Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

WGU, Information Security and Assurance (C725), SET I 2024/2025 Questions and Answers

Rating
-
Sold
-
Pages
16
Grade
A+
Uploaded on
11-02-2024
Written in
2023/2024

WGU, Information Security and Assurance (C725), SET I 2024/2025 Questions and Answers Information security is primarily a discipline to manage the behavior of _____. A. Technology B. People C. Processes D. Organizations People Careers in information security are booming because of which of the following factors? A. Threats of cyberterrorism B. Government regulations C. Growth of the Internet D. All of these All of these A program for information security should include which of the following elements? A. Security policies and procedures B. Intentional attacks only C. Unintentional attacks only D. None of these Security policies and proceduresExplanation: Answer A is correct. The Carnegie Melon Information Network Institute (INI) designed programs to carry out multiple tasks including Information Security Policies. The growing demand for InfoSec specialists is occurring predominantly in which of the following types of organizations? A. Government B. Corporations C. Not-for-profit foundations D. All of these D. All of these The concept of the measures used to ensure the protection of the secrecy of data, objects, or resources. Confidentiality A catchall safe rating for any box with a lock on it. This rating describes the thickness of the steel used to make the lockbox. No actual testing is performed to gain this rating. B-Rate Safe Rating This safe rating is defined as a variably thick steel box with a 1-inch-thick door and a lock. No tests are conducted to provide this rating, either. C-Rate Safe Rating Safes with an Underwriters Laboratory rating that have passed standardized tests as defined in Underwriters Laboratory Standard 687 using tools and an expert

Show more Read less
Institution
Course

Content preview

WGU, Information Security and Assurance (C725), SET I
2024/2025 Questions and Answers
Information security is primarily a discipline to manage the behavior of _____.

A. Technology
B. People
C. Processes
D. Organizations
People
Careers in information security are booming because of which of the following
factors?
A. Threats of cyberterrorism
B. Government regulations
C. Growth of the Internet
D. All of these
All of these
A program for information security should include which of the following
elements?
A. Security policies and procedures
B. Intentional attacks only
C. Unintentional attacks only
D. None of these
Security policies and proceduresExplanation:
Answer A is correct. The Carnegie Melon Information Network Institute (INI) designed
programs to carry out multiple tasks including Information Security Policies.
The growing demand for InfoSec specialists is occurring predominantly in which
of the following types of organizations?
A. Government
B. Corporations
C. Not-for-profit foundations
D. All of these
D. All of these
The concept of the measures used to ensure the protection of the secrecy of
data, objects, or resources.
Confidentiality
A catchall safe rating for any box with a lock on it. This rating describes the
thickness of the steel used to make the lockbox. No actual testing is performed to
gain this rating.
B-Rate Safe Rating
This safe rating is defined as a variably thick steel box with a 1-inch-thick door
and a lock. No tests are conducted to provide this rating, either.
C-Rate Safe Rating
Safes with an Underwriters Laboratory rating that have passed standardized tests
as defined in Underwriters Laboratory Standard 687 using tools and an expert

,group of safe-testing engineers. The safe rating label requires that the safe be
constructed of 1-inch solid steel or equivalent. The label means that the safe has
been tested for a net working time of 15 minutes using "common hand tools,
drills, punches hammers, and pressure applying devices." Net working time
means that when the tool comes off the safe, the clock stops. Engineers exercise
more than 50 different types of attacks that have proven effective for
safecracking.
UL TL-15 Safe Rating
This Underwriters Laboratory rating testing is essentially the same as the TL-15
testing, except for the net working time. Testers get 30 minutes and a few more
tools to help them gain access. Testing engineers usually have a safe's
manufacturing blueprints and can disassemble the safe before the test begins to
see how it works.
UL TL-30 Safe Rating
Related to information security, confidentiality is the opposite of which of the
following?

A. Closure
B. Disclosure
C. Disaster
D. Disposal
B. Disclosure Explanation: Confidentiality models are primarily intended to ensure that
no unauthorized access to information is permitted and that accidental disclosure of
sensitive information is not possible.
Integrity models have which of the three goals:

A. Prevent unauthorized users from making modifications to data or programs
B. Prevent authorized users from making improper or unauthorized modifications
C. Maintain internal and external consistency of data and programs
D. All of these
D. All of these Explanation: Integrity models keep data pure and trustworthy by
protecting system data from intentional or accidental changes.
Information security professionals usually address which of these three common
challenges to availability:

A. Denial of service (DoS) due to intentional attacks or because of undiscovered
flaws in implementation (for example, a program written by a programmer who is
unaware of a flaw that could crash the program if a certain unexpected input is
encountered)
B. Loss of information system capabilities because of natural disasters (fires,
floods, storms, or earthquakes) or human actions (bombs or strikes)
C. Equipment failures during normal use.
D. All of these
D. All of theseExplanation:Availability models keep data and resources available for
authorized use, especially during emergencies or disasters.

, Which of the following represents the three goals of information security?

A. Confidentiality, integrity, and availability
B. Prevention, detection, and response
C. People controls, process controls, and technology controls
D. Network security, PC security, and mainframe security
A. Confidentiality, integrity, and availabilityExplanation:These goals form the
confidentiality, integrity, availability (CIA) triad, the basis of all security programs.
Usually a documented argument or stated position in order to define a need to
make a decision or take some form of action.
Business Case
A type of security management planning where upper, or senior, management is
responsible for initiating and defining policies for the organization.
Top-down approach
A type of security management planning where IT staff makes security decisions
directly without input from senior management. This approach is rarely used in
organizations and is considered problematic in the IT industry.
Bottom-up approach
This security plan is a long-term plan that is fairly stable. It defines the
organization's security purpose. It also helps to understand security function and
align it to the goals, mission, and objectives of the organization. It's useful for
about five years if it is maintained and updated annually. This plan also serves as
the planning horizon. Long-term goals and visions for the future are discussed
this plan. Thisplan should include a risk assessment.
Strategic Plan
This security plan is a midterm plan developed to provide more details on
accomplishing the goals set forth in the strategic plan or can be crafted ad hoc
based upon unpredicted events. This plan is typically useful for about a year and
often prescribes and schedules the tasks necessary to accomplish organizational
goals. Some examples of these plans are project plans, acquisition plans, hiring
plans, budget plans, maintenance plans, support plans, and system development
plans.
Tactical Plan
This security plan is a short-term, highly detailed plan based on the strategic and
tactical plans. It is valid or useful only for a short time. These plans must be
updated often (such as monthly or quarterly) to retain compliance with tactical
plans. These plans spell out how to accomplish the various goals of the
organization. They include resource allotments, budgetary requirements, staffing
assignments, scheduling, and step-by-step or implementation procedures. These
plans include details on how the implementation processes are in compliance
with the organization's security policy. Examples of these plans are training
plans, system deployment plans, and product design plans.
Operational Plan
Also called classification, the primary means by which data is protected based on
its need for secrecy, sensitivity, or confidentiality. It is the process of organizing

Written for

Course

Document information

Uploaded on
February 11, 2024
Number of pages
16
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$13.98
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
katoinyambi96 stuvia
Follow You need to be logged in order to follow users or courses
Sold
49
Member since
3 year
Number of followers
31
Documents
1267
Last sold
5 months ago

4.5

6 reviews

5
4
4
1
3
1
2
0
1
0

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions