QUESTION 1 External auditing is an example of an operational risk assessment tas
ID: 3840821 • Letter: Q
Question
QUESTION 1
External auditing is an example of an operational risk assessment task.
True
False
12 points
QUESTION 2
Google is becoming a primary tool for would-be attackers to profile an organization looking for weaknesses.
True
False
12 points
QUESTION 3
Most passive testing involves either a tool or a person performing functions against a resource to look for known responses.
True
False
12 points
QUESTION 4
Storing or processing sensitive data off-site through a third party is not a cause of concern to be addressed when profiling a third-party vendor.
True
False
12 points
QUESTION 5
Blackbox application testing is a passive form of assessment.
True
False
QUESTION 6
On the Qualitative Vulnerability Severity Scale, the deviation from a recommended practice or standard would an example of moderate level severity criteria.
True
False
Explanation / Answer
Q1: True. Reason: Auditing is basically to check for compliance of law and industry standard, and external auditing may also help mitigate risk.
Q2 : True. Reason: Almost every organization has its site or web resources indexed by google. If organizations are not careful enough, they may expose certain pages or links which they do not want to be indexed. Unfortunatley once something is indexed by google, it becomes very difficult to completely delete with certainity from the internet. Google also maintains a cached version of sites which further complicates the task.
Q3: False : Passive testing just observes system without interaction. It does not look for know responses.
Q4: False: It should be a cause for concern as sensitive data should not be handed out to third party without express authorization and making sure the third party follows the highest standards of security as you would.
Q5: False: Blackbox is active form of testing, since it involes a user interacting with the software.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.