Skip to main content

IT Security Management Midterm Exam - 696 Verified Questions

Page 1


IT Security Management

Midterm Exam

Course Introduction

IT Security Management focuses on the strategies, policies, and procedures necessary to protect an organizations information assets in todays digital landscape. This course covers risk assessment, security frameworks, threat analysis, compliance requirements, and incident response planning. Students will explore best practices for managing security teams, enforcing security policies, ensuring business continuity, and navigating legal and ethical considerations. By the end of the course, learners will be equipped to design, implement, and oversee effective IT security programs that align with organizational goals and regulatory obligations.

Recommended Textbook

Principles of Information Security 5th Edition by Michael E. Whitman

Available Study Resources on Quizplus

12 Chapters

696 Verified Questions

696 Flashcards

Source URL: https://quizplus.com/study-set/2374

Page 2

Chapter 1: Introduction to the Management of Information Security

Available Study Resources on Quizplus for this Chatper

63 Verified Questions

63 Flashcards

Source URL: https://quizplus.com/quiz/47110

Sample Questions

Q1) Which function of InfoSec Management encompasses security personnel as well as aspects of the SETA program?

A) protection

B) people

C) projects

D) policy

Answer: B

Q2) What do audit logs that track user activity on an information system provide?

A) identification

B) authorization

C) accountability

D) authentication

Answer: C

Q3) The <U>malicious</U> code attack includes the execution of viruses,worms,Trojan horses,and active Web scripts with the intent to destroy or steal information._________________________

A)True

B)False

Answer: True

Page 3

To view all questions and flashcards with answers, click on the resource link above.

Chapter 2: Compliance: Law and Ethics

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/47111

Sample Questions

Q1) Information <U>ambiguation </U>occurs when pieces of non-private data are combined to create information that violates privacy._________________________

A)True

B)False

Answer: False

Q2) an approach that applies moral codes to actions drawn from realistic situations

A)criminal law

B)public law

C)ethics

D)Computer Security Act (CSA)

E)Electronic Communications Privacy Act

F)Cybersecurity Act

G)normative ethics

H)applied ethics

Answer: H

Q3) The act of attempting to prevent an unwanted action by threatening punishment orretaliation on the instigator if the act takes place is known as ___________.

Answer: deterrence

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Governance and Strategic Planning for Security

Available Study Resources on Quizplus for this Chatper

52 Verified Questions

52 Flashcards

Source URL: https://quizplus.com/quiz/47112

Sample Questions

Q1) Which of the following is true about planning?

A) Strategic plans are used to create tactical plans

B) Tactical plans are used to create strategic plans

C) Operational plans are used to create tactical plans

D) Operational plans are used to create strategic plans

Answer: A

Q2) A set of security tests and evaluations that simulate attacks by a malicious external source is known as ____________.

A) vulnerability assessment

B) penetration testing

C) exploit identification

D) safeguard neutralization

Answer: B

Q3) How does tactical planning differ from strategic planning?

Answer: Tactical planning has a more short-term focus than strategic planning-usually one to three years.It breaks down each applicable strategic goal into a series of incremental objectives.Each objective should be specific and ideally will have a delivery date within a year.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 4: Information Security Policy

Available Study Resources on Quizplus for this Chatper

56 Verified Questions

56 Flashcards

Source URL: https://quizplus.com/quiz/47113

Sample Questions

Q1) Which policy is the highest level of policy and is usually created first?

A) SysSP

B) USSP

C) ISSP

D) EISP

Q2) Which type of security policy is intended to provide a common understanding of the purposes for which an employee can and cannot use a resource?

A) issue-specific

B) enterprise information

C) system-specific

D) user-specific

Q3) Which of the following is a disadvantage of the individual policy approach to creating and managing ISSPs?

A) can suffer from poor policy dissemintation, enforcement, and review

B) may skip vulnerabilities otherwise reported

C) may be more expensive than necessary

D) implementation can be less difficult to manage

Q4) What are configuration rules?Provide examples.

Q5) What is a SysSP and what is one likely to include?

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Developing the Security Program

Available Study Resources on Quizplus for this Chatper

55 Verified Questions

55 Flashcards

Source URL: https://quizplus.com/quiz/47114

Sample Questions

Q1) What are the components of the security program element described as preparing for contingencies and disasters?

Q2) A study of information security positions found that positions can be classified into one of three types: ____________________ are the real technical types,who create and install security solutions.

Q3) Which of the following is an advantage of the user support group form of training?

A) Usually conducted in an informal social setting

B) Formal training plan

C) Can be live, or can be archived and viewed at the trainee's convenience

D) Can be customized to the needs of the trainee

Q4) Which of the following is an advantage of the formal class method of training?

A) Personal

B) Self-paced, can go as fast or as slow as the trainee needs

C) Can be scheduled to fit the needs of the trainee

D) Interaction with trainer is possible

Q5) What is the purpose of a security awareness program?What advantage does an awareness program have for the InfoSec program?

Q6) What is the role of help desk personnel in the InfoSec team?

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Risk Management: Identifying and Assessing Risk

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47115

Sample Questions

Q1) What are the included tasks in the identification of risks?

