Skip to main content

IT Risk Management Chapter Exam Questions - 496 Verified Questions

Page 1


IT Risk Management

Chapter Exam Questions

Course Introduction

IT Risk Management focuses on identifying, assessing, and mitigating risks associated with information technology systems within organizations. This course covers essential frameworks, methodologies, and tools used to evaluate IT vulnerabilities, threats, and impacts on business operations. Students will learn how to implement risk assessment techniques, develop risk mitigation strategies, and ensure compliance with legal and regulatory requirements. Practical case studies and current industry standards, such as ISO 27001 and NIST, are explored to provide students with hands-on experience in planning and managing IT risk in real-world scenarios.

Recommended Textbook Guide to Firewalls and VPNs 3rd Edition by Michael E. Whitman

Available Study Resources on Quizplus

10 Chapters

496 Verified Questions

496 Flashcards

Source URL: https://quizplus.com/study-set/2181 Page 2

Chapter 1: Introduction to Information Security

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43454

Sample Questions

Q1) Provide an example of a social engineering attack.

Answer: An example of a social engineering attack is the so-called Advance Fee Fraud (AFF), which is known internationally as the "4-1-9" fraud (named after a section of the Nigerian penal code).The perpetrators of 4-1-9 schemes often use fictitious companies, such as the Nigerian National Petroleum Company.Alternatively, they may invent other entities, such as a bank, a government agency, or a nongovernmental organization such as a lottery corporation.This scam is notorious for stealing funds from gullible individuals, first by requiring them to send money up-front in order to participate in a proposed money-making venture, and then by charging an endless series of fees.These 4-1-9 schemes have even been linked to kidnapping, extortion, and murder; and they have, according to the United States Secret Service, bilked over $100 million from unsuspecting Americans lured into disclosing personal banking information.

Q2) An individual who hacks the public telephone network to make free calls or disrupt services is called a ____.

A) phreaker

B) hactivist

C) packet monkey

D) cyberterrorist

Answer: A

To view all questions and flashcards with answers, click on the resource link above.

Page 3

Chapter 2: Security Policies and Standards

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43455

Sample Questions

Q1) A security framework specifies the tasks for deploying security tools in the order in which they are to be accomplished.

A)True

B)False

Answer: False

Q2) Basis for the design, selection, and implementation of all security program elements, including policy implementation, ongoing policy management, risk management programs, education and training programs, technological controls, and maintenance of the security program.

A)managerial guidance SysSP document

B)security training

C)incident response

D)business continuity plan

E)information security policy

F)de jure

G)de facto

H)security blueprint

I)business impact analysis

Answer: H

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Authenticating Users

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43456

Sample Questions

Q1) What is a disadvantage of centralized authentication?

Answer: In centralized authentication, the authentication server becomes a single point of failure.If that device fails or is compromised, the authentication process used for the entire organization will come to a standstill, and all information systems will become inoperable.This is a severe threat to the availability of these systems, when they are one glitch or one failed hard drive away from failure.An organization that uses this type of method must also have a contingency plan in place to get the server back online or provide alternative servers to limit the downtime a failure or compromise to this system would cause.

Q2) A PIN is an example of something you ____.

A) know B) have C) are D) do

Answer: A

Q3) Access controls are defined only using technology.

A)True

B)False

Answer: False

To view all questions and flashcards with answers, click on the resource link above.

Page 5

Chapter 4: Introduction to Firewalls

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43457

Sample Questions

Q1) A ____ firewall enables you to log passing traffic, protecting the whole network at one time.

A) stateful

B) stateless

C) perimeter

D) DMZ

Q2) Port numbers come in two flavors: well-known ports and ____________________ ports.

Q3) Application gateways function at the ____ layer of the OSI model.

A) presentation

B) transport

C) network

D) data link

Q4) A properly configured firewall only allows authorized connection attempts to the ports on the network it protects.

A)True

B)False

Q5) "____________________" refers to the era of technology a firewall evolved in.

Q6) Describe the differences between software and hardware firewalls.

Q7) Describe stateless packet-filtering firewalls.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Packet Filtering

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43458

Sample Questions

Q1) Some systems, like Windows and Linux, have built-in utilities that can filter packets on the TCP/IP stack of the server software.

