Skip to main content

IT Governance and Compliance Practice Exam - 349 Verified Questions

Page 1


IT Governance and Compliance Practice Exam

Course Introduction

This course explores the frameworks, practices, and regulations that guide the effective management and oversight of information technology within organizations. Students will learn how IT governance aligns technology strategies with business goals, manages risks, and ensures compliance with relevant laws, standards, and ethical guidelines. Emphasis is placed on understanding control mechanisms, policy development, audit processes, and compliance requirements such as GDPR, HIPAA, and SOX. By examining real-world cases and industry standards like COBIT and ISO/IEC 38500, students gain practical skills for implementing governance structures that foster transparency, accountability, and value creation in the use of IT resources.

Recommended Textbook

Information Security and IT Risk Management 1st Edition by Manish Agrawal

Available Study Resources on Quizplus

14 Chapters

349 Verified Questions

349 Flashcards

Source URL: https://quizplus.com/study-set/3541 Page 2

Chapter 1: Introduction

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70324

Sample Questions

Q1) Information security professional report spending a lot of time on

A) Researching new technologies

B) Political issues

C) Developing internal security policies, standards and procedures

D) Fixing software bugs

Answer: D

Q2) Confidentiality is

A) Protecting information and information systems from unauthorized use

B) Preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information Choices

C) Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity

D) Ensuring timely and reliable access to and use of information

Answer: B

To view all questions and flashcards with answers, click on the resource link above.

3

Chapter 2: System Administration

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70325

Sample Questions

Q1) Writing the necessary data in the appropriate locations on a computer 's hard drive for running a software program is called

A) Configuration

B) Access control

C) Installation

D) User management

Answer: C

Q2) The types of monitoring include

A) Penetration testing and access control

B) Health checking and log monitoring

C) Nagios and log monitoring

D) Reactive monitoring and pro-active testing

Answer: D

Q3) The domain controller in Active Directory

A) Serves web pages in the domain

B) Bills users in the domain

C) Implements the active directory rules in the domain

D) Installs updated on all computers in the domain

Answer: C

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: System Administration 2

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70326

Sample Questions

Q1) To view the contents of a file, we can use the command

A) less

B) more

C) cat

D) all of the above

Answer: D

Q2) In the context of system administration, the shell is

A) Software that manages computer hardware and provides common services to user applications

B) Software which controls hardware devices, manages memory, and hides underlying physical hardware from user applications

C) A text based program that allows users to interact with the shell

D) The graphical interface for users to interact with applications

Answer: C

Q3) The command used to copy files in Unix/ Linus is

A) cp

B) copy

C) pwd

D) rm

Answer: A

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Basic Information Security Model

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70327

Sample Questions

Q1) Threats are

A) Safeguards used to minimize the impact of threats

B) Capabilities, intentions and attack methods of adversaries to cause harm to assets

C) Resource or information that is to be protected

D) Weaknesses in an information system that can lead to a compromise of an asset

Q2) Vulnerabilities in IT systems can be eliminated through secure coding practices

A)True

B)False

Q3) Relative to physical security, information security is challenging because

A) Assets are largely invisible

B) Most assets are easily duplicated

C) Both the above

D) None of the above

Q4) Zero-day exploits are

A) Software used to hide the existence of malicious software on computer systems

B) Exploits that compromise a previously unknown software vulnerability

C) Computers that perform malicious tasks at the direction of a remote controller

D) Manipulating people into performing desired actions

To view all questions and flashcards with answers, click on the resource link above.

6

Chapter 5: Asset Identification and Characterization

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70328

Sample Questions

Q1) Essential assets are those whose loss of availability

A) Could be acceptable

B) Could be tolerated for a short period of time

C) Could cause confidentiality breaches

D) Would cause immediate severe repercussions to the organization

Q2) An example of a top-down approach to asset identification is

A) Reading the mission statement of the organization

B) Talking to co-workers

C) Reading on-boarding documentation

D) All of the above

Q3) Restricted assets are

A) Assets whose loss would cause severe repercussions to the organization immediately

B) Importance of an asset to the immediate survival of an organization

C) The damage caused to an organization from a breach of confidentiality or integrity of an asset

D) Assets whose disclosure or alteration would have adverse consequences for the organization

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Threats and Vulnerabilities

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70329

Sample Questions

Q1) Most attacks on organizations originate from

A) Internal agents

B) External agents

C) Partners

D) Competitors, organized groups and former employees

Q2) The threat model includes

A) Actors, agents and assistants

B) Actions, assets and ambitions

C) Agents, actions and assets

D) Agents, actors and assets

Q3) Phishing is

A) An activity performed by agents to compromise assets

B) Convincing users to do something they would not ordinarily do

C) Using email to try and get a user to divulge confidential information

D) Malicious content entered by an end user on a web-based system

Q4) In the information security context, Black Tuesday refers to

A) The day Google's stock fell by 50% immediately after its IPO

B) The day a company finally turns profitable for the year

C) The day the firm lost a bulk of its email

D) The typical day on which Microsoft releases patches

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Encryption Controls

Available Study Resources on Quizplus for this Chatper

24 Verified Questions

24 Flashcards

Source URL: https://quizplus.com/quiz/70330

Sample Questions

Q1) The first documented instance of encryption was used by

A) Egyptian pharaoh Tutankhamun

B) Italian inventor Leonardo da Vinci

C) Italian artist Michelangelo

D) Roman Emperor Julius Caesar

Q2) Claude Shannon developed the framework for secrecy known as

A) Confusion diffusion

B) 4P model

C) 4C model

D) Inversion of control

Q3) The current standard for secret key encryption is

A) DES Data Encryption Standard

B) AES Advanced Encryption Standard

C) IDEA International Data Encryption Algorithm

D) SHA Secure Hash Algorithm

Q4) The popular encryption method RSA is an example of

A) Secret key encryption

B) Public key encryption

C) Hash functions

D) AES

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Identity and Access Management

