The Ultimate Quiz On Information Assets

  • Grade 11th,
  • Grade 12th
  • ISO/IEC 27001
  • NIST SP 800-53
Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By P_baus
P
P_baus
Community Contributor
Quizzes Created: 1 | Total Attempts: 223
| Attempts: 223 | Questions: 200 | Updated: Mar 22, 2025
Please wait...
Question 1 / 201
🏆 Rank #--
0 %
0/100
Score 0/100

1. Information assets have ____ when authorized users - persons or computer systems - are able to access them in the specified format without interference or obstruction.

Explanation

Cap 1

Submit
Please wait...
About This Quiz
Cybersecurity Basics Quizzes & Trivia

Explore the essentials of safeguarding information assets with this quiz. Assess your understanding of availability, confidentiality, integrity, mitigation strategies, and recovery plans. Ideal for learners aiming to enhance their knowledge in information security practices.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. The purpose of the ____ is to define the scope of the CP operations and establish managerial intent with regard to timetables for response to incidents, recovery from disasters, and  reestablishment of operations for continuity.

Explanation

Cap 2

Submit

3. The focus during a(n) ____ is on learning what worked, what didn't, and where communications and response procedures may have failed.

Explanation

Cap 6

Submit

4. A ____ attack is much more substantial than a DoS attack because of the use of multiple systems to simultaneously attack a single target.

Explanation

Cap 7

Submit

5. The ____ team is responsible for reestablishing connectivity between systems and to the Internet.

Explanation

Cap 10

Submit

6. ____ is the process of moving an organization toward its vision.

Explanation

Cap 1

Submit

7. The Southeast Collegiate Cyber Defense Competition is unique in that it focuses on the operational aspect of managing and protecting an existing network infrastructure. Unlike "capture-the-flag " exercises, this competition is exclusively a real-world ____ competition.

Explanation

Cap 4

Submit

8. In an attack known as ____, valid protocol packets exploit poorly configured DNS servers to inject false information to corrupt the servers' answers to routine DNS queries from other systems on that network.

Explanation

Cap 5

Submit

9. The task of monitoring file systems for unauthorized change is best performed by using a(n) ____.

Explanation

Cap 5

Submit

10. The ____ team is primarily responsible for data restoration and recovery.

Explanation

Cap 10

Submit

11. A(n) ____ is an investigation and assessment of the impact that various attacks can have on the organizatio.

Explanation

Cap 1

Submit

12. A(n) ____ is used to anticipate, react to, and recover from events that threaten the security of information and information assets in an organization; it is also used to restore the organization to normal modes of business operations;

Explanation

Cap 1

Submit

13. ____ assigns a risk rating or score to each information asset. Although this number does not mean anything in absolute terms, it is useful in gauging the relative risk to each vulnerable information asset and facilitates the development of comparative ratings later in the risk control process.

Explanation

Cap 1

Submit

14. ____ is a risk control approach that attempts to shift the risk to other assets, other processes, or other organizations.

Explanation

Cap 1

Submit

15. A(n) ____ is a CSIRT team member, other than the team leader, who is currently performing the responsibilities of the team leader in scanning the organization's information infrastructure for signs of an incident.

Explanation

Cap 4

Submit

16. The U.S. National Institute of Standards and Technology defines the incident response life cycle as having four main processes: 1) preparation; 2) detection and analysis; 3) containment, eradication, and recovery; and 4) ____.

Explanation

Cap 4

Submit

17. One of the primary responsibilities of the IRP team is to ensure that the ____ is prepared to respond to each incident it may face.

Explanation

Cap 4

Submit

18. Using a process known as ____, network-based IDPSs look for attack patterns by comparing measured activity to known signatures in their knowledge base to determine whether or not an attack has occurred or may be under way.

Explanation

Cap 5

Submit

19. The first group to communicate the CSIRT's vision and operational plan is the managerial team or individual serving as the ____.

Explanation

Cap 6

Submit

20. According to NIST, which of the following is an example of a UA attack?

Explanation

Cap 7

Submit

21. ____ is used both for intrusion analysis and as part of evidence collection and analysis.

Explanation

Cap 8

Submit

22. ____ are highly probable when infected machines are brought back online or when other infected computers that may have been offline at the time of the attack are brought back up. 

Explanation

Cap 9

Submit

23. ____ is a valuable resource for additional information on building and staffing CSIRTs.

Explanation

Cap 6

Submit

24. The ____ handles computer crimes that are categorized as felonies.

Explanation

Cap 8

Submit

25. A ____ is used for an office or small campus, with segment distances measured in tens of meters. It may have only a few hosts, or it may have hundreds of clients with multiple servers.

Explanation

Cap 9

Submit

26. A(n) ____ is an object, person, or other entity that is a potential risk of loss to an asset.

Explanation

Cap 1

Submit

27. The ____ is an investigation and assessment of the impact that various events or incidents can have on the organization.

Explanation

Cap 2

Submit

28. Some recovery strategies seek to improve the ____ of a server or system in addition to, or instead of, performing backups of data.

Explanation

Cap 3

Submit

29. A resumption location known as a ____  or a _______ is a fully configured computer facility capable of establishing operations at a moment's notice.

