You work as a Network Auditor for Net Perfect Inc. The company has a Windows-based network. While auditing the company's network, you are facing problems in searching the faults and other entities that belong to it. Which of the following risks may occur due to the existence of these problems?
A. Residual risk
B. Secondary risk
C. Detection risk
D. Inherent risk
Which of the following is the duration of time and a service level within which a business process must be restored after a disaster in order to avoid unacceptable consequences associated with a break in business continuity?
A. RTO
B. RTA
C. RPO
D. RCO
Which of the following statements best describes the difference between the role of a data owner and the role of a data custodian?
A. The custodian makes the initial information classification assignments, and the operations manager implements the scheme.
B. The data owner implements the information classification scheme after the initial assignment by the custodian.
C. The custodian implements the information classification scheme after the initial assignment by the operations manager.
D. The data custodian implements the information classification scheme after the initial assignment by the data owner.
Which of the following methods offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling?
A. Service-oriented modeling framework (SOMF)
B. Service-oriented architecture (SOA)
C. Sherwood Applied Business Security Architecture (SABSA)
D. Service-oriented modeling and architecture (SOMA)
An attacker exploits actual code of an application and uses a security hole to carry out an attack before the application vendor knows about the vulnerability. Which of the following types of attack is this?
A. Replay
B. Zero-day
C. Man-in-the-middle
D. Denial-of-Service
Which of the following is used by attackers to record everything a person types, including usernames, passwords, and account information?
A. Packet sniffing
B. Keystroke logging
C. Spoofing
D. Wiretapping
Which of the following intrusion detection systems (IDS) monitors network traffic and compares it against an established baseline?
A. File-based
B. Network-based
C. Anomaly-based
D. Signature-based
Which of the following are the responsibilities of the owner with regard to data in an information classification program? Each correct answer represents a complete solution. Choose three.
A. Reviewing the classification assignments at regular time intervals and making changes as the business needs change.
B. Running regular backups and routinely testing the validity of the backup data.
C. Delegating the responsibility of the data protection duties to a custodian.
D. Determining what level of classification the information requires.
What are the various benefits of a software interface according to the "Enhancing the Development Life Cycle to Produce Secure Software" document? Each correct answer represents a complete solution. Choose three.
A. It modifies the implementation of a component without affecting the specifications of the interface.
B. It controls the accessing of a component.
C. It displays the implementation details of a component.
D. It provides a programmatic way of communication between the components that are working with different programming languages.
The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fundamental elements of cloud computing in its "Effectively and Securely Using the Cloud Computing Paradigm" presentation. Which of the following technologies are included in the primary technologies? Each correct answer represents a complete solution. Choose all that apply.
A. Web application framework
B. Free and open source software
C. SOA
D. Virtualization