

Information Systems Security Administration
Exam Questions
Course Introduction
Information Systems Security Administration provides a comprehensive overview of the principles, practices, and technologies used to protect information assets in organizations. The course covers key topics such as risk assessment, security policies, access control mechanisms, cryptography, network security, and incident response. Students learn to design, implement, and manage security measures to safeguard computer systems and data from internal and external threats. The course emphasizes the role of security administrators in enforcing compliance with legal and ethical standards, developing disaster recovery plans, and supporting business continuity, preparing students for professional roles in information security management.
Recommended Textbook Management of Information Security 3rd Edition by Michael
Available Study Resources on Quizplus
12 Chapters 1438 Verified Questions
1438 Flashcards
Source URL: https://quizplus.com/study-set/2354

Page 2
E. Whitman

Chapter 1: Introduction to the Management of Information Security
Available Study Resources on Quizplus for this Chatper
139 Verified Questions
139 Flashcards
Source URL: https://quizplus.com/quiz/46799
Sample Questions
Q1) If you are considering using an automated project management tools,which of the following do you NOT have to keep in mind?
A) Software programs cannot replace skilled and experienced project managers
B) Software tools can get in the way of the work
C) More complex tools make the project more efficient and effective
D) All of these should be kept in mind when using an automated project management tool
Answer: C
Q2) During the transmission of information,algorithms,hash values,and error-correcting codes help ensure the ____ of the information.
A) confidentiality
B) integrity
C) corruption
D) availability
Answer: B
Q3) A manager is responsible for coordinating the completion of tasks.
A)True
B)False
Answer: True
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Planning for Security
Available Study Resources on Quizplus for this Chatper
123 Verified Questions
123 Flashcards
Source URL: https://quizplus.com/quiz/46800
Sample Questions
Q1) The information security governance framework generally consists of which of the following?
A) Security policies that address each aspect of strategy, control, and regulation
B) A security strategy that talks about the value of information technologies protected
C) Institutionalized monitoring processes to ensure compliance and provide feedback on effectiveness and mitigation of risk
D) All of these are components of the information security governance framework
Answer: B
Q2) A(n)____ damages or steals an organization's information or physical asset.
A) attack culprit
B) threat entity
C) catalyst
D) threat agent
Answer: D
Q3) An act or event that exploits a vulnerability is known as a(n)____________________.
Answer: attack
To view all questions and flashcards with answers, click on the resource link above. Page 4
Chapter 3: Planning for Contingencies
Available Study Resources on Quizplus for this Chatper
114 Verified Questions
114 Flashcards
Source URL: https://quizplus.com/quiz/46801
Sample Questions
Q1) When dealing with an incident,the incident response team must conduct a(n)____________________,which entails a detailed examination of the events that occurred from first detection to final recovery.
Answer: after-action review
AAR
Q2) Which of the following is a probable indicator of an actual incident?
A) Presence of unfamiliar files
B) Unusual system crashes
C) Presence of new accounts
D) Presence or execution of unknown programs
Answer: C
Q3) The four components of contingency planning are the ____________________,the incident response plan,the disaster recovery plan,and the business continuity plan.
Answer: BIA
Business Impact Analysis
Q4) Notification from IDS is a probable indicator of an actual incident.
A)True
B)False
Answer: True

Page 5
To view all questions and flashcards with answers, click on the resource link above.

Chapter 4: Information Security Policy
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46802
Sample Questions
Q1) Many organizations create a single document that combines elements of both the management guidance SysSP and the technical specifications SysSP,known as a(n)____.
A) Modular SysSP
B) Combination SysSP
C) Integrated SysSP
D) None of these
Q2) The analysis phase of the SecSDLC in policy development should produce a new or recent<u> risk assessment</u> or IT audit documenting the current information security needs of the organization._________________________
A)True
B)False
Q3) A(n)<u>issue-specific</u> security policy sets the strategic direction,scope,and tone for all of an organization's security efforts._________________________
A)True
B)False
Q4) In order to avoid reprisal or retaliation against employees,reporting of violations of policy should be set up to be ____________________ .
To view all questions and flashcards with answers, click on the resource link above.
6