A)True

B)False

Q2) A stateless filter compares the header data against its ____ and forwards each packet as a rule is found to match the specifics of that packet.

A) ACK flag

B) rule base

C) state table

D) log

Q3) The ____ is a structure for organizing Internet names associated with IP addresses.

A) Domain Name System (DNS)

B) Transport Control Protocol (TCP)

C) Hypertext Transfer Protocol (HTTP)

D) Simple Mail Transfer Protocol (SMTP)

Q4) Why might a small-scale software-only personal firewall cause problems in a network situation?

Q5) Describe how a firewall can enable Web access.

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Firewall Configuration and Administration

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43459

Sample Questions

Q1) A(n) ____________________ interface is software that enables you to configure and monitor one or more firewalls that are located at different network locations.

Q2) Of central importance to the operation of the firewall software that it hosts.

A)boot-up password

B)firewall rules

C)bastion host

D)screen saver password

E)restrictive

F)IP forwarding

G)permissive

H)supervisor password

I)caching

Q3) Different types of hardware can be secured in different ways, but one of the most important ways is to ____.

A) never update once you have a good configuration defined

B) buy products from the same brand

C) only use on network administrator

D) choose good passwords that you then guard closely

Q4) Describe the Content Vectoring Protocol (CVP).

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Working With Proxy Servers and

Application-Level Firewalls

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43460

Sample Questions

Q1) Because a proxy server ____ all packets that pass between the Internet and the internal hosts, attacks that can start with mangled packet data never reach the internal host.

A) drops

B) rebuilds

C) routes

D) reformats

Q2) URLs are blocked on a proxy server as ____.

A) IP addresses

B) full-text URLs

C) screen hosts

D) domains

Q3) How can proxy servers affect performance of the network?

Q4) To enhance security, firewall rules can be used along with a proxy server to ____.

A) limit Internet access to only network administrators at all times

B) allow for internal users to bypass the proxy server at all times

C) enable external users to access any client computer directly

D) enable internal users to send outbound requests only at certain times

Q5) What is SOCKS?

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Implementing the Bastion Host

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43461

Sample Questions

Q1) What type of fees do hosting service charge?

Q2) Records detailing who accessed resources on the server and when the access attempts occurred.

A)instruction cache

B)log files

C)translation lookaside buffer

D)data cache

E)Demilitarized Zone

F)bastion host

G)UNIX

H)processor speed

I)syslog daemon

Q3) The ____ utility reports on the services that are currently started.

A) Security Compliance Manager

B) chkconfig

C) syslog

D) daemon

Q4) Why is it a good idea to disable user accounts on the bastion host?

Q5) What type of processor speed is best for a bastion host?

Q6) Where should a bastion host be located?

Page 10

To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Encryption - The Foundation for the Virtual

Private

Network

Available Study Resources on Quizplus for this Chatper

48 Verified Questions

48 Flashcards

Source URL: https://quizplus.com/quiz/43462

Sample Questions

Q1) Asymmetric encryption uses ____ separate keys for each message.

A) one

B) two

C) three

D) four

Q2) Firewalls have always performed encryption-related functions.

A)True

B)False

Q3) The mathematical formula or method used to convert an unencrypted message into an encrypted message or vice versa.

A)cipher

B)keyspace

C)encipher

D)cryptosystem

E)ciphertext

F)work factor

G)decipher

H)algorithm

I)cryptovariable

To view all questions and flashcards with answers, click on the resource link above. Page 11

Q4) Describe symmetric encryption.What is the weakness of this type of encryption?

Chapter 10: Setting up a Virtual Private Network

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43463

Sample Questions

Q1) L2TP uses ____ rather than MPPE to encrypt data sent over PPP.

A) SSL

B) SSH

C) IPSec

D) IKE

Q2) Describe software VPN systems.

Q3) ____________________ is a computer networking philosophy and a related set of protocols that are together used to evaluate the trustworthiness of a client wishing to join a network.

Q4) VPN that links two or more networks.

A)encapsulation

B)tunnel

C)client-to-site

D)transport mode

E)gateway

F)private leased lines

G)tunnel mode

H)site-to-site

I)Point-to-Point Tunneling Protocol

Q5) Describe the mesh configuration for a VPN.

Page 12

To view all questions and flashcards with answers, click on the resource link above.

Turn static files into dynamic content formats.

Create a flipbook