

IT Security Administration Exam
Bank
Course Introduction
IT Security Administration explores the principles and practices essential for safeguarding information technology systems within an organization. The course covers the fundamentals of security policies, risk management, user authentication, access control, firewalls, intrusion detection systems, and secure network design. Students will learn how to implement, monitor, and maintain security measures that protect data and resources from threats and vulnerabilities. Emphasis is placed on best practices for incident response, disaster recovery, regulatory compliance, and the daily operational tasks of IT security administrators. Through hands-on activities and real-world scenarios, students gain practical experience in securing computing environments.
Recommended Textbook Management of Information Security 3rd Edition by Michael E. Whitman
Available Study Resources on Quizplus
12 Chapters
1438 Verified Questions
1438 Flashcards
Source URL: https://quizplus.com/study-set/2354

Page 2
Chapter 1: Introduction to the Management of Information Security
Available Study Resources on Quizplus for this Chatper
139 Verified Questions
139 Flashcards
Source URL: https://quizplus.com/quiz/46799
Sample Questions
Q1) The ____ community supplies and supports information technology appropriate to a business needs.
A) information security
B) information technology
C) general business
D) general public
Answer: B
Q2) Project risk management is very similar to normal security risk management,except the ____ are usually much smaller because the area to be protected is the individual project and not the entire organization.
A) budget and resources
B) scope and scale
C) personnel and management support
D) none of these
Answer: B
Q3) The ____________________ process provides assurance that the user has been specifically and explicitly authorized by the proper authority to access,update,or delete the contents of an information asset.
Answer: authorization

Page 3
To view all questions and flashcards with answers, click on the resource link above.

Chapter 2: Planning for Security
Available Study Resources on Quizplus for this Chatper
123 Verified Questions
123 Flashcards
Source URL: https://quizplus.com/quiz/46800
Sample Questions
Q1) A(n)____ damages or steals an organization's information or physical asset.
A) attack culprit
B) threat entity
C) catalyst
D) threat agent
Answer: D
Q2) Information security governance consists of the leadership,organizational structures,and processes that safeguard information.Critical to the success of these structures and processes is effective interoperability between all parties,which requires constructive relationships,a common language,and shared commitment to addressing the issues.
A)True
B)False
Answer: False
Q3) Data ____________________ are responsible for the security and use of a particular set of information.
Answer: owners
Q4) An act or event that exploits a vulnerability is known as a(n)____________________.
Answer: attack
To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Planning for Contingencies
Available Study Resources on Quizplus for this Chatper
114 Verified Questions
114 Flashcards
Source URL: https://quizplus.com/quiz/46801
Sample Questions
Q1) The ____________________ team is charged with setting up and starting off-site operations in the event of an incident or disaster.
Answer: business continuity
Q2) The presence of hacker tools in a system definitely signals that an incident is in progress or has occurred.
A)True
B)False
Answer: True
Q3) ____________________ is a set of procedures that commence when an incident is detected.
Answer: Incident response IR
Q4) The bulk batch-transfer of data to an off-site facility is known as ____________________.
Answer: electronic vaulting
Q5) To perform parallel testing,the operations of the business must be halted.
A)True
B)False
Answer: False
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Information Security Policy
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46802
Sample Questions
Q1) In the Flesch Reading Ease scale,the higher the score,the harder it is to understand the writing.
A)True
B)False
Q2) Practices are created from ____.
A) profiles
B) procedures
C) guidelines
D) standards
Q3) A(n)<u>individual </u>approach to creating the ISSPs can suffer from poor policy dissemination,enforcement,and review._________________________
A)True
B)False
Q4) Standards are created from ____.
A) policies
B) guidelines
C) procedures
D) practices
Q5) List and briefly describe the major components of the ISSP.
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Developing the Security Program
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46803
Sample Questions
Q1) A security ____________________ is the most cost-effective method of disseminating security information and news to employees.
Q2) The information security budgets of very large organizations grow faster than their IT budgets.
A)True
B)False
Q3) The typical security staff in a small organization consists of ____.
A) one person
B) one to two people
C) one to three people
D) two to five people
Q4) To their advantage,some observers feel that small organizations avoid some threats precisely because of their<u> small size</u>._________________________
A)True
B)False
Q5) Training for management should be conducted in large groups.
A)True
B)False
Q6) List the steps of the seven-step methodology for implementing training.
Page 7
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Security Management Models
Available Study Resources on Quizplus for this Chatper
120 Verified Questions
120 Flashcards
Source URL: https://quizplus.com/quiz/46804
Sample Questions
Q1) The Brewer-Nash model is commonly known as a Japanese wall.
A)True
B)False
Q2) ____ access controls are implemented at the option of the data user.
A) Mandatory
B) Nondiscretionary
C) Discretionary
D) Lattice-based
Q3) There are two types of covert channels,storage channels and network channels.
A)True
B)False
Q4) Under the Biba model,the ____ property permits a subject to have read access to an object only if the security level of the subject is either lower or equal to the level of the object.
A) star (*)
B) simple security
C) integrity star (*)
D) simple integrity
Q5) ____________________ controls remedy a circumstance or mitigate damage done during an incident
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Security Management Practices
Available Study Resources on Quizplus for this Chatper
114 Verified Questions
114 Flashcards
Source URL: https://quizplus.com/quiz/46805
Sample Questions
Q1) One of the fundamental challenges in information security performance measurement is the definition of ____ security.
A) effective
B) modern
C) information
D) efficient
Q2) NIST recommends the documentation of each performance measure in a customized format to ensure repeatability of measures development,tailoring,collection,and reporting activities.
A)True
B)False
Q3) Organizations typically use three types of performance measures,including those that assess the impact of a(n)____________________ or other security event on the organization or its mission.
Q4) Another way to create a blueprint is to look at the paths taken by organizations similar to the one whose plan you are developing,known as baselining.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above.
Page 9
Chapter 8: Risk Management: Identifying and Assessing Risk
Available Study Resources on Quizplus for this Chatper
78 Verified Questions
78 Flashcards
Source URL: https://quizplus.com/quiz/46806
Sample Questions
Q1) Organizations should have a data classification scheme categorizing information assets based on their sensitivity and security needs; for example: confidential,internal and public.
A)True
B)False
Q2) Risk is the likelihood of the occurrence of a vulnerability multiplied by the value of the information asset minus the percentage of risk mitigated by current controls plus the uncertainty of current knowledge of the <u>vulnerability</u>._________________________
A)True
B)False
Q3) The ultimate goal of risk identification is to assess the circumstances and setting of each information asset to reveal any<u> threats</u>._________________________
A)True
B)False
Q4) Assessing risks includes assigning a value to each information asset. A)True
B)False

