

Introduction to Information Security Practice Exam
Course Introduction
Introduction to Information Security provides a comprehensive overview of the fundamental principles and practices that protect information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction. This course covers key concepts such as confidentiality, integrity, and availability, and explores critical topics including risk management, threat assessment, cryptography, network security, access control, and security policies. Students will learn about various types of security attacks and defenses, regulatory and ethical considerations, security technologies, and strategies for creating robust security frameworks. By the end of the course, students will have a solid foundation in the essential aspects of safeguarding digital assets and understanding evolving challenges in the field of information security.
Recommended Textbook
Principles of Information Security 6th Edition by Michael E. Whitman
Available Study Resources on Quizplus
12 Chapters
1148 Verified Questions
1148 Flashcards
Source URL: https://quizplus.com/study-set/2123

Page 2

Chapter 1: Introduction to Information Security
Available Study Resources on Quizplus for this Chatper
87 Verified Questions
87 Flashcards
Source URL: https://quizplus.com/quiz/42300
Sample Questions
Q1) A data custodian works directly with data owners and is responsible for the storage, maintenance, and protection of the information.
A)True
B)False
Answer: True
Q2) The protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology is known as ___________.
A) communications security
B) network security
C) physical security
D) information security
Answer: D
Q3) During the early years of computing, the primary threats to security were physical theft of equipment, espionage against the products of the systems, and sabotage.
A)True
B)False
Answer: True
To view all questions and flashcards with answers, click on the resource link above.
3

Chapter 2: The Need for Security
Available Study Resources on Quizplus for this Chatper
91 Verified Questions
91 Flashcards
Source URL: https://quizplus.com/quiz/42301
Sample Questions
Q1) The <u>macro</u> virus infects the key operating system files located in a computer's start-up sector. _________________________
A)True
B)False
Answer: False
Q2) A(n) ____________________ is a potential weakness in an asset or its defensive control(s).
Answer: vulnerability
Q3) Attempting to reverse-calculate a password is called ____________________. Answer: cracking
Q4) Much human error or failure can be prevented with effective training and ongoing awareness activities.
A)True
B)False
Answer: True
Q5) Script ____________________ are hackers of limited skill who use expertly written software to attack a system. Answer: kiddies
To view all questions and flashcards with answers, click on the resource link above. Page 4
Chapter 3: Legal, Ethical, and Professional Issues in Information Security
Available Study Resources on Quizplus for this Chatper
83 Verified Questions
83 Flashcards
Source URL: https://quizplus.com/quiz/42302
Sample Questions
Q1) The __________ is a nonprofit organization that focuses on the development and implementation of information security certifications and credentials.
Answer: International Information Systems Security Certification Consortium, Inc. (ISC)<sup>2</sup>
International Information Systems Security Certification Consortium, Inc. (ISC)<sup>2</sup>
International Information Systems Security Certification Consortium, Inc.(ISC)<sup>2</sup> (ISC)<sup>2</sup> ISC2
Q2) The National Information Infrastructure Protection Act of 1996 modified which act
A) USA PATRIOT Act
B) USA PATRIOT Improvement and Reauthorization Act
C) Computer Security Act
D) Computer Fraud and Abuse Act
Answer: D
Q3) Family law, commercial law, and labor law are all encompassed by __________ law.
Answer: private

5
To view all questions and flashcards with answers, click on the resource link above.

Chapter 4: Planning for Security
Available Study Resources on Quizplus for this Chatper
109 Verified Questions
109 Flashcards
Source URL: https://quizplus.com/quiz/42303
Sample Questions
Q1) A(n) ____________________ backup is the storage of all files that have changed or been added since the last full backup.
Q2) ____________________ controls are information security safeguards focusing on lower-level planning that deals with the functionality of the organization's security. These safeguards include disaster recovery and incident response planning.
Q3) The ISSP is a plan which sets out the requirements that must be met by the information security blueprint or framework.
A)True
B)False
Q4) NIST responded to a mandate and created a voluntary <u>Risk Management</u> Framework that provides an effective approachto manage cybersecurity risks. _________________________
A)True
B)False
Q5) Every member of the organization's InfoSec department must have a formal degree or certification in information security.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Risk Management
Available Study Resources on Quizplus for this Chatper
108 Verified Questions
108 Flashcards
Source URL: https://quizplus.com/quiz/42304
Sample Questions
Q1) Identifying human resources, documentation, and data information assets of an organization is less difficult than identifying hardware and software assets.
A)True
B)False
Q2) Risk <u>control</u> is the enumeration and documentation of risks to an organization's information assets. _________________________
A)True
B)False
Q3) A _________ assigns a status level to employees to designate the maximum level of classified data they may access.
A) security clearance scheme
B) data recovery scheme
C) risk management scheme
D) data classification scheme
Q4) ____________________ measures are generally less focused on numbers and are more strategic than metrics-based measures.
Q5) Cost ____________________ is the process of preventing the financial impact of an incident by implementing a control.
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Security Technology: Access Controls, Firewalls, and VPNS
Available Study Resources on Quizplus for this Chatper
106 Verified Questions
106 Flashcards
Source URL: https://quizplus.com/quiz/42305
Sample Questions
Q1) Lattice-based access control is a form of access control in which users are assigned a matrix of authorizations for particular areas of access.
A)True
B)False
Q2) Most firewalls use packet <u>header</u> information to determine whether a specific packet should be allowed to pass through or should be dropped.
A)True
B)False
Q3) A(n) ____________________ private network is a secure network connection between systems that uses the data communication capability of an unsecured and public network.
Q4) Task-based controls are associated with the assigned role a user performs in an organization, such as a position or temporary assignment like project manager. A)True
B)False
Q5) List and describe the interacting services of the Kerberos system.
Page 8
Q6) The application firewall is also known as a(n) ____________________ server.
To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Security Technology: Intrusion
Detection and Prevention Systems, and Other Security Tools
Available Study Resources on Quizplus for this Chatper
107 Verified Questions
107 Flashcards
Source URL: https://quizplus.com/quiz/42306
Sample Questions
Q1) In ____________________ protocol verification, the higher-order protocols are examined for unexpected packet behavior or improper use.
Q2) __________ applications use a combination of techniques to detect an intrusion and then trace it back to its source.
A) Honeynet
B) Trap-and-trace
C) HIDPS
D) Packet sniffer
Q3) A(n) ____________________ occurs when an attacker attempts to gain entry or disrupt the normal operations of an information system, almost always with the intent to do harm.
Q4) A(n)<u> log</u> file monitor is similar to an NIDPS.
A)True B)False
Q5) A passive vulnerability scanner is one that initiates traffic on the network in order to determine security holes.
A)True B)False
Q6) List and describe the three advantages of NIDPSs. Page 9
To view all questions and flashcards with answers, click on the resource link above.
Page 10