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70331

Sample Questions

Q1) The stages in identity management are

A) Denial, anger, bargaining, acceptance

B) Plan, do, check, act

C) Plan, acquire, deploy, manage

D) Discovery, reconciliation and enrichment

Q2) OpenID uses an

A) Insecure model of authentication

B) Centralized model for authentication

C) Federated model for authentication

D) Distributed model for authentication

Q3) Identity reconciliation involves

A) Locating all new and updated identities in the organization

B) Comparing each discovered identity to a master record of all individuals in the organization

C) Collecting data about each individual's relationship to the organization

D) Making decisions about granting users access to resources

Q4) Kerberos has been very useful in securing web applications

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Hardware and Software Controls

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70332

Sample Questions

Q1) Considerations while prioritizing patches include all of the following except the A) Importance of the vulnerability

B) Importance of the system to be patched

C) Licensing costs

D) Dependencies with other patches

Q2) In enterprise networks, power users can facilitate patch management by

A) Administering as much of the patch management themselves as possible

B) Setting automatic updates to as many services and software as possible

C) Using department funds to deploy local patch management systems to as many systems as possible

D) Allowing system administrators to controls as much of the patch management as possible

Q3) A password policy is

A) A set of rules for using passwords

B) Acquiring passwords from storage, network transmission or user knowledge

C) Repeated attempts to authenticate using possible passwords

D) Generating character strings to match existing passwords

To view all questions and flashcards with answers, click on the resource link above.

11

Chapter 10: Shell Scripting

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70333

Sample Questions

Q1) The command to view the contents of a variable at the shell prompt is

A) variablename

B) echo variablename

C) echo $variablename

D) $variablename

Q2) The first line of an executable script needs to be #!/bin/bash, in order to

A) Inform the shell which shell interpreter to use to execute the script

B) Remind the user of the shell interpreter to use when executing the script

C) Remind the user of the shell interpreter used to create the script

D) Serve as a comment for the shell interpreter when executing the script

Q3) Shell scripts are

A) A list of shell commands in a text file

B) Scripts used as a shell, with no content until used

C) A type of compiled programs

D) Lists of drugs prescribed by a physician

Q4) A user needs the following permissions to be able to use a script as a command

A) Read and write

B) Write

C) Read

D) Execute

Page 12

To view all questions and flashcards with answers, click on the resource link above.

Chapter 11: Incident Handling

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70334

Sample Questions

Q1) In the context of monitoring, a false positive is

A) An undetected problem

B) A component that is working intermittently

C) A component that is likely to fail soon

D) An alert that upon further investigation turns out to be not a problem

Q2) Performance records of a machine are called

A) Configuration files

B) Sysadmin

C) Logs

D) Debian

Q3) Containment is

A) Saving log files in a server container configured specially for this purpose

B) Preventing the expansion of harm

C) Removing the causes of the adverse event

D) Returning systems to owners for normal operations after the incident

Q4) Eradication is

A) Saving log files in a server container configured specially for this purpose

B) Preventing the expansion of harm

C) Removing the causes of the adverse event

D) Returning systems to owners for normal operations after the incident

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Incident Analysis

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70335

Sample Questions

Q1) Windows logs are also known as

A) Microsoft logs

B) Application logs

C) Operating system logs

D) Event logs

Q2) Developers use logs to

A) Analyze security incidents

B) Ensure that the application is behaving as expected

C) Monitor disk space requirements of applications

D) Ensure optimum performance of the application

Q3) File timestamps are known as MAC timestamps, where MAC stands for

A) Medium access control

B) Modification, access, creation

C) Multiple account creation

D) Media, agent and creativity

Q4) In IT, BYOD stands for

A) Bring your own drink

B) Buy your own drink

C) Buy your own dress'

D) Bring your own device

To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Policies, Standards and Guidelines

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70336

Sample Questions

Q1) The need for the policy is specified in the

A) Scope

B) Statement

C) Overview

D) Enforcement

Q2) A policy is

A) Procedures that tell units when it would be nice if things were operated a certain way, but it is not a requirement to do so

B) Guidelines to users and customers on what is appropriate and what is not appropriate to do with information technology resources

C) A document that records a high-level principle or course of action that has been decided on

D) A defined set of rules, accepted and adopted by several organizations

Q3) To minimize ambiguity, it is a good idea to specify the technologies to be used in a policy

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: It Risk Analysis and Risk Management

Available Study Resources on Quizplus for this Chatper

25 Verified Questions

25 Flashcards

Source URL: https://quizplus.com/quiz/70337

Sample Questions

Q1) Risk is quantified by taking the product of

A) Hours and hourly rates

B) GDP and growth rate

C) Likelihood and magnitude

D) Risk frame and risk assessment

Q2) The NIST risk management framework includes

A) Profits, losses

B) Agent, action, asset

C) Assets, threats, vulnerabilities, controls

D) Frame, assess, monitor, respond

Q3) Risk is

A) A quantified measure of the potential damage caused by a specified threat

B) Capabilities, intentions and attack methods of adversaries to cause harm to assets

C) Resource or information that is to be protected

D) Weaknesses in an information system that can lead to a compromise of an asset

Q4) A given threat is usually associated with one risk

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 16

Turn static files into dynamic content formats.

Create a flipbook
IT Governance and Compliance Practice Exam - 349 Verified Questions by Quizplus - Issuu