Explanation

A resumption location known as a hot site or a mirrored site is a fully configured computer facility capable of establishing operations at a moment's notice. These sites are designed to replicate the primary site's infrastructure, systems, and data, ensuring that critical operations can be quickly resumed in the event of a disaster or disruption. The term "hot site" refers to a facility that is ready and operational, while a "mirrored site" refers to a site that replicates the primary site's data and systems in real-time, providing continuous synchronization. Both hot sites and mirrored sites are essential for business continuity and disaster recovery planning.

Submit

30. The process of evaluating the circumstances around organizational events includes determining which adverse events are possible incidents, or ____.

Explanation

Cap 5

Submit

31. A(n) ____ is a sign that an activity now occurring may signal an incident that could occur in the future.

Explanation

Cap 5

Submit

32. The Business Continuity Institute offers an uncertified category of membership called a(n) ____ that is accepted by application and does not require assessment or a review process.

Explanation

Cap 11

Submit

33. When an organization completely outsources its IR work, typically to an on-site contractor, it is called a(n) ____ model.

Explanation

Cap 6

Submit

34. A key step in the ____ approach to incident response is to discover the identify of the intruder while documenting his or her activity.

Explanation

Cap 6

Submit

35. The determination of what systems fall under the CSIRT 's responsibility is called its ____.

Explanation

Cap 6

Submit

36. When an alert warns of new malicious code that targets software used by an organization, the first response should be to research the new virus to determine whether it is ____.

Explanation

Cap 7

Submit

37. When an incident includes a breach of physical security, all aspects of physical security should be escalated under a containment strategy known as ____.

Explanation

Cap 7

Submit

38. Clifford Stoll's book, ____, provides an excellent story about a real-world incident that turned into an international tale of espionage and intrigue.

Explanation

Cap 7

Submit

39. The ____ phase of forensic analysis involves the use of forensic tools to recover the content of files that were deleted, operating system artifacts (such as event data and logging of user actions), and other relevant facts.

Explanation

Cap 8

Submit

40. ____ are likely in the event of a hacker attack, when the attacker retreats to a chat room and describes in specific detail to his or her associates the method and results of his or her latest conquest. 

Explanation

Cap 9

Submit

41. In the context of disaster notification, the ____ is a scripted description of the disaster and consists of just enough information so that each response knows what port of the DR plan to implement.

Explanation

Cap 10

Submit

42. The ____ system is an information system with a telephony interface that can be used to automate the alert process.

Explanation

Cap 10

Submit

43. ____ ensures that only those with the rights and privileges to access information are able to do so.

Explanation

Cap 1

Submit

44. ____ is the risk control approach that attempts to reduce the impact caused by the exploitation of vulnerability through planning and preparation.

Explanation

Cap 1

Submit

45. Information assets have ____ when they are not exposed (while being stored, processed, or transmitted) to corruption, damage, destruction, or other disruption of their authentic states.

Explanation

Cap 1

Submit

46. The ____ illustrates the most critical characteristics of information and has been the industry standard for computer security since the development of the mainframe.

Explanation

Cap 1

Submit

47. ____ hack systems to conduct terrorist activities through network or Internet pathways.

Explanation

Cap 1

Submit

48. The ____ job functions and organizational roles focus on protecting the organization's information systems and stored information from attacks.

Explanation

Cap 2

Submit

49. The ____ is used to collect information directly from the end users and business managers.

Explanation

Cap 2

Submit

50. The first major business impact analysis task is to analyze and prioritize the organization's business processes based on their relationships to the organization's ____.

Explanation

Cap 2

Submit

51. The elements required to begin the ____ process are a planning methodology; a policy environment to enable the planning process; an understanding of the causes and effects of core precursor activities, and access to financial and other resources.

Explanation

Cap 2

Submit

52. Within an organization, a(n) ____ is a group of individuals who are united by shared interests or values and who have a common goal of making the organization function to meet its objectives.

Explanation

Cap 2

Submit

53. In a CPMT, a(n) ____ should be a high-level manager with influence and resources that can be used to support the project team, promote the objectives of the CP project, and endorse the results that come from the combined effort.

Explanation

Cap 2

Submit

54. A CPMT should include _____ who can oversee the security planning of the project and provide information on threats, vulnerabilities, and recovery requirements needed in the planning process.

Explanation

Cap 2

Submit

55. Considered to be the traditional "lock and copy" approach to database backup, _____ require the database to be inaccessible while a backup is created to a local drive.

Explanation

Cap 3

Submit

56. ____ uses a number of hard drives to store information across multiple drive units.

Explanation

Cap 3

Submit

57. An organization aggregates all local backups to a central repository and then backs up that repository to an online vendor, with a ____ backup strategy.

Explanation

Cap 3

Submit

58. A(n) ____ is often included in legal documents to ensure that a vendor is not liable for actions taken by a client.

Explanation

Cap 3

Submit

59. Advances in cloud computing have opened a new field in application redundancy and backup. Because organizations that lease ____ are in effect using a preconfigured set of applications on someone else's systems, it is reasonable to ask that the service agreement include contingencies for recovery.

Explanation

Cap 3

Submit

60. Both data backups and archives should be based on a(n) ____ schedule that guides the frequency of replacement and the duration of storage.

Explanation

Cap 3

Submit

61. A backup plan using WAN/VLAN replication and a recovery strategy using a warm site is most suitable for information systems that have ____ priority within an organization.

