Chapter 1 - Review Questions

1. What is the difference between a threat agent and a threat?

A threat is a general term used to describe a category of items that present a risk in jeopardizing the safety of an asset. A threat agent is a more specific term used to describe an exact piece of a threat. For example, all kitchen appliances pose a threat to those who use them, while a gas stove is a specific threat agent in this case.

2. What is the difference between vulnerability and exposure?

Vulnerability is a flaw in a system that leaves it open to damage. Exposure occurs when the vulnerability is known, or exposed, to an attacker. A car that is kept unlocked is an example of vulnerability. Exposure occurs when a thief knows that the car is kept unlocked.

3. How is infrastructure protection (assuring the security of utility services) related to information security?

Information security includes the protection of information assets in storage, processing, or transmission. To assure the security of things such as schools, prisons, toads, and power plants, the confidentiality and integrity of information must be protected.

4. What type of security was dominant in the early years of computing?

Physical controls (badges, keys, etc.) were dominant during World War II, because one of the main threats at that time was physical theft of equipment.

5. What are the three components of the CIA triangle? What are they used for?

The three components of the CIA triangle are confidentiality, integrity, and availability of information. These components are used as the industry standard for computer security and they describe the utility of information.

Chapter 1 - Exercises

3. Consider the information stored on your personal computer. For each of the terms listed, find an example and document it: threat, threat agent

Chapter 1-Introduction to Information Security: Principles of Information Security

...Chapter 1-Introduction to Information Security: 1. What is the difference between a threat and a threat agent? A threat is a constant danger to an asset, whereas a threat agent is the facilitator of an attack. 2. What is the difference between vulnerability and exposure? Vulnerability: is a fault within the system, such as software package flaws, unlocked doors or an unprotected system port. It leaves things open to an attack or damage. Exposure: is a single instance when a system is open to damage. Vulnerabilities can in turn be the cause of exposure. 3. How is infrastructure protection (assuring the security of utility services) related to information security? The organization needs to have clear parameters and set regulation when it comes to the protection of itself. Clear goals and objectives when it comes to protection will lead to a better protection on regards to the information security. 4. What type of security was dominant in the early years of computing? Early security was entirely physical security. - EX: Lock and Key 5. What are the 3 components of the CIA triangle and what are they used for? Confidentiality: Information should only be accessible to its intended recipients. Integrity: Information should arrive the same as it was sent. Availability: Information should be available to those authorized to use it. 6. If the CIA triangle is incomplete, why is it so commonly used in security? The CIA triangle is still...

Words: 965 - Pages: 4

Chapter 1 Information Security

... candidate for a job with access to sensitive computer information. Risks, Threats, and Vulnerabilities Commonly Found in the User Domain The User Domain is the weakest link in an IT infrastructure. Anyone responsible for computer security must understand what motivates someone to compromise an organization’s system, applications, or data. Table 1-1 lists the risks and threats commonly found in the User Domain and plans you can use to prevent them. Risks, threats, vulnerabilities, and mitigation plans for the User Domain. Risk, ThReaT, oR VulneRabiliTY | MiTigaTion | Lack of user awareness | Conduct security awareness training, display security awareness posters, insert reminders in banner greetings, and send e-mail reminders to employees. | User apathy toward policies | Conduct annual security awareness training, implement acceptable use policy, update staff manual and handbook, discuss during performance reviews. | Security policy violations | Place employee on probation, review AUP and employee manual, discuss during performance reviews | User inserts CDs and USB drives with personal photos, music, and videos. | Disable internal CD drives and USB ports. Enable automatic antivirus scans for inserted media drives, files, and e-mail attachments. An antivirus scanning system examines all new files on your computer’s hard drive for viruses. Set up antivirus scanning for e-mails with attachments. | User downloads photos, music, and videos. | Enable content...

Words: 12482 - Pages: 50

Principle of Information Security

... that acts as a proxy for a service request” It is more to deal with outgoing connections and making connections within the DMZ zone of an organization. 4. How is static filtering different from dynamic filtering of packets? Which is perceived to offer improved security? Static filtering works with rules that are already designated or “developed and installed with the firewall” and only a person can change it 5. What is stateful inspection? How is state information maintained during a network connection or transaction? Stateful inspection keeps track of each network connection between internal and external system using a state table. A state table track the context and state of each packet in the conversation by recording which station sent the packet and when it was dent . 6. What is a circuit gateway, and how does it differ from the other forms of firewalls? Operates at transport layer. Prevents direct connections between one network and another. It’s the transport. 7. What special function does a cache server perform? Why is this useful for large...

Words: 415 - Pages: 2