ITN 267 FINAL EXAM Legal Issues in Information
Security ACTUAL VERIFIED EXAM QUESTIONS AND
CORRECT DETAILED ANSWERS LATEST UPDATE
THIS YEAR.pdf||NEWEST EXAM!!!
The United States has one comprehensive data protection
law and relies on the Federal Trade Commission (FTC) to
ensure compliance.
True or false? - Answer-False
What is the process of applying safeguards to avoid a
negative impact?
risk mitigation
risk transfer
risk avoidance
risk analysis - Answer-risk mitigation
,2|Page
risk transfer
risk avoidance
risk analysis
The C-I-A triad refers to the way that the Central
Intelligence Agencies classifies sensitive information.
True or false? - Answer-False
_______________ is the process of reviewing known
vulnerabilities and threats.
Risk mitigation
Risk engineering
Risk analysis
Risk avoidance - Answer-Risk mitigation
,3|Page
Risk engineering
Risk analysis
Risk avoidance
A keystroke logger is harmful code intentionally left on a
computer system. It lies dormant for a certain period, and
when specific conditions are met, it "explodes" and carries
out its malicious function.
True or false? - Answer-False
Sometimes a vulnerability is exploited so soon after it is
discovered that there is no time to apply a patch to the
system quickly enough to prevent that data from being
compromised.
True or false? - Answer-True
What makes a distributed denial of service attack
"distributed"?
, 4|Page
It involves technological and physical systems to launch
the attack.
It involves many IP addresses.
It attacks multiple systems.
It involves multiple systems to launch the attack. - Answer-
It involves technological and physical systems to launch
the attack.
It involves many IP addresses.
It attacks multiple systems.
It involves multiple systems to launch the attack.
Which of the following statements summarizes why the
window of vulnerability is shrinking?