CHAPTERS 1 - 4 1 / 4
TEST BANK QUESTIONS
Business Data Networks and Security, 11e (Panko)
Appendix: Managing the Security Process
1) The Target attackers probably first broke into Target using the credentials of a(n) .
- low-level Target employee
- Target IT employee
- Target security employee
- employee in a firm outside Target
Answer: D
Difficulty: Basic
Question: 1a
Objective: Discuss failures to stop the target breach.
AACSB: Applying Information Technology
2) Target received warnings during the attack. This happened .
- on the vendor server
- when the POS download server was compromised
- when the exfiltration server was compromised
- none of the above
Answer: C
Difficulty: Deeper
Question: 1e
Objective: Discuss failures to stop the target breach.
AACSB: Applying Information Technology
3) In a kill chain, .
- stopping the attack at a single step stops the attack
- stopping the attack at multiple steps stops the attack
- stopping the attack at all steps stops the attack
- none of the above
Answer: A
Difficulty: Basic 2 / 4
Question: 1f
Objective: Discuss failures to stop the target breach.
AACSB: Applying Information Technology, Analytical Thinking, Application of Knowledge 4) Security is primarily about .
- technology
- planning
- management
- none of the above
Answer: C
Difficulty: Deeper
Question: 1hh
Objective: Explain why security is about management more than technology.
AACSB: Applying Information Technology, Application of Knowledge
5) Firewall operation takes place during the phase.
- plan
- protect
- response
- none of the above
Answer: B
Difficulty: Basic
Question: 2a
Objective: Explain the Plan-Protect-Respond cycle.
AACSB: Applying Information Technology, Application of Knowledge
6) Which phase of the plan-protect-respond cycle takes the largest amount of work?
- plan
- protect
- respond
- The phases require about equal amounts of effort.
Answer: B
Difficulty: Deeper
Question: 2b
Objective: Explain the Plan-Protect-Respond cycle.
AACSB: Applying Information Technology, Analytical Thinking, Application of Knowledge 7) The goal of security is to eliminate risk.
Answer: FALSE
Difficulty: Basic
Question: 3a
Objective: Describe and apply major security planning principles.
AACSB: Applying Information Technology, Application of Knowledge 3 / 4
8) Balancing threats against protection costs is called .
- economic justification
- risk analysis
- comprehensive security
- The Illusion of Cost
Answer: B
Difficulty: Basic
Question: 3b
Objective: Describe and apply major security planning principles.
AACSB: Applying Information Technology
- / 4