0% found this document useful (0 votes)
7 views18 pages

Confidentiality Controls in Accounting Systems

Chapter 9 of 'Accounting Information Systems' discusses the controls necessary to protect the confidentiality and privacy of organizational information. It outlines key actions such as identifying and classifying sensitive information, implementing encryption, controlling access, and training employees. Additionally, it highlights the importance of adhering to the Generally Accepted Privacy Principles (GAPP) for safeguarding personal information collected from customers and employees.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views18 pages

Confidentiality Controls in Accounting Systems

Chapter 9 of 'Accounting Information Systems' discusses the controls necessary to protect the confidentiality and privacy of organizational information. It outlines key actions such as identifying and classifying sensitive information, implementing encryption, controlling access, and training employees. Additionally, it highlights the importance of adhering to the Generally Accepted Privacy Principles (GAPP) for safeguarding personal information collected from customers and employees.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Accounting Information Systems, 14e (Romney/Steinbart)

Chapter 9 Confidentiality and Privacy Controls

1 Describe the controls that can be used to protect the confidentiality of an organization’s
information.

1) Identify the type of information below that is least likely to be considered confidential by an
organization.
A) Audited financial statements.
B) Legal documents.
C) Top executives' salaries.
D) New product development plans.
Answer: A
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Easy
AACSB: Analytical Thinking

2) Which of the following is not one of the basic actions that an organization must take to
preserve the confidentiality of sensitive information?
A) Identification of information to be protected.
B) Backing up the information.
C) Controlling access to the information.
D) Training.
Answer: B
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

3) Classification of confidential information is the responsibility of whom, according to


COBIT5?
A) External auditor.
B) Information owner.
C) IT security professionals.
D) Management.
Answer: B
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

1
Copyright © 2018 Pearson Education, Inc.
4) Encryption is one of the many ways to protect information in transit over the internet.
Answer: TRUE
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Easy
AACSB: Analytical Thinking

5) Encryption is not a panacea to protecting confidential information.


Answer: TRUE
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Easy
AACSB: Analytical Thinking

6) Encryption is a necessary part of which information security approach?


A) Defense in depth.
B) Time based defense.
C) Continuous monitoring.
D) Synthetic based defense.
Answer: A
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

7) Information rights management software can do all of the following except


A) limiting access to specific files.
B) limit action privileges to a specific time period.
C) authenticate individuals accessing information.
D) specify the actions individuals granted access to information can perform.
Answer: C
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Challenging
AACSB: Analytical Thinking

8) Identify the first step in protecting the confidentiality of intellectual property below.
A) Identifying who has access to the intellectual property.
B) Identifying the means necessary to protect the intellectual property.
C) Identifying the weaknesses surrounding the creation of the intellectual property.
D) Identifying what controls should be placed around the intellectual property.
Answer: A
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

2
Copyright © 2018 Pearson Education, Inc.
9) After the information that needs to be protected has been identified, what step should be
completed next?
A) The information needs to be placed in a secure, central area.
B) The information needs to be encrypted.
C) The information needs to be classified in terms of its value to the organization.
D) The information needs to be depreciated.
Answer: C
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

10) Identify the last step in protecting the confidentiality of intellectual property below.
A) Encrypt the information.
B) Control access to the information.
C) Train employees to properly handle the information.
D) Identify and classify the information to be protected.
Answer: C
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

11) Which type of software blocks outgoing messages containing key words or phrases
associated with an organization's sensitive data?
A) Anti-virus software.
B) Data loss prevention software.
C) A digital watermark.
D) Information rights software.
Answer: B
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

3
Copyright © 2018 Pearson Education, Inc.
12) Which type of software provides an additional layer of protection to sensitive information
that is stored in digital format, offering the capability not only to limit access to specific files or
documents but also to specify the actions that individuals who are granted access to that resource
can perform?
A) Anti-virus software.
B) Data loss prevention software.
C) A digital watermark.
D) Information rights software.
Answer: D
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

