Deck 1: Computer Systems Overview

Full screen (f)
exit full mode
Question
A loss of _________ is the unauthorized disclosure of information.

A)confidentiality
B)authenticity
C)integrity
D)availability
Use Space or
up arrow
down arrow
to flip the card.
Question
Threats are attacks carried out.
Question
The "A" in the CIA triad stands for "authenticity".
Question
Contingency planning is a functional area that primarily requires
computer security technical measures.
Question
________ assures that a system performs its intended function in an unimpaired manner,free from deliberate or inadvertent unauthorized manipulation of the system.

A)System Integrity
B)Availability
C)Data Integrity
D)Confidentiality
Question
Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
Question
__________ assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.

A)Availability
B)Privacy
C)System Integrity
D)Data Integrity
Question
Security mechanisms typically do not involve more than one particular
algorithm or protocol.
Question
A flaw or weakness in a system's design,implementation,or operation and management that could be exploited to violate the system's security policy is a(n)__________.

A)countermeasure
B)adversary
C)vulnerability
D)risk
Question
Data integrity assures that information and programs are changed only
in a specified and authorized manner.
Question
Computer security is protection of the integrity,availability,and
confidentiality of information system resources.
Question
Assurance is the process of examining a computer product or system
with respect to certain criteria.
Question
In the context of security our concern is with the vulnerabilities of
system resources.
Question
T F 4.Availability assures that systems works promptly and service is not
denied to authorized users.
Question
Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
Question
Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
Question
A ________ level breach of security could be expected to have a severe or catastrophic adverse effect on organizational operations,organizational assets,or individuals.

A)low
B)moderate
C)normal
D)high
Question
X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
Question
The more critical a component or service,the higher the level of
availability required.
Question
The first step in devising security services and mechanisms is to
develop a security policy.
Question
In the United States,student grade information is an asset whose confidentiality is regulated by the __________.
Question
Masquerade,falsification,and repudiation are threat actions that cause __________ threat consequences.

A)unauthorized disclosure
B)disruption
C)deception
D)usurpation
Question
__________ is the protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity,availability,and confidentiality of information system resources.
Question
The assets of a computer system can be categorized as hardware,software,communication lines and networks,and _________.
Question
An assault on system security that derives from an intelligent act that is a deliberate attempt to evade security services and violate the security policy of a system is a(n)__________.

A)risk
B)attack
C)asset
D)vulnerability
Question
Misappropriation and misuse are attacks that result in ________ threat consequences.
Question
__________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

A)Traffic padding
B)Traffic control
C)Traffic routing
D)Traffic integrity
Question
A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.

A)attack
B)adversary
C)countermeasure
D)protocol
Question
Release of message contents and traffic analysis are two types of _________ attacks.
Question
The _________ prevents or inhibits the normal use or management of communications facilities.

A)passive attack
B)denial of service
C)traffic encryption
D)masquerade
Question
A loss of _________ is the disruption of access to or use of information or an information system.
Question
Confidentiality,Integrity,and Availability form what is often referred to as the _____.
Question
A(n)_________ is any means taken to deal with a security attack.
Question
A(n)_________ is an attempt to learn or make use of information from the system that does not affect system resources.

A)passive attack
B)outside attack
C)inside attack
D)active attack
Question
The assurance that data received are exactly as sent by an authorized entity is __________.

A)authentication
B)access control
C)data confidentiality
D)data integrity
Question
A __________ is any action that compromises the security of information owned by an organization.

A)security mechanism
B)security policy
C)security attack
D)security service
Question
A(n)_________ is a threat that is carried out and,if successful,leads to an undesirable violation of security,or threat consequence.
Question
Replay,masquerade,modification of messages,and denial of service are example of _________ attacks.
Question
A threat action in which sensitive data are directly released to an unauthorized entity is __________.

A)corruption
B)intrusion
C)disruption
D)exposure
Question
An example of __________ is an attempt by an unauthorized user to gain access to a system by posing as an authorized user.

A)masquerade
B)repudiation
C)interception
D)inference
Question
The OSI security architecture focuses on security attacks,__________,and services.
Question
A __________ is data appended to,or a cryptographic transformation of,a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
Question
Establishing,maintaining,and implementing plans for emergency response,backup operations,and post disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations is a __________ plan.
Question
Security implementation involves four complementary courses of action: prevention,detection,response,and _________.
Question
A(n)_________ assessment is periodically assessing the risk to organizational operations,organizational assets,and individuals,resulting from the operation of organizational information systems and the associated processing,storage,or transmission or organizational information.
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/45
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 1: Computer Systems Overview
1
A loss of _________ is the unauthorized disclosure of information.

A)confidentiality
B)authenticity
C)integrity
D)availability
A
2
Threats are attacks carried out.
False
3
The "A" in the CIA triad stands for "authenticity".
False
4
Contingency planning is a functional area that primarily requires
computer security technical measures.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
5
________ assures that a system performs its intended function in an unimpaired manner,free from deliberate or inadvertent unauthorized manipulation of the system.