Explanation

Cap 3

Submit

62. The training delivery method with the lowest cost to the organization is ____.

Explanation

Cap 4

Submit

63. ____ is the process of systematically examining information assets for evidentiary material that can provide insight into how an incident transpired.

Explanation

Cap 4

Submit

64. General users require training on the technical details of how to do their jobs securely, including good security practices, ____ management, specialized access controls, and violation reporting.

Explanation

Cap 4

Submit

65. If an intruder can ____ a device, then no electronic protection can deter the loss of information.

Explanation

Cap 5

Submit

66. When implementing a BC plan, an organization reaches a predetermined state, known as a(n) ____, at which time the responsible executive indicates that the organization is to relocate to a pre-selected alternate site.

Explanation

Cap 11

Submit

67. Once BC activities have come to a close and the organization has reoccupied its primary facility or new permanent facility, the team should meet for a(n) ____.

Explanation

Cap 11

Submit

68. A certification offered by the Business Continuity Institute is called ____.

Explanation

Cap 11

Submit

69. The ____ section of the business continuity policy identifies the roles and responsibilities of the key players in the business continuity operation.

Explanation

Cap 11

Submit

70. A CSIRT model in which a single CSIRT handles incidents throughout the organization is called a(n) ____.

Explanation

Cap 6

Submit

71. Those services undertaken to prepare the organization or the CSIRT constituents to protect and secure systems in anticipation of problems, attacks, or other events are called ____.

Explanation

Cap 6

Submit

72. Those services performed in response to a request or a defined event such as a help desk alert are called ____.

Explanation

Cap 6

Submit

73. Known as ____, procedures for regaining control of systems and restoring operations to normalcy are the heart of the IR plan and the CSIRT's operations.

Explanation

Cap 7

Submit

74. In a "block" containment strategy, in which the attacker's path into the environment is disrupted, you should use the most precise strategy possible, starting with ____.

Explanation

Cap 7

Submit

75. A ____ is a small quantity of data kept by a Web site as a means of recording that a system has visited that Web site.

Explanation

Cap 7

Submit

76. Forensic investigators use ____ copying when making a forensic image of a device, which reads a sector (or block; 512 bytes on most devices) from the source drive and writes it to the target drive; this process continues until all sectors on the suspect drive have been copied.

Explanation

Cap 8

Submit

77. A continuously changing process presents challenges in acquisition, as there is not a fixed state that can be collected, hashed, and so forth. This has given rise to the concept of ____ forensics which captures a point-in-time picture of a process.

Explanation

Cap 8

Submit

78. ____ is the determination of the initial flaw or vulnerability that allowed an incident to occur.

Explanation

Cap 8

Submit

79. The forensic tool ____ does extensive pre-processing of evidence items that  recovers deleted files and extracts e-mail messages.

Explanation

Cap 8

Submit

80. A ____ is a description of the disasters that may befall an organization, along with information on their probability of occurrence, a brief description of the organization's actions to prepare for that disaster, and the best case, worst case, and most likely case outcomes of the disaster.

Explanation

Cap 9

Submit

81. The ____ assembles a disaster recovery team.

Explanation

Cap 9

Submit

82. An ____ may escalate into a disaster when it grows in scope and intensity.

Explanation

Cap 9

Submit

83. ____ disasters include acts of terrorism and acts of war.

Explanation

Cap 9

Submit

84. Which of the following is not usually an insurable loss?

Explanation

Cap 9

Submit

85. Deciding which technical contingency strategies are selected, developed, and implemented is most often based on the type of ____ being used.

Explanation

Cap 9

Submit

86. Useful resources in the DR planning process are the ____ provided by the Federal Agency Security Practices (FASP) section of NIST's Computer Security Resource Center (CSRC).  

Explanation

Cap 9

Submit

87. ____ is the deactivation of the disaster recovery teams, releasing individuals back to their normal duties.

Explanation

Cap 10

Submit

88. ____ is a set of focused steps that deal primarily with the safety and state of the people from the organization who are involved in the disaster.

Explanation

Cap 10

Submit

89. The ____ team is responsible for providing the initial assessments of the extent of damage to equipment and systems on-site and/or for physically recovering the equipment to be transported to a location where the other teams can evaluate it.

Explanation

Cap 10

Submit

90. ____ means making an organization ready for possible contingencies that can escalate to become disasters.

Explanation

Cap 10

Submit

91. A ____ is a document that describes how, in the event of a disaster, critical business functions continue at an alternate location while the organization recovers its ability to function at the primary site.

Explanation

Cap 1

Submit

92. A favorite pastime of information security professionals is ____, which is a simulation of attack and defense activities using realistic networks and information systems.

Explanation

Cap 4

Submit

93. The ____ is the point in the past to which the recovered applications and data at the alternate infrastructure will be restored.

Explanation

Cap 11

Submit

94. ____ is a tactic that deliberately permits an attack to continue while the entire event is observed and additional evidence is collected.

Explanation

Cap 7

Submit

95. A(n) ____ is any clearly identified attack on the organization's information assets that would threaten the assets' confidentiality, integrity, or availability.

Explanation

Cap 1

Submit

96. The last stage of a business impact analysis is prioritizing the resources associated with the ____, which brings a better understanding of what must be recovered first.

