Skip to main content

Risk Management in Information Systems Exam Answer Key - 1111 Verified Questions

Page 1


Chapter 1: Introduction to Information Security

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44634

Sample Questions

Q1) Hardware is often the most valuable asset possessed by an organization and it is the main target of intentional attacks.

A)True

B)False

Answer: False

Q2) In information security,salami theft occurs when an employee steals a few pieces of information at a time,knowing that taking more would be noticed - but eventually the employee gets something complete or useable._________________________

A)True

B)False Answer: True

Q3) Policies are written instructions for accomplishing a specific task._________________________

A)True

B)False Answer: False

Q4) ____________________ carries the lifeblood of information through an organization. Answer: Software

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: The Need for Security

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44635

Sample Questions

Q1) Attempting to reverse-calculate a password is called ____________________.

Answer: cracking

Q2) The timing attack explores the contents of a Web browser's ____________________.

Answer: cache

Q3) The malicious code attack includes the execution of viruses,worms,Trojan horses,and active Web scripts with the intent to destroy or steal information._________________________

A)True

B)False

Answer: True

Q4) Microsoft acknowledged that if you type a res:// URL (a Microsoft-devised type of URL)which is longer than ____ characters in Internet Explorer 4.0,the browser will crash. A)64

B)128

C)256

D)512

Answer: C

Q5) ESD means electrostatic ____________________.

Answer: discharge

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Legal, Ethical, and Professional Issues in Information Security

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44636

Sample Questions

Q1) The Computer ____ and Abuse Act of 1986 is the cornerstone of many computer-related federal laws and enforcement efforts.

A)Violence

B)Fraud

C)Theft

D)Usage Answer: B

Q2) Which of the following countries reported generally intolerant attitudes toward personal use of organizational computing resources?

A)Australia

B)United States

C)Singapore

D)Sweden

Answer: C

Q3) The Economic Espionage Act of 1996 protects American ingenuity,intellectual property,and competitive advantage._________________________

A)True

B)False

Answer: True

Page 5

To view all questions and flashcards with answers, click on the resource link above.

Available

Study

Chapter 4: Risk Management

Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/44637

Sample Questions

Q1) A(n)disaster recovery plan dictates the actions an organization can and perhaps should take while an incident is in progress._________________________

A)True

B)False

Q2) Comprehensive means that an information asset should fit in only one category.

A)True

B)False

Q3) If every vulnerability identified in the organization is handled through mitigation,it may reflect an inability to conduct proactive security activities and an apathetic approach to security in general.

A)True

B)False

Q4) The ____ security policy is a planning document that outlines the process of implementing security in the organization.

A)program

B)agency

C)issue-specific

D)system-specific

Q5) List Microsoft's "Ten Immutable Laws of Security" in any order

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Planning for Security

Available Study Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/44638

Sample Questions

Q1) ____ controls cover security processes that are designed by strategic planners and implemented by the security administration of the organization.

A)Managerial

B)Technical

C)Operational

D)Informational

Q2) A(n)sequential roster is activated as the first person calls a few people on the roster,who in turn call a few other people._________________________

A)True

B)False

Q3) The ____ is based on and directly supports the mission,vision,and direction of the organization and sets the strategic direction,scope,and tone for all security efforts.

A)ISP

B)EISP

C)GSP

D)ISSP

Q4) The transfer of live transactions to an off-site facility is called

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Security Technology: Firewalls and Vpns

Available Study Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/44639

Sample Questions

Q1) In addition to recording intrusion attempts,a(n)router can be configured to use the contact information to notify the firewall administrator of the occurrence of an intrusion attempt._________________________

A)True

B)False

Q2) All organizations with an Internet connection have some form of a router at the boundary between the organization's internal networks and the external service provider. A)True

B)False

Q3) SESAME uses ____________________ key encryption to distribute secret keys.

Q4) Simple firewall models enforce address ____________________,which are rules designed to prohibit packets with certain addresses or partial addresses from passing through the device.

Q5) In a DMZ configuration,connections into the trusted internal network are allowed only from the DMZ bastion host servers._________________________ A)True

B)False

Q6) List and describe the three interacting services of the Kerberos system.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Security Technology: Intrusion Detection and

Prevention Systems, and Other Security Tools

Available Study Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/44640

Sample Questions

Q1) Services using the TCP/IP protocol can run only on port 80.

