0% found this document useful (0 votes)
170 views14 pages

Internet Security Misconceptions Quiz

This document contains a multiple choice test bank with questions about information security concepts from MIS Chapter 8. There are 42 questions in total that cover topics like mobile malware, hacking techniques like spoofing and sniffing, security challenges in client-server environments, types of malware like viruses and worms, cyber attacks like DDoS and phishing, and computer crime. The questions test knowledge of key terms, technologies, threats, and attacks related to information security.

Uploaded by

IAMVIBE
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
170 views14 pages

Internet Security Misconceptions Quiz

This document contains a multiple choice test bank with questions about information security concepts from MIS Chapter 8. There are 42 questions in total that cover topics like mobile malware, hacking techniques like spoofing and sniffing, security challenges in client-server environments, types of malware like viruses and worms, cyber attacks like DDoS and phishing, and computer crime. The questions test knowledge of key terms, technologies, threats, and attacks related to information security.

Uploaded by

IAMVIBE
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • MIS Chapter 8 Test Bank

MIS Chapter 8 Test Bank

Study online at [Link]

1. 1) Smartphones have the same security flaws as other TRUE


Internet-connected devices.

2. 2) In 2013, the security firm McAfee identified approx- TRUE


imately 35,000 kinds of mobile malware.

3. 3) Viruses can be spread through e-mail. TRUE

4. 4) The term cracker is used to identify a hacker whose FALSE


specialty is breaking open security systems.

5. 5) To secure mobile devices, a company will need to TRUE


implement special mobile device management soft-
ware.

6. 6) Wireless networks are vulnerable to penetration TRUE


because radio frequency bands are easy to scan.

7. 7) Computer worms spread much more rapidly than TRUE


computer viruses.

8. 8) One form of spoofing involves forging the return ad- TRUE


dress on an e-mail so that the e-mail message appears
to come from someone other than the sender.

9. 9) Sniffers enable hackers to steal proprietary infor- TRUE


mation from anywhere on a network, including e-mail
messages, company files, and confidential reports.

10. 10) DoS attacks are used to destroy information and FALSE
access restricted areas of a company's information
system.

11. 11) The distributed nature of cloud computing makes FALSE


it somewhat easier to track unauthorized access.

12. 12) Zero defects cannot be achieved in larger software TRUE


programs because fully testing programs that contain
thousands of choices and millions of paths would
require thousands of years.
1 / 14
MIS Chapter 8 Test Bank
Study online at [Link]

13. 13) An acceptable use policy defines the acceptable FALSE


level of access to information assets for different
users.

14. 14) Biometric authentication is the use of physical TRUE


characteristics such as retinal images to provide iden-
tification.

15. 15) Packet filtering catches most types of network FALSE


attacks.

16. 16) NAT conceals the IP addresses of the organiza- TRUE


tion's internal host computers
to deter sniffer programs.

17. 17) SSL is a protocol used to establish a secure con- TRUE


nection between two computers.

18. 18) Public key encryption uses two keys. TRUE

19. 19) Over 70 percent of malware today is aimed at small FALSE


businesses.

20. 20) Smartphones typically feature state-of-the-art en- FALSE


cryption and security features, making them highly
secure tools for businesses.

21. 21) ________ refers to policies, procedures, and tech- A


nical measures used to prevent unauthorized access,
alteration, theft, or physical damage to information
systems.
A) "Security"
B) "Controls"
C) "Benchmarking"
D) "Algorithms"

22. 22) ________ refers to all of the methods, policies, and D


organizational procedures that ensure the safety of
the organization's assets, the accuracy and reliability
2 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
of its accounting records, and operational adherence
to management standards.
A) "Legacy systems"
B) "SSID standards"
C) "Vulnerabilities"
D) "Controls"

23. 23) Large amounts of data stored in electronic form C


are ________ than the same data in manual form.
A) less vulnerable to damage
B) more secure
C) vulnerable to many more kinds of threats
D) more critical to most businesses

24. 24) Electronic data are more susceptible to destruc- C


tion, fraud, error, and misuse because information
systems concentrate data in computer files that:
A) are easily decrypted.
B) can be opened with easily available software.
C) may be accessible by anyone who has access to
the same network.
D) are unprotected by up-to-date security systems.

25. 25) Specific security challenges that threaten the A


communications lines in a client/server environment
include:
A) tapping; sniffing; message alteration; radiation.
B) hacking; vandalism; denial of service attacks.
C) theft, copying, alteration of data; hardware or soft-
ware failure.
D) unauthorized access; errors; spyware.

26. 26) Specific security challenges that threaten clients D


in a client/server environment include:
A) tapping; sniffing; message alteration; radiation.
B) hacking; vandalism; denial of service attacks.
C) theft, copying, alteration of data; hardware or soft-
ware failure.
D) unauthorized access; errors; spyware.

