

Introduction to Cyber Risk Test Questions
Course Introduction
Introduction to Cyber Risk provides students with a foundational understanding of the crucial concepts, strategies, and technologies involved in identifying, assessing, and managing risks in the digital landscape. The course explores the nature and evolution of cyber threats, common vulnerabilities in information systems, and the impact of cyber risk on individuals, organizations, and society. Through real-world case studies, students will examine risk assessment methodologies, core cybersecurity principles, regulatory requirements, and best practices for mitigating and responding to cyber incidents. By the end of the course, students will be equipped with the knowledge and skills necessary to recognize cyber risks and contribute to the development of effective cybersecurity policies and practices.
Recommended Textbook
Information Security and IT Risk Management 1st Edition by Manish Agrawal
Available Study Resources on Quizplus
14 Chapters
349 Verified Questions
349 Flashcards
Source URL: https://quizplus.com/study-set/3541

Page 2

Chapter 1: Introduction
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70324
Sample Questions
Q1) A desired competency for information security professionals is
A) Marketing
B) End user awareness
C) Financial planning
D) Accounting
Answer: B
Q2) Of the measures you can take to improve your personal security, the least important is
A) Spending lot of money
B) Using end-point virus) protection
C) Automating software updates
D) Using appropriate passwords
Answer: A
Q3) Many users are vulnerable to
A) Attacks on ATM machines
B) Stolen usernames and passwords from a compromised site being used to compromise their bank accounts
C) Hackers compromising the IT systems at large financial institutions
D) Demands for usernames and passwords at gun-point
Answer: B
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: System Administration
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70325
Sample Questions
Q1) Common functions of Linux System Administration utilities include
A) Automated customer service
B) Automated business processing
C) Automated installation
D) Automated marketing
Answer: C
Q2) Active Directory
A) Encourages computer users to perform physical activities throughout the day
B) Adds icons to directories in Windows Explorer
C) Improves search features in Windows computers
D) Provides centralized user management and access control for computers
Answer: D
Q3) Common functions offered by system utilities in the Windows world include
A) Providing surplus capacity, to improve availability
B) Replacing failed components with minimal downtime
C) Automating the collection of music and other multimedia information
D) Automating and auditing the installation and maintenance of software
Answer: D
To view all questions and flashcards with answers, click on the resource link above.
4

Chapter 3: System Administration 2
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70326
Sample Questions
Q1) An example of an absolute path is
A) ./temp.txt
B) /temp.txt
C) temp.txt
D) ../temp.txt
Answer: B
Q2) To view the contents of a folder, we can use the command
A) ls
B) head
C) pwd
D) cd
Answer: A
Q3) Common shell programs include
A) Bourne shell, C shell, D shell
B) Born shell, C shell, Born again shell
C) Korn shell, Born shell, C shell
D) Bourne shell, C shell, Bourne-again shell
Answer: D
To view all questions and flashcards with answers, click on the resource link above.
5

Chapter 4: Basic Information Security Model
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70327
Sample Questions
Q1) A missing authorization vulnerability refers to a situation where
A) Users are allowed access to privileged parts of a program without verification of credentials
B) Input from other users is supplied as output to other users
C) A program puts more data into a storage location than it can hold
D) User input is used without confirming its validity
Q2) Vulnerabilities are
A) Safeguards used to minimize the impact of threats
B) Capabilities, intentions and attack methods of adversaries to cause harm to assets
C) Resource or information that is to be protected
D) Weaknesses in an information system that can lead to a compromise of an asset
Q3) A cross-site scripting vulnerability can occur when
A) Files are accepted as input without verifying their specifications
B) Input from other users is supplied as output to other users
C) A program puts more data into a storage location than it can hold
D) User input is used without confirming its validity
Q4) Vulnerabilities in IT systems can be eliminated through secure coding practices
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Asset Identification and Characterization
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70328
Sample Questions
Q1) Asset sensitivity refers to
A) Data that cannot be disclosed to outsiders
B) Importance of an asset to the immediate survival of an organization
C) The damage caused to an organization from a breach of confidentiality or integrity of an asset
D) Data that is not classified as restricted
Q2) Required assets are those whose loss of availability
A) Could be tolerated for a short period of time
B) Could be acceptable
C) Is not acceptable even for a short period of time
D) Would cause immediate severe repercussions to the organization
Q3) Asset criticality refers to
A) A measure of the importance of an asset to the immediate survival of an organization
B) Contractual arrangements that guide the use of hardware and software assets within the organization
C) Adverse consequences for the organization upon disclosure of information
D) Damage caused to the organization from a breach of confidentiality or violation of integrity of an asset
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Threats and Vulnerabilities
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70329
Sample Questions
Q1) Unapproved software can be a threat action because
A) The software may be exploited by hackers
B) Organizations do not like employees or users to pay for software
C) The software may take up hard disk space
D) The software may have been developed by a competitor
Q2) Natural causes include all of the following except
A) Arson
B) Earthquake
C) Tornadoes
D) Hurricanes
Q3) As a threat action, social engineering is
A) An activity performed by agents to compromise assets
B) Convincing users to do something they would not ordinarily do
C) Software that performs simple tasks automatically and repetitively, usually at the direction of another software
D) Malicious content entered by an end user on a web-based system
To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Encryption Controls
Available Study Resources on Quizplus for this Chatper
24 Verified Questions
24 Flashcards
Source URL: https://quizplus.com/quiz/70330
Sample Questions
Q1) A cryptographic algorithm is
A) Symbols that controls encipherment and decipherment
B) A well-defined sequence of steps used to describe cryptographic processes
C) An encryption method that uses no keys
D) Text that is unintelligible to the reader
Q2) Encryption is
A) The transformation of data to produce ciphertext
B) Text that is unintelligible to the reader
C) A sequence of symbols that controls the operations of encipherment and decipherment
D) A well-defined sequence of steps used to describe cryptographic processes
E) An encryption method that uses no keys
Q3) Ciphertext is
A) The transformation of data to produce ciphertext
B) Text that is unintelligible to the reader
C) A sequence of symbols that controls the operations of encipherment and decipherment
D) A well-defined sequence of steps used to describe cryptographic processes
E) An encryption method that uses no keys
To view all questions and flashcards with answers, click on the resource link above.
9

