<< Prev Question Next Question >>

Question 409/605

Identifying specific attempts to penetrate systems is the function of the _______________.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (605q)
Question 1: This is a common security issue that is extremely hard to co...
Question 2: A packet containing a long string of NOP's followed by a com...
Question 3: ________, _________, and __________ are required to successf...
Question 4: Which of the following describes a computer processing archi...
Question 5: What can be defined as a list of subjects along with their a...
Question 6: Which of the following is less likely to be used today in cr...
Question 7: The RSA algorithm is an example of what type of cryptography...
Question 8: Which backup method is used if backup time is critical and t...
Question 9: Which conceptual approach to intrusion detection system is t...
Question 10: What does RADIUS stand for?
Question 11: Which of the following is used to monitor network traffic or...
Question 12: Which of the following is most affected by denial-of-service...
Question 13: In which of the following model are Subjects and Objects ide...
Question 14: Controls provide accountability for individuals who are acce...
Question 15: Which of the following is the most reliable, secure means of...
Question 16: Which of the following is a symmetric encryption algorithm?...
Question 17: What are the three FUNDAMENTAL principles of security?...
Question 18: Which of the following is NOT an encryption method used by V...
Question 19: What is the main difference between a Smurf and a Fraggle at...
Question 20: Which of the following is an example of a passive attack?...
Question 21: Which of the following phases of a system development life-c...
Question 22: Only key members of the staff need to be educated in disaste...
Question 23: When a biometric system is used, which error type deals with...
Question 24: Which of the following describes a technique in which a numb...
Question 25: Which of the following statements pertaining to using Kerber...
Question 26: Which of the following rules pertaining to a Business Contin...
Question 27: Which of the following is often the greatest challenge of di...
Question 28: In computing what is the name of a non-self-replicating type...
Question 29: Which of the following statements pertaining to link encrypt...
Question 30: A prolonged high voltage is a:
Question 31: Wiretapping is an example of a passive network attack?...
Question 32: What is the RESULT of a hash algorithm being applied to a me...
Question 33: What kind of certificate is used to validate a user identity...
Question 34: Which of the following technologies has been developed to su...
Question 35: Which of the following is the primary reason why a user woul...
Question 36: In the CIA triad, what does the letter A stand for?...
Question 37: Complete the blanks. When using PKI, I digitally sign a mess...
Question 38: The Reference Validation Mechanism that ensures the authoriz...
Question 39: What is one disadvantage of content-dependent protection of ...
Question 40: The most secure method for storing backup tapes is?...
Question 41: In biometric identification systems, the parts of the body c...
Question 42: What is the role of IKE within the IPsec protocol?...
Question 43: In addition to the Legal Department, with what company funct...
Question 44: In an organization where there are frequent personnel change...
Question 45: Which of the following assertions is NOT true about pattern ...
Question 46: A server cluster looks like a:
Question 47: Which of the following would best describe the difference be...
Question 48: What can a packet filtering firewall also be called?...
Question 49: To understand the 'whys' in crime, many times it is necessar...
Question 50: Name three types of firewalls __________, _______________, a...
Question 51: The IDEA algorithm (used in PGP) is _______ bits long....
Question 52: Which of the following is a telecommunication device that tr...
Question 53: Memory management in TCSEC levels B3 and A1 operating system...
Question 54: In addition to the accuracy of the biometric systems, there ...
Question 55: What is the maximum length of cable that can be used for a t...
Question 56: Which of the following transmission media would NOT be affec...
Question 57: Layer 4 of the OSI stack is known as:...
Question 58: In stateful inspection firewalls, packets are:...
Question 59: MD5 is a ___________ algorithm
Question 60: The SubSeven Trojan has been known to exploit which service ...
Question 61: All following observations about IPSec are correct except:...
Question 62: The IP header contains a protocol field. If this field conta...
Question 63: This free (for personal use) program is used to encrypt and ...
Question 64: IKE - Internet Key Exchange is often used in conjunction wit...
Question 65: The principle of least privilege is effective in helping pre...
Question 66: Which of the following server contingency solutions offers t...
Question 67: Which of the following is NOT a common integrity goal?...
Question 68: The "vulnerability of a facility" to damage or attack may be...
Question 69: What is the act of obtaining information of a higher sensiti...
Question 70: When first analyzing an intrusion that has just been detecte...
Question 71: Which of the following exemplifies proper separation of duti...
Question 72: What is malware that can spread itself over open network con...
Question 73: What best describes a scenario when an employee has been sha...
Question 74: In biometric identification systems, at the beginning, it wa...
