i55s35Q

profiledav_r_
i553s5q.docx

QUESTION 1

· Blended attacks can occur via any type of Internet or network service, such as e-mail, Web servers or clients, and Windows shares. 



True 
False 





QUESTION 2

· The difficult part of recovery is the identification of data that may have been disclosed. 



True 
False 





QUESTION 3

· Blank 1
is the reestablishment of the pre-incident status of all organizational systems. 







QUESTION 4

· Network IDPSs cannot detect all incidents, especially those attacks that are not network-based.



True 
False 





 

QUESTION 5

· The initial determination of the scope of the breach of confidentiality, integrity, and availability of information and information assets is called the _______
.







QUESTION 6

· _____________
is the process by which the CSIRT acts to limit the scale and scope of an incident as it begins to regain control over the organization’s information assets.

·

·

· 







 

· ____________________
when an individual, an application, or another program, through access to the operating system’s application programming interface (API), attempts to and/or gains access to an information asset without explicit permission or authorization to do so.







QUESTION 8

· A(n) ____________________
attack is much more substantial than a DoS attack, resulting from the use of multiple systems to simultaneously attack a single target. 







QUESTION 9

· A(n)_____________________
attack occurs when an attacker’s action prevents the legitimate users of a system or network from using it – for example, by consuming the resources that a service normally provides.







QUESTION 10

If an attacking host responds to a ping or traceroute, it will most likely provide valid or useful information.





True 
False