Skip to main content

IT Security and Risk Management Exam Solutions - 696 Verified Questions

Page 1


IT Security and Risk Management

Exam Solutions

Course Introduction

This course provides an in-depth exploration of IT security principles and risk management strategies essential for protecting information systems in organizations. Students will learn about various types of security threats, vulnerabilities, and the frameworks used to assess and mitigate risks in IT environments. Topics include security policies, access control, cryptography, security operations, incident response, and compliance with legal and regulatory standards. Through case studies and real-world scenarios, learners will develop the skills necessary to identify, evaluate, and manage security risks, as well as to implement effective security measures and best practices to safeguard digital assets.

Recommended Textbook

Principles of Information Security 5th Edition by Michael E. Whitman

Available Study Resources on Quizplus

12 Chapters

696 Verified Questions

696 Flashcards

Source URL: https://quizplus.com/study-set/2374 Page 2

Chapter 1: Introduction to the Management of Information Security

Available Study Resources on Quizplus for this Chatper

63 Verified Questions

63 Flashcards

Source URL: https://quizplus.com/quiz/47110

Sample Questions

Q1) Which of the following is NOT a primary function of Information Security Management?

A) planning

B) protection

C) projects

D) performance

Answer: D

Q2) Which of the following is the first step in the problem-solving process?

A) Analyze and compare the possible solutions

B) Develop possible solutions

C) Recognize and define the problem

D) Select, implement and evaluate a solution

Answer: C

Q3) The <U>malicious</U> code attack includes the execution of viruses,worms,Trojan horses,and active Web scripts with the intent to destroy or steal information._________________________

A)True

B)False

Answer: True

Page 3

To view all questions and flashcards with answers, click on the resource link above.

Chapter 2: Compliance: Law and Ethics

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/47111

Sample Questions

Q1) The Secret Service is charged with the detection and arrest of any person committing a U.S.federal offense relating to computer fraud,as well as false identification crimes.

A)True

B)False

Answer: True

Q2) InfraGard began as a cooperative effortbetween the FBI's Cleveland field office and local<U> intelligence</U> professionals. ___________

A)True

B)False

Answer: False

Q3) The Gramm-Leach-Bliley (GLB)Act (alsoknown as the <U>Financial</U> Services Modernization Act of 1999)contains a number of provisionsthat affect banks,securities firms,and insurance companies.___________

A)True

B)False

Answer: True

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Governance and Strategic Planning for Security

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/47112

Sample Questions

Q1) _________resources include people,hardware,and the supporting system elements and resources associated with the management of information in all its states.

Answer: Physical

Q2) What is the first phase of the SecSDLC?

A) analysis

B) investigation

C) logical design

D) physical design

Answer: B

Q3) A set of security tests and evaluations that simulate attacks by a malicious external source is known as ____________.

A) vulnerability assessment

B) penetration testing

C) exploit identification

D) safeguard neutralization

Answer: B

Q4) The ______________________ phase is the last phase of SecSDLC,but perhaps the most important.

Answer: maintenance and change

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Information Security Policy

Available Study Resources on Quizplus for this Chatper

56 Verified Questions

56 Flashcards

Source URL: https://quizplus.com/quiz/47113

Sample Questions

Q1) In which phase of the development of an InfoSec policy must a plan to distribute the policies be developed?Why is this important?

Q2) In addition to specifying the penalties for unacceptable behavior,what else must a policy specify?

A) appeals process

B) legal recourse

C) what must be done to comply

D) the proper operation of equipment

Q3) <U>Technology</U> is the essential foundation of an effective information security program._____________

A)True

B)False

Q4) Policies must specify penalties for unacceptable behavior and define an appeals process.

A)True B)False

Q5) The responsibilities of both the users and the systems administrators with regard to specific systems administration duties should be specified in the ____________________ section of the ISSP.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Developing the Security Program

Available Study Resources on Quizplus for this Chatper

55 Verified Questions

55 Flashcards

Source URL: https://quizplus.com/quiz/47114

Sample Questions

Q1) What are some of the variables that determine how a given organization chooses to construct its InfoSec program?

Q2) The purpose of SETA is to enhance security in all but which of the following ways?

A) by building in-depth knowledge

B) by adding barriers

C) by developing skills

D) by improving awareness

Q3) Legal assessment for the implementation of the information security program is almost always done by the information security or IT departments.

A)True

B)False

Q4) A(n)____________________ is a specific point in the project plan when a task that has a noticeable impact on plan's the progress is complete.

Q5) The project planner should describe the skills or personnel needed for a task,often referred to as a(n)____________________,needed to accomplish a task.

Q6) What is the role of help desk personnel in the InfoSec team?

Q7) What minimum attributes for project tasks does the WBS document?

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Risk Management: Identifying and Assessing Risk

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47115

Sample Questions

Q1) Some threats can manifest in multiple ways,yielding multiple<U> exploits</U> for an asset-threat pair. ____________

A)True

B)False

Q2) A formal access control methodology used to assign a level ofconfidentiality to an information asset and thus restrict the number of people who can access it is known as a data <U>categorization</U> scheme.____________

A)True

B)False

Q3) The Australian and New Zealand Risk Management Standard 4360 uses qualitative methods to determine risk based on a threat's probability of occurrence and expected results of a successful attack.

A)True B)False

Q4) Describe the use of an IP address when deciding which attributes to track for each information asset.