Explanation

Cap 2

Submit

97. Which of the following collects and provides reports on failed login attempts, probes, scans, denial-of-service attacks, and detected malware?

Explanation

Cap 2

Submit

98. The final component to the CPMT planning process is to deal with ____.

Explanation

Cap 2

Submit

99. The ____ is the period of time within which systems, applications, or functions must be recovered after an outage.

Explanation

Cap 2

Submit

100. A(n) ____ is an extension of an organization's intranet into cloud computing.

Explanation

Cap 3

Submit

101. A ____ is an agency that provides physical facilities in the event of a disaster for a fee.

Explanation

Cap 3

Submit

102. A(n) ____ covers the confidentiality of information from everyone unless disclosure is mandated by the courts.

Explanation

Cap 3

Submit

103. The ____ of an organization defines the roles and responsibilities for incident response for the CSIRT and others who will be mobilized in the activation of the plan.

Explanation

Cap 4

Submit

104. In contingency planning, an adverse event that threatens the security of an organization's information is called a(n) ____.

Explanation

Cap 4

Submit

105. The responsibility for creating an organization's IR plan often falls to the ____.

Explanation

Cap 4

Submit

106. New systems can respond to an incident threat autonomously, based on preconfigured options that go beyond simple defensive actions usually associated with IDPS and IPS systems. These systems, referred to as ____, use a combination of resources to detect an intrusion and then to trace the intrusion back to its source.

Explanation

Cap 5

Submit

107. A(n) ____ is any system resource that is placed onto a functional system but has no normal use for that system. If it attracts attention, it is from unauthorized access and will trigger a notification or response.

Explanation

Cap 5

Submit

108. Two dominantly recognized professional institutions certifying business continuity professionals agree on the ____ as the basis for certification.

Explanation

Cap 11

Submit

109. A BC subteam called the ____ is responsible for establishing the core business functions needed to sustain critical business operations.

Explanation

Cap 11

Submit

110. The ____ section of the business continuity policy identifies the organizational units and groups of employees to which the policy applies.

Explanation

Cap 11

Submit

111. The ____ section of the business continuity policy provides an overview of the information storage and retrieval plans of the organization.

Explanation

Cap 11

Submit

112. Identifying measures, called ____, that reduce the effects of system disruptions can reduce continuity life-cycle costs.

Explanation

Cap 11

Submit

113. The CSIRT must have a clear and concise ____ statement that, in a few sentences, unambiguously articulates what it will do.

Explanation

Cap 6

Submit

114. The champion for the CSIRT may be the same person as the champion for the entire IR function-typically, the ____.

Explanation

Cap 6

Submit

115. A ____ attack is much more substantial than a DoS attack because of the use of multiple systems to simultaneously attack a single target.

Explanation

Cap 7

Submit

116. When a second attack, using the means and methods of the first attack is undertaken while the first attack is still underway, this is considered a(n) ____ recurrence.

Explanation

Cap 7

Submit

117. Essentially a DoS attack, a ____ is a message aimed at causing organizational users to waste time reacting to a nonexistent malware threat.

Explanation

Cap 7

Submit

118. A(n) ____ attack is a method of combining attacks with rootkits and back doors.

Explanation

Cap 7

Submit

119. There are a number of professional IR agencies, such as ____, that can provide additional resources to help prevent and detect DoS incidents.

Explanation

Cap 7

Submit

120. In evidence handling, specifically designed ____ are helpful because they are very difficult to remove without breaking.

Explanation

Cap 8

Submit

121. The ____ is a detailed examination of the events that occurred, from first detection to final recovery.

Explanation

Cap 8

Submit

122. One way to identify a particular digital item (collection of bits) is by means of a(n) ____.

Explanation

Cap 8

Submit

123. The primary vehicle for articulating the purpose of a disaster recovery program is the ____. 

Explanation

Cap 9

Submit

124. The ____ team is responsible for recovering and reestablishing operating systems (OSs).

Explanation

Cap 10

Submit

125. The purpose of the ____ is to provide a way for management to obtain input and feedback from representatives of each team.

Explanation

Cap 10

Submit

126. A(n) ____ occurs when a situation results in service disruptions for weeks or months, requiring a government to declare a state of emergency.

Explanation

Cap 10

Submit

127. The ____ is the phase associated with implementing the initial reaction to a disaster; it is focused on controlling or stabilizing the situation, if that is possible.

Explanation

Cap 10

Submit

128. ____ of risk is the choice to do nothing to protect an information asset and to accept the outcome of its potential exploitation.

Explanation

Cap 1

Submit

129. A(n) ____ is a plan or course of action used by an organization to convey instructions from its senior management to those who make decisions, take actions, and perform other duties on behalf of the organization.

Explanation

Cap 1

Submit

130. ____ (sometimes referred to as avoidance) is the risk control strategy that attempts to prevent the exploitation of a vulnerability.

Explanation

Cap 1

Submit

131. A(n) ____ attack&seeks$to*denyiilegitimate@users\access[to>services0byXeither tying up a server's available resources or causing it to shut down.

Explanation

Cap 1

Submit

132. A ____ deals with the preparation for and recovery from a disaster, whether natural or man-made.

Explanation

Cap 1

Submit

133. A manual alternative to the normal way of accomplishing an IT task might be employed in the event that IT is unavailable. This is called a ____.

