SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Assessment And Risk Mgmt
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. The following tools (Nessus - Qualys - Retina) are ______________ scanners
vulnerability
planning horizon
data owner
delayed
2. A tool that monitors network traffic - shows data and protocols in use - also known as a packet sniffer (i.e wireshark - TCPDump - Microsoft Network Monitor - Carnivore)
john the ripper
administrative
vulnerability
protocol analyzer
3. Ensures necessary level of secrecy and prevents unauthorized disclosure
Control Objectives for Information and related Technology
confidentiality
CobiT
FMEA
4. Method of ID functions and their failures - causes of failures their effect - originally designed for systems engineering
FMEA
annualized loss expectancy
physical
ISO 17799
5. Strategic - tactical and operational planning
annualized loss expectancy
planning horizon
security officer
confidentiality
6. __________ loss has a negative effect after a vulnerability is initially exploited
security program
ISO/IEC 27004
delayed
john the ripper
7. Type of audit that checks that accounts - groups and roles are correctly assigned
security officer
FMEA
COSO
privilege
8. An open language from mitre.org for determining vulnerabilities and problems on computer systems
delayed
port scanner
data owner
OVAL
9. Used to predict changes based on trends - detect deviations - and watch events across multiple system components
Facilitated Risk Analysis Process
technical
OCTAVE
performance monitor
10. A quantative risk assesment process that allows for tests to be conducted to allow users to determine areas that require a risk analysis
CobiT
AS/NZS 4360
FRAP
confidentiality
11. Long-term goals focused on risk managment - compliance - security responsiblities - continual improvement - using security to attract customers
vulnerability
single loss expectancy
annualized loss expectancy
strategic
12. Legal term used to determine liability - acting responsibly - have lower risk of liability due to security breach
due care
fault tree analysis
risk analysis
BS7799
13. Responsible for information classification and protection
data owner
BS7799
operational
integrity
14. Guide assist in the implemenation of information security based on risk managent approach
risk analysis
ISO/IEC 27005
FMEA
risk
15. Type of audit that checks information classification and change control procedures
administrative
performance baseline
Information Technology Infrastructure Library (ITIL)
delayed
16. Type of audit that checks that network resources - systems and software are used appropriately
COSO
usage
security governanace
availability
17. Midterm goals
tactical
countermeasure
vulnerability
john the ripper
18. A weakness (software - hardware - procedural - human) that can be exploited
corporate security officer
vulnerability
protocol analyzer
penetration
19. FMEA
strategic
ISO/IEC 27001
Operationally Critical Threat - Asset - and Vulnerability Evaluation
Failure Modes and Effect Analysis
20. Used to ID failures in a complex systems to understand underlying causes of threats
threat
Failure Modes and Effect Analysis
OCTAVE
fault tree analysis
21. Made up of ten domains - a mechanism to describe security processes
COSO
threat
ISO 17799
qualitative
22. Daily goals focused on productivity and task-oriented activities
network mapping
risk
AS/NZS 4360
operational
23. Ensures reliable timely access to data/resources to authorized individuals
CobiT
availability
administrative
vulnerability scanner
24. COSO
john the ripper
COSO
vulnerability
Committee of Sponsoring Organizations
25. Ensures managment security directives are fulfilled
security officer
FMEA
firewall
physical
26. The asset's value multiplied by the EF percentage - (SLE)
single loss expectancy
confidentiality
CobiT
tactical
27. Controls that manage facility access - locking systems - media sanitation - intrusion monitoring - environmental
physical
security officer
fault tree analysis
Facilitated Risk Analysis Process
28. De facto standard of best practices for IT service mgmt
CobiT
Information Technology Infrastructure Library (ITIL)
integrity
ISO/IEC 27799
29. Internationally recognized Information Security Management standard - provides high level conceptual recomendations on enterprise security - brish standard
technical
COSO
Facilitated Risk Analysis Process
BS7799
30. Risk mgmt method created by Carnegie Mellon University - people manage/direct the risk evaluation for IT security in a company
OCTAVE
technical
CISO
security governanace
31. Responsible for developing: security awareness program - budget for information security related activities; policies - procdures - and guidelines - a security compliance program - and metrics
single loss expectancy
due care
CISO
Control Objectives for Information and related Technology
32. Responsible for communicating to senior mgmt organizational risks and compliance regulations
performance baseline
CISO
OVAL
CobiT
33. Control environment - company culture - Risk assessment - manage change - Control activities - policies - procedures - practices - Information and communication - right people - info - time - Monitoring - detect and respond
Information Security Management
mappers
COSO
protocol analyzer
34. Event levels available for logging in a MS DNS server
No events - Errors only - Errors and warnings - All events
risk
Facilitated Risk Analysis Process
annualized rate of occurrence
35. An open source password cracker that uses dictionary and brute force attacks - stores previously cracked passwords - uses unshadow to merge password /shadow files
risk
exposure
john the ripper
annualized loss expectancy
36. Controls that implement access control - password mangement - identification and authentication methods - configuration
administrative
escalation
exposure factor
technical
37. Assurance of accurancy and reliability of information and systems
AS/NZS 4360
integrity
security governanace
vulnerability scanner
38. Provides a cost/benefit comparision
exposure
blueprints
risk analysis
data owner
39. A commercial password cracker that can test password strength and recover passwords; and perform dictionary and brute force attacks
planning horizon
elcomsoft
operational
annualized loss expectancy
40. SLE x ARO - (ALE)
annualized loss expectancy
CISO
vulnerability
chief information security officer
41. _______________ can test IDS - detect network congestion - detect bad / failing equipment - detect high processor loads - must be NOS appropriate
vulnerability
network mapping
security officer
vulnerability
42. IRM
Information risk management
No events - Errors only - Errors and warnings - All events
BS7799
exposure factor
43. A log that can record outgoing requests - incoming traffic - and internet usage
firewall
risk anlysis
Information Technology Infrastructure Library (ITIL)
single loss expectancy
44. CISO
tactical
BS7799
chief information security officer
ISO/IEC 27799
45. Physical damage - human interaction - equip malfunction - misuse of data - loss of data - application error
risk
ISO/IEC 27004
performance baseline
risk catagories
46. OCTAVE
escalation
vulnerability
Operationally Critical Threat - Asset - and Vulnerability Evaluation
network mapping
47. NIST risk management methodology
Facilitated Risk Analysis Process
ISO/IEC 27002
administrative
SP 800-30
48. The tools - personnel and business processes necessary to ensure that security meets needs
delayed
countermeasure
security governanace
risk
49. Focus on service level agreements between IT dept and internal customers
risk analysis
ITIL
blueprints
Operationally Critical Threat - Asset - and Vulnerability Evaluation
50. Process of ID and assessing risk - reducing to acceptable level - implementing mechanisms to maintain.
port scanner
IRM
exposure
Information Security Management