1/5
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
The most robust configuration in firewall rule base is:
A. Allow all traffic and deny the specified traffic
B. Deny all traffic and allow the specified traffic
C. Dynamically decide based on traffic
D. Control traffic on the basis of discretion of network administrator.
B. Deny all traffic and allow the specified traffic
Explanation:
In any given scenario, most robust configuration in firewall rule is ‘deny all traffic and allow specific traffic’ (as against ‘allow all traffic and deny specific traffic’). This will help to block unknown traffic to critical systems and servers.
An IS auditor should be most concern about which of the following while reviewing a firewall?
A. Properly defined security policy
B Use of latest firewall structure with most secure algorithm.
C. The effectiveness of the firewall in enforcing the security policy.
D. Technical knowledge of users.
The effectiveness of the firewall in enforcing the security policy.
Explanation:
In absence of effective firewall implementation, other factors will not be effective. The existence of a good security policy is important, but if the firewall has not been implemented so as to effectively enforce the policy, then the policy is of little value.
While implementing a firewall, the most likely error to occur is:
A. wrong configuration of the access lists.
B. compromise of the password due to shoulder surfing.
C. inadequate user training about firewall rules.
D. inadequate anti-virus updating.
A. wrong configuration of the access lists.
Explanation:
Updating of correct and current access list is a significant challenge and, therefore, has the greatest chance for errors at the time of the initial installation. Others are not an element in implementing a firewall.
An organization is introducing a single sign-on (SSO) system. In SSO, unauthorized access:
A. will have minor impact.
B. will have major impact.
C. is not possible.
D. is highly possible.
B. will have major impact.
Explanation:
Single sign-on (SSO) is a user authentication service that permits a user to use one set of login credentials (e.g., name and password) to access multiple applications. This constitutes risk of single point of failure. The impact will be greater since the hacker needs to know only one password to gain access to all the related applications and therefore, cause greater concerns than if only the password to one of the systems is known. Introduction of SSO will not have any relevance on possibility (higher or lower) of unauthorized access.
Which of the following is the Best technique for protecting critical data inside the server?
A. Security awareness
B. Reading the security policy
C. Security committee
D. Logical access controls
D. Logical access controls
Explanation:
(1) In any given scenario, preference to be given to preventive controls as compared to detective or deterrent controls. Logical access controls are best preventive controls to ensure data integrity and confidentiality.
(2) Awareness itself does not protect against unauthorized access or disclosure of information.
(3) Knowledge of an information systems security policy which should be known by the organizations employees, would help to protect information, but would not prevent the unauthorized access of information.
(4) A security committee is key to the protection of information assets, but would address security issues within a broader perspective
The FIRST step in data classification is to:
A. identify data owners.
B. perform a criticality analysis.
C. define access rules.
D. define firewall rules.
A. identify data owners.
Explanation:
Data classification is necessary to define access rules based on a need-to-do and need-to-know basis. The data owner is responsible for defining the access rules; hence, establishing ownership is the first step in data classification.