Question 75: What is the key size of the International Data Encryption Al...
Question 76: When compiling a risk assessment report, which of the follow...
Question 77: Which of the following is more suitable for a hardware imple...
Question 78: What is the Biba security model concerned with?...
Question 79: Which of the following is required in order to provide accou...
Question 80: Overloading or congesting a system's resources so that it is...
Question 81: A copy of evidence or oral description of its contents; whic...
Question 82: What is a hot-site facility?
Question 83: Which of the following computer crime is MORE often associat...
Question 84: Which of the following would best describe certificate path ...
Question 85: Which of the following is NOT true of the Kerberos protocol?...
Question 86: Which of the following is covered under Crime Insurance Poli...
Question 87: Which of the following biometric parameters are better suite...
Question 88: Your ATM card is a form of two-factor authentication for wha...
Question 89: Which of the following DoD Model layer provides non-repudiat...
Question 90: Define the term tuple.
Question 91: Which of the following is used in database information secur...
Question 92: What can best be defined as the detailed examination and tes...
Question 93: Which of the following is NOT a fundamental component of an ...
Question 94: An intrusion detection system is an example of what type of ...
Question 95: Kerberos can prevent which one of the following attacks?...
Question 96: Which layer of the DoD TCP/IP Model ensures error-free deliv...
Question 97: Which OSI/ISO layer is responsible for determining the best ...
Question 98: Masquerading is synonymous with __________....
Question 99: In order to enable users to perform tasks and duties without...
Question 100: Which of the following is the MOST important aspect relating...
Question 101: What is the main purpose of Corporate Security Policy?...
Question 102: Of the reasons why a Disaster Recovery plan gets outdated, w...
Question 103: Which of the following is NOT a characteristic of a host-bas...
Question 104: Which type of password provides maximum security because a n...
Question 105: The typical computer fraudsters are usually persons with whi...
Question 106: ___________________ is responsible for creating security pol...
Question 107: Which major vendor adopted TACACS into its product line as a...
Question 108: Which of the following would be an example of the best passw...
Question 109: Under the principle of culpable negligence, executives can b...
Question 110: Which of the following are Unix / Linux based security tools...
Question 111: Sandra has used Ethereal, a packet sniffer, to listen in on ...
Question 112: What size is an MD5 message digest (hash)?...
Question 113: Which method of password cracking takes the most time and ef...
Question 114: Which of the following would be best suited to oversee the d...
Question 115: The DES algorithm is an example of what type of cryptography...
Question 116: Who should direct short-term recovery actions immediately fo...
Question 117: While there are many different models for IT system life cyc...
Question 118: Which of the following best describes the purpose of debuggi...
Question 119: According to the annual CSI/FBI Computer Crime report, which...
Question 120: In order to ensure the privacy and integrity of the data, co...
Question 121: A X.509 public key certificate with the key usage attribute ...
Question 122: What can be described as an imaginary line that separates th...
Question 123: The primary purpose for using one-way hashing of user passwo...
Question 124: ___________ programs decrease the number of security inciden...
Question 125: What is called a system that is capable of detecting that a ...
Question 126: Which of the following is a method of multiplexing data wher...
Question 127: What are the two most critical aspects of risk analysis? (Ch...
Question 128: Under United States law, an investigator's notebook may be u...
Question 129: Which of the following is not a one-way hashing algorithm?...
Question 130: Attributable data should be:
Question 131: Which of the following pairings uses technology to enforce a...
Question 132: If Big Texastelephone company suddenly started billing you f...
Question 133: Which of the following access control models introduces user...
Question 134: Which of the following biometric devices offers the LOWEST C...
Question 135: What can be defined as a momentary low voltage?...
Question 136: Which of the following was developed in order to protect aga...
Question 137: Which of the following can best eliminate dial-up access thr...
Question 138: Which of the following forms of authentication would most li...
Question 139: The first step in the implementation of the contingency plan...
Question 140: How would nonrepudiation be best classified as?...
Question 141: Within the OSI model, at what layer are some of the SLIP, CS...
Question 142: Which of the following is most appropriate to notify an exte...
Question 143: An Intrusion Detection System (IDS) is what type of control?...
Question 144: Which of the following would best classify as a management c...
Question 145: Where parties do not have a shared secret and large quantiti...
Question 146: In a known plaintext attack, the cryptanalyst has knowledge ...
Question 147: The NT password cracking program L0pht is capable of pulling...
Question 148: What distinguishes a hacker / cracker from a phreak?...
Question 149: What is the primary role of smartcards in a PKI?...
Question 150: Encapsulating Security Payload (ESP) provides some of the se...
