolerance.
20. Unauthorized access is a security challenge that is most likely to occur in a network at the point of client
computers.
21. ________ refers to policies, procedures, and technical measures used to prevent unauthorized access,
alternation, theft, or physical damage to information systems.
A) “Controls”
B) “Benchmarking”
C) “Security”
D) “Algorithms”
22. ________ refers to all of the methods, policies, and organizational procedures that ensure the safety of the
organization’s assets, the accuracy and reliability of its accounting records, and operational adherence to
management standards.
A) “Controls”
B) “Legacy systems”
C) “Vulnerabilities”
D) “SSID standards”
23. Which of the following is not one of the challenges in securing wireless networks?
A) SQL injection attacks
B) geographic range of wireless signals
C) broadcasted SSIDs
D) scannability of radio frequency bands
24. Electronic data are more susceptible to destruction, fraud, error, and misuse because information systems
concentrate data in computer files that
A) are usually bound up in legacy systems that are difficult to access and difficult to correct in case of
error.
B) are frequently available on the Internet.
C) have the potential to be accessed by large numbers of people and by groups outside of the organization.
D) are not secure because the technology to secure them did not exist at the time the files were created.
25. All of the following are methods of ensuring software quality except for
A) walkthroughs.
B) software testing.
C) systems analysis.
D) internal corporate backend system.
26. Sniffing is a security challenge that is most likely to occur in which of the following points of a corporate
network?
A) internal corporate backend system
B) client computer
C) communications lines
D) corporate servers
27. Inputting data into a poorly programmed Web form in order to disrupt a company’s systems and networks
is called
A) a DDoS attack.
B) a Trojan horse.
C) key logging.
D) an SQL injection attack.
28. The Internet poses specific security problems because
A) Internet standards are universal.
B) it changes so rapidly.
C) it was designed to be easily accessible.
D) Internet data is not run over secure lines.
29. Which of the following statements about the Internet security is not true?
A) VoIP is more secure than the switched voice network.
B) A corporate network without access to the Internet is more secure than one provides access.
C) The use of P2P networks can expose a corporate computer to outsiders.
D) Instant messaging can provide hackers access to an otherwise secure network.
30. An independent computer program that copies itself from one computer to another over a network is called
a
A) worm.
B) pest.
C) bug.
D) Trojan horse.
31. A salesperson clicks repeatedly on the online ads of a competitor’s in order to drive the competitor’s
advertising costs up. This is an example of
A) pharming.
B) phishing.
C) spoofing.
D) click fraud.
32. In 2004, ICQ users were enticed by a sales message from a supposed antivirus vendor. On the vendor’s site,
a small program called Mitglieder was downloaded to the user’s machine. The program enabled outsiders to
infiltrate the user’s machine. What type of malware is this an example of?
A) worm
B) spyware
C) virus
D) Trojan horse
33. Redirecting a Web link to a different address is a form of
A) sniffing.
B) snooping.
C) spoofing.
D) war driving.
34. A keylogger is a type of
A) worm.
B) spyware.
C) Trojan horse.
D) virus.
35. Hackers create a botnet by
A) infecting Web search bots with malware.
B) using Web search bots to infect other computers.
C) infecting corporate servers with “zombie” Trojan horses that allow undetected access through a back
door.
D) causing other people’s computers to become “zombie” PCs following a master computer.
36. Using numerous computers to inundate and overwhelm the network from numerous launch points is called
a(n) ________ attack.
A) DDoS
B) DoS
C) phishing
D) SQL injection
37. Which of the following is not an example of a computer used as a target of crime?
A) illegally accessing stored electronic communication
B) knowingly accessing a protected computer to commit fraud
C) threatening to cause damage to a protected computer
D) accessing a computer system without authority
38. Which of the following is not an example of a computer used as an instrument of crime?
A) unauthorized copying of software
B) intentionally attempting to intercept electronic communication
C) breaching the confidentiality of protected computerized data
D) theft of trade secrets
39. Approximately how many new threats from malware were detected by Internet security firms in 2012?
A) 400 million
B) 4 million
C) 400 thousand
D) 40 million
40. An example of phishing is
A) setting up a fake medical Web site that asks users for confidential information.
