

![]()


This course provides an in-depth exploration of IT security principles and risk management strategies essential for protecting information systems in organizations. Students will learn about various types of security threats, vulnerabilities, and the frameworks used to assess and mitigate risks in IT environments. Topics include security policies, access control, cryptography, security operations, incident response, and compliance with legal and regulatory standards. Through case studies and real-world scenarios, learners will develop the skills necessary to identify, evaluate, and manage security risks, as well as to implement effective security measures and best practices to safeguard digital assets.
Recommended Textbook
Principles of Information Security 5th Edition by Michael E. Whitman
Available Study Resources on Quizplus
12 Chapters
696 Verified Questions
696 Flashcards
Source URL: https://quizplus.com/study-set/2374 Page 2
Available Study Resources on Quizplus for this Chatper
63 Verified Questions
63 Flashcards
Source URL: https://quizplus.com/quiz/47110
Sample Questions
Q1) Which of the following is NOT a primary function of Information Security Management?
A) planning
B) protection
C) projects
D) performance
Answer: D
Q2) Which of the following is the first step in the problem-solving process?
A) Analyze and compare the possible solutions
B) Develop possible solutions
C) Recognize and define the problem
D) Select, implement and evaluate a solution
Answer: C
Q3) The <U>malicious</U> code attack includes the execution of viruses,worms,Trojan horses,and active Web scripts with the intent to destroy or steal information._________________________
A)True
B)False
Answer: True

Page 3
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/47111
Sample Questions
Q1) The Secret Service is charged with the detection and arrest of any person committing a U.S.federal offense relating to computer fraud,as well as false identification crimes.
A)True
B)False
Answer: True
Q2) InfraGard began as a cooperative effortbetween the FBI's Cleveland field office and local<U> intelligence</U> professionals. ___________
A)True
B)False
Answer: False
Q3) The Gramm-Leach-Bliley (GLB)Act (alsoknown as the <U>Financial</U> Services Modernization Act of 1999)contains a number of provisionsthat affect banks,securities firms,and insurance companies.___________
A)True
B)False
Answer: True
To view all questions and flashcards with answers, click on the resource link above. Page 4

Available Study Resources on Quizplus for this Chatper
52 Verified Questions
52 Flashcards
Source URL: https://quizplus.com/quiz/47112
Sample Questions
Q1) _________resources include people,hardware,and the supporting system elements and resources associated with the management of information in all its states.
Answer: Physical
Q2) What is the first phase of the SecSDLC?
A) analysis
B) investigation
C) logical design
D) physical design
Answer: B
Q3) A set of security tests and evaluations that simulate attacks by a malicious external source is known as ____________.
A) vulnerability assessment
B) penetration testing
C) exploit identification
D) safeguard neutralization
Answer: B
Q4) The ______________________ phase is the last phase of SecSDLC,but perhaps the most important.
Answer: maintenance and change
To view all questions and flashcards with answers, click on the resource link above. Page 5

Available Study Resources on Quizplus for this Chatper
56 Verified Questions
56 Flashcards
Source URL: https://quizplus.com/quiz/47113
Sample Questions
Q1) In which phase of the development of an InfoSec policy must a plan to distribute the policies be developed?Why is this important?
Q2) In addition to specifying the penalties for unacceptable behavior,what else must a policy specify?
A) appeals process
B) legal recourse
C) what must be done to comply
D) the proper operation of equipment
Q3) <U>Technology</U> is the essential foundation of an effective information security program._____________
A)True
B)False
Q4) Policies must specify penalties for unacceptable behavior and define an appeals process.
A)True B)False
Q5) The responsibilities of both the users and the systems administrators with regard to specific systems administration duties should be specified in the ____________________ section of the ISSP.
To view all questions and flashcards with answers, click on the resource link above. Page 6

Available Study Resources on Quizplus for this Chatper
55 Verified Questions
55 Flashcards
Source URL: https://quizplus.com/quiz/47114
Sample Questions
Q1) What are some of the variables that determine how a given organization chooses to construct its InfoSec program?
Q2) The purpose of SETA is to enhance security in all but which of the following ways?
A) by building in-depth knowledge
B) by adding barriers
C) by developing skills
D) by improving awareness
Q3) Legal assessment for the implementation of the information security program is almost always done by the information security or IT departments.
A)True
B)False
Q4) A(n)____________________ is a specific point in the project plan when a task that has a noticeable impact on plan's the progress is complete.
Q5) The project planner should describe the skills or personnel needed for a task,often referred to as a(n)____________________,needed to accomplish a task.
Q6) What is the role of help desk personnel in the InfoSec team?
Q7) What minimum attributes for project tasks does the WBS document?
To view all questions and flashcards with answers, click on the resource link above. Page 7

Available Study Resources on Quizplus for this Chatper
60 Verified Questions
60 Flashcards
Source URL: https://quizplus.com/quiz/47115
Sample Questions
Q1) Some threats can manifest in multiple ways,yielding multiple<U> exploits</U> for an asset-threat pair. ____________
A)True
B)False
Q2) A formal access control methodology used to assign a level ofconfidentiality to an information asset and thus restrict the number of people who can access it is known as a data <U>categorization</U> scheme.____________
A)True
B)False
Q3) The Australian and New Zealand Risk Management Standard 4360 uses qualitative methods to determine risk based on a threat's probability of occurrence and expected results of a successful attack.
A)True B)False
Q4) Describe the use of an IP address when deciding which attributes to track for each information asset.
Q5) List the stages in the risk identification process in order of occurrence.
Page 8
Q6) What are the included tasks in the identification of risks?
Q7) For the purposes of relative risk assessment how is risk calculated?
To view all questions and flashcards with answers, click on the resource link above.

