{"id":17162,"date":"2021-07-16T03:08:55","date_gmt":"2021-07-16T03:08:55","guid":{"rendered":"https:\/\/papersspot.com\/blog\/2021\/07\/16\/it279m1-1-examine-engineering-processes-and-secure-design-principles-gel-1-02-demonstrate-college-level-communication-through-the-composition-of-original\/"},"modified":"2021-07-16T03:08:55","modified_gmt":"2021-07-16T03:08:55","slug":"it279m1-1-examine-engineering-processes-and-secure-design-principles-gel-1-02-demonstrate-college-level-communication-through-the-composition-of-original","status":"publish","type":"post","link":"https:\/\/papersspot.com\/blog\/2021\/07\/16\/it279m1-1-examine-engineering-processes-and-secure-design-principles-gel-1-02-demonstrate-college-level-communication-through-the-composition-of-original\/","title":{"rendered":"IT279M1-1:\u00a0Examine engineering processes and secure design principles.GEL-1.02:\u00a0Demonstrate college-level communication through the composition of original"},"content":{"rendered":"<p>IT279M1-1:\u00a0Examine engineering processes and secure design principles. <br \/>GEL-1.02:\u00a0Demonstrate college-level communication through the composition of original materials in Standard English. <br \/>Purpose <br \/>This Assessment tests your knowledge about engineering processes and secure design principles. You will also be completing the university-mandated communication literacy for the course. <br \/>Instructions <br \/>Part 1:\u00a0Computer Architecture and Protection Mechanisms <br \/>Answer the following 12 questions by selecting the one best answer for each. Cite your course texts, or other credible source,\u00a0and provide a 50\u2013100-word explanation of why you chose your answer. <br \/>1.\u00a0 Which statement is true of complex instruction set computers (CISC)? <br \/>A.\u00a0 An instruction set executes a single low-level operation. <br \/>B.\u00a0\u00a0 The access calls to main memory are fewer as compared to RISC. <br \/>C.\u00a0 The instruction set supports all the low-level programming languages. <br \/>2.\u00a0 What is the best description of reduced instruction set computing (RISC)? <br \/>A.\u00a0 Processing that executes one instruction at a time <br \/>B.\u00a0\u00a0 Computing using instructions that perform many operations per instruction <br \/>C.\u00a0 Computing using instructions that are simpler and require fewer clock <br \/> cycles to execute <br \/>3.\u00a0 Memory space that is insulated from other running processes in a multipurpose system is part of a _________. <br \/>A.\u00a0 Security perimeter <br \/>B.\u00a0\u00a0 Protection domain <br \/>C.\u00a0 Trusted path <br \/>4.\u00a0 What is the best description of an execution domain? <br \/>A.\u00a0 Memory space insulated from other running processes in a multiprocessing system. <br \/>B.\u00a0\u00a0 A communication channel between an application and the kernel in the TCB. <br \/>C.\u00a0 An isolated area that is used by trusted processes when they are run in privileged state. <br \/>5.\u00a0 The trusted computing system is defined as __________. <br \/>A.\u00a0 The total combination of protection mechanisms within a computer system that are\u00a0trusted to enforce\u00a0security policy. <br \/>B.\u00a0\u00a0 The boundary separating the trusted mechanisms from the remainder of the system. <br \/>C.\u00a0 A system that employs the necessary hardware and software assurance measures to enable\u00a0processing multiple levels of classified or sensitive information to occur. <br \/>6.\u00a0 You are responsible for managing the virtual computers on your network. Which guideline is important when managing virtual computers? <br \/>A.\u00a0 Update the operating system and applications only on the host computer. <br \/>B.\u00a0\u00a0 Implement a firewall only on the host computer. <br \/>C.\u00a0 Isolate the host computer and each virtual computer from each other. <br \/>7.\u00a0 Which statements do NOT define the requirements of a security kernel? <br \/>a.\u00a0\u00a0 The reference monitor should be verified as correct. <br \/>b.\u00a0 The reference monitor should provide process isolation. <br \/>c.\u00a0\u00a0 The security kernel should be verified in a comprehensive manner. <br \/>d.\u00a0 A method to circumvent the security should be implemented by the reference monitor. <br \/>A.\u00a0 Option a <br \/>B.\u00a0\u00a0 Option b <br \/>C.\u00a0 Option c <br \/>D. Option d <br \/>E.\u00a0\u00a0 Option a and c <br \/>F.\u00a0\u00a0 Option b and d <\/p>\n<p>8.\u00a0 Which characteristics do NOT identify a reference monitor? <br \/>a.\u00a0\u00a0 analysis <br \/>b.\u00a0 isolation <br \/>c.\u00a0\u00a0 verifiability <br \/>d.\u00a0 vulnerability <br \/>A.\u00a0 option a <br \/>B.