Question 151: Which of the following statements pertaining to message dige...
Question 152: In this type of attack, the intruder re-routes data traffic ...
Question 153: The main difference between MD5 and SHA is what?...
Question 154: Packet Filtering Firewalls can also enable access for:...
Question 155: Secure Shell (SSH-2) provides all the following services exc...
Question 156: Which backup type run at regular intervals would take the le...
Question 157: A prolonged power supply that is below normal voltage is a:...
Question 158: A momentary high voltage is a:
Question 159: Which of the following is not a logical control when impleme...
Question 160: Which of the following is a cryptographic protocol and infra...
Question 161: Sensitivity labels are an example of what application contro...
Question 162: Cryptography does NOT help in:
Question 163: Which of the following is most likely to be useful in detect...
Question 164: Which of the following groups represents the leading source ...
Question 165: A boot sector virus goes to work when what event takes place...
Question 166: In a Public Key Infrastructure, how are public keys publishe...
Question 167: Which of the following rules is least likely to support the ...
Question 168: Which backup method copies only files that have changed sinc...
Question 169: Controls to keep password sniffing attacks from compromising...
Question 170: ___________________ is ultimately responsible for security a...
Question 171: The two categories of threats are natural and ___________....
Question 172: The Telecommunications Security Domain of information securi...
Question 173: Computer evidence may have a higher burden of proof. Typical...
Question 174: Which of the following can prevent hijacking of a web sessio...
Question 175: Which type of control is concerned with restoring controls?...
Question 176: Heuristic scanning in antivirus software is designed to catc...
Question 177: Which authentication technique best protects against hijacki...
Question 178: Which of the following is an example of a connectionless com...
Question 179: Which of the following protocols suite does the Internet use...
Question 180: Which of the following is the WEAKEST authentication mechani...
Question 181: What is defined as the hardware, firmware and software eleme...
Question 182: When a possible intrusion into your organization's informati...
Question 183: Which of the following floors would be most appropriate to l...
Question 184: What are the three components of the AIC triad? (Choose thre...
Question 185: Which of the following binds a subject name to a public key ...
Question 186: What is the main problem of the renewal of a root CA certifi...
Question 187: What would be the name of a Logical or Virtual Table dynamic...
Question 188: Qualitative loss resulting from the business interruption do...
Question 189: A deviation from an organization-wide security policy requir...
Question 190: What does the (star) integrity axiom mean in the Biba model?...
Question 191: Which ISO/OSI layer establishes the communications link betw...
Question 192: Which of the following elements is NOT included in a Public ...
Question 193: The session layer provides a logical persistent connection b...
Question 194: Logical or technical controls involve the restriction of acc...
Question 195: Which of the following could be BEST defined as the likeliho...
Question 196: The ___________ protocol converts IP addresses (logical) to ...
Question 197: Trin00 is an example of what type of attack?...
Question 198: What can be defined as secret communications where the very ...
Question 199: In order to be able to successfully prosecute an intruder:...
Question 200: Which of the following statements pertaining to key manageme...
Question 201: Which of the following statements is most accurate regarding...
Question 202: Why is infrared generally considered to be more secure to ea...
Question 203: A Wide Area Network (WAN) is basically everything outside of...
Question 204: Step-by-step instructions used to satisfy control requiremen...
Question 205: What is NOT an authentication method within IKE and IPsec?...
Question 206: Which of the following would best describe secondary evidenc...
Question 207: In what type of attack does an attacker try, from several en...
Question 208: What can be defined as a batch process dumping backup data t...
Question 209: Which of the following statements pertaining to the Bell-LaP...
Question 210: Why do buffer overflows happen? What is the main cause?...
Question 211: Which disaster recovery plan test involves functional repres...
Question 212: A code, as is pertains to cryptography:...
Question 213: Which of the following should be emphasized during the Busin...
Question 214: Which layer of the OSI model handles encryption?...
Question 215: Which of the following is considered the weakest link in a s...
Question 216: Which of the following is an IP address that is private (i.e...
Question 217: What is the main characteristic of a multi-homed host?...
Question 218: Which of the following is NOT an asymmetric key algorithm?...
Question 219: A periodic review of user account management should not dete...
Question 220: Which of the following encryption methods is known to be unb...
Question 221: Which of the following is a large hardware/software backup s...
Question 222: ________ attacks generally prevent valid authorized users fr...
Question 223: During the testing of the business continuity plan (BCP), wh...
Question 224: Which of the following questions are least likely to help in...
Question 225: Which of the following media is MOST resistant to tapping?...