Explanation

Cap 2

Submit

134. In a CPMT, a(n) ____ leads the project to make sure a sound project planning process is used, a complete and useful project plan is developed, and project resources are prudently managed.

Explanation

Cap 2

Submit

135. The ____ job functions and organizational roles focus on costs of system creation and operation, ease of use for system users, timeliness of system creation, and transaction response time.

Explanation

Cap 2

Submit

136. What is a common approach used in the discipline of systems analysis and design to understand the ways systems operate and to chart process flows and interdependency studies?

Explanation

Cap 2

Submit

137. The ____ is the point in time, determined by the business unit, from which systems and data can be recovered after an outage.

Explanation

Cap 2

Submit

138. One modeling technique drawn from systems analysis and design that can provide an excellent way to illustrate how a business functions is a(n) ____.

Explanation

Cap 2

Submit

139. A ____ is commonly a single device or server that attaches to a network and uses TCP/IP-based protocols and communications methods to provide an online storage environment.

Explanation

Cap 3

Submit

140. A(n) ____ backup only archives the files that have been modified since the last backup.

Explanation

Cap 3

Submit

141. RAID 0 creates one logical volume across several available hard disk drives and stores the data using ____, in which data segments are written in turn to each disk drive in the array.

Explanation

Cap 3

Submit

142. A potential disadvantage of a ____ site-resumption strategy is that more than one organization might need the facility simultaneously.

Explanation

Cap 3

Submit

143. A ____ is a contractual document guaranteeing certain minimal levels of service provided by a vendor.

Explanation

Cap 3

Submit

144. The ____ Department of an organization needs to review the procedures of the CSIRT and understand the steps the CSIRT will perform to ensure it is within legal and ethical guidelines for the municipal, state, and federal jurisdictions.

Explanation

Cap 4

Submit

145. The IR plan is usually ____ when an incident causes minimal damage with little or no disruption to business operations.

Explanation

Cap 4

Submit

146. ____ incident responses enables the organization to react to a detected incident quickly and effectively, without confusion or wasted time and effort.

Explanation

Cap 4

Submit

147. Should an incident begin to escalate, the CSIRT team leader continues to add resources and skill sets as necessary to attempt to contain and terminate the incident. The resulting team is called the ____ for this particular incident.

Explanation

Cap 4

Submit

148. Incident analysis resources include network diagrams and lists of ____, such as database servers.

Explanation

Cap 4

Submit

149. The ____ approach for detecting intrusions is based on the frequency with which certain network activities take place.

Explanation

Cap 5

Submit

150. In the event that a definite indicator is recognized, the corresponding ____ must be activated immediately.

Explanation

Cap 5

Submit

151. ____ are closely monitored network decoys serving that can distract adversaries from more valuable machines on a network; can provide early warning about new attack and exploitation trends; and can allow in-depth examination of adversaries during and after exploitation.

Explanation

Cap 5

Submit

152. The use of IDPS sensors and analysis systems can be quite complex. One very common approach is to use an open source software program called ____ running on an open source UNIX or Linux system that can be managed and queried from a desktop computer using a client interface.

Explanation

Cap 5

Submit

153. The ongoing activity from alarm events that are accurate and noteworthy but not necessarily significant as potentially successful attacks is called ____.

Explanation

Cap 5

Submit

154. Most organizations will find themselves awash in incident candidates at one time or another, and the vast majority will be ____.

Explanation

Cap 5

Submit

155. The ____ is the amount of time that a business can tolerate losing capabilities until alternate capabilities are available.

Explanation

Cap 11

Submit

156. ____ planning represents the final response of the organization when faced with any interruption of its critical operations.

Explanation

Cap 11

Submit

157. In the ____ section of the business continuity policy, the training requirements for the various employee groups are defined and highlighted.

Explanation

Cap 11

Submit

158. The CSIRT should be available for contact by anyone who discovers or suspects that an incident involving the organization has occurred. Some organizations prefer that employees contact a ____, which then makes the determination as to whether to contact the CSIRT or not.

Explanation

Cap 6

Submit

159. A CSIRT model that is effective for large organizations and for organizations with major computing resources at distant locations is the ____.

Explanation

Cap 6

Submit

160. One way to build and maintain staff skills is to develop incident-handling ____ and have the team members discuss how they would handle them.

Explanation

Cap 6

Submit

161. The announcement of an operational CSIRT should minimally include ____.

Explanation

Cap 6

Submit

162. ____ incidents are predominantly characterized as a violation of policy rather than an effort to abuse existing systems.

Explanation

Cap 7

Submit

163. ____ is a common indicator of a DoS attack.

Explanation

Cap 7

Submit

164. Which of the following is the most suitable as a response strategy for malware outbreaks?

Explanation

Cap 7

Submit

165. The CSIRT may not wish to "tip off" attackers that they have been detected, especially if the organization is following a(n) ____ approach.

Explanation

Cap 7

Submit

166. A forensics team typically uses two methods to document a scene as it exists at the time of arrival: photography and ____.

Explanation

Cap 8

Submit

167. Grounds for challenging the results of a digital investigation can come from possible ____-that is, alleging that the relevant evidence came from somewhere else or was somehow tainted in the collection process.

