Kuis Sim Bahasa Inggris Topik 8
Kuis Sim Bahasa Inggris Topik 8
Kuis Sim Bahasa Inggris Topik 8
Topik 8
_______ refers to policies, procedures, and technical measures used to prevent unauthorized access,
alternation, theft, or physical damage to information systems.
A) "Security"
B) "Controls"
C) "Benchmarking"
D) "Algorithms"
_______ refers to all of the methods, policies, and organizational procedures that ensure the safety of
the organization's assets, the accuracy and reliability of its accounting records, and operational
adherence to management standards.
A) "Legacy systems"
B) "SSID standards"
C) "Vulnerabilities"
D) "Controls"
Which of the following is not one of the challenges in securing wireless networks?
A) broadcasted SSIDs
B) scannability of radio frequency bands
C) SQL injection attacks
D) geographic range of wireless signals
Electronic data are more susceptible to destruction, fraud, error, and misuse because information
systems concentrate data in computer files that
A) are usually bound up in legacy systems that are difficult to access and difficult to correct in case of
error.
B) are not secure because the technology to secure them did not exist at the time the files were created.
C) have the potential to be accessed by large numbers of people and by groups outside of the
organization.
D) are frequently available on the Internet.
All of the following are methods of ensuring software quality except for
A) systems analysis.
B) walkthroughs.
C) software testing.
D) internal corporate back-end system.
Sniffing is a security challenge that is most likely to occur in which of the following points of a corporate
network?
A) client computer
B) communications lines
C) corporate servers
D) internal corporate back-end system
Inputting data into a poorly programmed Web form in order to disrupt a company's systems and
networks is called
A) a Trojan horse.
B) an SQL injection attack.
C) key logging.
D) a DDoS attack.
Which of the following statements about the Internet security is not true?
A) The use of P2P networks can expose a corporate computer to outsiders.
B) A corporate network without access to the Internet is more secure than one provides access.
C) VoIP is more secure than the switched voice network.
D) Instant messaging can provide hackers access to an otherwise secure network.
An independent computer program that copies itself from one computer to another over a network is
called a
A) worm.
B) Trojan horse.
C) bug.
D) pest.
A
A salesperson clicks repeatedly on the online ads of a competitor's in order to drive the competitor's
advertising costs up. This is an example of
A) phishing.
B) pharming.
C) spoofing.
D) click fraud.
In 2004, ICQ users were enticed by a sales message from a supposed anti-virus vendor. On the vendor's
site, a small program called Mitglieder was downloaded to the user's machine. The program enabled
outsiders to infiltrate the user's machine. What type of malware is this an example of?
A) Trojan horse
B) virus
C) worm
D) spyware
A keylogger is a type of
A) worm.
B) Trojan horse.
C) virus.
D) spyware.
C
Using numerous computers to inundate and overwhelm the network from numerous launch points is
called a(n) ________ attack.
A) DDoS
B) DoS
C) SQL injection
D) phishing
Approximately how many new threats from malware were detected by Internet security firms in 2012?
A) 400 thousand
B) 4 million
C) 40 million
D) 400 million
An example of phishing is
A) setting up bogus Wi-Fi hot spots.
B) setting up a fake medical Web site that asks users for confidential information.
C) pretending to be a utility company's employee in order to garner information from that company
about their security system.
D) sending bulk e-mail that asks for financial aid under a false pretext.
Pharming involves
A) redirecting users to a fraudulent Web site even when the user has typed in the correct address in the
Web browser.
B) pretending to be a legitimate business's representative in order to garner information about a
security system.
C) setting up fake Web sites to ask users for confidential information.
D) using e-mails for threats or harassment.
You have been hired as a security consultant for a law firm. Which of the following constitutes the
greatest source of security threats to the firm?
A) wireless network
B) employees
C) authentication procedures
D) lack of data encryption
How do software vendors correct flaws in their software after it has been distributed?
A) issue bug fixes
B) issue patches
C) re-release software
D) issue updated versions
Electronic evidence on computer storage media that is not visible to the average user is called ________
data.
A) defragmented
B) ambient
C) forensic
D) fragmented
Application controls
A) can be classified as input controls, processing controls, and output controls.
B) govern the design, security, and use of computer programs and the security of data files in general
throughout the organization.
C) apply to all computerized applications and consist of a combination of hardware, software, and
manual procedures that create an overall control environment.
D) include software controls, computer operations controls, and implementation controls.
______ controls ensure that valuable business data files on either disk or tape are not subject to
unauthorized access, change, or destruction while they are in use or in storage.
A) Software
B) Administrative
C) Data security
D) Implementation
Analysis of an information system that rates the likelihood of a security incident occurring and its cost is
included in a(n)
A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.
A(n) ________ system is used to identify and authorize different categories of system users and specify
which portions of the organization's systems each user can access.
A) identity management
B) AUP
C) authentication
D) firewall
Which of the following is not one of the main firewall screening techniques?
A) application proxy filtering
B) static packet filtering
C) NAT
D) secure socket filtering
Which of the following is not a trait used for identification in biometric systems?
A) retinal image
B) voice
C) hair color
D) face
In which technique are network communications analyzed to see whether packets are part of an
ongoing dialogue between a sender and a receiver?
A) stateful inspection
B) intrusion detection system
C) application proxy filtering
D) packet filtering
Which of the following is the greatest threat that employees pose to an organization's information
systems?
A) forgetting passwords
B) lack of knowledge
C) entering faulty data
D) introducing software errors
B
Currently, the protocols used for secure information transfer over the Internet are
A) TCP/IP and SSL.
B) S-HTTP and CA.
C) HTTP and TCP/IP.
D) SSL, TLS, and S-HTTP.
In which method of encryption is a single encryption key sent to the receiver so both sender and
receiver share the same key?
A) SSL
B) symmetric key encryption
C) public key encryption
D) private key encryption
In controlling network traffic to minimize slow-downs, a technology called ________ is used to examine
data files and sort low-priority data from high-priority data.
A) high availability computing
B) deep-packet inspection
C) application proxy filtering
D) stateful inspection
The development and use of methods to make computer systems resume their activities more quickly
after mishaps is called
A) high availability computing.
B) recovery oriented computing.
C) fault tolerant computing.
D) disaster recovery planning.