Is a technique used to gain unauthorized access to computers?

Is a technique used to gain unauthorized access to computers?

( -p spoof ing) (n.) A technique used to gain unauthorized access to computers, whereby the intruder sends messages to a computer with an IP address indicating that the message is coming from a trusted host.

Are software programs that hide their true nature using social engineering techniques and reveal their designed behavior only when activated group of answer choices?

Cards

Term Exploit Definition a technique used to compromise a system.
Term Trojan Horses Definition Software programs that hide their true nature and reveal their designed behavior only when activated.
Term Back Door / Trap Door Definition Allows the attacker to access the system at will with special privileges

What is a technique where attackers modify legitimate software to hide a malicious application?

Code Caves Technique where attackers modify legitimate software to hide a malicious application. FALSE POSITIVES N/A Anti-malware solutions may incorrectly identify legitimate software as malicious, impacting end users’ ability to work.

What type of malware is triggered by a certain date time or event?

A logic bomb is a malicious program that is triggered when a logical condition is met, such as after a number of transactions have been processed, or on a specific date (also called a time bomb). Malware such as worms often contain logic bombs, behaving in one manner, then changing tactics on a specific date and time.

Is a potential weakness in an asset or its defensive control s?

– threat: a potential risk of an asset’s loss of value. a potential weakness in an asset or its defensive control(s). attack. an act against an asset that could result in a loss.

Is the set of activities taken to plan for detect and correct the impact of an incident on information assets?

Incident —– is the set of activities taken to plan for, detect, and correct the impact of an incident on information assets. Incident —- is the process of examining a potential incident, or incident candidate, and determining whether or not the candidate constitutes an actual incident.

Which of the following acts is also known as the Gramm Leach Bliley Act?

The Gramm-Leach-Bliley Act (GLBA), which is also known as the Financial Services Modernization Act of 1999, provides limited privacy protections against the sale of your private financial information.

Which of the following is a valid type of role when it comes to data ownership?

Which of the following is a valid type of data ownership? A data custodian works directly with data owners and is responsible for the storage, maintenance, and protection of the information.

Which of the following is not considered an example of data hiding?

Which of the following is not considered an example of data hiding? Preventing an authorized reader of an object from deleting that object is just an example of access control, not data hiding. If you can read an object, it is not hidden from you.

What is the most important protection for information classified as public?

A reasonable level of security controls should be applied to Private data. Data should be classified as Public when the unauthorized disclosure, alteration or destruction of that data would result in little or no risk to the University and its affiliates.

When information is whole complete and uncorrupted?

Principles of information security

Question Answer
Information has…when it is whole, complete, and uncorrupted. Integrity
The senior technology officer is typically the chief officer. Executive

What term is used to describe the quality or state of ownership or control of information?

possession – this is the state or quality of ownership/control of some object or item (data is said to be in the possession of the one who has obtained it-independent of format or other characteristics.)

Are detailed written instructions for accomplishing a specific task?

(Policies) are written instructions for accomplishing a specific task.

Has become a widely accepted evaluation standard?

Answer Expert Verified. NSTISSI NO 4011 has become a widely accepted evaluation standard for training and education related to the security of information system.

Which of the following phases is often considered the longest and most expensive?

implementation phase

Is a network project that preceded the Internet?

A project which began in the Pentagon that year, called Arpanet, gave birth to the Internet protocols sometime later (during the 1970’s), but 1969 was not the Internet’s beginnings.

What is the subject of the Computer Security Act?

The Computer Security Act establishes minimum acceptable security practices for Federal computer systems containing sensitive information. It stipulates that each Federal agency provide mandatory periodic training in computer security awareness and accepted computer security practices.

Is the Patriot Act still in effect?

After reauthorization bills failed to pass Congress, parts of the Patriot Act expired on June 1, 2015. The USA Freedom Act, which became law on June 2, 2015, reenacted these expired sections through 2019.

What replaced the Computer Security Act?

Summary. 33 years since the passage of the CSA, responsibilities and oversight for cybersecurity have shifted to the Federal Information Security Management Act (FISMA) of 2002. FISMA 2002 was superseded by the Federal Information Security Modernization Act of 2014.

What is the purpose of Fisma?

The Federal Information Security Management Act (FISMA) is a United States federal law passed in 2002 that made it a requirement for federal agencies to develop, document, and implement an information security and protection program.

Who does Fisma regulate and directly apply to?

Federal Information Security Management Act (FISMA) applies to all agencies within the U.S. federal government. However, since the law was enacted in 2002, the government expanded FISMA to include state agencies administering federal programs such as unemployment insurance, student loans, Medicare, and Medicaid.

Who protects Fisma?

Overview. FISMA 2014 codifies the Department of Homeland Security’s role in administering the implementation of information security policies for federal Executive Branch civilian agencies, overseeing agencies’ compliance with those policies, and assisting OMB in developing those policies.

How do you comply with Fisma?

Some FISMA requirements include:

  1. Maintain an inventory of information systems.
  2. Categorize information and information systems according to risk level.
  3. Maintain a system security plan.
  4. Implement security controls (NIST 800-53)
  5. Conduct risk assessments.
  6. Certification and accreditation.
  7. Conduct continuous monitoring.

What are the Fisma controls?

FISMA is U.S. government legislation that defines a comprehensive framework to protect government information, operations, and assets against threats. Signed into law in 2002 and updated in 2014, FISMA requires that federal systems meet a set level of security requirements (also known as “controls”).

How does NIST and Fisma work together?

NIST develops the security standards and guidelines necessary for FISMA implementation including a risk-based approach for selecting, implementing, and assessing security controls for federal systems and for determining risk to organizational operations and assets, individuals, other organizations, and the Nation.

What issues were raised by GCN about Fisma act?

The largest categories of causes were non-cyber (29 percent) and policy violations (19 percent). Malware accounted for 18 percent, and suspicious network activity and social engineering were 5 percent each.

Begin typing your search term above and press enter to search. Press ESC to cancel.

Back To Top