Due in 3 hours Kim woods

profileDr Kathy William

Question 1 (3 points)

 Question 1 Saved
 

Reasons people might be reluctant to use biometrics for authentication is: hygiene or fear of personal injury and false negatives (falsely not being allowed into a system). 

 

Save

 

Question 2 (3 points)

 Question 2 Saved
 

A hash algorithm  uses a one-way cryptographic function, whereas both secret-key and public-key systems use two-way (i.e., reversible) cryptographic functions.

 

Save

 

Question 3 (3 points)

 Question 3 Saved
 

AES uses the Rijndael algorithm.

 

Save

 

Question 4 (3 points)

 Question 4 Unsaved
 

Encrypting a message with the sender’s private key ensures proof of receipt of a message.

 

Save

 

Question 5 (3 points)

 Question 5 Unsaved
 

Two purpose of using a salt value in storing (hashed) passwords is to prevent password duplication and thwart guessing whether a user has the same password on multiple systems.

 

Save

 

Question 6 (3 points)

 Question 6 Unsaved
 

In Role-Based Access Control Systems, a user is assigned no more than one role to limit the damage a user can do.

 

Save

 

Question 7 (3 points)

 Question 7 Unsaved
 

If person A uses AES to transmit an encrypted message to person B, which key or keys will A have to use:

 

Save

 

Question 8 (3 points)

 Question 8 Unsaved
 

Which one of the following is not a goal of cryptographic systems?

 

Save

 

Question 9 (3 points)

 Question 9 Unsaved
 

Mia, Ashley, Mark, and Chris are studying at Café Roma. Who may be putting their personal information at risk (select all that apply)?

 

Save

 

Question 10 (3 points)

 Question 10 Unsaved
 

For any organization, understanding the nature of the cybersecurity threat requires knowing at least which of the following elements: (select all that apply)

 

Save

 

Question 11 (3 points)

 Question 11 Unsaved
 

There are basically three categories of rules in control models:

 

Save

 

Question 12 (3 points)

 Question 12 Unsaved
 

To control access by a subject (____________) to an object (              ) requires management to establish access rules.

 

Save

 

Question 13 (3 points)

 Question 13 Unsaved
 

__________ implements a security policy that specifies who or what may have access to each specific system resource and the type of access that is permitted in each instance.

 

Save

 

Question 14 (3 points)

 Question 14 Unsaved
 

IT security management functions include:

 

Save

 

Question 15 (3 points)

 Question 15 Unsaved
 

To counter threats to remote user authentication, systems generally rely on some form of ___________ protocol.

 

Save

 

Question 16 (3 points)

 Question 16 Unsaved
 

Each individual who is to be included in the database of authorized users must first be __________ in the system.

 

Save

 

Question 17 (3 points)

 Question 17 Unsaved
 

A __________ is an entity capable of accessing objects.

 

Save

 

Question 18 (3 points)

 Question 18 Unsaved
 

Based on the concept in Chapter 4, the final permission bit is the _________ bit.

 

Save

 

Question 19 (3 points)

 Question 19 Unsaved
 

What is the general term for the process of protecting objects that are part of the multiprocessing environment?     

 

Save

 

Question 20 (3 points)

 Question 20 Unsaved
 

__________ defines user authentication as “the process of verifying an identity claimed by or for a system entity”.

 

Save

 

Question 21 (3 points)

 Question 21 Unsaved
 

Recognition by fingerprint, retina, and face are examples of __________.

 

Save

 

Question 22 (3 points)

 Question 22 Unsaved
 

The __________ strategy is when users are told the importance of using hard to guess passwords and provided with guidelines for selecting strong passwords.

 

Save

 

Question 23 (3 points)

 Question 23 Unsaved
 

To counter threats to remote user authentication, systems generally rely on some form of ___________ protocol.

 

Save

 

Question 24 (3 points)

 Question 24 Unsaved
 

An institution that issues debit cards to cardholders and is responsible for the cardholder’s account and authorizing transactions is the _________.

 

Save

 

Question 25 (3 points)

 Question 25 Unsaved
 

Any program that is owned by, and SetUID to, the “superuser” potentially grants unrestricted access to the system to any user executing that program.

 

Save

 

Question 26 (3 points)

 Question 26 Unsaved
 

The main innovation of the NIST standard is the introduction of the RBAC System and Administrative Functional Specification,which defines the features required for an RBAC system.

 

Save

 

Question 27 (3 points)

 Question 27 Unsaved
 

__________ is the traditional method of implementing access control.

 

Save

 

Question 28 (3 points)

 Question 28 Unsaved
 

A concept that evolved out of requirements for military information security is ______ .

 

Save

 

Question 29 (3 points)

 Question 29 Unsaved
 

The default set of rights should always follow the rule of least privilege or read-only access.

 

Save

 

Question 30 (3 points)

 Question 30 Unsaved
 

The principal objectives of computer security are to prevent unauthorized users from gaining access to resources, to prevent legitimate users from accessing resources in an unauthorized manner, and to enable legitimate users to access resources in an authorized manner.

 

Save

 

Question 31 (3 points)

 Question 31 Unsaved
 

__________ implements a security policy that specifies who or what may have access to each specific system resource and the type of access that is permitted in each instance.

 

Save

 

Question 32 (3 points)

 Question 32 Unsaved
 

_________ is the granting of a right or permission to a system entity to access a system resource.

 

Save

 

Question 33 (3 points)

 Question 33 Unsaved
 

A __________ is a named job function within the organization that controls this computer system.

 

Save

 

Question 34 (6 points)

 Question 34 Unsaved
 

Can a user cleared for <secret; {dog, cat, pig}> have access to documents classified in each of the following ways under the military security model? (6 points)

Yes/No

  1. <top secret; dog>             _________________
  2. <secret; {dog}>                 __________________
  3. <secret; {dog, cow}>        __________________
  4. <secret; {moose}>                           _________________
  5. <confidential; {dog, cat, pig}>      _________
  6. <confidential; {moose}> __________________
 
Spell check

Save

 

    • 10 years ago
    • 20
    Answer(1)

    Purchase the answer to view it

    blurred-text
    • attachment
      algorithms.docx