What are the three FUNDAMENTAL principles of security?
What is called the formal acceptance of the adequacy of a system's overall security by the management?
Which of the following is not a responsibility of an information (data) owner?
Which property ensures that only the intended recipient can access the data and nobody else?
Which of the following phases of a software development life cycle normally addresses Due Care and Due Diligence?
When it comes to magnetic media sanitization, what difference can be made between clearing and purging information?
What is called a system that is capable of detecting that a fault has occurred and has the ability to correct the fault or operate around it?
Which of the following rules is least likely to support the concept of least privilege?
A security evaluation report and an accreditation statement are produced in which of the following phases of the system development life cycle?
Which of the following would provide the BEST stress testing environment taking under consideration and avoiding possible data exposure and leaks of sensitive data?
Which of the following classes is defined in the TCSEC (Orange Book) as discretionary protection?
An alternative to using passwords for authentication in logical or technical access control is:
Which access control model was proposed for enforcing access control in government and military applications?
In which of the following security models is the subject's clearance compared to the object's classification such that specific rules can be applied to control how the subject-to-object interactions take place?
Which of the following biometric parameters are better suited for authentication use over a long period of time?
When a biometric system is used, which error type deals with the possibility of GRANTING access to impostors who should be REJECTED?
Which of the following would be used to implement Mandatory Access Control (MAC)?
What does the Clark-Wilson security model focus on?
Which of the following Operation Security controls is intended to prevent unauthorized intruders from internally or externally accessing the system, and to lower the amount and impact of unintentional errors that are entering the system?
Which type of password token involves time synchronization?