3 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
27. 27) Specific security challenges that threaten corpo- B
rate servers in a client/server environment include:
A) tapping; sniffing; message alteration; radiation.
B) hacking; vandalism; denial of service attacks.
C) theft, copying, alteration of data; hardware or soft-
ware failure.
D) unauthorized access; errors; spyware.

28. 28) The Internet poses specific security problems be- A


cause:
A) it was designed to be easily accessible.
B) Internet data is not run over secure lines.
C) Internet standards are universal.
D) it changes so rapidly.

29. 29) Which of the following statements about the Inter- C


net security is not true?
A) The use of P2P networks can expose a corporate
computer to outsiders.
B) A corporate network without access to the Internet
is more secure than one that provides access.
C) VoIP is more secure than the switched voice net-
work.
D) Instant messaging can provide hackers access to
an otherwise secure network.

30. 30) An independent computer program that copies A


itself from one computer to another over a network is
called a:
A) worm.
B) Trojan horse.
C) bug.
D) pest.

31. 31) A salesperson clicks repeatedly on the online ads D


of a competitor's in order to drive the competitor's
advertising costs up. This is an example of:
A) phishing.
B) pharming.

4 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
C) spoofing.
D) click fraud.

32. 32) In 2004, ICQ users were enticed by a sales mes- A


sage from a supposed anti-virus vendor. On the ven-
dor's site, a small program called Mitglieder was
downloaded to the user's machine. The program en-
abled outsiders to infiltrate the user's machine. What
type of malware is this an example of?
A) Trojan horse
B) Virus
C) Worm
D) Spyware

33. 33) Redirecting a Web link to a different address is a B


form of:
A) snooping.
B) spoofing.
C) sniffing.
D) war driving.

34. 34) A keylogger is a type of: D


A) worm.
B) Trojan horse.
C) virus.
D) spyware.

35. 35) Hackers create a botnet by: C


A) infecting Web search bots with malware.
B) using Web search bots to infect other computers.
C) causing other people's computers to become
"zombie" PCs following a master computer.
D) infecting corporate servers with "zombie" Trojan
horses that allow undetected access through a back
door.

36. 36) Using numerous computers to inundate and over- A


whelm the network from numerous launch points is
called a(n) ________ attack.
A) DDoS
5 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
B) DoS
C) SQL injection
D) phishing

37. 37) Which of the following is not an example of a C


computer used as a target of crime?
A) Knowingly accessing a protected computer to com-
mit fraud
B) Accessing a computer system without authority
C) Illegally accessing stored electronic communica-
tion
D) Threatening to cause damage to a protected com-
puter

38. 38) Which of the following is not an example of a D


computer used as an instrument of crime?
A) Theft of trade secrets
B) Intentionally attempting to intercept electronic
communication
C) Unauthorized copying of software
D) Breaching the confidentiality of protected comput-
erized data

39. 39) Phishing is a form of: A


A) spoofing.
B) logging.
C) sniffing.
D) driving.

40. 40) An example of phishing is: B


A) setting up a bogus Wi-Fi hot spot.
B) setting up a fake medical Web site that asks users
for confidential information.
C) pretending to be a utility company's employee in
order to garner information from that company about
their security system.
D) sending bulk e-mail that asks for financial aid under
a false pretext.

41. D
6 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
41) Evil twins are:
A) Trojan horses that appears to the user to be a
legitimate commercial software application.
B) e-mail messages that mimic the e-mail messages
of a legitimate business.
C) fraudulent Web sites that mimic a legitimate busi-
ness's Web site.
D) bogus wireless network access points that look
legitimate to users.

42. 42) Pharming involves: A


A) redirecting users to a fraudulent Web site even
when the user has typed in the correct address in the
Web browser.
B) pretending to be a legitimate business's represen-
tative in order to garner information about a security
system.
C) setting up fake Web sites to ask users for confiden-
tial information.
D) using e-mails for threats or harassment.

43. 43) You have been hired as a security consultant for a B


law firm. Which of the following constitutes the great-
est source of security threats to the firm?
A) Wireless network
B) Employees
C) Authentication procedures
D) Lack of data encryption

44. 44) Tricking employees to reveal their passwords by B


pretending to be a legitimate member of a company is
called:
A) sniffing.
B) social engineering.
C) phishing.
D) pharming.

45. 45) How do software vendors correct flaws in their B


software after it has been distributed?
A) They issue bug fixes.
7 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
B) They issue patches.
C) They re-release the software.
D) They release updated versions of the software.