A)True

B)False

Q2) ____ is a specially configured connection on a network device that is capable of viewing all of the traffic that moves through the entire device.

A)NIDPS

B)SPAN

C)DPS

D)IDSE

Q3) A(n)____________________-based IDPS resides on a particular computer or server and monitors activity only on that system.

Q4) For Linux or BSD systems,there is a tool called "scanner" that allows a remote individual to "mirror" entire Web sites._________________________

A)True

B)False

Q5) The initial estimation of the defensive state of an organization's networks and systems is called doorknob ____________________.

Page 9

Q6) List and describe the three advantages of NIDPSs.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Cryptography

Available Study Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/44641

Sample Questions

Q1) DES uses a 64-bit key.

A)True

B)False

Q2) Sequence encryption is a series of encryptions and decryptions between a number of systems,wherein each system in a network decrypts the message sent to it and then reencrypts it using different keys and sends it to the next neighbor,and this process continues until the message reaches the final destination.

A)True

B)False

Q3) The most popular modern version of steganography involves hiding information within files that contain digital pictures or other images._________________________

A)True

B)False

Q4) A message ____________________ is a fingerprint of the author's message that is compared with the recipient's locally calculated hash of the same message.

Q5) A mathematical ____________________ is a "secret mechanism that enables you to easily accomplish the reverse function in a one-way function."

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Physical Security

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44642

Sample Questions

Q1) Electronic monitoring includes ____ systems.

A)blocked video

B)local video

C)open-circuit television

D)closed-circuit television

Q2) Static electricity is not noticeable to humans until levels approach 150 volts.

A)True

B)False

Q3) One of the leading causes of damage to sensitive circuitry is ____.

A)CPU

B)EPA

C)ESD

D)HVAC

Q4) Mechanical locks can accept a variety of inputs as keys,including magnetic strips on ID cards,radio signals from name badges,personal identification numbers (PINs)typed into a keypad,or some combination of these to activate an electrically powered locking mechanism._________________________

A)True

B)False

Q5) A(n)_________________________ is typically worn concealed.

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Implementing Information Security

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44643

Sample Questions

Q1) A task or subtask becomes an action step when it can be completed by one individual or skill set and when it includes a single deliverable._________________________

A)True

B)False

Q2) The ____ layer of the bull's-eye model receives attention last.

A)Policies

B)Networks

C)Systems

D)Applications

Q3) The size of the organization and the normal conduct of business may preclude a single large training program on new security procedures or technologies.

A)True

B)False

Q4) A cybernetic loop ensures that progress is measured periodically._________________________

A)True

B)False

Q5) One of the oldest models of change is the ____________________ change model.

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Security and Personnel

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/44644

Sample Questions

Q1) ISSEP stands for Information Systems Security Expert Professional._________________________

A)True

B)False

Q2) Upper management should learn more about the budgetary needs of the information security function and the positions within it._________________________

A)True

B)False

Q3) Friendly departures include termination for cause,permanent downsizing,temporary lay-off,or some instances of quitting._________________________

A)True

B)False

Q4) SCP stands for Security Certified Program._________________________ A)True B)False

Q5) Describe the concept of separation of duties.

Q6) It is important to gather employee ____________________ early about the information security program and respond to it quickly.

Page 13

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Information Security Maintenance

Available Study Resources on Quizplus for this Chatper

103 Verified Questions

103 Flashcards

Source URL: https://quizplus.com/quiz/44645

Sample Questions

Q1) A key component in the engine that drives change in the information security program is a relatively straightforward process called an information security ____________________ risk assessment.

Q2) The ____________________ interconnections are network devices,communications channels,and applications that may not be owned by the organization but are essential to the continued operation of the organization's partnership with another company.

Q3) When possible,major plan elements should be rehearsed._________________________

A)True

B)False

Q4) When the memory usage associated with a particular CPU-based system averages ____% or more over prolonged periods,consider adding more memory.

A)30

B)60

C)90

D)100

Q5) The Analysis step of Internet vulnerability assessment is when a knowledgeable and experienced vulnerability analyst screens the test results for the ____________________ vulnerabilities logged during scanning.

Page 14

To view all questions and flashcards with answers, click on the resource link above.

Turn static files into dynamic content formats.

Create a flipbook
Risk Management in Information Systems Exam Answer Key - 1111 Verified Questions by Quizplus - Issuu