What are the subordinate tasks of the Initiate and Plan IA CandA phase of the DIACAP process? Each correct answer represents a complete solution. Choose all that apply.
A. Initiate IA implementation plan
B. Develop DIACAP strategy
C. Assign IA controls.
D. Assemble DIACAP team
E. Register system with DoD Component IA Program.
F. Conduct validation activity.
Joseph works as a Software Developer for WebTech Inc. He wants to protect the algorithms and the techniques of programming that he uses in developing an application. Which of the following laws are used to protect a part of software?
A. Code Security law
B. Patent laws
C. Trademark laws
D. Copyright laws
Which of the following is a set of exclusive rights granted by a state to an inventor or his assignee for a fixed period of time in exchange for the disclosure of an invention?
A. Copyright
B. Snooping
C. Utility model
D. Patent
Which of the following types of activities can be audited for security? Each correct answer represents a complete solution. Choose three.
A. File and object access
B. Data downloading from the Internet
C. Printer access
D. Network logons and logoffs
Which of the following are the principle duties performed by the BIOS during POST (power-on- self-test)? Each correct answer represents a part of the solution. Choose all that apply.
A. It provides a user interface for system's configuration.
B. It identifies, organizes, and selects boot devices.
C. It delegates control to other BIOS, if it is required.
D. It discovers size and verifies system memory.
E. It verifies the integrity of the BIOS code itself.
F. It interrupts the execution of all running programs.
Which of the following methods can be helpful to eliminate social engineering threat? Each correct answer represents a complete solution. Choose three.
A. Password policies
B. Data classification
C. Data encryption
D. Vulnerability assessments
The DARPA paper defines various procedural patterns to perform secure system development practices. Which of the following patterns does it include? Each correct answer represents a complete solution. Choose three.
A. Hidden implementation
B. Document the server configuration
C. Patch proactively
D. Red team the design
E. Password propagation
Which of the following security models focuses on data confidentiality and controlled access to classified information?
A. Clark-Wilson model
B. Biba model
C. Take-Grant model
D. Bell-La Padula model
Which of the following are the important areas addressed by a software system's security policy? Each correct answer represents a complete solution. Choose all that apply.
A. Identification and authentication
B. Punctuality
C. Data protection
D. Accountability
E. Scalability
F. Access control
Which of the following elements of the BCP process emphasizes on creating the scope and the additional elements required to define the parameters of the plan?
A. Business continuity plan development
B. Plan approval and implementation
C. Business impact analysis
D. Scope and plan initiation