Chapter 5: Developing the Security Program
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46803
Sample Questions
Q1) ____________________ training consists of trainees learning the specifics of their jobs while working,using the software,hardware,and procedures they will continue to use.
Q2) Large organizations spend an average of ____ of the IT budget on security.
A) 5%
B) 10%
C) 11%
D) 20%
Q3) ____ are accountable for the day-to-day operation of the information security program.
A) Security administrators
B) Security managers
C) Security technicians
D) Security analysts
Q4) A(n)<u>medium</u>-sized organization typically spends about 20 percent of the total IT budget on information security.________________________
A)True
B)False
Q5) Explain the conflict between the goals and objectives of the CIO and the CISO.
Page 7
Q6) List the steps of the seven-step methodology for implementing training.
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Security Management Models
Available Study Resources on Quizplus for this Chatper
120 Verified Questions
120 Flashcards
Source URL: https://quizplus.com/quiz/46804
Sample Questions
Q1) Under the Bell-LaPadula model,the ____ property prohibits a subject of lower clearance from reading an object of higher classification,but allows a subject with a higher clearance level to read an object at a lower level.
A) star (*)
B) simple security
C) integrity star (*)
D) simple integrity
Q2) In the ____________________ confidentiality model,rules prevent information from being moved from a level of higher security to a level of lower security.
Q3) The principle by which members of the organization can access the minimum amount of information for the minimum amount of time necessary to perform their required duties is known as ____.
A) need-to-know
B) eyes only
C) least privilege
D) separation of duties
Q4) A(n)____________________ is the outline of an information security blueprint.
Q5) Access controls are build on three key principles.List and briefly define them.
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Security Management Practices
Available Study Resources on Quizplus for this Chatper
114 Verified Questions
114 Flashcards
Source URL: https://quizplus.com/quiz/46805
Sample Questions
Q1) It is no longer sufficient to simply assert effective information security; an organization must demonstrate that it is taking effective measures in the spirit of
Q2) In information security,two categories of benchmarks are used: standards of due care and due diligence and <u>recommended practices</u>._________________________
A)True
B)False
Q3) In the NIST performance measures implementation process,the comparison of observed measurements with target values is known as a ____ analysis.
A) shortfall
B) gap
C) corrective D) failure
Q4) A(n)____________________ is an external "value or profile of a performance metric against which changes in the performance metric can be usefully compared."
Q5) When choosing from among recommended practices,an organization should consider a number of questions.List four.
To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Risk Management: Identifying and Assessing Risk
Available Study Resources on Quizplus for this Chatper
78 Verified Questions
78 Flashcards
Source URL: https://quizplus.com/quiz/46806
Sample Questions
Q1) Examples of technical software failures or errors include code problems,unknown loopholes,and ____.
A) bugs
B) piracy
C) employee mistakes
D) equipment failure
Q2) The information technology community often takes on the leadership role in addressing risk.
A)True
B)False
Q3) <u>Weighting </u>criteria can be used to assess the value of information assets or impact evaluation._________________________
A)True
B)False
Q4) ____ should be avoided when identifying people assets.
A) Position titles
B) Roles
C) Security clearance levels
D) Names
To view all questions and flashcards with answers, click on the resource link above. Page 10
Q5) A(n)____________________ number uniquely identifies a specific device.

Chapter 9: Risk Management: Controlling Risk
Available Study Resources on Quizplus for this Chatper
105 Verified Questions
105 Flashcards
Source URL: https://quizplus.com/quiz/46807
Sample Questions
Q1) <u>Mitigation </u>of risk involves applying safeguards that eliminate or reduce the remaining uncontrolled risks._________________________
A)True
B)False
Q2) ____ is the choice to do nothing to protect an information asset from risk and to accept the outcome from any resulting exploitation.
A) Avoidance
B) Acceptance
C) Mitigation
D) Risk tolerance
Q3) The effectiveness of controls should be ____________________ and measured regularly once a control strategy has been selected.
Q4) Which of the following plans would not be a considered a mitigation control approach?
A) Incident response plan
B) Acceptance plan
C) Disaster recovery plan
D) Business continuity plan
To view all questions and flashcards with answers, click on the resource link above.

Chapter 10: Protection Mechanisms
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46808
Sample Questions
Q1) The Internet is an example of a <u>trusted </u>network._________________________
A)True
B)False
Q2) An intrusion detection and prevention device denies access to a system by default.
A)True
B)False
Q3) Although literally hundreds of variations exist,four architectural implementations of firewalls are especially common: packet filtering routers,screened-host firewalls,dual-homed host firewalls,and <u>screened-subnet </u>firewalls.
A)True
B)False
Q4) ____ architecture makes use of a demilitarized zone between the trusted and untrusted network.
A) Dual-homed host firewall
B) Packet filtering router
C) Screened-subnet firewall
D) Screened-host firewall system
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Personnel and Security
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46809
Sample Questions
Q1) <u>Contract</u> workers are brought in by organizations to temporarily fill positions or to supplement the existing workforce._________________________
A)True
B)False
Q2) The CISSP has recently had three concentrations added: the Information Systems Security Architecture Professional (ISSAP),the Information Systems Security Engineering Professional (ISSEP)and the <u>Information Systems Security Management Professional (ISSMP)</u>._________________________
A)True
B)False
Q3) Briefly describe the similarities and differences between the CISSP and CISM certification programs.
Q4) In an organization,the security technician coordinates the information security efforts of all internal groups that have one or more information security-related responsibilities.
A)True
B)False
Q5) The best method of preventing social engineering attacks is
To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Law and Ethics
Available Study Resources on Quizplus for this Chatper
113 Verified Questions
113 Flashcards
Source URL: https://quizplus.com/quiz/46810
Sample Questions
Q1) Laws and policies and their associated penalties only deter if three conditions are present.Which of the following is NOT one of these conditions?
A) Fear of penalty
B) Probability of being caught
C) Fear of social contempt
D) Probability of penalty being administered
Q2) ____________________ is the best method for preventing an illegal or unethical activity and includes laws,policies,and technical controls.
Q3) The ____ seeks to educate,train,inform,and involve the business and public sector in information security.
A) National InfraGard Program
B) U.S. Secret Service
C) National Security Agency
D) Information Assurance Directorate
Q4) Credit agencies are exempted from some of the regulations of the Federal Privacy Act so that they can perform their functions.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above.
Page 14