Question 226: Preservation of confidentiality within information systems r...
Question 227: Which of the following keys has the SHORTEST lifespan?...
Question 228: Rule-Based Access Control (RuBAC) access is determined by ru...
Question 229: During which phase of an IT system life cycle are security r...
Question 230: The security of a computer application is most effective and...
Question 231: Accounting, __________, and ____________ are the AAAs of inf...
Question 232: In the context of network enumeration by an outside attacker...
Question 233: Related to information security, integrity is the opposite o...
Question 234: Which of the following statements pertaining to software tes...
Question 235: What is the name of the first mathematical model of a multi-...
Question 236: Which of the following is a LAN transmission method?...
Question 237: What is the main concern with single sign-on?...
Question 238: What layer of the ISO/OSI model do routers normally operate ...
Question 239: Which of the following protocol was used by the INITIAL vers...
Question 240: The MOST common threat that impacts a business's ability to ...
Question 241: Which of the following is an IP address that is private (i.e...
Question 242: Of the protocols list, which one is connection oriented?...
Question 243: When considering an IT System Development Life-cycle, securi...
Question 244: What ensures that the control mechanisms correctly implement...
Question 245: Which of the following classes is the first level (lower) de...
Question 246: When an outgoing request is made on a port number greater th...
Question 247: Which device acting as a translator is used to connect two n...
Question 248: Unshielded Twisted Pair cabling is a:...
Question 249: A security evaluation report and an accreditation statement ...
Question 250: Which of the following remote access authentication systems ...
Question 251: Which of the following statements pertaining to Kerberos is ...
Question 252: Which of the following IEEE standards defines the token ring...
Question 253: What is the primary reason why some sites choose not to impl...
Question 254: Which of the following is best at defeating frequency analys...
Question 255: What is called an attack in which an attacker floods a syste...
Question 256: Which of the following LAN topologies offers the highest ava...
Question 257: Why are coaxial cables called "coaxial"?...
Question 258: Which of the following is NOT a transaction redundancy imple...
Question 259: The primary service provided by Kerberos is which of the fol...
Question 260: Which type of attack involves the alteration of a packet at ...
Question 261: Insiders have a clear advantage in committing computer crime...
Question 262: The ability to identify and audit a user and his / her actio...
Question 263: Which of the following biometric devices has the lowest user...
Question 264: An access system that grants users only those rights necessa...
Question 265: Which of the following focuses on sustaining an organization...
Question 266: Which of the following Kerberos components holds all users' ...
Question 267: _____________ states that users should only be given enough ...
Question 268: Which type of password token involves time synchronization?...
Question 269: Which of the following security models does NOT concern itse...
Question 270: Which integrity model defines a constrained data item, an in...
Question 271: Unshielded Twisted Pair (UTP) cables comes in several catego...
Question 272: Which of the following is NOT an advantage that TACACS+ has ...
Question 273: What is called the use of technologies such as fingerprint, ...
Question 274: What can be defined as an abstract machine that mediates all...
Question 275: Which of the following statements pertaining to Kerberos is ...
Question 276: When preparing a business continuity plan, who of the follow...
Question 277: Which of the following is an unintended communication path t...
Question 278: Which of the following is not an example of a block cipher?...
Question 279: Name two types of Intrusion Detection Systems ________ and _...
Question 280: Which of the following Intrusion Detection Systems (IDS) use...
Question 281: Which of the following algorithms does NOT provide hashing?...
Question 282: What is the MOST critical piece to disaster recovery and con...
Question 283: Which of the following rules appearing in an Internet firewa...
Question 284: Which of the following tasks is NOT usually part of a Busine...
Question 285: Companies can now be sued for privacy violations just as eas...
Question 286: Which of the following technologies is a target of XSS or CS...
Question 287: Which of the following protects Kerberos against replay atta...
Question 288: Which of the following choice is NOT normally part of the qu...
Question 289: In what way can violation clipping levels assist in violatio...
Question 290: Some Unix systems use a very simple cipher called _________....
Question 291: Out of the steps listed below, which one is not one of the s...
Question 292: When a station communicates on the network for the first tim...
Question 293: In regards to information classification what is the main re...
Question 294: What ISO/OSI layer do switches primarily operate at? Do take...
Question 295: A DMZ is located:
Question 296: Which of the following is not a two-factor authentication me...
Question 297: Which type of attack involves impersonating a user or a syst...
Question 298: Which of the following is the best reason for the use of an ...
Question 299: Which of the following is the most complete disaster recover...
Question 300: Which of the following items is NOT a benefit of cold sites?...
