the organization require protection?

3. Which management groups are responsible for implementing information security to
protect the organization’s ability to function?
4. Has the implementation of networking technology created more or less risk for busi-
nesses that use information technology? Why?
5. What is information extortion? Describe how such an attack can cause losses, using an
example not found in the text.
6. Why are employees one of the greatest threats to information security?
7. How can you protect against shoulder surfing?
8. How has the perception of the hacker changed over recent years? What is the profile of
a hacker today?
9. What is the difference between a skilled hacker and an unskilled hacker, other than
skill levels? How does the protection against each differ?
10. What are the various types of malware? How do worms differ from viruses? Do Trojan
horses carry viruses or worms?
11. Why does polymorphism cause greater concern than traditional malware? How does it
affect detection?
12. What is the most common violation of intellectual property? How does an organization
protect against it? What agencies fight it?
13. What are the various forces of nature? Which type might be of greatest concern to an
organization in Las Vegas? Jakarta? Oklahoma City? Amsterdam? Miami? Tokyo?
14. How is technological obsolescence a threat to information security? How can an orga-
nization protect against it?
15. Does the intellectual property owned by an organization usually have value? If so, how
can attackers threaten that value?
16. What are the types of password attacks? What can a systems administrator do to pro-
tect against them?
17. What is the difference between a denial-of-service attack and a distributed denial-
of-service attack? Which is more dangerous? Why?
18. For a sniffer attack to succeed, what must the attacker do? How can an attacker gain
access to a network to use the sniffer system?
19. What methods does a social engineering hacker use to gain information about a user’s
login ID and password? How would this method differ if it targeted an administrator’s
assistant versus a data-entry clerk?
20. What is a buffer overflow, and how is it used against a Web server?

21. How does encryption protect information in transit and at rest? What are some common encryption methods used in information security?

22. What is the role of firewalls in protecting an organization’s network? How do they work to prevent unauthorized access?
23. What is the importance of regular security audits and penetration testing in ensuring the security of an organization’s information systems?
24. How can an organization ensure the physical security of its information assets, such as servers and storage devices?
25. What is the impact of insider threats on information security? How can organizations detect and prevent such threats?
26. What is ransomware and how does it work? How can organizations protect themselves against ransomware attacks?
27. How does compliance with regulations such as GDPR and HIPAA affect an organization’s information security practices?
28. What is the role of incident response planning in managing and mitigating the impact of security breaches or cyber attacks?
29. How can organizations ensure the security of their cloud-based systems and data? What are some best practices for securing cloud environments?
30. What is the importance of employee training and awareness in maintaining information security within an organization?