Explanation

Cap 8

Submit

168. A search is constitutional if it does not violate a person's reasonable or legitimate____.

Explanation

Cap 8

Submit

169. ____ are those that occur suddenly, with little warning, taking the lives of people and destroying the means of production.

Explanation

Cap 9

Submit

170. In disaster recovery, the ____ is the point at which a management decision to react is made in reaction to a notice or other datum such as a weather report or an activity report from IT indicating the escalation of an incident.

Explanation

Cap 9

Submit

171. The ____ team is responsible for providing any needed supplies, space, materials, food, services, or facilities needed at the primary site other than vendor-acquired technology and other material obtained by the vendor team.

Explanation

Cap 10

Submit

172. During the ____ phase, the organization begins the recovery of the most time-critical business functions - those necessary to reestablish business operations and prevent further economic and image loss to the organization.

Explanation

Cap 10

Submit

173. The ____ team is responsible for working with the remainder of the organization to assist in the recovery of nontechnology functions.

Explanation

Cap 10

Submit

174. The ____ involves providing copies of the DR plan to all teams and team members for review.

Explanation

Cap 10

Submit

175. Companies may want to consider budgeting for contributions to employee loss expenses (such as funerals) as well as for counseling services for employees and loved ones as part of ____

Explanation

Cap 2

Submit

176. A(n) ____ is an agreement in which the client agrees not to use the vendor's services to compete directly with the vendor, and for the client not to use vendor information to gain a better deal with another vendor.

Explanation

Cap 3

Submit

177. A recommended practice for the implementation of the physical IR plan document is to organize the contents so that the first page contains the ____ actions.

Explanation

Cap 4

Submit

178. The committees of the CPMT follow a set of general stages to develop their subordinate plans. In the case of incident planning, the first stage is to ____.

Explanation

Cap 4

Submit

179. A recommended practice for the implementation of the physical IR plan is to select a ____ binder.

Explanation

Cap 4

Submit

180. A(n) ____ is the set of rules and configuration guidelines governing the implementation and operation of IDPSs within the organization.

Explanation

Cap 5

Submit

181. A(n) ____ , a type of IDPS that is similar to the NIDPS, reviews the log files generated by servers, network devices, and even other IDPSs.

Explanation

Cap 5

Submit

182. A ____ rootkit is one that becomes a part of the system bootstrap process and is loaded every time the system boots.

Explanation

Cap 5

Submit

183. A(n) ____ is a sign that an adverse event is underway and has a probability of becoming an incident.

Explanation

Cap 5

Submit

184. When the measured activity is outside the baseline parameters in a behavior-based IDPS, it is said to exceed the ____ (the level at which the IDPS triggers an alert to notify the administrator).

Explanation

Cap 5

Submit

185. The ____ is the group responsible for initiating the occupation of the alternate facility.

Explanation

Cap 11

Submit

186. Essential BC supplies needed at an alternate site include portable computers, software media, and ____.

Explanation

Cap 11

Submit

187. The U.S. Department of Homeland Security's Federal Emergency Management Association has developed a support Web site at ____ that includes a suite of tools to guide the development of disaster recovery/business continuity plans.

Explanation

Cap 11

Submit

188. The organization must first understand what skills are needed to effectively respond to an incident. If necessary, management must determine if it is willing to acquire needed ____ to fill in the gaps.

Explanation

Cap 6

Submit

189. If a user receives a message whose tone and terminology seems intended to invoke a panic or sense of urgency, it may be a(n) ____.

Explanation

Cap 7

Submit

190. The number-one IU preparation-and-prevention strategy is ____.

Explanation

Cap 7

Submit

191. Many malware attacks are ____ attacks, which involve more than one type of malware and/or more than one type of transmission method.

Explanation

Cap 7

Submit

192. ____ involves an attempt made by those who may become subject to digital forensic techniques to obfuscate or hide items of evidentiary value.

Explanation

Cap 8

Submit

193. The stability of information over time is called its ____.

Explanation

Cap 8

Submit

194. Many private sector organizations require a formal statement, called a(n) ____, which provides search authorization and furnishes much of the same information usually found in a public sector search warrant.

Explanation

Cap 8

Submit

195. The functional part of forensics called ____ is about assessing the "scene," identifying the sources of relevant digital information, and preserving it for later analysis using sound processes.

Explanation

Cap 8

Submit

196. A ____ is a collection of nodes in which the segments are geographically dispersed and the physical link is often a data communications channel provided by a public carrier.

Explanation

Cap 9

Submit

197. ____ occur over time and slowly deteriorate the organization's capacity to withstand their effects.

Explanation

Cap 9

Submit

198. ____ may be caused by earthquakes, floods, storm winds, tornadoes, or mud flows.

Explanation

Cap 9

Submit

199. The part of a disaster recovery policy that identifies the organizational units and groups of employees to which the policy applies is called the ____ section.