Question 301: Which of the following services relies on UDP?...
Question 302: Which of the following defines session hijacking?...
Question 303: A timely review of system access audit records would be an e...
Question 304: Proxies works by transferring a copy of each accepted data p...
Question 305: Why should batch files and scripts be stored in a protected ...
Question 306: What is the difference between Advisory and Regulatory secur...
Question 307: Which of the following is used to find the Media Access Cont...
Question 308: Which port does the Post Office Protocol Version 3 (POP3) ma...
Question 309: What can best be described as a domain of trust that shares ...
Question 310: Buffer overflow and boundary condition errors are subsets of...
Question 311: Which access control model provides upper and lower bounds o...
Question 312: The IP header contains a protocol field. If this field conta...
Question 313: The Diffie-Hellman algorithm is primarily used to provide wh...
Question 314: What is a packet sniffer?
Question 315: Which of the following is not a DES mode of operation?...
Question 316: Public Key Infrastructure (PKI) uses asymmetric key encrypti...
Question 317: ________ ___________ refers to the act of requiring more tha...
Question 318: Which software development model is actually a meta-model th...
Question 319: A program that intentionally leaves a security hole or cover...
Question 320: What security model is dependent on security labels?...
Question 321: Which of the following is not an element of a business conti...
Question 322: Corporate networks are safer if an end user connects through...
Question 323: Which of the following is true about Kerberos?...
Question 324: Spoofing is a sophisticated technique of authenticating one ...
Question 325: Which of the following type of cryptography is used when bot...
Question 326: What is called the probability that a threat to an informati...
Question 327: Which of the following is NOT an example of an operational c...
Question 328: The deliberate planting of apparent flaws in a system for th...
Question 329: Which of the following is the act of performing tests and ev...
Question 330: The Diffie-Hellman algorithm is used for:...
Question 331: Which of the following phases of a software development life...
Question 332: Which of the following statements pertaining to VPN protocol...
Question 333: A _________ is an information path that is not normally used...
Question 334: Which of the following is an extension to Network Address Tr...
Question 335: Which of the following is an advantage in using a bottom-up ...
Question 336: What security principle is based on the division of job resp...
Question 337: Authentication Headers (AH) and Encapsulating Security Paylo...
Question 338: What is called the access protection system that limits conn...
Question 339: ____________ is a file system that was poorly designed and h...
Question 340: Before the advent of classless addressing, the address 128.1...
Question 341: Related to information security, availability is the opposit...
Question 342: What is also known as 10Base5?
Question 343: There are parallels between the trust models in Kerberos and...
Question 344: In which phase of Internet Key Exchange (IKE) protocol is pe...
Question 345: Why would a memory dump be admissible as evidence in court?...
Question 346: One purpose of a security awareness program is to modify:...
Question 347: Single Sign-on (SSO) is characterized by which of the follow...
Question 348: What is called the act of a user professing an identity to a...
Question 349: Which of the following control pairings include: organizatio...
Question 350: Related to information security, the prevention of the inten...
Question 351: Which of the following would assist the most in Host Based i...
Question 352: What is defined as the manner in which the network devices a...
Question 353: What is the primary role of cross certification?...
Question 354: The fact that a network-based IDS reviews packets payload an...
Question 355: The property of a system or a system resource being accessib...
Question 356: Which of these virus incidents did not occur in 1999? (Choos...
Question 357: Which of the following firewall rules found on a firewall in...
Question 358: How should a doorway of a manned facility with automatic loc...
Question 359: Crime Prevention Through Environmental Design (CPTED) is a d...
Question 360: Which of the following OSI layers provides routing and relat...
Question 361: Which of the following should NOT be performed by an operato...
Question 362: Secure Electronic Transaction (SET) and Secure HTTP (S-HTTP)...
Question 363: Only law enforcement personnel are qualified to do computer ...
Question 364: Which of the following best defines add-on security?...
Question 365: The ____________ protocol sends passwords in clear text, whi...
Question 366: Of the following, which is NOT a risk assessment system?...
Question 367: The term "principle of least privilege" is best as:...
Question 368: ______________ is a vendor neutral authorization and authent...
Question 369: Which of the following is responsible for MOST of the securi...
Question 370: In an online transaction processing system (OLTP), which of ...
Question 371: PGP uses which of the following to encrypt data?...
Question 372: If your property Insurance has Actual Cash Valuation (ACV) c...
Question 373: ________ is the authoritative entity which lists port assign...
Question 374: A DMZ is also known as a
Question 375: Which of the following addresses a portion of the primary me...
Question 376: BIND should be disabled on which of the following?...