Chapter 8: Identity and Access Management
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70331
Sample Questions
Q1) A password is
A) The process of proving that a user is the owner of the identity being used
B) A secret series of characters known only to the user
C) The use of minute differences in physical traits to prove identity
D) A protocol that allows nodes in an insecure network to securely identify themselves to each other using tokens
Q2) Match/ merge is an industry term for
A) Identity reconciliation
B) Identity discovery
C) Identity enrichment
D) Access control
Q3) Access management involves
A) Locating all new and updated identities in the organization
B) Comparing each discovered identity to a master record of all individuals in the organization
C) Making decisions about granting users access to resources
D) Collecting data about each individual's relationship to the organization
Q4) Kerberos has been very useful in securing corporate desktop infrastructures
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Hardware and Software Controls
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70332
Sample Questions
Q1) Assessing the safety of a file using scores calculated from its observable attributes is called
A) Reputation based end-point protection
B) Protocol-based end-point protection
C) Anomaly-based end-point protection
D) Signature-based end-point protection
Q2) Password cracking is
A) Passwords on the system known to unauthorized users
B) Acquiring passwords from storage, network transmission or user knowledge
C) Repeated attempts to authenticate using possible passwords
D) Generating character strings to match existing passwords
Q3) An IDS that compares observed activity with defined patterns is a
A) Firewall
B) Signature-based IDS
C) Anomaly-based IDS
D) Protocol-state IDS
Q4) Patches should always be installed as soon as they become available
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 11
Chapter 10: Shell Scripting
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70333
Sample Questions
Q1) The command that will create a new variable in a bash script is A) let firstname = "John"
B) firstname="John"
C) string firstname = "John"
D) str firstname = "John"
Q2) A specific set of commands is to be executed until a pre-specified condition is reached. The most appropriate loop construct to accomplish this is A) for B) while C) do D) if
Q3) The redirect operator used to send the output of a command to a file is written as A) / B) # C) | D) >
To view all questions and flashcards with answers, click on the resource link above.

12

Chapter 11: Incident Handling
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70334
Sample Questions
Q1) Information about the incident should be disseminated
A) Exhaustively, to all constituents
B) Primarily to end users
C) Primarily to the organization's leadership
D) On a need-to-know basis
Q2) The leader of the IRT is preferably
A) Someone from the senior leadership of the organization
B) A technically competent professional with high credibility within the organization
C) The functional leader of the business unit affected by the incident
D) The leader of the IT function within the organization
Q3) Recovery is
A) Saving log files in a server container configured specially for this purpose
B) Preventing the expansion of harm
C) Removing the causes of the adverse event
D) Returning systems to owners for normal operations after the incident
Q4) During an incident, it is advisable to pull members away from current projects to assist the IRT
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Incident Analysis
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70335
Sample Questions
Q1) The application log in Windows will contain logging information from all of the following except
A) Internet Information Services
B) Microsoft Office
C) Video games
D) Databases
Q2) Information about users currently logged into the system is recorded in
A) authlog
B) wtmp
C) messages
D) utmp
Q3) File timestamps can be useful for all of the following except
A) Identifying files manipulated by the hacker
B) Determine how the hacker compromised the system
C) Identifying the attacker
D) Preventing similar attacks on other similar systems
Q4) Cloud storage adds complexity to the work of security administrators
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Policies, Standards and Guidelines
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70336
Sample Questions
Q1) Key information security issues for which an organization should have policies include all of the following except
A) Employee count
B) Incident response
C) Acceptable use
D) Information classification
Q2) To minimize ambiguity, it is a good idea to specify the technologies to be used in a policy
A)True
B)False
Q3) Acceptable use policies describe
A) Procedures that tell units when it would be nice if things were operated a certain way, but it is not a requirement to do so
B) A defined set of rules, accepted and adopted by several organizations
C) Guidelines to users and customers on what is appropriate and what is not appropriate to do with information technology resources
D) A document that records a high-level principle or course of action that has been decided on
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: It Risk Analysis and Risk Management
Available Study Resources on Quizplus for this Chatper
25 Verified Questions
25 Flashcards
Source URL: https://quizplus.com/quiz/70337
Sample Questions
Q1) The motivation for the passage of the Sarbanes-Oxley act was
A) Failure of Internet technologies
B) Denial of culpability by senior executives for falsification of records
C) To prevent stock market crashes
D) To recover retiree savings
Q2) In the NIST 800-39 framework, risk monitoring
A) Addresses how organizations respond to risks
B) Identifies and aggregates the risks facing the organization
C) Describes the environment in which risk-based decisions are made
D) Evaluates the effectiveness of the organization's risk-management plan
Q3) A certain risk has a 1% likelihood of occurrence in the coming year. If the risk is observed, the organization estimates a loss of $1million. A second risk has a 15% likelihood of occurrence in the coming year. If the second risk is observed, the organization estimates a loss of $100,000. Comparing the two risks
A) Risk 2 is greater than risk 1
B) Risk 1 is greater than risk 2
C) Risk 2 is equal to risk 1
D) Risk 2 is negligible
To view all questions and flashcards with answers, click on the resource link above. Page 16