13) The Bear Corporation uses a tool that embeds a code into all of its digital documents. It then
scours the internet, searching for codes that it has embedded into its files. When Bear finds an
embedded code on the internet, it knows that confidential information has been leaked. Bear then
begins identifying how the information was leaked and who was involved with the leak. Bear is
using
A) an information rights management software.
B) a data loss prevention software.
C) a digital watermark.
D) a stop leak software.
Answer: C
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

14) What confidentiality and security risk does using VoIP present to organizations?
A) Internet e-mail communications can be intercepted.
B) Internet photographs can be intercepted.
C) Internet video can be intercepted.
D) Internet voice conversations can be intercepted.
Answer: D
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Analytical Thinking

4
Copyright © 2018 Pearson Education, Inc.
15) Describe the four basic actions that organizations must take to preserve the confidentiality of
sensitive information.
Answer: The four basic actions that must be taken to preserve the confidentiality of sensitive
information are (1) identify and classify the information to be protected, (2) encrypt the
information, (3) control access to the information, and (4) train employees to properly handle the
information.
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Easy
AACSB: Analytical Thinking

16) Discuss the most important control for protecting confidentiality.


Answer: Training is arguably the most important control for protecting confidentiality.
Employees need
to know what information they can share with outsiders and what information needs to be
protected. Employees also need to be taught how to protect confidential data. With proper
training, employees can play an important role in protecting the confidentiality of an
organization's information and enhance the effectiveness of related controls.
Concept: Preserving confidentiality
Objective: Learning Objective 1
Difficulty: Moderate
AACSB: Reflective Thinking

2 Explain the controls that organizations can use to protect the privacy of personal information
they collect from customers, suppliers, and employees, and discuss how the Generally Accepted
Privacy Principles (GAPP) framework provides guidance in developing a comprehensive
approach to protecting privacy.

1) Which of the following is not one of the 10 internationally recognized best practices for
protecting the privacy of customers' personal information?
A) Provide free credit report monitoring for customers.
B) Inform customers of the option to opt-out of data collection and use of their personal
information.
C) Allow customers' browsers to decline to accept cookies.
D) Utilize controls to prevent unauthorized access to, and disclosure of, customers' information.
Answer: A
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

5
Copyright © 2018 Pearson Education, Inc.
2) A client approached Paxton Uffe and said, "Paxton, I need for my customers to make
payments online using credit cards, but I want to make sure that the credit card data isn't
intercepted. What do you suggest?" Paxton responded, "The most effective solution is to
implement
A) a data masking program."
B) a virtual private network."
C) a private cloud environment."
D) an encryption system with digital signatures."
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

3) Describe some steps you can take to minimize your risk of identity theft.
Answer: Shred documents containing personal information. Never send personally identifying
information in unencrypted e-mail. Beware of e-mail/phone/print requests to verify personal
information that the requesting party should already possess. Do not carry your social security
card with you. Print only your initials and last name on checks. Limit the amount of other
information preprinted on checks. Do not use your mailbox for outgoing mail. Do not carry more
than a few blank checks with you. Use special software to digitally clean any digital media prior
to disposal. Monitor your credit cards regularly. File a police report as soon as you discover a
purse or wallet missing. Make photocopies of your driver's license, passport and credit cards and
keep them in a safe location. Immediately cancel any stolen or lost credit cards.
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

4) The first steps in protecting the privacy of personal information is to identify


A) what sensitive information is possessed by the organization.
B) where sensitive information is stored.
C) who has access to sensitive information.
D) All of the above are first steps in protecting privacy.
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Easy
AACSB: Analytical Thinking

5) It is impossible to encrypt information transmitted over the Internet.


