SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Assessment And Risk Mgmt
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Responsible for communicating to senior mgmt organizational risks and compliance regulations
AS/NZS 4360
CISO
countermeasure
ISO/IEC 27005
2. Number of time the incident might occur annually - (ARO)
ITIL
COSO
countermeasure
annualized rate of occurrence
3. CISO
chief information security officer
physical
security governanace
countermeasure
4. Plan and Organize - Implement - Operate and Maintain - Monitor and Evaluate
CobiT
security program
due care
OCTAVE
5. OCTAVE
administrative
vulnerability
Operationally Critical Threat - Asset - and Vulnerability Evaluation
OCTAVE
6. Port scanners - vulnerability scanners - protocol analyzers - password crackers - network mappers - open vulnerability and assessment language (OVAL) are all tool used in a ___________________ assessment
ISO/IEC 27002
Facilitated Risk Analysis Process
john the ripper
vulnerability
7. This type of testing scans for vulnerabilities - attacks to determine extent - tests countermeasures by circumvention - and can be internal or external
ISO/IEC 27004
strategic
vulnerability
penetration
8. Type of audit that checks that network resources - systems and software are used appropriately
usage
confidentiality
penetration
threat
9. An open language from mitre.org for determining vulnerabilities and problems on computer systems
availability
OVAL
administrative
OCTAVE
10. Ensures managment security directives are fulfilled
ISO 17799
CISO
AS/NZS 4360
security officer
11. Percentage of an asset's value that would be lost in a single incident - (EF)
risk anlysis
exposure factor
corporate security officer
COSO
12. Used to ID failures in a complex systems to understand underlying causes of threats
vulnerability
fault tree analysis
privilege
ISO/IEC 27799
13. Made up of ten domains - a mechanism to describe security processes
ISO 17799
vulnerability scanner
vulnerability
port scanner
14. __________ loss has a negative effect after a vulnerability is initially exploited
delayed
integrity
ISO/IEC 27004
protocol analyzer
15. Internationally recognized Information Security Management standard - provides high level conceptual recomendations on enterprise security - brish standard
Facilitated Risk Analysis Process
BS7799
data owner
annualized rate of occurrence
16. Used to predict changes based on trends - detect deviations - and watch events across multiple system components
technical
vulnerability scanner
security officer
performance monitor
17. The likelihood of exploitation and the loss potential
CISO
risk
network mapping
qualitative
18. Derived from the COSO framework
CobiT
Information Technology Infrastructure Library (ITIL)
security program
threat
19. Type of audit that checks procedures and policies for escalating issues to management
countermeasure
administrative
escalation
annualized rate of occurrence
20. Long-term goals focused on risk managment - compliance - security responsiblities - continual improvement - using security to attract customers
CISO
technical
strategic
port scanner
21. A process to ID assests and their value - ID vulnerabilities and threats - quantify probability and impact of threats - provide balance between impact and cost
AS/NZS 4360
port scanner
risk anlysis
SP 800-30
22. Security policy - map business objectives to security - Security infrastructure - security officer - reviews - Assest classification/control - inventory - Personnel security - screening - training - roles - Physical security - Communication/operation
ISO 17799
due care
port scanner
FRAP
23. NIST risk management methodology
vulnerability
SP 800-30
tactical
Information Technology Infrastructure Library (ITIL)
24. A tool that monitors network traffic - shows data and protocols in use - also known as a packet sniffer (i.e wireshark - TCPDump - Microsoft Network Monitor - Carnivore)
protocol analyzer
performance baseline
security officer
network mapping
25. IRM
escalation
Information risk management
ISO/IEC 27004
vulnerability
26. ____________ can discover network devices / application - check password strength - measure internal / external access - analyze vulnerabilities in NOS - test response to DOS attacks
network mapping
port scanner
Information risk management
threat
27. The asset's value multiplied by the EF percentage - (SLE)
escalation
risk analysis
network mapping
single loss expectancy
28. SLE x ARO - (ALE)
annualized loss expectancy
single loss expectancy
exposure
security program
29. Establish - implement - control and improve the Information Security Managment System (based on BS7799 Part 2)
FRAP
ISO/IEC 27001
administrative
AS/NZS 4360
30. Focus on service level agreements between IT dept and internal customers
privilege
ITIL
countermeasure
performance monitor
31. Daily goals focused on productivity and task-oriented activities
fault tree analysis
risk analysis
planning horizon
operational
32. Provides good practice advice on ISMS (ISO 17799)(based on BS7799 Part 1)
ISO/IEC 27002
IRM
COSO
vulnerability
33. Risk assessment that is scenario based - ranks threats and countermeasures - uses experience - judgment - intuition and opinion
network mapping
qualitative
performance baseline
technical
34. A log that can record outgoing requests - incoming traffic - and internet usage
firewall
privilege
usage
technical
35. Responsible for information classification and protection
fault tree analysis
CISO
data owner
exposure factor
36. Possiblity of damage and the ramifications should it occur
risk
Failure Modes and Effect Analysis
strategic
ISO/IEC 27002
37. ISM Standard
COSO
COSO
Information Security Management
fault tree analysis
38. CSO
network mapping
Control Objectives for Information and related Technology
FMEA
corporate security officer
39. Collection of controls an organization must have in place
technical
vulnerability
security program
chief information security officer
40. Potential danger to information or systems
threat
Operationally Critical Threat - Asset - and Vulnerability Evaluation
Control Objectives for Information and related Technology
network mapping
41. Assurance of accurancy and reliability of information and systems
No events - Errors only - Errors and warnings - All events
integrity
L0phtCrack
privilege
42. Controls that include policies - standards - procedures -risk management - personnel screening - training - change control
Information Security Management
administrative
CISO
escalation
43. Event levels available for logging in a MS DNS server
No events - Errors only - Errors and warnings - All events
Failure Modes and Effect Analysis
FMEA
confidentiality
44. Type of audit that checks that accounts - groups and roles are correctly assigned
COSO
FMEA
COSO
privilege
45. FMEA
ISO/IEC 27002
Failure Modes and Effect Analysis
ITIL
network mapping
46. Framework/set of best practices that define goals for controls used to properly manage IT and to ensure IT maps to business needs
Information risk management
administrative
FMEA
CobiT
47. Ensures necessary level of secrecy and prevents unauthorized disclosure
confidentiality
OCTAVE
vulnerability
security officer
48. Developed by the Treadway Commission in 1985 to deal with fraudulent financial activities and reporting
risk catagories
COSO
annualized rate of occurrence
Failure Modes and Effect Analysis
49. Method of ID functions and their failures - causes of failures their effect - originally designed for systems engineering
IRM
COSO
risk
FMEA
50. Guide to illustrate how to protect personal health information
threat
Control Objectives for Information and related Technology
ISO/IEC 27799
IRM