\u00a0\u00a0 option b <br \/>C.\u00a0 option c <br \/>D. option d <br \/>E.\u00a0\u00a0 option a and d <br \/>F.\u00a0\u00a0 obtion b and c <br \/>9.\u00a0 What part of the TCB concept validates access to every resource prior to granting the requested access? <br \/>A.\u00a0 Security kernel <br \/>B.\u00a0\u00a0 TCB partition <br \/>C.\u00a0 Reference monitor <br \/>10.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 What is the best definition of a security model? <br \/>A.\u00a0 A security model provides a framework to implement\u00a0security policy. <br \/>B.\u00a0\u00a0 A security model states policies that an organization must follow. <br \/>C.\u00a0 Hey security. <br \/>11.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 What is an access object? <br \/>A.\u00a0 A list of valid access rules <br \/>B.\u00a0\u00a0 A resource a user or process wants to access <br \/>C.\u00a0 A user\u00a0we&#8217;re process that wants to access a resource <br \/>12.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 What is a security\u00a0control? <br \/>A.\u00a0 A mechanism that limits access to an object. <br \/>B.\u00a0\u00a0 A list of valid access rules. <br \/>C.\u00a0 A security component that stores\u00a0attributes that describe an object. <br \/>\u00a0 <br \/>Part 2: Computer Hardware Security Concepts <br \/>Section 1: Using Credible Sources, Justify Your Answers to Questions <br \/>Answer the following 12 questions by selecting the one best answer for each. Cite your course texts, or other credible source, and provide a 50\u2013100-word explanation of why you chose your answer. <br \/>1.\u00a0 Which statement is true of the dedicated security mode? <br \/>A.\u00a0 All users have the clearance and formal approval required to access all the data. <br \/>B.\u00a0\u00a0 Some users have the clearance and formal approval required to access all the data. <br \/>C.\u00a0 All the users have the clearance and formal approval required to access some of the data. <br \/>2.\u00a0 Which statement is true of a multilevel security mode? <br \/>A.\u00a0 The multilevel security mode involves the use of sensitivity labels. <br \/>B.\u00a0\u00a0 The multilevel security\u00a0mode is based on role-based memberships. <br \/>C.\u00a0 The multilevel security mode is represented by the Chinese Wall model. <br \/>3.\u00a0 Which processes define the supervisor mode? <br \/>A.\u00a0 Processes with no protection mechanism. <br \/>B.\u00a0\u00a0 Processes that are executed in the outer protection rings. <br \/>C.\u00a0 Processes that are executed in the inner protection rings. <br \/>4.\u00a0 What happens when a trusted computing base (TCB) failure occurs as a result of a lower-privileged process trying to access restricted memory segments? <br \/>A.\u00a0 The system reboots immediately. <br \/>B.\u00a0\u00a0 The system goes into maintenance mode. <br \/>C.\u00a0 Administrator intervention is required. <br \/>5.\u00a0 Which statement is true of covert channels? <br \/>A.\u00a0 A covert channel is addressed by a C2 rating provided by TCSEC. <br \/>B.\u00a0\u00a0 A covert channel is not controlled by a security mechanism. <br \/>C.\u00a0 A covert channel\u00a0acts a trusted path for authorized communication. <br \/>6.\u00a0 What type of channel is used when one process writes data to a hard drive and another process reads it? <br \/>A.\u00a0 Covert timing channel <br \/>B.\u00a0\u00a0 Covert storage channel <br \/>C.\u00a0 Overt timing channel <br \/>7.\u00a0 What is another name for an asynchronous attack? <br \/>A.\u00a0 Buffer overflow <br \/>B.\u00a0\u00a0 Maintenance hook <br \/>C.\u00a0 Time-of-check\/time-of-use (TOC\/TOU) attack <br \/>8.\u00a0 What is meant by the term fail safe? <br \/>A.\u00a0 A system&#8217;s ability to recover automatically through a reboot <br \/>B.\u00a0\u00a0 A system&#8217;s ability to preserve a secure state before and after failure <br \/>C.\u00a0 A system&#8217;s ability to terminate processes when a failure is identified <br \/>9.\u00a0 Which term is\u00a0an evaluation of security components and their compliance prior to formal acceptance? <br \/>A.\u00a0 Accreditation <br \/>B.\u00a0\u00a0 Security control <br \/>C.\u00a0 Certification <br \/>10.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There are several types of audits used in various situations that you might encounter in the enterprise. Which type of audit would include audits in support of SOX, HIPAA, or SAS 70? <br \/>A.\u00a0 Compliance audits <br \/>B.\u00a0\u00a0 Forensic audits <br \/>C.\u00a0 Operational audits <br \/>11.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Which of the following statements CORRECTLY\u00a0describe Qualitative Risk Analysis methods? <br \/>A.