Answer: FALSE
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

6
Copyright © 2018 Pearson Education, Inc.
6) Data masking is also referred to as
A) encryption.
B) tokenization.
C) captcha.
D) cookies.
Answer: B
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Challenging
AACSB: Analytical Thinking

7) Abbie Johnson is a programmer at Healtheast network. Abbie has recently developed a new
computer program for Healtheast. As part of the testing process, Abbie needs to use realistic
patients data to ensure that the system is working properly. To protect privacy, management at
Healtheast uses a program that replaces private patient information with fake values before
sending the data to Abbie for testing. The program that replaces patient information with fake
values is called
A) data encryptioning.
B) data masking.
C) data wiping.
D) data redacting.
Answer: B
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

8) Cindy Vindoolo logged on to her e-mail account to find that she had received 50 e-mails from
a company called LifeCo that promised her extreme weight loss if she bought their diet pills.
Cindy angrily deleted all 50 e-mails, realizing she was a victim of
A) telemarketing.
B) spam.
C) direct mail.
D) MLM.
Answer: B
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Easy
AACSB: Analytical Thinking

7
Copyright © 2018 Pearson Education, Inc.
9) Under CAN-SPAM legislation, an organization that receives an opt-out request from an
individual has ________ days to implement steps to ensure they do not send out any additional
unsolicited e-mail to the individual again.
A) 2
B) 5
C) 7
D) 10
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Easy
AACSB: Analytical Thinking

10) Identify the item below that is not a step you could take to prevent yourself from becoming a
victim of identity theft.
A) Shred all documents that contain your personal information.
B) Only print your initial and last name on your personal checks.
C) Monitor your credit reports regularly.
D) Refuse to disclose your social security number to anyone or any organization.
Answer: D
Concept: Protecting information resources
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

11) Identify the item below which is not a piece of legislation passed to protect individuals
against identity theft or to secure individuals' privacy.
A) The Health Insurance Portability and Accountability Act (HIPAA).
B) The Health Information Technology for Economic and Clinical Health Act (HITECH).
C) The Gramm––Leach––Bliley Act.
D) The Dodd-Frank Act.
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

8
Copyright © 2018 Pearson Education, Inc.
12) If an organization asks you to disclose your social security number, yet fails to permit you to
opt-out before you provide the information, the organization has likely violated which of the
Generally Accepted Privacy Principles?
A) Management.
B) Notice.
C) Choice and consent.
D) Use and retention.
Answer: C
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

13) If an organization asks you to disclose your social security number, but fails to establish a set
of procedures and policies for protecting your privacy, the organization has likely violated which
of the Generally Accepted Privacy Principles?
A) Management.
B) Notice.
C) Choice and consent.
D) Use and retention.
Answer: A
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

14) If an organization asks you to disclose your social security number, but fails to tell you about
its privacy policies and practices, the organization has likely violated which of the Generally
Accepted Privacy Principles?
A) Management.
B) Notice.
C) Choice and consent.
D) Use and retention.
Answer: B
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

9
Copyright © 2018 Pearson Education, Inc.
15) If an organization asks you to disclose your social security number, yet fails to properly
dispose of your private information once it has fulfilled its purpose, the organization has likely
violated which of the Generally Accepted Privacy Principles?
A) Management.
B) Notice.
C) Choice and consent.
D) Use and retention.
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

16) If an organization asks you to disclose your social security number, but decides to use it for a
different purpose than the one stated in the organization's privacy policies, the organization has
likely violated which of the Generally Accepted Privacy Principles?
A) Collection.
B) Access.
C) Security.
D) Quality.
Answer: A
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

17) If an organization asks you to disclose your date of birth and your address, but refuses to let
you review or correct the information you provided, the organization has likely violated which of
the Generally Accepted Privacy Principles?
A) Collection.
B) Access.
C) Security.
D) Choice and consent.
Answer: B
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

10
Copyright © 2018 Pearson Education, Inc.
18) If an organization asks you to disclose your date of birth and your address, but fails to take
any steps to protect your private information, the organization has likely violated which of the
Generally Accepted Privacy Principles?
A) Collection.
B) Access.
C) Security.
D) Quality.
Answer: C
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

19) If an organization asks you to disclose your date of birth and your address, but fails to
establish any procedures for responding to customer complaints, the organization has likely
violated which of the Generally Accepted Privacy Principles?
A) Collection.
B) Access.
C) Security.
D) Monitoring and enforcement.
Answer: D
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Reflective Thinking

20) Discuss to the key CAN-SPAM's guidelines on commercial e-mail that has the primary
purpose of advertising.
Answer: The key guidelines include: (1) The sender's identity must be clearly displayed in the
header of the message. (2) The subject field in the header must clearly identify the message as an
advertisement or solicitation. (3) The body of the message must provide recipients with a
working link that can be used to opt out of future e-mail. (4) The body of the message must
include the sender's valid postal address. (5) Organizations should not send commercial e-mail to
randomly generated addresses, nor should they set up websites designed to "harvest" e-mail
addresses of potential customers.
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

21) CAN-SPAM applies to both commercial and personal e-mail.


