3. Provide a real example or describe a hypothetical situation where a legitimate organization
used spam in an effective and nonintrusive manner to promote a product or service.
4. Some IT security personnel believe that their organizations should employ former com–
puter criminals to identify weaknesses in their organizations’ security defenses. Do you
agree? Why or why not?
5. You have been assigned to be a computer security trainer for your firm’s 2,000 employees
and contract workers. What are the key topics you would cover in your initial one-hour basic
training program for non-IT personnel? What kind of additional security-related training
might be appropriate once people have the basics covered?
6. Your computer science instructor has assigned a semester-long project to develop a zeroday
exploit for the Windows 8 operating system. Do you think this is an appropriate class
project? Why or why not?