Q5) List the stages in the risk identification process in order of occurrence.

Page 8

Q6) What are the included tasks in the identification of risks?

Q7) For the purposes of relative risk assessment how is risk calculated?

To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Risk Management: Controlling Risk

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47116

Sample Questions

Q1) In which technique does a group rate or rank a set of information,compile the results and repeat until everyone is satisfied with the result?

A) OCTAVE

B) FAIR

C) Hybrid Measures

D) Delphi

Q2) What is the result of subtracting the post-control annualized loss expectancy and the ACS from the pre-control annualized loss expectancy?

A) cost-benefit analysis

B) exposure factor

C) single loss expectancy

D) annualized rate of occurrence

Q3) A <U>benchmark </U>is derived by comparing measured actual performance against established standards for the measured category.____________

A)True

B)False

Q4) Describe the use of hybrid assessment to create a quantitative assessment of asset value.

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Security Management Models

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47117

Sample Questions

Q1) Dumpster <U>delvingis</U> an information attack that involves searching through a target organization'strash and recycling bins for sensitive information.____________

A)True

B)False

Q2) Which of the following is a generic blueprint offered by a service organization which must be flexible,scalable,robust,and detailed?

A) framework

B) security model

C) security standard

D) both A & B are correct

Q3) What are the two primary access modes of the Bell-LaPadula model and what do they restrict?

Q4) In a lattice-based access control,a<U> restriction </U>table is the row of attributes associated with aparticular subject (such as a user). ____________

A)True

B)False

Q5) Under what circumstances should access controls be centralized vs.decentralized?

Q6) Access controls are build on three key principles.List and briefly define them.

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Security Management Practices

Available Study Resources on Quizplus for this Chatper

59 Verified Questions

59 Flashcards

Source URL: https://quizplus.com/quiz/47118

Sample Questions

Q1) List the four factors critical to the success of an InfoSec performance program,according to NIST SP 800-55,Rev.1.

Q2) Problems with benchmarking include all but which of the following?

A) Organizations don't often share information on successful attacks

B) Organizations being benchmarked are seldom identical

C) Recommended practices change and evolve, thus past performance is no indicator of future success

D) Benchmarking doesn't help in determining the desired outcome of the security process

Q3) Which of the following is NOT a consideration when selecting recommended best practices?

A) Threat environment is similar

B) Resource expenditures are practical

C) Organization structure is similar

D) Same certification and accreditation agency or standard

Q4) Describe the three tier approach of the RMF as defined by NIST SP 800-37.

Q5) Best security practices balance the need for user _____________ to information with the need for adequate protection while simultaneously demonstrating fiscal responsibility.

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Planning for Contingencies

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47119

Sample Questions

Q1) An alert <U>digest </U>is a description of the incident or disaster that usually contains just enoughinformation so that each person knows what portion of the IR or DR plan to implement withoutslowing down the notification process.____________

A)True

B)False

Q2) When undertaking the BIA,whatshouldthe organization consider?

Q3) Which of the following is a part of the incident recovery process?

A) Identifying the vulnerabilities that allowed the incident to occur and spread

B) Determining the event's impact on normal business operations and, if necessary, making a disaster declaration

C) Supporting personnel and their loved ones during the crisis

D) Keeping the public informed about the event and the actions being taken to ensure the recovery of personnel and the enterprise

Q4) A(n)____________________ is a document containing contact information of the individuals to notify in the event of an actual incident.

Q5) List the seven steps of the incident recovery process according to Donald Pipkin.

Q6) Compare and contrast a hot site,a warm site,and a cold site.

To view all questions and flashcards with answers, click on the resource link above.

Page 12

Chapter 11: Personnel and Security

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47120

Sample Questions

Q1) Briefly describe the two outprocessing methods of handling employees who leave their positions at a company.

Q2) Which of the following InfoSec positions is responsible for the day-to-day operation of the InfoSec program?

A) CISO

B) Security manager

C) Security officer

D) Security technician

Q3) Before hiring security personnel,which of the following should be conducted before the organization extends an offer to any candidate,regardless of job level?

A) New hire orientation

B) Covert surveillance

C) Organizational tour

D) Background check

Q4) InfoSec is a profession with little personnel turnover - most InfoSec professionals stay in their positions for a very long time.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Protection Mechanisms

Available Study Resources on Quizplus for this Chatper

61 Verified Questions

61 Flashcards

Source URL: https://quizplus.com/quiz/47121

Sample Questions

Q1) What should you look for when selecting a firewall for your network?

Q2) What is a packet sniffer and how can it be used for good or nefarious purposes?

Q3) Technical controls alone,when properly configured,can secure an IT environment.

A)True

B)False

Q4) Briefly describe how biometric technologies are generally evaluated.

Q5) The Ticket Granting Service (TGS)is one of three services in the __________ system,andprovides tickets to clients who request services.

Q6) What tool would you use if you want to collect information as it is being transmitted on the network and analyze the contents for the purpose of solving network problems?

A) Port scanner

B) Packet sniffer

C) Vulnerability scanner

D) Content filter

Q7) Which port number is commonly used for the Hypertext Transfer Protocol service.

A) 25

B) 53

C) 80

D) 8080

14

To view all questions and flashcards with answers, click on the resource link above.

Turn static files into dynamic content formats.

Create a flipbook
IT Security and Risk Management Exam Solutions - 696 Verified Questions by Quizplus - Issuu