Name:     ID: 
 
Email: 

COSC 1302 Chap 14 Quiz

True/False
Indicate whether the statement is true or false.
 

 1. 

“Shoulder surfing”occurs when an identity thief simply stands next to someone at a public office, such as the Bureau of Motor Vehicles, and watches as the person fills out personal information on a form.
 

 2. 

Originally, the term cracker was used to describe a person who enjoyed computer technology and spent time learning and using computer systems.
 

 3. 

Worms can create copies on the same computer or can send the copies to other computers via a network.
 

 4. 

Some antivirus software is capable of repairing common virus infections automatically, without interrupting your work.
 

 5. 

Using a password sniffer, a criminal hacker can gain access to computers and networks to steal data and information, invade privacy, plant viruses, and disrupt computer operations.
 

 6. 

Internet-based software piracy occurs when software is legally downloaded from the Internet.
 

 7. 

Intrusion detection systems send an alarm, often by e-mail or pager, to network security personnel when they detect an apparent attack.
 

 8. 

The Sarbanes-Oxley Act is a federal law passed in December 2000 that required federally funded libraries to use some form of prevention measure (such as Internet filters) to block access to obscene material and other material considered harmful to minors.
 

 9. 

A firewall can include both hardware and software that act as a barrier between an organization’s information system and the outside world.
 

 10. 

Federal law prohibits employers from monitoring e-mail sent and received by employees.
 

 11. 

E-mail messages that have been erased from hard disks can be retrieved and used in lawsuits because the laws of discovery demand that companies produce all relevant business documents.
 

 12. 

Instead of forcing users to find and read through the privacy policy for each site they visit, P3P software in a computer’s browser will download the privacy policy from each site, scan it, and notify the user if the policy does not match his or her preferences.
 

 13. 

The Children’s Online Privacy Protection Act (COPPA) was passed by Congress in October 2002.
 

 14. 

A federal law that was passed in 1999 allows unsolicited fax advertisements.
 

 15. 

CTS involves wrist pain, a feeling of tingling and numbness, and difficulty grasping and holding objects.
 

Multiple Choice
Identify the choice that best completes the statement or answers the question.
 

 16. 

The goal of the ____ act is to require healthcare organizations to implement cost-effective procedures for exchanging medical data.
a.
PA74
b.
Gramm-Leach-Bliley Financial Services Modernization
c.
Sarbanes-Oxley
d.
HIPAA
 

 17. 

____ involves the use of one’s social skills to get computer users to provide you with information to access an information system and/or its data.
a.
Dumpster diving
c.
Software piracy
b.
Social engineering
d.
Password sniffing
 

 18. 

Going through the trash cans of an organization to find secret or confidential information, including information needed to access an information system and/or its data, is known as ____.
a.
dumpster diving
c.
software piracy
b.
social engineering
d.
phishing
 

 19. 

____ are employees, disgruntled or otherwise, working solo or in concert with outsiders to compromise corporate systems.
a.
Script bunnies
c.
Insiders
b.
System analysts
d.
Internal auditors
 

 20. 

A ____ is a computer program file capable of attaching to disks or other files and replicating itself repeatedly, typically without the user’s knowledge or permission.
a.
virus
c.
PKI
b.
firewall
d.
biometric
 

 21. 

____ are parasitic computer programs that replicate but, unlike viruses, do not infect other computer program files.
a.
Firewalls
c.
Intrusion detection systems
b.
Worms
d.
Biometrics
 

 22. 

A ____ is a malicious program that disguises itself as a useful application and purposefully does something the user does not expect.
a.
firewall
c.
Trojan horse
b.
intrusion detection system
d.
biometric
 

 23. 

____ is the process of converting an original electronic message into a form that can be understood only by the intended recipients.
a.
Decryption
c.
Intrusion detection
b.
Software piracy
d.
Encryption
 

 24. 

____ enables users of an unsecured public network such as the Internet to securely and privately exchange data through the use of a public and a private cryptographic key pair that is obtained and shared through a trusted authority.
a.
Public key infrastructure
c.
Social engineering
b.
Ergonomics
d.
Biometrics
 

 25. 

____ involves the measurement of one of a person’s traits, whether physical or behavioral.
a.
Public key infrastructure
c.
Social engineering
b.
Ergonomics
d.
Biometrics
 

 26. 

A(n) ____ monitors system and network resources and notifies network security personnel when it senses a possible intrusion.
a.
password sniffer
c.
Trojan horse
b.
intrusion detection system
d.
antivirus software
 

 27. 

____ is the science of designing machines, products, and systems to maximize the safety, comfort, and efficiency of the people who use them.
a.
Biometrics
c.
Ergonomics
b.
PKI
d.
Encryption
 

 28. 

Many organizations implement ____ to measure actual results against established goals, such as percentage of end-user reports produced on time, percentage of data input errors detected, number of input transactions entered per eight-hour shift, and so on.
a.
ergonomics
c.
biometrics
b.
internal audits
d.
external audits
 

 29. 

The ____ Act requires public companies to implement procedures to ensure that their audit committees can document underlying financial data to validate earnings reports.
a.
Sarbanes-Oxley
c.
Gramm-Leach-Bliley
b.
PA74
d.
HIPPA
 

 30. 

____ is charged with coordinating communication among experts during computer security emergencies and helping to prevent future incidents.
a.
DARPA
b.
The World Wide Consortium
c.
CERT
d.
The Software and Information Industry Alliance
 

 31. 

____ employees study Internet security vulnerabilities, handle computer security incidents, publish security alerts, research long-term changes in networked systems, develop information and training to help organizations improve security at their sites, and conduct an ongoing public awareness campaign.
a.
DARPA
c.
CERT
b.
Hewlett Packard
d.
Google
 

 32. 

The specific goals of ____ are to protect children from potentially harmful material, while also safeguarding free speech on the Internet.
a.
CERT
b.
DARPA
c.
the Internet Content Rating Association
d.
the Software and Information Industry Alliance
 



 
         Start Over