Reference no: EM133954100
Assignment:
1. You are an IT Security Administrator at a large enterprise and receive the following e-mail apparently from the IT Help Desk:
"Dear Corporate User,
Next week we will be deleting all inactive user accounts in order to secure our authentication services. If you still require the use of your user account please send the following information by return e-mail by close of business today. If we do not receive this information your account will be deemed inactive and marked for deletion.
1. Name (first and last)
2. Username/Login
3. Password
4. Date of birth
5. Secret Question Answer
Thank you for your immediate attention."
What is this e-mail an attempt at and how should you handle this request as an IT Security Administrator?
2. One of your work colleagues is an avid triathlete and subscribes to a number of free triathlon blog sites. Among the questions she was asked during the subscription process, one site asked for her month of birth, a second asked for her year of birth, and a third asked for her mother's maiden name.
Explain and justify what you think the major risk here is and what can be done to mitigate against that risk.
3. What is data leakage and how do you detect and prevent it?
4. How do you define a security incident and how would you manage it?
5. When using a public Wi-Fi network there is a risk of the unauthorised disclosure of your personal information. List 5 technical recommendations you would make to reduce the risk of this information disclosure.
6. Your friend comes to you with her concern about the growing trend of identity theft. What top 5 advice/tips would you give her to help her keep her digital identity safe?
7. In your role as security manager you are responsible for the security awareness program in your company. The annual company meeting is next month and representatives from all state offices will arrive at your headquarters for a three-day visit. You've been asked to speak about the importance of strong passwords throughout the organization. What things could you talk about in your presentation to impress on the staff the importance of adequate password security?
8. It is estimated that 60% of security incidents are a result of factors internal to an organisation. Outline why internal factors represent a greater threat than external factors and how this changes the level of risk associated with internal factors.
9. The concept of a security perimeter is now considered quite limited. Discuss a scenario where the traditional idea of the security perimeter breaks down.
10. Discuss the benefits of creating a security baseline and how doing so enhances the overall security posture of a securely designed network.