exam
INFA 660-9040 Fall 2020
FINAL EXAM
EXAM INSTRUCTIONS
• This final exam is worth 30% of your final grade.
• The exam is due at midnight or 11:59PM (Eastern) Tuesday, November 10, 2020.
• This is an open-book individual examination. The questions may require research beyond the OERs, lecture notes, and conferences. Each answer must include at least one citation of an authoritative source. A single Reference List should be included at the end of the exam.
• There are six (6) questions. Choose 5 to answer. Each response is worth 20 points. Each response is limited to 300 words. Points may be deducted for exceeding the word limit. The following criteria will be used for grading: relevance and correctness, completeness, clarity and logical flow, spelling, grammar, and proper citations/Reference List.
• Be sure to “sign” and include the Certification statement.
• If you have a question about the exam, contact me by email ([email protected]).
EXAM QUESTIONS:
1. Bring Your Own Device (BYOD) and Acceptable Use
BYOD means that devices employees own are being used for work. Discuss how an
organization can/should manage the use of personal devices. What are the most important
restrictions the organization can impose? Why are these limits important? How can they be
established and enforced?
2. The Privacy Act and Data Brokers
The Privacy Act controls the federal government protection of certain data in its systems of
records. Explain how or if that Act applies to data the government accesses from
commercial data brokers. Are there any restrictions on government use of commercial data
broker data?
3. Ransomware and Data Integrity
Government agencies are warning hospitals and health care providers of the imminent
cybercrime threat of ransomware. Ransomware attacks present challenges to data
integrity. What key actions could/should an organization do before ransomware attacks?
Why?
4. Encryption and Law Enforcement
Explain the conflict between law enforcement and end-to-end encryption. What is the
current status?
5. Computer Fraud and Abuse Act (CFAA)
This key cybersecurity law makes it a federal crime to intentionally access a computer
without authorization or exceeding authorized access. Explain the issue(s) presented by
the CFAA term, “authorization,” using an example(s), and how it could be
improved/corrected.
6. Section 230 of the Communications Decency Act
What was the purpose of this section when enacted? What is the main issue now? Please
explain.
Be sure to include the certification statement:
"This paper or presentation is my own work. Any assistance I received in its preparation is acknowledged within the paper or presentation, in accordance with academic practice. If I used data, ideas, words, diagrams, pictures, or other information from any source, I have cited the sources fully and completely in footnotes and bibliography entries. This includes sources which I have quoted or paraphrased. Furthermore, I certify that this paper or presentation was prepared by me specifically for this class and has not been submitted, in whole or in part, to any other class in this University or elsewhere, or used for any purpose other than satisfying the requirements of this class, except that I am allowed to submit the paper or presentation to a professional publication, peer reviewed journal, or professional conference. In adding my name following the word 'Signature', I intend that this certification will have the same authority and authenticity as a document executed with my hand-written signature.
Signature __________________________________________________________________________