You work as a Network Auditor for Net Perfect Inc. The company has a Windows-based network. While auditing the company's network, you are facing problems in searching the faults and other entities that belong to it. Which of the following risks may occur due to the existence of these problems?
The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security assessment? Each correct answer represents a part of the solution. Choose all that apply.
ACertification agent
BDesignated Approving Authority
CIS program manager
DInformation Assurance Manager
EUser representative
Which of the following penetration testing techniques automatically tests every phone line in an exchange and tries to locate modems that are attached to the network?
ADemon dialing
BSniffing
CSocial engineering
DDumpster diving
You work as a project manager for BlueWell Inc. You are working on a project and the management wants a rapid and cost-effective means for establishing priorities for planning risk responses in your project. Which risk management process can satisfy management's objective for your project?
AQualitative risk analysis
BHistorical information
CRolling wave planning
DQuantitative analysis
What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process? Each correct answer represents a complete solution. Choose all that apply.
Become a Supporter and enjoy a completely ad-free experience, plus unlock Learn Mode, Exam Mode, AstroTutor AI, and more.
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Ask AstroTutor
0
Which of the following attacks causes software to fail and prevents the intended users from accessing software?
AEnabling attack
BReconnaissance attack
CSabotage attack
DDisclosure attack
Which of the following is a name, symbol, or slogan with which a product is identified?
ATrademark
BCopyright
CTrade secret
DPatent
Which of the following coding practices are helpful in simplifying code? Each correct answer represents a complete solution. Choose all that apply.
AProgrammers should use multiple small and simple functions rather than a single complex function.
BSoftware should avoid ambiguities and hidden assumptions, recursions, and GoTo statements.
CProgrammers should implement high-consequence functions in minimum required lines of code and follow proper coding standards.
DProcesses should have multiple entry and exit points.
You have a storage media with some data and you make efforts to remove this data. After performing this, you analyze that the data remains present on the media. Which of the following refers to the above mentioned condition?
AObject reuse
BDegaussing
CResidual
DData remanence
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.
ACertification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
BAccreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
CAccreditation is the official management decision given by a senior agency official to authorize operation of an information system.
DCertification is the official management decision given by a senior agency official to authorize operation of an information system.
What component of the change management system is responsible for evaluating, testing, and documenting changes created to the project scope?
AProject Management Information System
BIntegrated Change Control
CConfiguration Management System
DScope Verification
You are the project manager of the NNN project for your company. You and the project team are working together to plan the risk responses for the project. You feel that the team has successfully completed the risk response planning and now you must initiate what risk process it is. Which of the following risk processes is repeated after the plan risk responses to determine if the overall project risk has been satisfactorily decreased?
AQuantitative risk analysis
BRisk identification
CRisk response implementation
DQualitative risk analysis
Which of the following statements is true about residual risks?
AIt is the probabilistic risk after implementing all security measures.
BIt can be considered as an indicator of threats coupled with vulnerability.
CIt is a weakness or lack of safeguard that can be exploited by a threat.
DIt is the probabilistic risk before implementing all security measures.
A Web-based credit card company had collected financial and personal details of Mark before issuing him a credit card. The company has now provided Mark's financial and personal details to another company. Which of the following Internet laws has the credit card issuing company violated?
ATrademark law
BSecurity law
CPrivacy law
DCopyright law
Which of the following life cycle modeling activities establishes service relationships and message exchange paths?
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy? Each correct answer represents a part of the solution. Choose all that apply.
AWhat is being secured?
BWhere is the vulnerability, threat, or risk?
CWho is expected to exploit the vulnerability?
DWho is expected to comply with the policy?
Which of the following areas of information system, as separated by Information Assurance Framework, is a collection of local computing devices, regardless of physical location, that are interconnected via local area networks (LANs) and governed by a single security policy?
ALocal Computing Environments
BNetworks and Infrastructures
CSupporting Infrastructures
DEnclave Boundaries
You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of
Federal Information Systems?
ANIST Special Publication 800-60
BNIST Special Publication 800-53
CNIST Special Publication 800-37
DNIST Special Publication 800-59
Which of the following DoD directives is referred to as the Defense Automation Resources Management Manual?
ADoD 8910.1
BDoD 7950.1-M
CDoDD 8000.1
DDoD 5200.22-M
EDoD 5200.1-R
Della works as a security engineer for BlueWell Inc. She wants to establish configuration management and control procedures that will document proposed or actual changes to the information system. Which of the following phases of NIST SP 800-37 C&A methodology will define the above task?
AInitiation
BSecurity Certification
CContinuous Monitoring
DSecurity Accreditation
Joseph works as a Software Developer for WebTech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the following laws are used to protect a part of software?
Which of the following types of signatures is used in an Intrusion Detection System to trigger on attacks that attempt to reduce the level of a resource or system, or to cause it to crash?
AAccess
BBenign
CDoS
DReconnaissance
Which of the following is a set of exclusive rights granted by a state to an inventor or his assignee for a fixed period of time in exchange for the disclosure of an invention?
ACopyright
BSnooping
CUtility model
DPatent
Which of the following actions does the Data Loss Prevention (DLP) technology take when an agent detects a policy violation for data of all states? Each correct answer represents a complete solution. Choose all that apply.
AIt creates an alert.
BIt quarantines the file to a secure location.
CIt reconstructs the session.
DIt blocks the transmission of content.
In which of the following processes are experienced personnel and software tools used to investigate, resolve, and handle process deviation, malformed data, infrastructure, or connectivity issues?