B) pretending to be a utility company’s employee in order to garner information from that company about
their security system.
C) sending bulk email that asks for financial aid under a false pretext.
D) setting up bogus WiFi hot spots.
41. Evil twins are
A) bogus wireless network access points that look legitimate to users.
B) Trojan horses that appears to the user to be a legitimate commercial software application.
C) fraudulent Web sites that mimic a legitimate business’s Web site.
D) email messages that mimic the email messages of a legitimate business.
42. Pharming involves
A) pretending to be a legitimate business’s representative in order to garner information about a security
system.
B) redirecting users to a fraudulent Web site even when the user has typed in the correct address in the
Web browser.
C) setting up fake Web sites to ask users for confidential information.
D) using emails for threats or harassment.
43. You have been hired as a security consultant for a law firm. Which of the following constitutes the greatest
source of security threats to the firm?
A) lack of data encryption
B) employees
C) wireless network
D) authentication procedures
44. Tricking employees to reveal their passwords by pretending to be a legitimate member of a company is
called
A) sniffing.
B) pharming.
C) phishing.
D) social engineering.
45. How do software vendors correct flaws in their software after it has been distributed?
A) issue bug fixes
B) issue patches
C) issue updated versions
D) rerelease software
46. The HIPAA Act
A) specifies best practices in information systems security and control.
B) outlines medical security and privacy rules.
C) requires financial institutions to ensure the security of customer data.
D) imposes responsibility on companies and management to safeguard the accuracy of financial
information.
47. The GrammLeachBliley Act
A) outlines medical security and privacy rules.
B) imposes responsibility on companies and management to safeguard the accuracy of financial
information.
C) specifies best practices in information systems security and control.
D) requires financial institutions to ensure the security of customer data.
48. The SarbanesOxley Act
A) imposes responsibility on companies and management to safeguard the accuracy of financial
information.
B) requires financial institutions to ensure the security of customer data.
C) outlines medical security and privacy rules.
D) specifies best practices in information systems security and control.
49. The most common type of electronic evidence is
A) spreadsheets.
B) email.
C) instant messages.
D) voicemail.
50. Electronic evidence on computer storage media that is not visible to the average user is called ________ data.
A) forensic
B) ambient
C) defragmented
D) fragmented
51. Application controls
A) govern the design, security, and use of computer programs and the security of data files in general
throughout the organization.
B)
can be classified as input controls, processing controls, and output controls.
C) include software controls, computer operations controls, and implementation controls.
D) apply to all computerized applications and consist of a combination of hardware, software, and manual
procedures that create an overall control environment.
52. ________ controls ensure that valuable business data files on either disk or tape are not subject to
unauthorized access, change, or destruction while they are in use or in storage.
A) Data security
B) Implementation
C) Administrative
D) Software
53. Analysis of an information system that rates the likelihood of a security incident occurring and its cost is
included in a(n)
A) risk assessment.
B) security policy.
C) business impact analysis.
D) AUP.
54. A(n) ________ system is used to identify and authorize different categories of system users and specify
which portions of the organization’s systems each user can access.
A) identity management
B) AUP
C) firewall
D) authentication
55. Which of the following is not one of the main firewall screening techniques?
A) NAT
B) static packet filtering
C) secure socket filtering
D) application proxy filtering
56. Rigorous password systems
A) may hinder employee productivity.
B) are often disregarded by employees.
C) are one of the most effective security tools.
D) are costly to implement.
57. An authentication token is a(n)
A) gadget that displays passcodes.
B) electronic marker attached to a digital authorization file.
C) type of smart card.
D) device the size of a credit card that contains access permission data.
58. Which of the following is not a trait used for identification in biometric systems?
A) voice
B) retinal image
C) hair color
D) face
59. A firewall allows the organization to
A) prevent known spyware and malware from entering the system.
B) prevent unauthorized communication both into and out of the network.
C) monitor network hot spots for signs of intruders.
D) all of the above.
60. In which technique are network communications analyzed to see whether packets are part of an ongoing
dialogue between a sender and a receiver?
A) intrusion detection system
B) application proxy filtering
C) packet filtering
D) stateful inspection
61. Which of the following is the greatest threat that employees pose to an organization’s information systems?
A) lack of knowledge