10
Q5) A(n)____________________ number uniquely identifies a specific device.
To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Risk Management: Controlling Risk
Available Study Resources on Quizplus for this Chatper
105 Verified Questions
105 Flashcards
Source URL: https://quizplus.com/quiz/46807
Sample Questions
Q1) If the organization has information assets totaling 1 million dollars,how much should the organization spend to protect them?
A) $10,000
B) $100,000
C) 1 million dollars
D) an appropriate amount determined through an effective cost-benefit analysis
Q2) <u>Mitigation </u>of risk involves applying safeguards that eliminate or reduce the remaining uncontrolled risks._________________________
A)True
B)False
Q3) The ____ is the calculation of the value associated with the most likely loss from an attack.
A) SLE
B) ALE
C) CBA
D) ARO
Q4) Risk ____________________ defines the quantity and nature of risk that an organization is willing to accept.
Q5) What is a cost/benefit analysis and how is it calculated?
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Protection Mechanisms
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46808
Sample Questions
Q1) Automated control systems for the most part can learn from mistakes,and they can adapt to changing situations.
A)True
B)False
Q2) Which of the following biometric authentication systems is the most accepted by users?
A) Keystroke pattern recognition
B) Fingerprint recognition
C) Voice pattern recognition
D) Retina pattern recognition
Q3) The intermediate area between trusted and untrusted networks is referred to as the ____.
A) safety zone
B) cache
C) demilitarized zone
D) proxy
Q4) "Something you are" and "something you ____________________" are considered to be biometric.
Q5) Describe and provide an example for each of the four types of authentication mechanisms.
To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Personnel and Security
Available Study Resources on Quizplus for this Chatper
133 Verified Questions
133 Flashcards
Source URL: https://quizplus.com/quiz/46809
Sample Questions
Q1) In their efforts to hire an effective mix of information security personnel,organizations have control over the supply and demand of varied skills and experience levels that the market has to offer.
A)True
B)False
Q2) In the classification of information security positions,the real technical types who create and install security solutions fall under the category of those that <u>define</u>._________________________
A)True
B)False
Q3) ____ is one of the practice areas covered by the CISM examination.
A) Infrastructure security
B) Communication security
C) Response management
D) Protection of information assets
Q4) The most common qualification for the CISO is the certification.
Q5) The ____________________ prohibits employers from obtaining a credit report without the candidate's written consent.
Page 13
To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Law and Ethics
Available Study Resources on Quizplus for this Chatper
113 Verified Questions
113 Flashcards
Source URL: https://quizplus.com/quiz/46810
Sample Questions
Q1) ____ law is classified as a private law.
A) Commercial
B) Administrative
C) Criminal
D) Constitutional
Q2) The organizations must choose one of two approaches when employing digital forensics; ____ and ____.
A) Protect and forget; Apprehend and prosecute
B) Protect and prosecute; Apprehend and pursue
C) Patch and proceed; Protect and forget
D) Pursue and prosecute; Identify and apprehend
Q3) By enacting the ____ in 1996,Congress sought to protect intellectual property and competitive advantage.
A) DMCA
B) EEA
C) HIPAA
D) FOIA
Q4) ____________________ law covers a wide variety of laws pertaining to relationships between and among individuals and organizations.
To view all questions and flashcards with answers, click on the resource link above. Page 14