\u00a0 Qualitative analysis is based on some categories like low, medium, or high. <br \/>B.\u00a0\u00a0 Qualitative risk analysis uses value at risk. <br \/>C.\u00a0 Qualitative analysis is based on calculations. <br \/>12.\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Which of the following statements\u00a0BEST describes an attribute for effective risk management strategy? <br \/>A.\u00a0 Risk awareness communication may not be required at each step of the risk management process. <br \/>B.\u00a0\u00a0 Effective risk management activities should not be supported on on-going activities by all the members of orgainization. <br \/>C.\u00a0 Risk management strategy must be an integrated business\u00a0processes with defined objectives that incorporates all of the organization\u2019s risk management processes. <br \/>\u00a0 <br \/>\u00a0 <br \/>\u00a0 <br \/>\u00a0 <br \/>\u00a0 <br \/>Minimum Submission Requirements <br \/>This Assessment should be a Microsoft Word document and\u00a0PowerPoint presentation that fulfills the minimum length requirements and any other special requirements listed in the instructions, in addition to the title and reference pages. <br \/>Respond to the questions in a thorough manner, providing specific examples of concepts, topics, definitions, and other elements asked for in the questions. Your submission should be highly organized, logical, and focused. <br \/>Your submission must be written in Standard English and demonstrate exceptional content, organization, style, and grammar and mechanics. <br \/>Your submission should provide a clearly established and sustained viewpoint and purpose. <br \/>Your writing should be well ordered, logical and unified, as well as original and insightful. <br \/>A separate page at the end of your submission should contain a list of references, in APA format. Use your textbook, the Library, and the internet for research. <br \/>Be sure to cite both in-text and reference list citations where appropriate and reference all sources. Your sources and content should follow\u00a0proper APA citation style. Review the writing resources for APA formatting and citation found in Academic Tools. Additional writing resources can be found within the Academic Success Center. For more information on APA style formatting, go to Academic Writer, formerly APA Style Central, under the Academic Tools area of this course. <br \/>Your submission should: <br \/>include a cover sheet; <br \/>be double-spaced; <br \/>be typed in Times New Roman, 12 -point font; <br \/>include correct citations <br \/>be written in Standard English with no spelling or punctuation errors; and <br \/>include correct references at the bottom of the last page. <br \/>If work submitted for this competency assessment does not meet the minimum submission requirements, it will be returned without being scored. <br \/>\u00a0 <br \/>\u00a0 <br \/>Plagiarism <br \/>Plagiarism is an act of academic dishonesty. It violates the University Honor Code, and the offense is subject to disciplinary action. You are expected to be the sole author of your work. Use of another person&#8217;s work or ideas must be accompanied by specific citations and references. Whether the action is intentional or not, it still constitutes plagiarism. <br \/>\u00a0 <br \/>\u00a0 <\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT279M1-1:\u00a0Examine engineering processes and secure design principles. GEL-1.02:\u00a0Demonstrate college-level communication through the composition of original materials in Standard English. Purpose This Assessment tests your knowledge about engineering processes and secure design principles. You will also be completing the university-mandated communication literacy for the course. Instructions Part 1:\u00a0Computer Architecture and Protection Mechanisms Answer the following 12 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[36],"class_list":["post-17162","post","type-post","status-publish","format-standard","hentry","category-research-paper-writing","tag-information-technology"],"_links":{"self":[{"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/posts\/17162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/comments?post=17162"}],"version-history":[{"count":0,"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/posts\/17162\/revisions"}],"wp:attachment":[{"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/media?parent=17162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/categories?post=17162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/papersspot.com\/blog\/wp-json\/wp\/v2\/tags?post=17162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}