Chapter 8: Cryptography
Available Study Resources on Quizplus for this Chatper
109 Verified Questions
109 Flashcards
Source URL: https://quizplus.com/quiz/42307
Sample Questions
Q1) Ciphertext or a <u>cryptogram</u> is an encoded message, or a message that has been successfully encrypted. _________________________
A)True
B)False
Q2) The AES algorithm was the first public-key encryption algorithm to use a 256-bit key length.
A)True B)False
Q3) <u>Encryption</u> is the process of converting the ciphertext message back into plaintext so that it can be readily understood. _________________________
A)True
B)False
Q4) <u>Pretty Good Privacy (PGP)</u> uses the freeware ZIP algorithm to compress the message after it has been digitally signed but before it is encrypted.
A)True B)False
Q5) To use a(n) ____________________ cipher, you substitute one value for another.
Q6) Describe how hash functions work and what they are used for.
11
To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Physical Security
Available Study Resources on Quizplus for this Chatper
77 Verified Questions
77 Flashcards
Source URL: https://quizplus.com/quiz/42308
Sample Questions
Q1) A(n) _________________________ security plan requires that every building have clearly marked fire exits and maps posted throughout the facility.
Q2) In a double conversion <u>offline</u> UPS, the primary power source is the inverter, and the power feed from the utility is constantly recharging the battery, which in turn powers the output inverter. _________________________
A)True
B)False
Q3) Halon is one of a few chemicals designated as a(n) _________________________ agent, which means that it does not leave any residue after use, nor does it interfere with the operation of electrical or electronic equipment.
Q4) A(n) _________________________ system has pressurized water in all pipes and has some form of valve in each protected area.
Q5) The _________________________ lock may rely on a key that is a carefully shaped piece of metal and is rotated to turn tumblers that release secured loops of steel, aluminum, or brass.
Q6) A(n) _________________________ or offline UPS is an offline battery backup that detects the interruption of power to the power equipment.
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 10: Implementing Information Security
Available Study Resources on Quizplus for this Chatper
78 Verified Questions
78 Flashcards
Source URL: https://quizplus.com/quiz/42309
Sample Questions
Q1) Corrective action decisions are usually expressed in terms of <u>trade-offs</u>.
A)True B)False
Q2) The project planner should describe the skills or personnel needed for a task, often referred to as a(n) ____________________.
Q3) All organizations should designate a champion from the general management community of interest to supervise the implementation of an information security project plan.
A)True B)False
Q4) In project planning, the tasks or action steps that come before the specific task at hand are commonly referred to as <u>prerequisites</u>.
A)True B)False
Q5) Once a project is underway, it is managed to using a process known as a negative ____________________ loop.
Q6) What can the organization do by managing the process of change
Page 13
To view all questions and flashcards with answers, click on the resource link above.

Chapter 11: Security and Personnel
Available Study Resources on Quizplus for this Chatper
77 Verified Questions
77 Flashcards
Source URL: https://quizplus.com/quiz/42310
Sample Questions
Q1) The model commonly used by large organizations places the information security department within the __________ department.
A) management
B) information technology
C) financial
D) production
Q2) According to Schwartz, Erwin, Weafer, and Briney, "__________" are the real techies who create and install security solutions.
A) Builders
B) Administrators
C) Engineers
D) Definers
Q3) Separation of ____________________ is used to reduce the chance of an individual violating information security and breaching the confidentiality, integrity, or availability of information.
Q4) Once a candidate has accepted a job offer, the employment ____________________ becomes an important security instrument.
Q5) What functions does the CISO perform
Q6) Describe the concept of separation of duties.
Page 14
To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Information Security Maintenance
Available Study Resources on Quizplus for this Chatper
116 Verified Questions
116 Flashcards
Source URL: https://quizplus.com/quiz/42311
Sample Questions
Q1) Digital ___________ is a crime against or using digital media, computer technology, or related components; in other words, a computer is the source of the crime or the object of it.
Q2) Tracking compliance involves assessing the status of the program as indicated by the database information and mapping it to <u>goals</u> established by the agency.
A)True
B)False
Q3) In some instances, risk is acknowledged as being part of an organization's business process.
A)True
B)False
Q4) The vulnerability database, like the risk, threat, and attack database, both stores and tracks information.
A)True
B)False
Q5) List and describe the choices an organization has when setting policy about how to employ digital forensics.
Q6) List the four steps to developing a CM plan.
Page 15
To view all questions and flashcards with answers, click on the resource link above.