Answer: FALSE
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

11
Copyright © 2018 Pearson Education, Inc.
22) CAN-SPAM provides both criminal and civil penalties for violations of the law.
Answer: TRUE
Concept: Protecting the privacy of information
Objective: Learning Objective 2
Difficulty: Moderate
AACSB: Analytical Thinking

3 Discuss how different types of encryption systems work, and explain how digital signatures
provide the means for creating legally-enforceable contracts.

1) Which of the following is not true regarding virtual private networks (VPN)?
A) VPNs provide the functionality of a privately owned network using the Internet.
B) Using VPN software to encrypt information while it is in transit over the Internet in effect
creates private communication channels, often referred to as tunnels, which are accessible only
to those parties possessing the appropriate encryption and decryption keys.
C) It is more expensive to reconfigure VPNs to include new sites than it is to add or remove the
corresponding physical connections in a privately owned network.
D) The cost of the VPN software is much less than the cost of leasing or buying the
infrastructure (telephone lines, satellite links, communications equipment, etc.) needed to create
a privately owned secure communications network.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

2) All of the following are associated with asymmetric encryption except


A) speed.
B) private keys.
C) public keys.
D) no need for key exchange.
Answer: A
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

12
Copyright © 2018 Pearson Education, Inc.
3) The system and processes used to issue and manage asymmetric keys and digital certificates
are known as
A) asymmetric encryption.
B) certificate authority.
C) digital signature.
D) public key infrastructure.
Answer: D
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

4) Text that was transformed into unreadable gibberish using encryption is called
A) plaintext.
B) ciphertext.
C) encryption text.
D) private text.
Answer: B
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

5) Identify one weakness of encryption below.


A) Encrypted packets cannot be examined by a firewall.
B) Encryption provides for both authentication and non-repudiation.
C) Encryption protects the privacy of information during transmission.
D) Encryption protects the confidentiality of information while in storage.
Answer: A
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

6) Using a combination of symmetric and asymmetric key encryption, Sofia sent a report to her
home office in Indiana. She received an e-mail acknowledgement that her report had been
received, but a few minutes later she received a second e-mail that contained a different hash
total than the one associated with her report. This most likely explanation for this result is that
A) the public key had been compromised.
B) the private key had been compromised.
C) the symmetric encryption key had been compromised.
D) the asymmetric encryption key had been compromised.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Challenging
AACSB: Reflective Thinking

13
Copyright © 2018 Pearson Education, Inc.
7) Encryption has a remarkably long and varied history. The invention of writing was apparently
soon followed by a desire to conceal messages. One of the methods, was the simple substitution
of numbers for letters, for example A = 1, B = 2, etc. This is an example of
A) a hashing algorithm.
B) symmetric key encryption.
C) asymmetric key encryption.
D) a public key.
Answer: B
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

8) An electronic document that certifies the identity of the owner of a particular public key.
A) Asymmetric encryption.
B) Digital certificate.
C) Digital signature.
D) Public key.
Answer: B
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

9) Which systems use the same key to encrypt communications and to decrypt communications?
A) Asymmetric encryption.
B) Symmetric encryption.
C) Hashing encryption.
D) Public key encryption
Answer: B
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

10) The creation of a digital signature is a two-step process.