Explanation

Cap 9

Submit

200. Once the incident has been contained, and all signs of the incident removed, the ____ phase begins.

Explanation

Cap 9

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (200)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Information assets have ____ when authorized users - persons or...
The purpose of the ____ is to define the scope of the CP operations...
The focus during a(n) ____ is on learning what worked, what...
A ____ attack is much more substantial than a DoS attack because of...
The ____ team is responsible for reestablishing connectivity between...
____ is the process of moving an organization toward its vision.
The Southeast Collegiate Cyber Defense Competition is unique in that...
In an attack known as ____, valid protocol packets exploit poorly...
The task of monitoring file systems for unauthorized change is best...
The ____ team is primarily responsible for data restoration and...
A(n) ____ is an investigation and assessment of the impact that...
A(n) ____ is used to anticipate, react to, and recover from events...
____ assigns a risk rating or score to each information asset....
____ is a risk control approach that attempts to shift the risk to...
A(n) ____ is a CSIRT team member, other than the team leader, who is...
The U.S. National Institute of Standards and Technology defines the...
One of the primary responsibilities of the IRP team is to ensure that...
Using a process known as ____, network-based IDPSs look for attack...
The first group to communicate the CSIRT's vision and operational...
According to NIST, which of the following is an example of a UA...
____ is used both for intrusion analysis and as part of evidence...
____ are highly probable when infected machines are brought back...
____ is a valuable resource for additional information on building and...
The ____ handles computer crimes that are categorized as felonies.
A ____ is used for an office or small campus, with segment distances...
A(n) ____ is an object, person, or other entity that is a potential...
The ____ is an investigation and assessment of the impact that various...
Some recovery strategies seek to improve the ____ of a server or...
A resumption location known as a ____  or a _______ is a fully...
The process of evaluating the circumstances around organizational...
A(n) ____ is a sign that an activity now occurring may signal an...
The Business Continuity Institute offers an uncertified category of...
When an organization completely outsources its IR work, typically to...
A key step in the ____ approach to incident response is to discover...
The determination of what systems fall under the CSIRT 's...
When an alert warns of new malicious code that targets software used...
When an incident includes a breach of physical security, all aspects...
Clifford Stoll's book, ____, provides an excellent story about a...
The ____ phase of forensic analysis involves the use of forensic tools...
____ are likely in the event of a hacker attack, when the attacker...
In the context of disaster notification, the ____ is a scripted...
The ____ system is an information system with a telephony interface...
____ ensures that only those with the rights and privileges to access...
____ is the risk control approach that attempts to reduce the impact...
Information assets have ____ when they are not exposed (while being...
The ____ illustrates the most critical characteristics of information...
____ hack systems to conduct terrorist activities through network or...
The ____ job functions and organizational roles focus on protecting...
The ____ is used to collect information directly from the end users...
The first major business impact analysis task is to analyze and...
The elements required to begin the ____ process are a planning...
Within an organization, a(n) ____ is a group of individuals who are...
In a CPMT, a(n) ____ should be a high-level manager with influence and...
A CPMT should include _____ who can oversee the security planning of...
Considered to be the traditional "lock and copy" approach to...
____ uses a number of hard drives to store information across multiple...
An organization aggregates all local backups to a central repository...
A(n) ____ is often included in legal documents to ensure that a vendor...
Advances in cloud computing have opened a new field in application...
Both data backups and archives should be based on a(n) ____ schedule...
A backup plan using WAN/VLAN replication and a recovery strategy using...
The training delivery method with the lowest cost to the organization...
____ is the process of systematically examining information assets for...
General users require training on the technical details of how to do...
If an intruder can ____ a device, then no electronic protection can...
When implementing a BC plan, an organization reaches a predetermined...
Once BC activities have come to a close and the organization has...
A certification offered by the Business Continuity Institute is called...
The ____ section of the business continuity policy identifies the...
A CSIRT model in which a single CSIRT handles incidents throughout the...
Those services undertaken to prepare the organization or the CSIRT...
Those services performed in response to a request or a defined event...
Known as ____, procedures for regaining control of systems and...
In a "block" containment strategy, in which the...
A ____ is a small quantity of data kept by a Web site as a means of...
Forensic investigators use ____ copying when making a forensic image...
A continuously changing process presents challenges in acquisition, as...
____ is the determination of the initial flaw or vulnerability that...
The forensic tool ____ does extensive pre-processing of evidence items...
A ____ is a description of the disasters that may befall an...
The ____ assembles a disaster recovery team.
An ____ may escalate into a disaster when it grows in scope and...
____ disasters include acts of terrorism and acts of war.
Which of the following is not usually an insurable loss?
Deciding which technical contingency strategies are selected,...
Useful resources in the DR planning process are the ____ provided by...
____ is the deactivation of the disaster recovery teams, releasing...
____ is a set of focused steps that deal primarily with the safety and...
The ____ team is responsible for providing the initial assessments of...
____ means making an organization ready for possible contingencies...
A ____ is a document that describes how, in the event of a disaster,...
A favorite pastime of information security professionals is ____,...
The ____ is the point in the past to which the recovered applications...
____ is a tactic that deliberately permits an attack to continue while...
A(n) ____ is any clearly identified attack on the organization's...
The last stage of a business impact analysis is prioritizing the...
Which of the following collects and provides reports on failed login...
The final component to the CPMT planning process is to deal with ____.
