

Information Security Test Preparation
Course Introduction
Information Security explores the principles, technologies, and practices used to protect digital information from unauthorized access, disruption, or destruction. The course covers foundational concepts such as confidentiality, integrity, availability, and threats to information systems, including malware, social engineering, and network attacks. Students learn about encryption methods, authentication processes, security policies, risk management strategies, and legal and ethical aspects of information security. Hands-on exercises and case studies help illustrate how organizations defend against cyber threats and maintain secure computing environments.
Recommended Textbook Guide to Firewalls and VPNs 3rd Edition by Michael E. Whitman
Available Study Resources on Quizplus
10 Chapters
496 Verified Questions
496 Flashcards
Source URL: https://quizplus.com/study-set/2181

Page 2

Chapter 1: Introduction to Information Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43454
Sample Questions
Q1) What is the role of the chief information security officer (CISO)?
Answer: The chief information security officer (CISO) is the individual primarily responsible for the assessment, management, and implementation of information security in the organization.The CISO may also be referred to as the manager for IT security, the security administrator, information security officer (ISO), chief security officer (CSO), or by a similar title.The CISO usually reports directly to the CIO, although in larger organizations it is not uncommon for one or more layers of management to exist between the two.
Q2) ____ means that information is free from mistakes or errors.
A) Accuracy
B) Availability
C) Confidentiality
D) Integrity
Answer: A
Q3) The most common Intellectual Property breach is ____________________.
Answer: software piracy
Q4) A(n) ____________________ is an application error that occurs when more data is sent to a buffer than it can handle.
Answer: buffer overflow
To view all questions and flashcards with answers, click on the resource link above. Page 3
Chapter 2: Security Policies and Standards
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43455
Sample Questions
Q1) Policies are put in place to support the organization's mission, vision, and strategic planning.
A)True
B)False
Answer: True
Q2) Attack profiles should include scenarios depicting a typical attack, with details on the method, the indicators, and the broad consequences of the attack.
A)True
B)False
Answer: True
Q3) Within a SETA program, ____ is only available to some of the organization's employees.
A) security-related trinkets
B) security education
C) security training
D) security awareness programs
Answer: B
To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Authenticating Users
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43456
Sample Questions
Q1) ____ authentication is most commonly set up as a form of auditing and occurs when a system records the activities of each user and writes details about each activity to a log file.
A) Local
B) Discretionary
C) Centralized
D) Decentralized
Answer: C
Q2) Some firewalls use authentication to give employees access to common resources.
A)True
B)False
Answer: True
Q3) IEEE 802.1x is one of the fastest growing standards being used in enterprise networks today.
A)True
B)False
Answer: True
Q4) In ____________________-based access controls, access is granted based on a set of rules specified by the central authority.
Answer: rule
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Introduction to Firewalls
Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43457
Sample Questions
Q1) Mobile devices such as laptops, PDAs, and smartphones blur the perimeter boundary.
A)True
B)False
Q2) Segment of the DMZ where additional authentication and authorization controls are put into place to provide services that are not available to the general public.
A)PAT and NAT
B)bastion host
C)application proxy
D)extranet
E)header
F)perimeter
G)data
H)port
I)packet filtering
Q3) A packet-filtering firewall installed on a TCP/IP-based network typically functions at the TCP level.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above.
Page 6

