ASSESSMENT NEWEST ACTUAL EXAM COMPLETE 100
QUESTIONS AND CORRECT DETAILED ANSWERS |
ALREADY GRADED A+
acceptable use policy (AUP) - ANSWER: A document that stipulates restrictions and
practices that a user must agree in order to use organizational computing and
network resources.
advanced persistent threat (APT) - ANSWER: A network attack in which an intruder
gains access to a network and stays there—undetected—with the intention of
stealing data over a long period of time (weeks or even months).
Agreement on Trade-Related Aspects of Intellectual Property Rights (TRIPS) -
ANSWER: An agreement of the World Trade Organization that requires member
governments to ensure that intellectual property rights can be enforced under their
laws and that penalties for infringement are tough enough to deter further
violations.
American Recovery and Reinvestment Act - ANSWER: A wide-ranging act that
authorized $787 billion in spending and tax cuts over a 10-year period and included
strong privacy provisions for electronic health records, such as banning the sale of
health information, promoting the use of audit trails and encryption, and providing
rights of access for patients.
annualized loss expectancy (ALE) - ANSWER: The estimated loss from a potential risk
event over the course of a year. The following equation is used to calculate the
annual loss expectancy: ARO × SLE = ALE. Where ARO is the annualized rate of
occurrence, an estimate of the probability that this event will occur over the course
of a year and SLE is the single loss expectancy, the estimated loss that would be
incurred if the event happens.
annualized rate of occurrence (ARO) - ANSWER: An estimate of the probability that a
risk event will occur over the course of a year.
anonymous remailer service - ANSWER: A service that allows anonymity on the
Internet by using a computer program that strips the originating header and/or IP
address from the message and then forwards the message to its intended recipient.
anti-SLAPP laws - ANSWER: Laws designed to reduce frivolous SLAPPs (strategic
lawsuit against public participation (SLAPP), which is a lawsuit filed by corporations,
government officials, and others against citizens and community groups who oppose
them on matters of concern).
,audit committee - ANSWER: A group that provides assistance to the board of
directors in fulfilling its responsibilities with respect to the oversight of the quality
and integrity of the organization's accounting and reporting practices and controls,
including financial statements and reports; the organization's compliance with legal
and regulatory requirements; the qualifications, independence, and performance of
the company's independent auditor; and the performance of the company's internal
audit team.
Bathsheba syndrome - ANSWER: The moral corruption of people in power, which is
often facilitated by a tendency for people to look the other way when their leaders
act inappropriately.
Bill of Rights - ANSWER: The first 10 amendments to the United States Constitution
that spell out additional rights of individuals.
black-box testing - ANSWER: A type of dynamic testing that involves viewing the
software unit as a device that has expected input and output behaviors but whose
internal workings are unknown (a black box).
blended threat - ANSWER: A sophisticated threat that combines the features of a
virus, worm, Trojan horse, and other malicious code into a single payload.
body of knowledge - ANSWER: An agreed-upon sets of skills and abilities that all
licensed professionals must possess.
botnet - ANSWER: A large group of computers, which are controlled from one or
more remote locations by hackers, without the knowledge or consent of their
owners.
breach of the duty of care - ANSWER: The failure to act as a reasonable person
would act.
BSA | The Software Alliance - ANSWER: A trade group that represent the world's
largest software and hardware manufacturers.
business continuity plan - ANSWER: A risk-based strategy that includes an occupant
emergency evacuation plan, a continuity of operations plan, and an incident
management plan with an active governance process to minimize the potential
impact of any security incident and to ensure business continuity in the event of a
cyberattack or some form of disaster.
business information system - ANSWER: A set of interrelated components—including
hardware, software, databases, networks, people, and procedures—that collects and
processes data and disseminates the output.
Capability Maturity Model Integration (CMMI) models - ANSWER: Collection of best
practices that help organizations improve their processes.
, CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans
Apart) - ANSWER: Software that generates and grades tests that humans can pass
and all but the most sophisticated computer programs cannot.
Child Online Protection Act (COPA) - ANSWER: An act signed into law in 1998 with
the aim of prohibiting the making of harmful material available to minors via the
Internet; the law was ultimately ruled largely unconstitutional.
Children's Internet Protection Act (CIPA) - ANSWER: An act passed in 2000; it
required federally financed schools and libraries to use some form of technological
protection (such as an Internet filter) to block computer access to obscene material,
pornography, and anything else considered harmful to minors.
Children's Online Privacy Protection Act (COPPA) - ANSWER: An act implemented in
1998 in an attempt to give parents control over the collection, use, and disclosure of
their children's personal information.
CIA security triad - ANSWER: Refers to confidentiality, integrity, and availability.
clinical decision support (CDS) - ANSWER: A process and a set of tools designed to
enhance healthcare-related decision making through the use of clinical knowledge
and patientspecific information to improve healthcare delivery.
CMMI-Development (CMMI-DEV) - ANSWER: A specific application of CMMI
frequently used to assess and improve software development practices.
code of ethics - ANSWER: A statement that highlights an organization's key ethical
issues and identifies the overarching values and principles that are important to the
organization and its decision making.
coemployment relationship - ANSWER: A employment situation in which two
employers have actual or potential legal rights and duties with respect to the same
employee or group of employees.
Communications Assistance for Law Enforcement Act (CALEA) - ANSWER: An act
passed in 1994 that amended the Wiretap Act and Electronic Communications
Privacy Act, which required the telecommunications industry to build tools into its
products that federal investigators could use—after obtaining a court order—to
eavesdrop on conversations and intercept electronic communications.
Communications Decency Act (CDA) - ANSWER: Title V of the Telecommunications
Act, it aimed at protecting children from pornography, including imposing $250,000
fines and prison terms of up to two years for the transmission of "indecent" material
over the Internet.