Answer: TRUE
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

14
Copyright © 2018 Pearson Education, Inc.
11) ________ are used to create digital signatures.
A) Asymmetric encryption and hashing
B) Hashing and packet filtering
C) Packet filtering and encryption
D) Symmetric encryption and hashing
Answer: A
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

12) Information encrypted with the creator's private key that is used to authenticate the sender is
called
A) asymmetric encryption.
B) digital certificate.
C) digital signature.
D) public key.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

13) Which of the following is not one of the three important factors determining the strength of
any encryption system?
A) Key length.
B) Policies for managing cryptographic keys.
C) Encryption algorithm.
D) Storage of digital signatures.
Answer: D
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

14) A process that takes plaintext of any length and transforms it into a short code is called
A) asymmetric encryption.
B) encryption.
C) hashing.
D) symmetric encryption.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

15
Copyright © 2018 Pearson Education, Inc.
15) Which of the following descriptions is not associated with symmetric encryption?
A) A shared secret key.
B) Faster encryption.
C) Lack of authentication.
D) Separate keys for each communication party.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

16) Encryption has a remarkably long and varied history. Spies have been using it to convey
secret messages ever since there were secret messages to convey. One powerful method of
encryption uses random digits. Two documents are prepared with the same random sequence of
numbers. The spy is sent out with one and the spy master retains the other. The digits are used as
follows. Suppose that the word to be encrypted is SPY and the random digits are 352. Then S
becomes V (three letters after S), P becomes U (five letters after P), and Y becomes A (two letters
after Y, restarting at A after Z). The spy would encrypt a message and then destroy the document
used to encrypt it. This is an early example of
A) a hashing algorithm.
B) asymmetric key encryption.
C) symmetric key encryption.
D) public key encryption.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Reflective Thinking

17) One way to circumvent the counterfeiting of public keys is by using


A) a digital certificate.
B) digital authority.
C) encryption.
D) cryptography.
Answer: A
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

16
Copyright © 2018 Pearson Education, Inc.
18) In a private key system the sender and the receiver have ________, and in the public key
system they have ________.
A) different keys; the same key
B) a decrypting algorithm; an encrypting algorithm
C) the same key; two separate keys
D) an encrypting algorithm; a decrypting algorithm
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

19) Asymmetric key encryption combined with the information provided by a certificate
authority allows unique identification of
A) the user of encrypted data.
B) the provider of encrypted data.
C) both the user and the provider of encrypted data.
D) either the user or the provider of encrypted data.
Answer: D
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

20) A laptop computer belonging to the Novak group was stolen from the trunk of a sales
manager's car while she was attending a conference. After reporting the theft, the manager
considered the implications for the company's network security and concluded there was little to
worry about because
A) the computer was insured against theft.
B) the computer was protected by a password.
C) the data stored on the computer was encrypted.
D) it was unlikely that the thief would know how to access the company data stored on the
computer.
Answer: C
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Easy
AACSB: Analytical Thinking

17
Copyright © 2018 Pearson Education, Inc.
21) You are assisting a manager from your company's headquarters in New York. The manager
needs to interact online in real time with one of your company's affiliate overseas. The manager
wants to make sure that her communications with the overseas affiliate won't be intercepted.
What should you suggest to the manager?
A) A virtual private network connection.
B) A multifactor authentication network connection.
C) A private cloud network connection.
D) An asymmetric encryption system with digital signatures connection.
Answer: A
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

22) Describe symmetric encryption and identify three limitations.


Answer: Symmetric encryption systems use the same key to encrypt and decrypt data.
Symmetric encryption is much faster than asymmetric encryption, but the sender and receiver
need to know the shared secret key, which requires a different secure method of exchanging the
key. Also, different secret keys must be used with each different communication party. Finally,
there is no way to prove who created a specific document.
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Analytical Thinking

23) Compare the advantages and disadvantage of symmetric and asymmetric encryption.
Answer: The advantage of symmetric encryption is much faster speed. The disadvantages are
the requirement of a separate key for everyone who wishes to communicate and the need to find
a secure way to share the secret key with the other party. The advantages of asymmetric
encryption include (a) everyone can use your public key to communicate with you, (b) no need
to store keys for each party with whom you wish to communicate, and (c) can be used to create
legally binding digital signatures. The disadvantages are slower speed and the need to have a
public key infrastructure (PKI) to validate ownership of public keys.
Concept: Encryption
Objective: Learning Objective 3
Difficulty: Moderate
AACSB: Reflective Thinking

18
Copyright © 2018 Pearson Education, Inc.

You might also like