Question 377: Which of the following is true about digital certificate?...
Question 378: Attackers have been known to search through company trash bi...
Question 379: A ______________ is an electronically generated record that ...
Question 380: Passfilt.dll enforces which of the following? (Choose all th...
Question 381: Which of the following statements is NOT true of IPSec Trans...
Question 382: Which of the following is not a preventive login control?...
Question 383: The difference between fraud and embezzlement is ___________...
Question 384: Which of the following division is defined in the TCSEC (Ora...
Question 385: What is a decrease in amplitude as a signal propagates along...
Question 386: Which of the following would best define a digital envelope?...
Question 387: Which security model introduces access to objects only throu...
Question 388: What is the name of the third party authority that vouches f...
Question 389: What principle focuses on the uniqueness of separate objects...
Question 390: Which of the following is a tool often used to reduce the ri...
Question 391: Which of the following is a not a preventative control?...
Question 392: Which of the following models does NOT include data integrit...
Question 393: Once evidence is seized, a law enforcement officer should em...
Question 394: What attack involves the perpetrator sending spoofed packet(...
Question 395: Which expert system operating mode allows determining if a g...
Question 396: Which of the following statements relating to the Bell-LaPad...
Question 397: Which of the following statements pertaining to packet switc...
Question 398: Which of the following is most appropriate to notify an inte...
Question 399: A public key algorithm that does both encryption and digital...
Question 400: Examples of types of physical access controls include all EX...
Question 401: Identification and authentication are the keystones of most ...
Question 402: What would be considered the biggest drawback of Host-based ...
Question 403: What is called the type of access control where there are pa...
Question 404: What enables a workstation to boot without requiring a hard ...
Question 405: Which of the following is an advantage of a qualitative over...
Question 406: Which of the following statements pertaining to biometrics i...
Question 407: What is the effective key size of DES?...
Question 408: Which of the following packets should NOT be dropped at a fi...
Question 409: Identifying specific attempts to penetrate systems is the fu...
Question 410: As a result of a risk assessment, your security manager has ...
Question 411: What is called a sequence of characters that is usually long...
Question 412: Unlike like viruses and worm, __________ are bogus messages ...
Question 413: The Orange Book states that "Hardware and software features ...
Question 414: Which of the following statements pertaining to the maintena...
Question 415: How often should tests and disaster recovery drills be perfo...
Question 416: The concept of best effort delivery is best associated with?...
Question 417: Encryption ciphers that use the same key to encrypt and decr...
Question 418: ______________ is a major component of an overall risk manag...
Question 419: Which of the following is NOT a task normally performed by a...
Question 420: In order to use L0pht, the ___________ must be exported from...
Question 421: What is the primary difference between FTP and TFTP?...
Question 422: Which of the following would constitute the best example of ...
Question 423: Flooding network ports is an example of which type of attack...
Question 424: Which of the following questions is less likely to help in a...
Question 425: An alternative to using passwords for authentication in logi...
Question 426: What key size is used by the Clipper Chip?...
Question 427: Which of the following is TRUE regarding Transmission Contro...
Question 428: Echo, chargen, finger, and bootp are all examples of?...
Question 429: Which of the following is an advantage of prototyping?...
Question 430: If an organization were to monitor their employees' e-mail, ...
Question 431: How are memory cards and smart cards different?...
Question 432: __________ is the most famous Unix password cracking tool....
Question 433: What is considered the most important type of error to avoid...
Question 434: Frame relay uses a public switched network to provide:...
Question 435: Telnet and rlogin use which protocol?...
Question 436: Which protocol makes USE of an electronic wallet on a custom...
Question 437: Which of the following algorithms is used today for encrypti...
Question 438: Which of following is not a service provided by AAA servers ...
Question 439: Which of the following was developed to address some of the ...
Question 440: Which access control model would a lattice-based access cont...
Question 441: Controlling access to information systems and associated net...
Question 442: The end result of implementing the principle of least privil...
Question 443: A confidential number used as an authentication factor to ve...
Question 444: __________ is a tool used by network administrators to captu...
Question 445: ________, _________, and __________ are required to successf...
Question 446: _____________ is the process of capturing network packets, b...
Question 447: Which of the following is the most reliable authentication m...
Question 448: Which access model is most appropriate for companies with a ...
Question 449: In non-discretionary access control using Role Based Access ...
Question 450: Which of the following access methods is used by Ethernet?...
Question 451: AH - Authentication Header is used in what industry standard...
Question 452: What prevents a process from accessing another process' data...
Question 453: A proxy is considered a:
Question 454: Penetration testing involves three steps. At which step shou...
