Skip to main content

Information Systems Security Administration Exam Questions - 1438 Verified Questions

Page 1


Information Systems Security Administration

Exam Questions

Course Introduction

Information Systems Security Administration provides a comprehensive overview of the principles, practices, and technologies used to protect information assets in organizations. The course covers key topics such as risk assessment, security policies, access control mechanisms, cryptography, network security, and incident response. Students learn to design, implement, and manage security measures to safeguard computer systems and data from internal and external threats. The course emphasizes the role of security administrators in enforcing compliance with legal and ethical standards, developing disaster recovery plans, and supporting business continuity, preparing students for professional roles in information security management.

Recommended Textbook Management of Information Security 3rd Edition by Michael

Available Study Resources on Quizplus

12 Chapters 1438 Verified Questions

1438 Flashcards

Source URL: https://quizplus.com/study-set/2354

Page 2

Chapter 1: Introduction to the Management of Information Security

Available Study Resources on Quizplus for this Chatper

139 Verified Questions

139 Flashcards

Source URL: https://quizplus.com/quiz/46799

Sample Questions

Q1) If you are considering using an automated project management tools,which of the following do you NOT have to keep in mind?

A) Software programs cannot replace skilled and experienced project managers

B) Software tools can get in the way of the work

C) More complex tools make the project more efficient and effective

D) All of these should be kept in mind when using an automated project management tool

Answer: C

Q2) During the transmission of information,algorithms,hash values,and error-correcting codes help ensure the ____ of the information.

A) confidentiality

B) integrity

C) corruption

D) availability

Answer: B

Q3) A manager is responsible for coordinating the completion of tasks.

A)True

B)False

Answer: True

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Planning for Security

Available Study Resources on Quizplus for this Chatper

123 Verified Questions

123 Flashcards

Source URL: https://quizplus.com/quiz/46800

Sample Questions

Q1) The information security governance framework generally consists of which of the following?

A) Security policies that address each aspect of strategy, control, and regulation

B) A security strategy that talks about the value of information technologies protected

C) Institutionalized monitoring processes to ensure compliance and provide feedback on effectiveness and mitigation of risk

D) All of these are components of the information security governance framework

Answer: B

Q2) A(n)____ damages or steals an organization's information or physical asset.

A) attack culprit

B) threat entity

C) catalyst

D) threat agent

Answer: D

Q3) An act or event that exploits a vulnerability is known as a(n)____________________.

Answer: attack

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Planning for Contingencies

Available Study Resources on Quizplus for this Chatper

114 Verified Questions

114 Flashcards

Source URL: https://quizplus.com/quiz/46801

Sample Questions

Q1) When dealing with an incident,the incident response team must conduct a(n)____________________,which entails a detailed examination of the events that occurred from first detection to final recovery.

Answer: after-action review

AAR

Q2) Which of the following is a probable indicator of an actual incident?

A) Presence of unfamiliar files

B) Unusual system crashes

C) Presence of new accounts

D) Presence or execution of unknown programs

Answer: C

Q3) The four components of contingency planning are the ____________________,the incident response plan,the disaster recovery plan,and the business continuity plan.

Answer: BIA

Business Impact Analysis

Q4) Notification from IDS is a probable indicator of an actual incident.

A)True

B)False

Answer: True

Page 5

To view all questions and flashcards with answers, click on the resource link above.

Chapter 4: Information Security Policy

Available Study Resources on Quizplus for this Chatper

133 Verified Questions

133 Flashcards

Source URL: https://quizplus.com/quiz/46802

Sample Questions

Q1) Many organizations create a single document that combines elements of both the management guidance SysSP and the technical specifications SysSP,known as a(n)____.

A) Modular SysSP

B) Combination SysSP

C) Integrated SysSP

D) None of these

Q2) The analysis phase of the SecSDLC in policy development should produce a new or recent<u> risk assessment</u> or IT audit documenting the current information security needs of the organization._________________________

A)True

B)False

Q3) A(n)<u>issue-specific</u> security policy sets the strategic direction,scope,and tone for all of an organization's security efforts._________________________

A)True

B)False

Q4) In order to avoid reprisal or retaliation against employees,reporting of violations of policy should be set up to be ____________________ .

To view all questions and flashcards with answers, click on the resource link above.

6

Chapter 5: Developing the Security Program

Available Study Resources on Quizplus for this Chatper

133 Verified Questions

133 Flashcards

Source URL: https://quizplus.com/quiz/46803

Sample Questions

Q1) ____________________ training consists of trainees learning the specifics of their jobs while working,using the software,hardware,and procedures they will continue to use.

Q2) Large organizations spend an average of ____ of the IT budget on security.

A) 5%

B) 10%

C) 11%

D) 20%

Q3) ____ are accountable for the day-to-day operation of the information security program.

A) Security administrators

B) Security managers

C) Security technicians

D) Security analysts

Q4) A(n)<u>medium</u>-sized organization typically spends about 20 percent of the total IT budget on information security.________________________

A)True

B)False

Q5) Explain the conflict between the goals and objectives of the CIO and the CISO.

Page 7

Q6) List the steps of the seven-step methodology for implementing training.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Security Management Models

Available Study Resources on Quizplus for this Chatper

120 Verified Questions

120 Flashcards

Source URL: https://quizplus.com/quiz/46804

Sample Questions

Q1) Under the Bell-LaPadula model,the ____ property prohibits a subject of lower clearance from reading an object of higher classification,but allows a subject with a higher clearance level to read an object at a lower level.