Available Study Resources on Quizplus for this Chatper
60 Verified Questions
60 Flashcards
Source URL: https://quizplus.com/quiz/47116
Sample Questions
Q1) In which technique does a group rate or rank a set of information,compile the results and repeat until everyone is satisfied with the result?
A) OCTAVE
B) FAIR
C) Hybrid Measures
D) Delphi
Q2) What is the result of subtracting the post-control annualized loss expectancy and the ACS from the pre-control annualized loss expectancy?
A) cost-benefit analysis
B) exposure factor
C) single loss expectancy
D) annualized rate of occurrence
Q3) A <U>benchmark </U>is derived by comparing measured actual performance against established standards for the measured category.____________
A)True
B)False
Q4) Describe the use of hybrid assessment to create a quantitative assessment of asset value.
To view all questions and flashcards with answers, click on the resource link above. Page 9

Available Study Resources on Quizplus for this Chatper
60 Verified Questions
60 Flashcards
Source URL: https://quizplus.com/quiz/47117
Sample Questions
Q1) Dumpster <U>delvingis</U> an information attack that involves searching through a target organization'strash and recycling bins for sensitive information.____________
A)True
B)False
Q2) Which of the following is a generic blueprint offered by a service organization which must be flexible,scalable,robust,and detailed?
A) framework
B) security model
C) security standard
D) both A & B are correct
Q3) What are the two primary access modes of the Bell-LaPadula model and what do they restrict?
Q4) In a lattice-based access control,a<U> restriction </U>table is the row of attributes associated with aparticular subject (such as a user). ____________
A)True
B)False
Q5) Under what circumstances should access controls be centralized vs.decentralized?
Q6) Access controls are build on three key principles.List and briefly define them.
To view all questions and flashcards with answers, click on the resource link above. Page 10

Available Study Resources on Quizplus for this Chatper
59 Verified Questions
59 Flashcards
Source URL: https://quizplus.com/quiz/47118
Sample Questions
Q1) List the four factors critical to the success of an InfoSec performance program,according to NIST SP 800-55,Rev.1.
Q2) Problems with benchmarking include all but which of the following?
A) Organizations don't often share information on successful attacks
B) Organizations being benchmarked are seldom identical
C) Recommended practices change and evolve, thus past performance is no indicator of future success
D) Benchmarking doesn't help in determining the desired outcome of the security process
Q3) Which of the following is NOT a consideration when selecting recommended best practices?
A) Threat environment is similar
B) Resource expenditures are practical
C) Organization structure is similar
D) Same certification and accreditation agency or standard
Q4) Describe the three tier approach of the RMF as defined by NIST SP 800-37.
Q5) Best security practices balance the need for user _____________ to information with the need for adequate protection while simultaneously demonstrating fiscal responsibility.
To view all questions and flashcards with answers, click on the resource link above. Page 11

Available Study Resources on Quizplus for this Chatper
60 Verified Questions
60 Flashcards
Source URL: https://quizplus.com/quiz/47119
Sample Questions
Q1) An alert <U>digest </U>is a description of the incident or disaster that usually contains just enoughinformation so that each person knows what portion of the IR or DR plan to implement withoutslowing down the notification process.____________
A)True
B)False
Q2) When undertaking the BIA,whatshouldthe organization consider?
Q3) Which of the following is a part of the incident recovery process?
A) Identifying the vulnerabilities that allowed the incident to occur and spread
B) Determining the event's impact on normal business operations and, if necessary, making a disaster declaration
C) Supporting personnel and their loved ones during the crisis
D) Keeping the public informed about the event and the actions being taken to ensure the recovery of personnel and the enterprise
Q4) A(n)____________________ is a document containing contact information of the individuals to notify in the event of an actual incident.
Q5) List the seven steps of the incident recovery process according to Donald Pipkin.
Q6) Compare and contrast a hot site,a warm site,and a cold site.
To view all questions and flashcards with answers, click on the resource link above.
Page 12

Available Study Resources on Quizplus for this Chatper
60 Verified Questions
60 Flashcards
Source URL: https://quizplus.com/quiz/47120
Sample Questions
Q1) Briefly describe the two outprocessing methods of handling employees who leave their positions at a company.
Q2) Which of the following InfoSec positions is responsible for the day-to-day operation of the InfoSec program?
A) CISO
B) Security manager
C) Security officer
D) Security technician
Q3) Before hiring security personnel,which of the following should be conducted before the organization extends an offer to any candidate,regardless of job level?
A) New hire orientation
B) Covert surveillance
C) Organizational tour
D) Background check
Q4) InfoSec is a profession with little personnel turnover - most InfoSec professionals stay in their positions for a very long time.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 13
Available Study Resources on Quizplus for this Chatper
61 Verified Questions
61 Flashcards
Source URL: https://quizplus.com/quiz/47121
Sample Questions
Q1) What should you look for when selecting a firewall for your network?
Q2) What is a packet sniffer and how can it be used for good or nefarious purposes?
Q3) Technical controls alone,when properly configured,can secure an IT environment.
A)True
B)False
Q4) Briefly describe how biometric technologies are generally evaluated.
Q5) The Ticket Granting Service (TGS)is one of three services in the __________ system,andprovides tickets to clients who request services.
Q6) What tool would you use if you want to collect information as it is being transmitted on the network and analyze the contents for the purpose of solving network problems?
A) Port scanner
B) Packet sniffer
C) Vulnerability scanner
D) Content filter
Q7) Which port number is commonly used for the Hypertext Transfer Protocol service.
A) 25
B) 53
C) 80
D) 8080

14
To view all questions and flashcards with answers, click on the resource link above.