Question 455: What is a characteristic of using the Electronic Code Book m...
Question 456: What is the Maximum Tolerable Downtime (MTD)?...
Question 457: Which of the following questions is less likely to help in a...
Question 458: Which of the following is not a security goal for remote acc...
Question 459: Which of the following type of traffic can easily be filtere...
Question 460: Which of the following protocols is designed to send individ...
Question 461: Which of the following is a set of data processing elements ...
Question 462: Which of the following is the LEAST user accepted biometric ...
Question 463: Which of the following is NOT a valid reason to use external...
Question 464: Volatile memory is referred to as ROM....
Question 465: What is the PRIMARY reason to maintain the chain of custody ...
Question 466: Who first described the DoD multilevel military security pol...
Question 467: What does the directive of the European Union on Electronic ...
Question 468: A virus is considered to be "in the ______ " if it has been ...
Question 469: Which of the following statements pertaining to disk mirrori...
Question 470: Which of the following attacks could capture network user pa...
Question 471: What is used to bind a document to its creation at a particu...
Question 472: Who is responsible for providing reports to the senior manag...
Question 473: What can be defined as the maximum acceptable length of time...
Question 474: Which of the following is less likely to accompany a conting...
Question 475: A password audit consists of checking for ____________?...
Question 476: The Logical Link Control sub-layer is a part of which of the...
Question 477: Which of the following is NOT a common backup method?...
Question 478: The International Standards Organization / Open Systems Inte...
Question 479: Which backup method usually resets the archive bit on the fi...
Question 480: Each data packet is assigned the IP address of the sender an...
Question 481: While using IPsec, the ESP and AH protocols both provides in...
Question 482: What is the most critical characteristic of a biometric iden...
Question 483: Tripwire is a ___________________-...
Question 484: If an operating system permits shared resources such as memo...
Question 485: Which of the following is related to physical security and i...
Question 486: Secure Shell (SSH) is a strong method of performing:...
Question 487: Which of the following best ensures accountability of users ...
Question 488: Which of the following networking devices allows the connect...
Question 489: Which of the following is NOT a correct notation for an IPv6...
Question 490: Which of the following phases of a software development life...
Question 491: The type of discretionary access control (DAC) that is based...
Question 492: ___________, generally considered "need to know" access is g...
Question 493: Unclassified, Private, Confidential, Secret, Top Secret, and...
Question 494: Which IPSec operational mode encrypts the entire data packet...
Question 495: What is the main focus of the Bell-LaPadula security model?...
Question 496: Under the Business Exemption Rule to the hearsay evidence, w...
Question 497: Good security is built on which of the following concept?...
Question 498: Transport Layer Security (TLS) is a two-layered socket layer...
Question 499: Which of the following statements do not apply to a hot site...
Question 500: How many bits of a MAC address uniquely identify a vendor, a...
Question 501: What is the most secure way to dispose of information on a C...
Question 502: Which layer of the DoD TCP/IP model controls the communicati...
Question 503: Which backup method only copies files that have been recentl...
Question 504: Which of the following is NOT a factor related to Access Con...
Question 505: Which of the following mechanisms was created to overcome th...
Question 506: Which of the following choices describe a condition when RAM...
Question 507: Who should measure the effectiveness of Information System s...
Question 508: A business continuity plan is an example of which of the fol...
Question 509: A prolonged complete loss of electric power is a:...
Question 510: Which of the following is currently used in conjunction with...
Question 511: Which of the following would be the best criterion to consid...
Question 512: Which of the following choices describe a Challenge-response...
Question 513: Which of the following cannot be undertaken in conjunction o...
Question 514: Which of the following is NOT a compensating measure for acc...
Question 515: Which of the following reviews system and event logs to dete...
Question 516: Which of the following is an issue with signature-based intr...
Question 517: The control measures that are intended to reveal the violati...
Question 518: Secure Shell (SSH-2) supports authentication, compression, c...
Question 519: Risk reduction in a system development life-cycle should be ...
Question 520: A contingency plan should address:...
Question 521: The number of violations that will be accepted or forgiven b...
Question 522: Brute force attacks against encryption keys have increased i...
Question 523: Which of the following are the two MOST common implementatio...
Question 524: What is called the percentage of valid subjects that are fal...
Question 525: What is the main characteristic of a bastion host?...
Question 526: Computer-generated evidence is considered:...
Question 527: Which of the following offers confidentiality to an e-mail m...
Question 528: Which of the following statements regarding an off-site info...
Question 529: Which three things must be considered for the design, planni...
