EHE: chapter 1 : information security fundamentals

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:05 PM on 9/28/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

Integrity

The trustworthiness of data or resources in terms of preventing improper or unauthorized changes.

2
New cards

Non-repudiation

A guarantee that the sender of a message cannot later deny having sent the message and that the recipient cannot deny having received the message.

3
New cards

Availability

Assurance that the systems responsible for delivering, storing, and processing information are accessible when required by the authorized users.

4
New cards

Confidentiality

Assurance that the information is accessible only to those authorized to have access.

5
New cards

Authenticity

characteristic of communication, documents, or any data that ensures the quality of being genuine or uncorrupted.Controls such as biometrics, smart cards, and digital certificates ensure the authenticity of data, transactions, communications, and documents.

6
New cards

close in attack

are performed when the attacker is in close physical proximity with the target system or network. For example, an attacker might shoulder surf user credentials. Attackers gain close proximity through surreptitious entry, open access, or both

7
New cards

Active attack

it tamper with the data in transit or disrupt communication or services between the systems to bypass or break into secured systems. Attackers launch attacks on the target system or network by sending traffic actively that can be detected.

8
New cards

Ruby, a hacker, visited her target company disguised as an aspiring candidate seeking a job. She noticed that certain sensitive documents were thrown in the trash near an employee’s desk. She collected these documents, which included critical information that helped her to perform further attacks.

Identify the type of attack performed by Ruby in the above scenario.

closin attack

9
New cards

James, a malware programmer, intruded into a manufacturing plant that produces computer peripheral devices. James tampered with the software inside devices ready to be delivered to clients. The tampered program creates a backdoor that allows unauthorized access to the systems.

Identify the type of attack performed by James in the above scenario to gain unauthorized access to the delivered systems.



distribution attack

10
New cards

David, a professional hacker, has initiated a DDoS attack against a target organization. He developed a malicious code and distributed it through emails to compromise the systems. Then, all the infected systems were grouped together to launch a DDoS attack against the organization.

Identify the type of attack launched by David on the target organization.

botnet

11
New cards

pod slurping

an insider attack that physically data theft using portable usb drives to extract large amounts of data from computer or network

12
New cards

directory traversal attack

An attacker may be able to perform a directory traversal attack owing to a vulnerability in the code of a web application. In addition, poorly patched or configured web server software can make the web server vulnerable

13
New cards

Identify the insider attack wherein the miscreant can easily bypass security rules by using privileged access and cause a threat to the organization’s information systems?

pod slurping

14
New cards

Which of the following titles in The Digital Millennium Copyright Act (DMCA) allows the owner of a copy of a program to make reproductions or adaptations when these are necessary to use the program in conjunction with a system?

Title III: Computer Maintenance or Repair

15
New cards

Which of the following titles of the Sarbanes Oxley Act (SOX) mandates that only senior executives should take individual responsibility for the accuracy and completeness of corporate financial reports?


Title III: Corporate Responsibility

16
New cards

Which of the following titles in Sarbanes Oxley Act (SOX) is referred to as the White Collar Crime Penalty Enhancement Act of 2002, which increases the criminal penalties associated with white-collar crimes and conspiracies?

title IX

17
New cards

Which of the following countries has implemented “The Copyright Act 1968” and “The Patents Act 1990”?

Australia

18
New cards

Identify the civilian act designed to protect investors and the public by increasing the accuracy and reliability of corporate disclosures. 

SOX act

19
New cards

Which of the following acts defines legal prohibitions against circumvention of the technological protection measures employed by copyright owners to protect their works and against the removal or alteration of copyright management information?

DMCA

20
New cards

An organization located in Europe maintains a large amount of user data by following all the security-related laws. It also follows GDPR protection principles, one of which states that the organization should only collect and process data necessary for the specified task.

Which of the following GDPR protection principle is discussed in the above scenario?

Data minimization