IT Risks and Responses Flashcards

1
Q

What is data encryption and the 2 types of data encryption?

A
  • using a password or a digital key to scramble a readable (plaintext) message into an unreadable (ciphertext) message
  • the intended recipient of the message then uses another digital key to decrypt or decipher the ciphertext back into plaintext
  • the longer the length of the key, the less likely that the message or transaction will be decrypted by the wrong party

Symmetic encryption- the sender and the recipient use the same shared key

Asymmetric encryption- 2 keys are used; one is public and the other private

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are digital certificates?

A
  • electronic docs created and digitally signed by a trusted party and that certify the identity of the owners of a particular public key
  • operate on a Public Key Infrastucture (PKI) which is the system and processes used to issue and manage asymmetric keys and digital certificates
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a full backup?

A
  • an exact copy of the entire database
  • are time consuming, so most orgs only do full back us weekly and supplement with daily partial backups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an incremental backup?

A
  • copying only the data that has changed since the last backup
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a differential backup?

A
  • copies all changes made since the last full backup
  • each new differential backup file contains the cumulative effects of all activity since the last full backup
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Disaster Recovery Plan?

A
  • an entity’s plans for restoring and continuing its information technology function in the event of the destruction of not only program and data files, but computer processing capability as well
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Cold Site?

A
  • an off site location that has all the electrical connections and other physical requirements for data processing, but is missing the actual equipment
  • cheapest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Warm Site?

A
  • has hardware installed but will fall short of the processing capabilities typically found in a hot site or at the actual business due to a lack of fully operational computer and office equipment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Hot Site?

A
  • an off site location that is equipped to take over the company’s data processing and include the necessary hardware and office equipment to perform the functions of the org
  • most expensive
  • can restore info technology functions within a few hours of a disaster
How well did you know this?
1
Not at all
2
3
4
5
Perfectly