The three main goals of computer security are:

Confidentiality, protection, and reliability.

Confidentiality, integrity, and availability.

Detection, response, and correction.

Confidentiality, performance, and reliability.

Detection, protection, and access control.


Which of the following considerations is NOT a factor in theeconomics of data protection

All of the choices are principal factors

Storage costs

Time to achieve partial or full recovery

Value of data

Point in time recovery requirement (last second, minute, hour,day, …)


In the context of Information Assurance and Security, the HIPAASecurity Rule requires that individually identifiable patientinformation must be protected.

Which of the following type(s) of safeguards are required by theHIPAA Security Rule.

Administrative and Technical safeguards

Technical safeguards

Administrative, Physical, and Technical safeguards

Physical and Technical safeguards

Administrative safeguards


Within the context of larger organizations, which of thefollowing is NOT a characteristic of role-basedaccess control

Simplifies administration when the privileges of users arechanged

Establishes a N:1 relationship between users and accessprivilege assignment

Requires a role engineering activity prior to implementation

All of the choices are characteristics of role-based accesscontrol

Was an approach to access control largely pioneered by the U.S.National Institute of Standards & Technology


Within the context of Information Assurance and Security, whichof the following offer the most complete set of Black Swanattributes.

Attribute 1 – surprise

Attribute 2 – risk

Attribute 3 – danger

Attribute 4 – statistically likely to occur

Attributes 1 and 3

Attributes 1, 2, and 3

Attributes 2 and 4

Attributes 3 and 4

Attributes 1 and 2

Attributes 2, 3, and 4


Protecting national critical infrastructure requires developingindividual, free-standing plans for each sector and updating themon a regular basis.

