Quiz 80 

 
Please note: In order to obtain your CPE certificate for having passed the quiz, you must turn off your pop-up blocker.

Ross Article
Butler Article
Lobb Article
Moody Article
Leiman Article

 

CPE Quiz # 80

Based on Information Systems Control Journal Volume 5, 2001

A passing score of 75 percent qualifies for one (1) hour of CISA/CISM/CGEIT Continuing Professional Education (CPE) Credit

Your results will appear in a new window.

Enter your name below so it displays on the quiz results page:

Name:

Ross Article

1. HIPAA implications on information security architecture include mandated technical security mechanisms to protect patient information. These mechanisms include documented, formal practices to manage the selection and execution of security measures to protect data and to manage the conduct of personnel in relation to the protection of data.
2. HIPAA violations can be punished by both fines and jail for lawbreakers.
3. HIPAA is significant because it is the first US legislation mandating use of digital certificates for authentication of users.

Butler Article

4. UK customs and tax auditors who tested spreadsheets found serious errors with approximately 10 percent of the spreadsheets used for customs tax declarations.
5. A methodology called SpACE has been developed to allow staff with a low level of spreadsheet knowledge to assess whether spreadsheet errors exist within an application being tested.
6. Spreadsheet applications for indirect taxes are particularly high-risk because of the complex calculations involved.

Lobb Article

7. ACL was chosen for testing data integrity at the author's organization. This decision was driven by the small, simple data structure and ACL's capabilities with small datasets.

Moody Article

8. The article considers physical and logical port scanning risks and control mechanisms. Physical port scanning risks are considered more severe than those of software ports.
9. Port scanning is a popular technique used by hackers to discover services which can be broken into from remote computers.
10. Strobe port scanning is an attempt to connect to each of the 65,536 ports on a computer connected to the Internet.
11. Intrusion detection features usually feature active inspection of host-based systems, including password rules and other policy violations.
12. Examples of commonly open, potentially vulnerable ports include Trivial File Transfer Protocol and global file sharing via NetBIOS, Windows NT or UNIX services.

Leiman Article

13. An effective way to present results of penetration tests is to show how compromised systems may directly impact stock values, which will result in the highest levels of management being held accountable.
14. Use of story-telling is advocated to explain the penetration test process.
15. A penetration test is synonymous with ethical hacking and other cyberattacks.
16. A benefit of a penetration test is that it cannot affect current system configuration.

Your results will appear in a new window.

Please note: This quiz requires a JavaScript-enabled browser. If the quiz is not displayed above, you either do not have a browser which supports JavaScript or JavaScript support has been disabled.