Chapter 5: Packet Filtering
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43458
Sample Questions
Q1) How does a packet filter process IP header criteria?
Q2) List and describe the types of hardware devices and software programs that perform packet filtering.
Q3) Using TCP or UDP port numbers can help you filter a wide variety of information, including SMTP and POP e-mail messages, NetBIOS sessions, ____, and Network News Transfer Protocol (NNTP) newsgroup sessions.
A) DNS requests
B) ICMP messages
C) stateful transfers
D) Trojan horses
Q4) A(n) ____________________ is hardware or software that blocks or allows transmission of information packets based on criteria such as port, IP address, and protocol.
Q5) It is good practice to block ____ access to all internal servers from the public networks.
A) HTTP
B) Telnet
C) Simple Mail Transport Protocol
D) DNS
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Firewall Configuration and Administration
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43459
Sample Questions
Q1) Password you need to enter to make your screen saver vanish so you can return to your desktop and resume working.
A)boot-up password
B)firewall rules
C)bastion host
D)screen saver password
E)restrictive
F)IP forwarding
G)permissive
H)supervisor password
I)caching
Q2) Many companies use the Internet to enable a(n) ____________________ that connects internal hosts with specific clients in other organizations.
Q3) A critical ____________________ is defined as a software- or hardware-related item that is indispensable to the operation of a device or program.
Q4) What is an intrusion detection and prevention system?
Q5) Describe best practices for adding software updates and patches.
Q6) Describe the need for firewall scalability.
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Working With Proxy Servers and Application-Level Firewalls
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43460
Sample Questions
Q1) A network must have one or more proxy servers available for each ____ proxied on the network.
A) packet filter
B) network connection
C) service protocol
D) client computer
Q2) Microsoft ____________________ is a complex, full-featured firewall that includes stateful packet filtering as well as proxy services, NAT, and intrusion detection.
Q3) Configured so that they are totally invisible to end users.
A)dual-homed host
B)URL redirection
C)nontransparent proxies
D)log files
E)parameters
F)SOCKS
G)WinGate
H)proxy servers
I)transparent proxies
Q4) How can a proxy server be used for e-mail protection?
Page 9
To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Implementing the Bastion Host
Available Study Resources on Quizplus for this Chatper
49 Verified Questions
49 Flashcards
Source URL: https://quizplus.com/quiz/43461
Sample Questions
Q1) Speed up the retrieval and storage of stored data.
A)instruction cache
B)log files
C)translation lookaside buffer
D)data cache
E)Demilitarized Zone
F)bastion host
G)UNIX
H)processor speed
I)syslog daemon
Q2) When selcting a bastion host operating system, the most important consideration is
A) Choose UNIX/LINUX only
B) Choose Windows only
C) Choose the OS you're most familiar with
D) Choose the OS that is the most cost effective
Q3) ____________________ occurs when a company physically hosts its server(s) in a data center that is managed by a third party.
Q4) What type of processor speed is best for a bastion host?
Q5) Why is it a good idea to disable user accounts on the bastion host?
Page 10
To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Encryption - The Foundation for the Virtual
Private
Network
Available Study Resources on Quizplus for this Chatper
48 Verified Questions
48 Flashcards
Source URL: https://quizplus.com/quiz/43462
Sample Questions
Q1) One of the most popular public key cryptosystems is a proprietary model named
A) Triple DES
B) Rijndael
C) Rivest-Shamir-Aldeman (RSA)
D) certificate authority (CA)
Q2) ____ was developed by Netscape in 1994 to provide security for online electronic commerce transactions.
A) Secure Hypertext Transfer Protocol (SHTTP)
B) Secure Shell (SSH)
C) Secure Sockets Layer (SSL)
D) Secure Electronic Transactions (SET)
Q3) AES has been the federally approved standard for nonclassified data since 2002.
A)True
B)False
Q4) Describe some of the common protocols used to secure e-mail.
Q5) Describe asymmetric encryption.
Q7) What is a timing attack? Page 11
Q6) Describe some of the challenges that organizations face when it comes to cryptographic controls.
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Setting up a Virtual Private Network
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/43463
Sample Questions
Q1) L2TP uses ____ rather than MPPE to encrypt data sent over PPP.
A) SSL
B) SSH
C) IPSec
D) IKE
Q2) The host encrypts traffic when it is generated; the data part of packets is encrypted, but not the headers.
A)encapsulation
B)tunnel
C)client-to-site
D)transport mode
E)gateway
F)private leased lines
G)tunnel mode
H)site-to-site
I)Point-to-Point Tunneling Protocol
Q3) Describe the features of IP encapsulation provided by a VPN.
Q4) What should be specified in a VPN security policy?
Q5) What are VPN endpoints?
Q6) Describe the drawbacks of VPNs.
To view all questions and flashcards with answers, click on the resource link above. Page 13