Question 530: Authentication is based on which of the following:&lt;br&gt;...
Question 531: Which of the following is NOT a property of the Rijndael blo...
Question 532: Which of the following is an attribute of polymorphic code?...
Question 533: Which OSI/ISO layer is the Media Access Control (MAC) sublay...
Question 534: Which of the following would BEST be defined as an absence o...
Question 535: Which of the following ASYMMETRIC encryption algorithms is b...
Question 536: Which of the following statements pertaining to biometrics i...
Question 537: Why are clipping levels used?
Question 538: What is the PRIMARY use of a password?...
Question 539: The most important component of antivirus software is the __...
Question 540: The controls that usually require a human to evaluate the in...
Question 541: Which is the last line of defense in a physical security sen...
Question 542: There are ______ available service ports...
Question 543: The Crossover Error Rate (CER) is a good measure of performa...
Question 544: L2TP is considered to be a less secure protocol than PPTP....
Question 545: The __________ is the most dangerous part of a virus program...
Question 546: The Clipper Chip utilizes which concept in public key crypto...
Question 547: SATAN is a _____________ based tool and COPS is a __________...
Question 548: Which of the following methods of providing telecommunicatio...
Question 549: SMTP can best be described as:
Question 550: Which access control type has a central authority that deter...
Question 551: Which of the following can be best defined as computing tech...
Question 552: Which of the following is best defined as a mode of system t...
Question 553: What is called an exception to the search warrant requiremen...
Question 554: Which of the following NAT firewall translation modes offers...
Question 555: The absence of a safeguard, or a weakness in a system that m...
Question 556: What are the main goals of an information security program? ...
Question 557: What is used to protect programs from all unauthorized modif...
Question 558: What is defined as the rules for communicating between compu...
Question 559: Organizations should not view disaster recovery as which of ...
Question 560: Which of the following are NOT a countermeasure to traffic a...
Question 561: What mechanism automatically causes an alarm originating in ...
Question 562: Controls like guards and general steps to maintain building ...
Question 563: Degaussing is used to clear data from all of the following m...
Question 564: The Data Encryption Algorithm performs how many rounds of su...
Question 565: Which of the following is NOT a common category/classificati...
Question 566: Layer 4 of the OSI model corresponds to which layer of the D...
Question 567: Countermeasures address security concerns in which of the fo...
Question 568: What can best be described as an abstract machine which must...
Question 569: Which of the following would be LESS likely to prevent an em...
Question 570: A common way to create fault tolerance with leased lines is ...
Question 571: Within the legal domain what rule is concerned with the lega...
Question 572: Which protocol of the TCP/IP suite addresses reliable data t...
Question 573: Which of the following is the biggest concern with firewall ...
Question 574: A Security Reference Monitor relates to which DoD security s...
Question 575: What does the Clark-Wilson security model focus on?...
Question 576: Which of the following best describes signature-based detect...
Question 577: Recovery Site Strategies for the technology environment depe...
Question 578: Which of the following teams should NOT be included in an or...
Question 579: Which one of the following is usually not a benefit resultin...
Question 580: At which OSI/ISO layer is an encrypted authentication betwee...
Question 581: Whose role is it to assign classification level to informati...
Question 582: Which layer defines how packets are routed between end syste...
Question 583: Which of the following can be defined as a framework that su...
Question 584: Which of the following is an Internet IPsec protocol to nego...
Question 585: ___________________ viruses change the code order of the str...
Question 586: Which of the following backup methods is primarily run when ...
Question 587: What is the greatest danger from DHCP?...
Question 588: Another name for a VPN is a:
Question 589: Which of the following layers provides end-to-end data trans...
Question 590: An attempt to break an encryption algorithm is called ______...
Question 591: In biometrics, "one-to-many" search against database of stor...
Question 592: Integrity = ______________
Question 593: Which of the following are NT Audit events? (Choose all that...
Question 594: A network-based vulnerability assessment is a type of test a...
Question 595: Which of the following is a reason to use a Firewall?...
Question 596: What is electronic vaulting?
Question 597: Which of the following is most concerned with personnel secu...
Question 598: Which of the following tools is less likely to be used by a ...
Question 599: Which layer of the OSI/ISO model handles physical addressing...
Question 600: Which approach to a security program ensures people responsi...
Question 601: What can best be defined as a strongly protected computer th...
Question 602: Which of the following statements pertaining to firewalls is...
Question 603: Which of the following is implemented through scripts or sma...
Question 604: Which of the following will a Business Impact Analysis NOT i...
Question 605: Which xDSL flavour, appropriate for home or small offices, d...