The ____ is the period of time within which systems, applications, or...
A(n) ____ is an extension of an organization's intranet into cloud...
A ____ is an agency that provides physical facilities in the event of...
A(n) ____ covers the confidentiality of information from everyone...
The ____ of an organization defines the roles and responsibilities for...
In contingency planning, an adverse event that threatens the security...
The responsibility for creating an organization's IR plan often...
New systems can respond to an incident threat autonomously, based on...
A(n) ____ is any system resource that is placed onto a functional...
Two dominantly recognized professional institutions certifying...
A BC subteam called the ____ is responsible for establishing the core...
The ____ section of the business continuity policy identifies the...
The ____ section of the business continuity policy provides an...
Identifying measures, called ____, that reduce the effects of system...
The CSIRT must have a clear and concise ____ statement that, in a few...
The champion for the CSIRT may be the same person as the champion for...
A ____ attack is much more substantial than a DoS attack because of...
When a second attack, using the means and methods of the first attack...
Essentially a DoS attack, a ____ is a message aimed at causing...
A(n) ____ attack is a method of combining attacks with rootkits and...
There are a number of professional IR agencies, such as ____, that can...
In evidence handling, specifically designed ____ are helpful because...
The ____ is a detailed examination of the events that occurred, from...
One way to identify a particular digital item (collection of bits) is...
The primary vehicle for articulating the purpose of a disaster...
The ____ team is responsible for recovering and reestablishing...
The purpose of the ____ is to provide a way for management to obtain...
A(n) ____ occurs when a situation results in service disruptions for...
The ____ is the phase associated with implementing the initial...
____ of risk is the choice to do nothing to protect an information...
A(n) ____ is a plan or course of action used by an organization to...
____ (sometimes referred to as avoidance) is the risk control strategy...
A(n) ____...
A ____ deals with the preparation for and recovery from a disaster,...
A manual alternative to the normal way of accomplishing an IT task...
In a CPMT, a(n) ____ leads the project to make sure a sound project...
The ____ job functions and organizational roles focus on costs of...
What is a common approach used in the discipline of systems analysis...
The ____ is the point in time, determined by the business unit, from...
One modeling technique drawn from systems analysis and design that can...
A ____ is commonly a single device or server that attaches to a...
A(n) ____ backup only archives the files that have been modified since...
RAID 0 creates one logical volume across several available hard disk...
A potential disadvantage of a ____ site-resumption strategy is that...
A ____ is a contractual document guaranteeing certain minimal levels...
The ____ Department of an organization needs to review the procedures...
The IR plan is usually ____ when an incident causes minimal damage...
____ incident responses enables the organization to react to a...
Should an incident begin to escalate, the CSIRT team leader continues...
Incident analysis resources include network diagrams and lists of...
The ____ approach for detecting intrusions is based on the frequency...
In the event that a definite indicator is recognized, the...
____ are closely monitored network decoys serving that can distract...
The use of IDPS sensors and analysis systems can be quite complex. One...
The ongoing activity from alarm events that are accurate and...
Most organizations will find themselves awash in incident candidates...
The ____ is the amount of time that a business can tolerate losing...
____ planning represents the final response of the organization when...
In the ____ section of the business continuity policy, the training...
The CSIRT should be available for contact by anyone who discovers or...
A CSIRT model that is effective for large organizations and for...
One way to build and maintain staff skills is to develop...
The announcement of an operational CSIRT should minimally include...
____ incidents are predominantly characterized as a violation of...
____ is a common indicator of a DoS attack.
Which of the following is the most suitable as a response strategy for...
The CSIRT may not wish to "tip off" attackers that they have...
A forensics team typically uses two methods to document a scene as it...
Grounds for challenging the results of a digital investigation can...
A search is constitutional if it does not violate a person's...
____ are those that occur suddenly, with little warning, taking the...
In disaster recovery, the ____ is the point at which a management...
The ____ team is responsible for providing any needed supplies, space,...
During the ____ phase, the organization begins the recovery of the...
The ____ team is responsible for working with the remainder of the...
The ____ involves providing copies of the DR plan to all teams and...
Companies may want to consider budgeting for contributions to employee...
A(n) ____ is an agreement in which the client agrees not to use the...
A recommended practice for the implementation of the physical IR plan...
The committees of the CPMT follow a set of general stages to develop...
A recommended practice for the implementation of the physical IR plan...
A(n) ____ is the set of rules and configuration guidelines governing...
A(n) ____ , a type of IDPS that is similar to the NIDPS, reviews the...
A ____ rootkit is one that becomes a part of the system bootstrap...
A(n) ____ is a sign that an adverse event is underway and has a...
When the measured activity is outside the baseline parameters in a...
The ____ is the group responsible for initiating the occupation of the...
Essential BC supplies needed at an alternate site include portable...
The U.S. Department of Homeland Security's Federal Emergency...
The organization must first understand what skills are needed to...
If a user receives a message whose tone and terminology seems intended...
The number-one IU preparation-and-prevention strategy is ____.
Many malware attacks are ____ attacks, which involve more than one...
____ involves an attempt made by those who may become subject to...
The stability of information over time is called its ____.
Many private sector organizations require a formal statement, called...
The functional part of forensics called ____ is about assessing the...
A ____ is a collection of nodes in which the segments are...
____ occur over time and slowly deteriorate the organization's...
____ may be caused by earthquakes, floods, storm winds, tornadoes, or...
The part of a disaster recovery policy that identifies the...
Once the incident has been contained, and all signs of the incident...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!