,C1, 13e - Introduction to Computer Security
True / False
1. The Domain Name Service is what translates human-readable domain names into IP
addresses that computers and routers understand.
True
M
2. The type of hacking that involves breaking into telephone systems is called sneaking.
False—This type of hacking is called phreaking.
3. The technique for breaching a system’s security by exploiting human nature rather than
ED
technology is war-driving.
False—This describes social engineering.
4. Malware is a generic term for software that has a malicious purpose.
True
CO
5. Software that lays dormant until some specific condition is met is a Trojan horse.
False—This describes a logic bomb. Usually the condition that is met is a date
and time.
NN
6. Someone who breaks into a system legally to assess security deficiencies is a sneaker.
True—Companies may solicit the services of a sneaker to assess the company’s
vulnerabilities.
7. Auditing is the process to determine if a user’s credentials are authorized to access a
OI
network resource.
False—This describes authentication. Auditing is the process to review logs,
records, and procedures.
SS
8. Confidentiality, integrity, and availability are three pillars of the CIA triangle.
True
9. The Health Insurance Portability and Accountability Act of 1996 requires government
EU
agencies to identify sensitive systems, conduct computer security training, and develop
computer security plans.
False—This describes the Computer Security Act of 1987.
R
10The SANS Institute website is a vast repository of security-related documentation.
True
Multiple Choice
,1. In which type of hacking does the user block access from legitimate users without
actually accessing the attacked system?
a. Denial of service
b. Web attack
c. Session hijacking
d. None of the above
Answer A. A denial-of-service attack is probably the most common attack on the web.
M
2. Your company is instituting a new security awareness program. You are responsible
for educating end users on a variety of threats, including social engineering. Which of the
following best defines social engineering?
ED
a. Illegal copying of software
b. Gathering information from discarded manuals and printouts
c. Using people skills to obtain proprietary information
d. Destruction or alteration of data
CO
Answer D. Social Engineering is basically using people skills to gather information
3. Which type of hacking occurs when the attacker monitors an authenticated session
between the client and the server and takes over that session?
a. Denial of service
NN
b. Web attack
c. Session hijacking
d. None of the above
Answer C.
OI
4. Someone who finds a flaw in a system and reports that flaw to the vendor of the
system is a __________.
a. White hat hacker
SS
b. Black hat hacker
c. Gray hat hacker
d. Red hat hacker
EU
Answer A. White hat hackers are often hired by companies to do penetration tests.
5. Someone who gains access to a system and causes harm is a __________?
a. White hat hacker
b. Black hat hacker
R
c. Grey hat hacker
d. Red hat hacker
Answer B. A black hat hacker might steal data, erase files, or deface websites.
6. A black hat hacker is also called a ___________
a. Thief
, b. Cracker
c. Sneaker
d. None of the above
Answer B.
7. Someone who calls himself a hacker but lacks the expertise is a ________.
a. Script kiddy
b. Sneaker
M
c. White hat hacker
d. Black hat hacker
ED
Answer A. There are many Internet tools that can be used to perform hacking tasks, and
users of these tools who don’t understand the target system are script kiddies.
8. Someone who legally breaks into a system to assess security deficiencies is a
________.
CO
a. Script kiddy
b. Penetration tester
c. White hat hacker
d. Black hat hacker
NN
Answer B. Anyone hired to assess the vulnerabilities of a system should be both
technically proficient and ethical.
9. A(n) ______ is a basic security device that filters traffic and is a barrier between a
network and the outside world or between a system and other systems.
OI
a. Firewall
b. Proxy server
c. Intrusion detection system
d. Network Monitor
SS
Answer A. A firewall can be a server, a router, or software running on a machine.
10. A(n) hides the internal network’s IP address and presents a single IP address to the
EU
outside world.
a. Firewall
b. Proxy server
c. Intrusion detection system
d. Network Monitor
R
Answer B.
11. Which one of these is NOT one the three pillars of security in the CIA triangle?
a. Confidentiality
b. Integrity
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller MedConnoisseur. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $19.99. You're not tied to anything after your purchase.