Chapter 14 Review Question Answers

  1. A statement regarding due diligence would be found in which security policy?
  1. Disposal and destruction policy
  2. Acceptable use policy
  3. Privacy policy
  4. Security-related human resource policy
  1. Which risk category addresses events that impact the daily business of the organization?
  1. Strategic
  2. Operational
  3. Tactical
  4. Daily
  1. _____ management covers the procedures of managing object authorizations.
  1. Privilege
  2. Threat
  3. Task
  4. Asset
  1. Which of the following is not a characteristic of a policy?
  1. Policies communicate a unanimous agreement of judgment.
  2. Policies may be helpful in the event that it is necessary to prosecute violators.
  3. Policies identify what tools and procedures are needed.
  4. Policies define appropriate user behavior.
  1. Which of the following is not an approach to trust?
  1. Trust all people all the time.
  2. Trust everyone all of the time.
  3. Trust authorized individuals only.
  4. Trust some people some of the time.
  1. _____ is defined as the obligations that are imposed on owners and operators of assets to exercise reasonable care of the assets and take necessary precautions to protect them.
  1. Due care
  2. Due obligations
  3. Due process
  4. Due diligence
  1. What is a collection of suggestions that should be implemented?
  1. Policy
  2. Guideline
  3. Standard
  4. Code
  1. Each of the following is a guideline for developing a security policy except ______.
  1. notify users in advance that a new security policy is being developed and explain why the policy is needed
  2. require all users to approve the policy before it is implemented
  3. provide a sample of people affected by the policy with an opportunity to review and comment
  4. prior to deployment, give all users at least two weeks to review and comment
  1. Each of the following is what a security policy must do except _____.
  1. balance protection with productivity
  2. be able to implement and enforce it
  3. state reasons why the policy is necessary
  4. be concise and easy to understand
  1. Which of the following should not serve on a security policy development team?
  1. Senior level administrator
  2. Member of the legal staff
  3. Member of management who can enforce the policy
  4. Representative from a hardware vendor
  1. Which policy defines the actions users may perform while accessing systems and networking equipment?
  1. End user policy
  2. Internet use policy
  3. User permission policy
  4. Acceptable use policy
  1. _____ may be defined as the study of what people understand to be good and right behavior and how people make those judgments.
  1. Morals
  2. Values
  3. Ethics
  4. Principles
  1. A classification of information policy is designed to produce a standardized framework for classifying _____.
  1. information assets
  2. types of policies
  3. user password violations
  4. free hard drive
  1. Which of the following would be found in a password management and complexity policy?
  1. Do not use alphabetic characters.
  2. Do not use a password that is a word found in a dictionary.
  3. Do not use the name of a pet.
  4. Do not use personally identifiable information.
  1. Which of the following is true regarding a privacy policy?
  1. It covers the same material as that found in an AUP.
  2. It must be certified before it can be used.
  3. It is required on all Internet Web sites.
  4. It is also called a personally identifiable information policy.
  1. Which is not one of the challenges in a classification of information policy?
  1. The number of supervisors needed to oversee the work.
  2. There is a tendency to create multiple levels of classification.
  3. There are attempts to use information classification categories developed by another organization and “force” them to fit.
  4. The desire to classify all items as high security.
  1. For adult learners a(n) _____ approach (the art of helping an adult learn) is often preferred.
  1. andragogical
  2. institutional
  3. proactive
  4. pedagogical
  1. Requiring employees to clear their workspace of all papers at the end of each business day is called ______.
  1. empty workspace policy
  2. clean desk policy
  3. disposal and removal policy
  4. sunshine policy
  1. What is the security risk of a P2P network?
  1. A virus can be transmitted.
  2. It consumes bandwidth.
  3. It allows law enforcement agencies to monitor the user’s actions.
  4. It is issued to spread spam.
  1. Which of the following is NOT a general security recommendation when using social networking sites?
  1. Consider carefully who is accepted as a friend.
  2. Show “limited friends” a reduced version of your profile.
  3. Only access a social networking site on personal time.
  4. Disable options and then reopen them only as necessary.