A) star (*)

B) simple security

C) integrity star (*)

D) simple integrity

Q2) In the ____________________ confidentiality model,rules prevent information from being moved from a level of higher security to a level of lower security.

Q3) The principle by which members of the organization can access the minimum amount of information for the minimum amount of time necessary to perform their required duties is known as ____.

A) need-to-know

B) eyes only

C) least privilege

D) separation of duties

Q4) A(n)____________________ is the outline of an information security blueprint.

Q5) Access controls are build on three key principles.List and briefly define them.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Security Management Practices

Available Study Resources on Quizplus for this Chatper

114 Verified Questions

114 Flashcards

Source URL: https://quizplus.com/quiz/46805

Sample Questions

Q1) It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of

Q2) In information security,two categories of benchmarks are used: standards of due care and due diligence and <u>recommended practices</u>._________________________

A)True

B)False

Q3) In the NIST performance measures implementation process,the comparison of observed measurements with target values is known as a ____ analysis.

A) shortfall

B) gap

C) corrective D) failure

Q4) A(n)____________________ is an external "value or profile of a performance metric against which changes in the performance metric can be usefully compared."

Q5) When choosing from among recommended practices,an organization should consider a number of questions.List four.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Risk Management: Identifying and Assessing Risk

Available Study Resources on Quizplus for this Chatper

78 Verified Questions

78 Flashcards

Source URL: https://quizplus.com/quiz/46806

Sample Questions

Q1) Examples of technical software failures or errors include code problems,unknown loopholes,and ____.

A) bugs

B) piracy

C) employee mistakes

D) equipment failure

Q2) The information technology community often takes on the leadership role in addressing risk.

A)True

B)False

Q3) <u>Weighting </u>criteria can be used to assess the value of information assets or impact evaluation._________________________

A)True

B)False

Q4) ____ should be avoided when identifying people assets.

A) Position titles

B) Roles

C) Security clearance levels

D) Names

To view all questions and flashcards with answers, click on the resource link above. Page 10

Q5) A(n)____________________ number uniquely identifies a specific device.

Chapter 9: Risk Management: Controlling Risk

Available Study Resources on Quizplus for this Chatper

105 Verified Questions

105 Flashcards

Source URL: https://quizplus.com/quiz/46807

Sample Questions

Q1) <u>Mitigation </u>of risk involves applying safeguards that eliminate or reduce the remaining uncontrolled risks._________________________

A)True

B)False

Q2) ____ is the choice to do nothing to protect an information asset from risk and to accept the outcome from any resulting exploitation.

A) Avoidance

B) Acceptance

C) Mitigation

D) Risk tolerance

Q3) The effectiveness of controls should be ____________________ and measured regularly once a control strategy has been selected.

Q4) Which of the following plans would not be a considered a mitigation control approach?

A) Incident response plan

B) Acceptance plan

C) Disaster recovery plan

D) Business continuity plan

To view all questions and flashcards with answers, click on the resource link above.

Chapter 10: Protection Mechanisms

Available Study Resources on Quizplus for this Chatper

133 Verified Questions

133 Flashcards

Source URL: https://quizplus.com/quiz/46808

Sample Questions

Q1) The Internet is an example of a <u>trusted </u>network._________________________

A)True

B)False

Q2) An intrusion detection and prevention device denies access to a system by default.

A)True

B)False

Q3) Although literally hundreds of variations exist,four architectural implementations of firewalls are especially common: packet filtering routers,screened-host firewalls,dual-homed host firewalls,and <u>screened-subnet </u>firewalls.

A)True

B)False

Q4) ____ architecture makes use of a demilitarized zone between the trusted and untrusted network.

A) Dual-homed host firewall

B) Packet filtering router

C) Screened-subnet firewall

D) Screened-host firewall system

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Personnel and Security

Available Study Resources on Quizplus for this Chatper

133 Verified Questions

133 Flashcards

Source URL: https://quizplus.com/quiz/46809

Sample Questions

Q1) <u>Contract</u> workers are brought in by organizations to temporarily fill positions or to supplement the existing workforce._________________________

A)True

B)False

Q2) The CISSP has recently had three concentrations added: the Information Systems Security Architecture Professional (ISSAP),the Information Systems Security Engineering Professional (ISSEP)and the <u>Information Systems Security Management Professional (ISSMP)</u>._________________________

A)True

B)False

Q3) Briefly describe the similarities and differences between the CISSP and CISM certification programs.

Q4) In an organization,the security technician coordinates the information security efforts of all internal groups that have one or more information security-related responsibilities.

A)True

B)False

Q5) The best method of preventing social engineering attacks is

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Law and Ethics

Available Study Resources on Quizplus for this Chatper

113 Verified Questions

113 Flashcards

Source URL: https://quizplus.com/quiz/46810

Sample Questions

Q1) Laws and policies and their associated penalties only deter if three conditions are present.Which of the following is NOT one of these conditions?

A) Fear of penalty

B) Probability of being caught

C) Fear of social contempt

D) Probability of penalty being administered

Q2) ____________________ is the best method for preventing an illegal or unethical activity and includes laws,policies,and technical controls.

Q3) The ____ seeks to educate,train,inform,and involve the business and public sector in information security.

A) National InfraGard Program

B) U.S. Secret Service

C) National Security Agency

D) Information Assurance Directorate

Q4) Credit agencies are exempted from some of the regulations of the Federal Privacy Act so that they can perform their functions.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above.

Page 14

Turn static files into dynamic content formats.

Create a flipbook