NEW QUESTION NO: 7
Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Security Policy, Information Protection Policy, Information Security Policy, network Security Policy, Physical Security Policy, Remote Access Policy, and User Account Policy.
What is the main theme of the sub-policies for Information Technologies?
A. Authenticity, Confidentiality, Integrity
B. Authenticity, Integrity, Non-repudiation
C. Confidentiality, Integrity, Availability
D. Availability, Non-repudiation, Confidentiality
Answer: C
NEW QUESTION NO: 8
On performing a risk assessment, you need to determine the potential impacts when some of the critical business process of the company interrupt its service. What is the name of the process by which you can determine those critical business?
A. Disaster Recovery Planning (DRP)
B. Risk Mitigation
C. Business Impact Analysis (BIA)
D. Emergency Plan Response (EPR)
Answer: C
NEW QUESTION NO: 9
Which protocol is used for setting up secure channels between two devices, typically in VPNs?
A. SET
B. IPSEC
C. PEM
D. PPP
Answer: B
NEW QUESTION NO: 10
A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer's software and hardware without the owner's permission. Their intention can either be to simply gain knowledge or to illegally make changes.
Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?
A. Black Hat
B. Suicide Hacker
C. White Hat
D. Gray Hat
Answer: D
NEW QUESTION NO: 11
What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?
A. SSH
B. SYN Flood
C. Manipulate format strings in text fields
D. Through Web servers utilizing CGI (Common Gateway Interface) to send a malformed environment variable to a vulnerable Web server
Answer: D
NEW QUESTION NO: 12
Chandler works as a pen-tester in an IT-firm in New York. As a part of detecting viruses in the systems, he uses a detection method where the anti-virus executes the malicious codes on a virtual machine to simulate CPU and memory activities.
Which type of virus detection method did Chandler use in this context?
A. Code Emulation
B. Scanning
C. Integrity checking
D. Heuristic Analysis
Answer: A
NEW QUESTION NO: 13
This asymmetry cipher is based on factoring the product of two large prime numbers.
What cipher is described above?
A. RSA
B. SHA
C. MD5
D. RC5
Answer: A
NEW QUESTION NO: 14
Bob, your senior colleague, has sent you a mail regarding aa deal with one of the clients. You are requested to accept the offer and you oblige.
After 2 days, Bob denies that he had ever sent a mail.
What do you want to "know" to prove yourself that it was Bob who had send a mail?
A. Non-Repudiation
B. Integrity
C. Authentication
D. Confidentiality
Answer: A
NEW QUESTION NO: 15
Due to a slowdown of normal network operations, the IT department decided to monitor internet traffic for all of the employees. From a legal stand point, what would be troublesome to take this kind of measure?
A. All of the employees would stop normal work activities
B. Not informing the employees that they are going to be monitored could be an invasion of privacy.
C. IT department would be telling employees who the boss is
D. The network could still experience traffic slow down.
Answer: B
NEW QUESTION NO: 16
A company's Web development team has become aware of a certain type of security vulnerability in their Web software. To mitigate the possibility of this vulnerability being exploited, the team wants to modify the software requirements to disallow users from entering HTML as input into their Web application.
What kind of Web application vulnerability likely exists in their software?
A. Cross-site Request Forgery vulnerability
B. SQL injection vulnerability
C. Cross-site scripting vulnerability
D. Web site defacement vulnerability
Answer: C
NEW QUESTION NO: 17
Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything except.
A. Work at the Data Link Layer
B. Authenticate
C. Protect the payload and the headers
D. Encrypt
Answer: A