1.
Which of the following would best describe the difference between white-box testing and black-box testing?
2.
Who should measure the effectiveness of Information System security related controls in an organization?
3.
Which must bear the primary responsibility for determining the level of protection needed for information systems resources?
4.
Common Criteria has assurance level from EAL 1 to EAL 7 regarding the depth of design and testing. Which of following assure the Target of Evaluation (or TOE) is methodically designed, tested and reviewed?
5.
Which Orange Book evaluation level is described as "Verified Design"?
6.
Which Orange Book evaluation level is described as "Structured Protection"?
7.
What can be BEST defined as the examination of threat sources against system vulnerabilities to determine the threats for a particular system in a particular operational environment?
8.
Operations Security seeks to PRIMARILY protect against which of the following?
9.
The viewing of recorded events after the fact using a closed-circuit TV camera is considered a
10.
How would nonrepudiation be BEST classified as?