A)System Integrity
B)Availability
C)Data Integrity
D)Confidentiality
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
6
Hardware is the most vulnerable to attack and the least susceptible to
automated controls.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
7
__________ assures that individuals control or influence what information related to them may be collected and stored and by whom and to whom that information may be disclosed.

A)Availability
B)Privacy
C)System Integrity
D)Data Integrity
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
8
Security mechanisms typically do not involve more than one particular
algorithm or protocol.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
9
A flaw or weakness in a system's design,implementation,or operation and management that could be exploited to violate the system's security policy is a(n)__________.

A)countermeasure
B)adversary
C)vulnerability
D)risk
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
10
Data integrity assures that information and programs are changed only
in a specified and authorized manner.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
11
Computer security is protection of the integrity,availability,and
confidentiality of information system resources.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
12
Assurance is the process of examining a computer product or system
with respect to certain criteria.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
13
In the context of security our concern is with the vulnerabilities of
system resources.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
14
T F 4.Availability assures that systems works promptly and service is not
denied to authorized users.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
15
Many security administrators view strong security as an impediment to
efficient and user-friendly operation of an information system.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
16
Computer security is essentially a battle of wits between a perpetrator
who tries to find holes and the administrator who tries to close them.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
17
A ________ level breach of security could be expected to have a severe or catastrophic adverse effect on organizational operations,organizational assets,or individuals.

A)low
B)moderate
C)normal
D)high
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
18
X.800 architecture was developed as an international standard and
focuses on security in the context of networks and communications.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
19
The more critical a component or service,the higher the level of
availability required.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
20
The first step in devising security services and mechanisms is to
develop a security policy.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
21
In the United States,student grade information is an asset whose confidentiality is regulated by the __________.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
22
Masquerade,falsification,and repudiation are threat actions that cause __________ threat consequences.

A)unauthorized disclosure
B)disruption
C)deception
D)usurpation
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
23
__________ is the protection afforded to an automated information system in order to attain the applicable objectives of preserving the integrity,availability,and confidentiality of information system resources.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
24
The assets of a computer system can be categorized as hardware,software,communication lines and networks,and _________.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
25
An assault on system security that derives from an intelligent act that is a deliberate attempt to evade security services and violate the security policy of a system is a(n)__________.

A)risk
B)attack
C)asset
D)vulnerability
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
26
Misappropriation and misuse are attacks that result in ________ threat consequences.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
27
__________ is the insertion of bits into gaps in a data stream to frustrate traffic analysis attempts.

A)Traffic padding
B)Traffic control
C)Traffic routing
D)Traffic integrity
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
28
A(n)__________ is an action,device,procedure,or technique that reduces a threat,a vulnerability,or an attack by eliminating or preventing it,by minimizing the harm it can cause,or by discovering and reporting it so that correct action can be taken.

A)attack
B)adversary
C)countermeasure
D)protocol
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
29
Release of message contents and traffic analysis are two types of _________ attacks.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
30
The _________ prevents or inhibits the normal use or management of communications facilities.

A)passive attack
B)denial of service
C)traffic encryption
D)masquerade
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
31
A loss of _________ is the disruption of access to or use of information or an information system.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
32
Confidentiality,Integrity,and Availability form what is often referred to as the _____.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
33
A(n)_________ is any means taken to deal with a security attack.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
34
A(n)_________ is an attempt to learn or make use of information from the system that does not affect system resources.

A)passive attack
B)outside attack
C)inside attack
D)active attack
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
35
The assurance that data received are exactly as sent by an authorized entity is __________.

A)authentication
B)access control
C)data confidentiality
D)data integrity
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
36
A __________ is any action that compromises the security of information owned by an organization.

A)security mechanism
B)security policy
C)security attack
D)security service
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
37
A(n)_________ is a threat that is carried out and,if successful,leads to an undesirable violation of security,or threat consequence.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
38
Replay,masquerade,modification of messages,and denial of service are example of _________ attacks.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
39
A threat action in which sensitive data are directly released to an unauthorized entity is __________.

A)corruption
B)intrusion
C)disruption
D)exposure
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
40
An example of __________ is an attempt by an unauthorized user to gain access to a system by posing as an authorized user.

A)masquerade
B)repudiation
C)interception
D)inference
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
41
The OSI security architecture focuses on security attacks,__________,and services.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
42
A __________ is data appended to,or a cryptographic transformation of,a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
43
Establishing,maintaining,and implementing plans for emergency response,backup operations,and post disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations is a __________ plan.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
44
Security implementation involves four complementary courses of action: prevention,detection,response,and _________.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
45
A(n)_________ assessment is periodically assessing the risk to organizational operations,organizational assets,and individuals,resulting from the operation of organizational information systems and the associated processing,storage,or transmission or organizational information.
Unlock Deck
Unlock for access to all 45 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 45 flashcards in this deck.