FINAL EXAM REVIEW Questions and
Answers Graded A+
The Fabrication attack type most commonly affects which principle(s) of the CIA
triad?
A. Availability
B. Integrity
C. Confidentiality
D. Integrity and Availability
E. Confidentiality and Integrity - Correct answer-Integrity and Availability
The Interception attack type most commonly affects which principle(s) of the CIA
triad? This task contains the radio buttons and checkboxes for options. The shortcut
keys to perform this task are A to H and alt+1 to alt+9.
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,A.Integrity and Availability
B.Confidentiality and Integrity
C.Availability
D.Integrity
E.Confidentiality - Correct answer-Confidentiality
Something that has the potential to cause harm to our assets is known as a(n)
________.
A.Threat
B.Impact
C.Risk
D.Vulnerability - Correct answer-Threat
Controls that protect the systems, networks, and environments that process,
transmit, and store our data are called _______.
A.Logical controls
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
,B.Administrative controls
C.Physical controls - Correct answer-Logical Control
What is the first and arguably one of the most important steps of the risk
management process?
A.Assess risks
B.Mitigate risks
C.Identify threats
D.Assess vulnerabilities
E.Identify assets - Correct answer-Identify assets
Protects information and information systems from unauthorized access, use,
disclosure, disruption, modification, or destruction - Correct answer-information
security
A type of attack, primarily against confidentiality - Correct answer-Interception
Something that has the potential to cause harm to our assets - Correct answer-
Threat
A weakness that can be used to harm us - Correct answer-Vulnerability
The likelihood that something bad will happen - Correct answer-Risk
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3
, An attack that involves tampering with our assets - Correct answer-Modification
attack
A model that adds three more principles to the CIA triad: possession or control,
utility, and authenticity - Correct answer-Parkerian hexad
The physical disposition of the media on which the data is stored - Correct answer-
Possession or control
An attack that involves generating data, processes, communications, or other
similar activities with a system - Correct answer-Fabrication attack
A multilayered defense that will allow us to achieve a successful defense should
one or more of our defensive measures fail - Correct answer-Defense in depth
Sometimes called technical controls, these protect the systems, networks, and
environments that process, transmit, and store our data - Correct answer-Logical
controls
Controls that protect the physical environment in which our systems sit, or where
our data is stored - Correct answer-Physical controls
The risk management phase that consists of all of the activities that we can perform
in advance of the incident itself, in order to better enable us to handle it - Correct
answer-Preparation phase
©COPYRIGHT 2025, ALL RIGHTS RESERVED 4