46. 46) The HIPAA Act of 1996: D


A) requires financial institutions to ensure the securi-
ty of customer data.
B) specifies best practices in information systems
security and control.
C) imposes responsibility on companies and manage-
ment to safeguard the accuracy of financial informa-
tion.
D) outlines medical security and privacy rules.

47. 47) The Gramm-Leach-Bliley Act: A


A) requires financial institutions to ensure the securi-
ty of customer data.
B) specifies best practices in information systems
security and control.
C) imposes responsibility on companies and manage-
ment to safeguard the accuracy of financial informa-
tion.
D) outlines medical security and privacy rules.

48. 48) The Sarbanes-Oxley Act: C


A) requires financial institutions to ensure the securi-
ty of customer data.
B) specifies best practices in information systems
security and control.
C) imposes responsibility on companies and manage-
ment to safeguard the accuracy of financial informa-
tion.
D) outlines medical security and privacy rules.

49. 49) The most common type of electronic evidence is: D


A) voice-mail.
B) spreadsheets.
C) instant messages.
D) e-mail.

8 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
50. 50) Your company, an online clothing store, has cal- A
culated that a loss of Internet connectivity for 5 hours
results in a potential loss of $1,000 to $2,000 and that
there is a 50% chance of this occurring. What is the
annual expected loss from this exposure?
A) $750
B) $1,000
C) $1,500
D) $3,000

51. 51) Application controls: A


A) can be classified as input controls, processing
controls, and output controls.
B) govern the design, security, and use of computer
programs and the security of data files in general
throughout the organization.
C) apply to all computerized applications and consist
of a combination of hardware, software, and manu-
al procedures that create an overall control environ-
ment.
D) include software controls, computer operations
controls, and implementation controls.

52. 52) ________ controls ensure that valuable business C


data files on either disk or tape are not subject to
unauthorized access, change, or destruction while
they are in use or in storage.
A) Software
B) Administrative
C) Data security
D) Implementation

53. 53) Analysis of an information system that rates the C


likelihood of a security incident occurring and its cost
is included in a(n):
A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.

9 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
54. 54) Statements ranking information risks and identify- A
ing security goals are included in a(n):
A) security policy.
B) AUP.
C) risk assessment.
D) business impact analysis.

55. 55) Which of the following specifications replaces D


WEP with a stronger security standard that features
changing encryption keys?
A) TLS
B) AUP
C) VPN
D) WPA2

56. 56) Rigorous password systems: B


A) are one of the most effective security tools.
B) may hinder employee productivity.
C) are costly to implement.
D) are often disregarded by employees.

57. 57) An authentication token is a(n): C


A) device the size of a credit card that contains access
permission data.
B) type of smart card.
C) gadget that displays passcodes.
D) electronic marker attached to a digital authoriza-
tion file.

58. 58) Biometric authentication: C


A) is inexpensive.
B) is used widely in Europe for security applications.
C) can use a person's voice as a unique, measurable
trait.
D) only uses physical measurements for identifica-
tion.

59. 59) A firewall allows the organization to: A


A) enforce a security policy on data exchanged be-
tween its network and the Internet.
10 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
B) check the accuracy of all transactions between its
network and the Internet.
C) create an enterprise system on the Internet.
D) check the content of all incoming and outgoing
e-mail messages.

60. 60) Which of the following is a type of ambient data? B


A) Computer log containing recent system errors
B) A file deleted from a hard disk
C) A file that contains an application's user settings
D) A set of raw data from an environmental sensor

61. 61) ________ use scanning software to look for known B


problems such as bad passwords, the removal of im-
portant files, security attacks in progress, and system
administration errors.
A) Stateful inspections
B) Intrusion detection systems
C) Application proxy filtering technologies
D) Packet filtering technologies

62. 62) Currently, the protocols used for secure informa- D


tion transfer over the Internet are:
A) TCP/IP and SSL.
B) S-HTTP and CA.
C) HTTP and TCP/IP.
D) SSL, TLS, and S-HTTP.

63. 63) Most antivirus software is effective against: D


A) only those viruses active on the Internet and
through e-mail.
B) any virus.
C) any virus except those in wireless communications
applications.
D) only those viruses already known when the soft-
ware is written.

64. 64) In which method of encryption is a single en- B


cryption key sent to the receiver so both sender and
receiver share the same key?
11 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
A) SSL
B) Symmetric key encryption
C) Public key encryption
D) Private key encryption

65. 65) A digital certificate system: A


A) uses third-party CAs to validate a user's identity.
B) uses digital signatures to validate a user's identity.
C) uses tokens to validate a user's identity.
D) is used primarily by individuals for personal corre-
spondence.

66. 66) All of the following are types of information sys- A


tems general controls except:
A) application controls.
B) computer applications controls.
C) physical hardware controls.
D) administrative controls.

