Skip to main content

Information Security Management Midterm Exam - 251 Verified Questions

Page 1


Information Security Management

Midterm Exam

Course Introduction

Information Security Management focuses on the strategies, processes, and tools necessary to protect organizational information assets from internal and external threats. The course covers key principles such as risk assessment, security policies, governance frameworks, compliance standards, and incident response planning. Students will explore how to develop and implement security controls that align with business objectives, address evolving cyber threats, and ensure the confidentiality, integrity, and availability of information systems. Practical case studies emphasize the role of management in fostering a security-conscious culture and in meeting legal and ethical obligations within a rapidly changing technological landscape.

Recommended Textbook

Disaster Recovery Principles and Practices 1st Edition by April Wells

Available Study Resources on Quizplus

9 Chapters

251 Verified Questions

251 Flashcards

Source URL: https://quizplus.com/study-set/2239

Page 2

Chapter 1: Introduction to Disaster Recovery

Available Study Resources on Quizplus for this Chatper

23 Verified Questions

23 Flashcards

Source URL: https://quizplus.com/quiz/44514

Sample Questions

Q1) In the event of a major disaster,the first goal of the business is to maintain the __________ sustainable level of services for the organization.

Answer: minimal

Q2) The FEMA web site assists you in determining your __________ for a given situation.

Answer: risk

Q3) On whose web site can you find itemized lists,by state and counties within a state,of the declared disasters on a yearly basis?

A)CIA

B)FEMA

C)FBI

D)IRS

Answer: B

Q4) Which of the following is an example of a technological breakdown?

A)Chemical spill

B)Employee death

C)Spam

D)Air conditioning failure

Answer: D

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Preparing to Develop the Disaster Recovery Plan

Available Study Resources on Quizplus for this Chatper

41 Verified Questions

41 Flashcards

Source URL: https://quizplus.com/quiz/44515

Sample Questions

Q1) The input the user support team provides allows planning for how to __________ users in a disaster situation.

Answer: support

Q2) Security Team

A)arranges for outsourcing of security issues

B)maintains proper backup procedures

C)recovers the hardware and the software installations

D)reconfigures software to hardware

E)carries on business logically

Answer: A

Q3) Who will be responsible for creating the disaster recovery plan and will likely be responsible for testing it and keeping up with its ongoing maintenance?

A)The disaster recovery team

B)Upper management

C)The disaster recovery planning team

D)The insurance company

Answer: C

To view all questions and flashcards with answers, click on the resource link above.

4

Chapter 3: Assessing Risk and Impact

Available Study Resources on Quizplus for this Chatper

43 Verified Questions

43 Flashcards

Source URL: https://quizplus.com/quiz/44516

Sample Questions

Q1) Functions need to be assessed by problems that their __________ will cause to the everyday operations of the business.

Answer: loss

Q2) In __________ process,rather than identifying the assets and disasters and then driving the process from those perspectives,you address the whole organization from the perspective of the perceived threats.

Answer: The Business Impact Analysis

Q3) Assessment

A)magnitude of the potential loss

B)result of judging the worth or value of something or someone

C)the possibility of suffering harm or loss because of an event

Answer: B

Q4) First

A)assess hazards

B)implement controls

C)test and evaluate

D)identify hazards

E)develop controls and make risk decisions

Answer: D

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Prioritizing Systems and Functions for Recovery

Available Study Resources on Quizplus for this Chatper

21 Verified Questions

21 Flashcards

Source URL: https://quizplus.com/quiz/44517

Sample Questions

Q1) It is critical to include those areas that either generate revenue for the organization or process revenue for it in __________.

A)tier 1 systems

B)tier 2 systems

C)tier 3 systems

D)tier 4 systems

Q2) Tier ________ is a set of functions and processes that an organization can do without for more than a week to 10 days.

Q3) Not every "event" impacting an organization can be considered a(n)__________.

Q4) Which category does the payroll system likely fall into?

A)tier 1 systems

B)tier 2 systems

C)tier 3 systems

D)tier 4 systems

Q5) One function that is often overlooked during recovery is __________.

A)payroll

B)disaster assessment

C)accounts receivable

D)backup

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Identify Data Storage and Recovery Sites

Available Study Resources on Quizplus for this Chatper

23 Verified Questions

23 Flashcards

Source URL: https://quizplus.com/quiz/44518

Sample Questions

Q1) Which of the following governmental regulations deals with health and insurance information privacy protection for individuals?

