SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Assessment And Risk Mgmt
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Derived from the COSO framework
physical
CobiT
Facilitated Risk Analysis Process
performance monitor
2. An password cracker that uses dictionary and brute force attacks - rainbow tables - can test password strength and recover passwords - was originally free - but now a commercial product
risk
SP 800-30
exposure
L0phtCrack
3. Event levels available for logging in a MS DNS server
AS/NZS 4360
CobiT
vulnerability
No events - Errors only - Errors and warnings - All events
4. Used to ID failures in a complex systems to understand underlying causes of threats
Information risk management
fault tree analysis
SP 800-30
ISO 17799
5. Type of audit that checks information classification and change control procedures
Committee of Sponsoring Organizations
vulnerability
security program
administrative
6. FRAP
administrative
Failure Modes and Effect Analysis
risk analysis
Facilitated Risk Analysis Process
7. Process of ID and assessing risk - reducing to acceptable level - implementing mechanisms to maintain.
Committee of Sponsoring Organizations
risk
IRM
FMEA
8. Corporate governance at the strategic level
ISO/IEC 27004
COSO
CobiT
risk analysis
9. A plan of action to deal with risks defined in the risk assessment - may remediate or transfer risk
john the ripper
risk mitigation
technical
elcomsoft
10. _______________ can test IDS - detect network congestion - detect bad / failing equipment - detect high processor loads - must be NOS appropriate
elcomsoft
ISO 17799
protocol analyzer
network mapping
11. Controls that manage facility access - locking systems - media sanitation - intrusion monitoring - environmental
protocol analyzer
physical
AS/NZS 4360
exposure factor
12. IT governance at the operational level
CobiT
CISO
OVAL
risk analysis
13. Internationally recognized Information Security Management standard - provides high level conceptual recomendations on enterprise security - brish standard
security program
ISO 17799
annualized loss expectancy
BS7799
14. The following tools (Nessus - Qualys - Retina) are ______________ scanners
COSO
single loss expectancy
vulnerability
privilege
15. A tool that monitors network traffic - shows data and protocols in use - also known as a packet sniffer (i.e wireshark - TCPDump - Microsoft Network Monitor - Carnivore)
CISO
performance monitor
chief information security officer
protocol analyzer
16. Type of audit that checks procedures and policies for escalating issues to management
exposure
escalation
due care
Control Objectives for Information and related Technology
17. Risk mgmt method created by Carnegie Mellon University - people manage/direct the risk evaluation for IT security in a company
OCTAVE
No events - Errors only - Errors and warnings - All events
escalation
threat
18. Midterm goals
usage
tactical
security governanace
FRAP
19. A method of ID vulnerabililties and threats and assessing possible impacts to determine where to implement security safeguards
risk analysis
confidentiality
delayed
ISO/IEC 27005
20. Guide to illustrate how to protect personal health information
privilege
Information Security Management
ISO/IEC 27799
network mapping
21. FMEA
vulnerability
risk
blueprints
Failure Modes and Effect Analysis
22. Possiblity of damage and the ramifications should it occur
ISO 17799
risk
confidentiality
integrity
23. Ensures managment security directives are fulfilled
ISO 17799
FMEA
security officer
performance monitor
24. IRM
CISO
Information risk management
strategic
planning horizon
25. Provides a cost/benefit comparision
vulnerability
risk analysis
administrative
operational
26. Collection of controls an organization must have in place
planning horizon
security program
OVAL
delayed
27. A weakness (software - hardware - procedural - human) that can be exploited
annualized loss expectancy
firewall
network mapping
vulnerability
28. Responsible for information classification and protection
blueprints
data owner
elcomsoft
BS7799
29. Control environment - company culture - Risk assessment - manage change - Control activities - policies - procedures - practices - Information and communication - right people - info - time - Monitoring - detect and respond
COSO
integrity
fault tree analysis
risk
30. Used in assurance risk mgmt - methodical way to ID major failure modes (not useful for complex failure modes)
blueprints
countermeasure
usage
FMEA
31. This type of testing scans for vulnerabilities - attacks to determine extent - tests countermeasures by circumvention - and can be internal or external
OVAL
countermeasure
Failure Modes and Effect Analysis
penetration
32. SLE x ARO - (ALE)
annualized loss expectancy
availability
elcomsoft
threat
33. Expected or predetermined performance level - developed from policy - performance - requirements
risk mitigation
performance baseline
john the ripper
strategic
34. Ensures reliable timely access to data/resources to authorized individuals
countermeasure
delayed
availability
ISO/IEC 27001
35. Risk mgmt method with much broader focus than IT security
risk analysis
vulnerability
qualitative
AS/NZS 4360
36. The asset's value multiplied by the EF percentage - (SLE)
single loss expectancy
fault tree analysis
firewall
delayed
37. Physical damage - human interaction - equip malfunction - misuse of data - loss of data - application error
mappers
risk catagories
exposure
IRM
38. The likelihood of exploitation and the loss potential
vulnerability
risk
confidentiality
integrity
39. A commercial password cracker that can test password strength and recover passwords; and perform dictionary and brute force attacks
ISO 17799
elcomsoft
security officer
Information risk management
40. OCTAVE
Operationally Critical Threat - Asset - and Vulnerability Evaluation
threat
OVAL
port scanner
41. Long-term goals focused on risk managment - compliance - security responsiblities - continual improvement - using security to attract customers
security program
risk anlysis
strategic
network mapping
42. Legal term used to determine liability - acting responsibly - have lower risk of liability due to security breach
john the ripper
qualitative
single loss expectancy
due care
43. Provides good practice advice on ISMS (ISO 17799)(based on BS7799 Part 1)
CISO
ISO/IEC 27002
integrity
ISO/IEC 27004
44. An open language from mitre.org for determining vulnerabilities and problems on computer systems
vulnerability
risk
Control Objectives for Information and related Technology
OVAL
45. Potential danger to information or systems
confidentiality
threat
Failure Modes and Effect Analysis
administrative
46. Percentage of an asset's value that would be lost in a single incident - (EF)
performance baseline
network mapping
exposure factor
CobiT
47. __________ loss has a negative effect after a vulnerability is initially exploited
delayed
tactical
CobiT
network mapping
48. Controls that include policies - standards - procedures -risk management - personnel screening - training - change control
ISO 17799
annualized rate of occurrence
administrative
Committee of Sponsoring Organizations
49. CobiT
Control Objectives for Information and related Technology
tactical
FMEA
Operationally Critical Threat - Asset - and Vulnerability Evaluation
50. Responsible for communicating to senior mgmt organizational risks and compliance regulations
Committee of Sponsoring Organizations
CobiT
john the ripper
CISO