67. 67) For 100 percent availability, online transaction pro- C


cessing requires:
A) high-capacity storage.
B) a multi-tier server network.
C) fault-tolerant computer systems.
D) dedicated phone lines.

68. 68) In controlling network traffic to minimize B


slow-downs, a technology called ________ is used
to examine data files and sort low-priority data from
high-priority data.
A) high availability computing
B) deep-packet inspection
C) application proxy filtering
D) stateful inspection

69. 69) The development and use of methods to make B


computer systems resume their activities more quick-
ly after mishaps is called:
A) high-availability computing.
B) recovery-oriented computing.
12 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
C) fault-tolerant computing.
D) disaster-recovery planning.

70. 70) Smaller firms may outsource some or many secu- C


rity functions to:
A) ISPs.
B) MISs.
C) MSSPs.
D) CAs.

71. 71) A practice in which eavesdroppers drive by build- A


ings or park outside and try to intercept wireless net-
work traffic is referred to as:
A) war driving.
B) sniffing.
C) cybervandalism.
D) driveby tapping.

72. 72) Malicious software programs referred to as spy- FALSE


ware include a variety of threats such as computer
viruses, worms, and Trojan horses.

73. 73) ________ is a crime in which an imposter obtains A


key pieces of personal information to impersonate
someone else.
A) Identity theft
B) Spoofing
C) Social engineering
D) Evil twins

74. 74) Computer forensics tasks include all of the follow- C


ing except:
A) presenting collected evidence in a court of law.
B) securely storing recovered electronic data.
C) collecting physical evidence on the computer.
D) finding significant information in a large volume of
electronic data.

75. 75) ________ identify the access points in a Wi-Fi D


network.
13 / 14
MIS Chapter 8 Test Bank
Study online at [Link]
A) NICs
B) Mac addresses
C) URLs
D) SSIDs

76. 76) A foreign country attempting to access govern- C


ment networks in order to disable a national power
grid would be an example of:
A) phishing.
B) denial-of-service attacks.
C) cyberwarfare.
D) cyberterrorism.

77. 77) Authorization refers to the ability to know that a FALSE


person is who he or she claims to be.

78. 78) Comprehensive security management products, D


with tools for firewalls, VPNs, intrusion detection sys-
tems, and more, are called ________ systems.
A) DPI
B) MSSP
C) NSP
D) UTM

79. 79) A walkthrough is a type of software testing used TRUE


before software is even written.

80. 80) When errors are discovered in software programs, TRUE


the sources of the errors are found and eliminated
through a process called debugging.

14 / 14

Common questions

Powered by AI

Phishing involves tricking individuals into providing personal information by pretending to be a legitimate entity. Pharming redirects users to fraudulent websites even when the correct web address is entered. Spoofing involves deceiving systems or users into accepting a false identity .

To mitigate risks of unauthorized access, organizations should implement rigorous password systems, use authentication tokens, ensure data encryption, and establish comprehensive application controls including input, processing, and output controls to safeguard against unauthorized access .

The primary security challenges threatening communications lines in a client/server environment include tapping, sniffing, message alteration, and radiation . These involve the interception and potential modification of data as it is transferred over the network, posing significant risks to data integrity and confidentiality.

A security policy plays a crucial role by outlining statements that rank information risks, specifying security goals, and providing the framework for how information security is implemented and maintained. It guides the development of specific security measures and enforcement protocols within an organization .

The Sarbanes-Oxley Act impacts information systems security by imposing responsibility on companies and management to safeguard the accuracy of financial information. This involves implementing IT controls to ensure data integrity, consistency, and protection against unauthorized access or disclosure, thereby fostering transparency and accountability .

Hackers create a botnet by causing other people’s computers to become "zombie" PCs, which are then controlled by a master computer. This is often achieved through malware, leading to coordinated attacks like DDoS, which can overwhelm and damage network resources .

Intrusion detection systems enhance network security by using scanning software to detect known problems such as bad passwords, removal of important files, ongoing security attacks, and administration errors. This proactive monitoring helps in identifying and mitigating potential threats before they cause harm .

Electronic data are more vulnerable because they are concentrated in computer files, which may be accessible by anyone with network access. This centralization increases susceptibility to destruction, fraud, error, and misuse compared to manual data forms .

The Internet is inherently insecure because it was designed to be easily accessible . This openness, while beneficial for communication and information sharing, also makes it susceptible to various security threats such as hacking and network intrusions.

Social engineering poses a security threat by manipulating employees into revealing confidential information, such as passwords, by pretending to be a legitimate authority within the organization . This form of attack exploits human psychology, bypassing traditional security safeguards.

You might also like