A)Gramm-Leach-Bliley Act

B)Sarbanes-Oxley Act

C)HIPAA

D)All of the above

Q2) One of the most __________ things in a disaster recovery plan and in the selection of the disaster recovery site location selection is the ability to acquire office supplies.

A)overworked

B)overlooked

C)obvious

D)confusing

Q3) In the end,the decision to rent or share a recovery site comes down to __________.

Q4) Travel cost may be even more of a consideration than the __________ of the contracted recovery site.

Q5) Restoring an entire tape is __________ labor and time intensive than recovering a single deleted file.

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Developing Plans, Procedures, and Relationships

Available Study Resources on Quizplus for this Chatper

23 Verified Questions

23 Flashcards

Source URL: https://quizplus.com/quiz/44519

Sample Questions

Q1) What is one of the first things to be done after a recovery or drill?

A)Have everyone that was involved sit down and debrief.

B)Decide who is at fault for any failures in the system.

C)Notify the disaster recovery team that a disaster has taken place.

D)All of the above.

Q2) What is the role of the owner of the disaster recovery document?

A)ultimately responsible for the maintenance of the document

B)oversees the changes and change control

C)see to it that all pieces of the document are kept in sync

D)all of the above

Q3) Which backup allows very large amounts of data to be backed up in a matter of seconds or just a few minutes?

A)full backups

B)incremental backups

C)split-mirror backups

D)none of the above

Q4) It is important that all discussions and interviews be __________ so that they can be incorporated into what will evolve into the disaster recovery plan.

Q5) It is important to remember that the recovery plan is a(n)__________ document.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Developing Procedures for Special Circumstances

Available Study Resources on Quizplus for this Chatper

20 Verified Questions

20 Flashcards

Source URL: https://quizplus.com/quiz/44520

Sample Questions

Q1) There are occasions when,even though contracts are in place and hardware has been provided as compatible,it is difficult,if not impossible,to __________.

Q2) Your SLAs should limit the number of nested disasters to __________.

A)2

B)5

C)10

D)No limit

Q3) Which of the following is a disaster recovery risk?

A)Everyone is in an unfamiliar location.

B)People are likely to be less mindful of security precautions if they are different than those at the primary work location.

C)The recovery will be performed on different systems than everyone is used to dealing with.

D)All of the above .

Q4) What is the first area where gaps in the recovery plan are identified?

A)Testing

B)Backups

C)Planning

D)Recovery

9

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Testing the Disaster Recovery Plan

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/44521

Sample Questions

Q1) The disaster recovery test needs to have a set of __________so everyone knows whether the plan and the team have passed.

Q2) The least intrusive sections of the plan can be tested _________ hours.

A)after business

B)during normal business

C)during peak business

D)during offline

Q3) What is the main reason organizations give for not testing the recovery plan?

A)it is a drain on time and resources

B)they have confidence in the plan

C)it provides motivation for maintaining and updating the recovery plan

D)it may reveal gaps in the plan

Q4) Which of the following is a reason for testing the disaster recovery plan?

A)determine the feasibility and compatibility of backup facilities and procedures

B)identify areas of the plan that need modification

C)provide training to the team managers and team members on how to recover the organization from a disaster

D)all of the above

To view all questions and flashcards with answers, click on the resource link above.

10

Chapter 9: Continued Assessment of Needs, Threats, and Solutions

Available Study Resources on Quizplus for this Chatper

21 Verified Questions

21 Flashcards

Source URL: https://quizplus.com/quiz/44522

Sample Questions

Q1) What type of threat occurs when a Web page is faked to look exactly like a legitimate company's Web page?

A)Repudiation

B)Denial of Service

C)Tampering

D)Spoofing

Q2) Ideally,every threat should be addressed __________ as it is a gap,a place where your organization may find that it is in danger of a future disaster,or at the very least an emergency situation.

Q3) __________ in some operating systems are well known by some people,and they are more than capable of testing systems to see if one is open.

Q4) What is the next vital step after a recovery test?

A)Decide where to place blame on the things that went wrong.

B)Meet as a team and discuss lessons learned.

C)Determine the order in which backups need to be restored.

D)All of the above.

Q5) It is important,before the team has too long of a period of downtime to forget,that they meet at least once to discuss what was done well,what was done poorly,and what was _________

To view all questions and flashcards with answers, click on the resource link above. Page 11

Turn static files into dynamic content formats.

Create a flipbook
Information Security Management Midterm Exam - 251 Verified Questions by Quizplus - Issuu