Q2) Having an established risk management program means that an organization's assets are completely protected.

A)True

B)False

Q3) Two of the activities involved in risk management include identifying risks and assessing risks.Which of the following activities is part of the risk assessment process?

A) Creating an inventory of information assets

B) Classifying and organizing information assets into meaningful groups

C) Assigning a value to each information asset

D) Calculating the severity of risks to which assets are exposed in their current setting

Q4) What does it mean to 'know the enemy' with respect to risk management?

Q5) Describe the use of an IP address when deciding which attributes to track for each information asset.

Q6) As each information asset is identified,categorized,and classified,a ________ value must also be assigned to it.

Q7) Why is threat identification so important in the process of risk management?

Page 8

To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Risk Management: Controlling Risk

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47116

Sample Questions

Q1) Application of training and education is a common method of which risk control strategy?

A) mitigation

B) defense

C) acceptance

D) transferal

Q2) What are the four stages of a basic FAIR analysis?

Q3) What are the four phases of the Microsoft risk management strategy?

Q4) Discuss three alternatives to feasibility analysis.

Q5) Describe operational feasibility.

Q6) The ISO 27005 Standard for Information Security Risk Management includes five stages including all but which of the following?

A) risk assessment

B) risk treatment

C) risk communication

D) risk determination

Q7) To keep up with the competition organizations must design and create a ____________ environment in which business processes and procedures can function and evolve effectively.

Q8) What is the OCTAVE method approach to risk management?

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Security Management Models

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47117

Sample Questions

Q1) In which form of access control is access to a specific set of information contingent on its subject matter?

A) content-dependent access controls

B) constrained user interfaces

C) temporal isolation

D) None of these

Q2) A TCSEC-defined covert channel,which transmit information by managing the relative timing of events.

A)blueprint

B)DAC

C)content-dependent access controls

D)rule-based access controls

E)separation of duties

F)sensitivity levels

G)storage channels

H)task-based controls

I)timing channels

J)TCB

Q3) Under what circumstances should access controls be centralized vs.decentralized?

Q4) Access controls are build on three key principles.List and briefly define them.

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Security Management Practices

Available Study Resources on Quizplus for this Chatper

59 Verified Questions

59 Flashcards

Source URL: https://quizplus.com/quiz/47118

Sample Questions

Q1) According to NIST SP 800-37,which of the following is the first step in the security controls selection process?

A) Categorize the information system and the information processed

B) Select an initial set of baseline security controls

C) Assess the security controls using appropriate assessment procedures

D) Authorize information system operation based on risk determination

Q2) The biggest barrier to<U>baselining </U>in InfoSec is the fact that many organizations do notshare warnings with other organizations.____________

A)True

B)False

Q3) Before beginning the process of designing,collecting,and using measures,the CISO should be prepared to answer the following questions posed by Kovacich.List four of these questions.

Q4) Which of the following is Tier 3 (indicating environment of operation)of the tiered risk management approach?

A) Mission/business process

B) Information system

C) Accounting/logistics

D) Organization

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Planning for Contingencies

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47119

Sample Questions

Q1) In which contingency plan testing strategy do individuals participate in a role-playing exercise inwhich the CP team is presented with a scenario of an actual incident or disaster and expected to react as if it had occurred?

A) Desk check

B) Simulation

C) Structured walk-through

D) Parallel testing

Q2) Which of the following has the main goal of restoring normal modes of operation with minimal cost and disruption to normal business activities after an adverse event?

A) Risk management

B) Contingency planning

C) Business response

D) Disaster readiness

Q3) In most organizations,the COO is responsible for creating the IR plan.

A)True

B)False

Q4) The bulk batch-transfer of data to an off-site facility is known as ____________________.

Q5) List four of the eight key components of a typical IR policy.

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Personnel and Security

Available Study Resources on Quizplus for this Chatper

60 Verified Questions

60 Flashcards

Source URL: https://quizplus.com/quiz/47120

Sample Questions

Q1) Which of the following policies requires that two individuals review and approve each other's work before the task is considered complete?

A) Task rotation

B) Two-person control

C) Separation of duties

D) Job rotation

Q2) Maintaining a secure environment requires that the information security (InfoSec)departmentbe carefully structured and staffed with appropriately skilled and <U>screened</U> personnel..____________

A)True

B)False

Q3) Briefly describe at least five types of background checks.

Q4) The SSCP certification is more applicable to the security manager than the security technician.

A)True B)False

Q5) What are some of the common qualifications for a CISO?

Q6) What are the qualifications and position requirements of a typical security technician?

Page 13

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Protection Mechanisms

Available Study Resources on Quizplus for this Chatper

61 Verified Questions

61 Flashcards

Source URL: https://quizplus.com/quiz/47121

Sample Questions

Q1) Which technology employs sockets to map internal private network addresses to a public address using a one-to-many mapping?

A) Network-address translation

B) Screened-subnet firewall

C) Port-address translation

D) Private address mapping

Q2) What should you look for when selecting a firewall for your network?

Q3) ________ recognition authentication captures the analog waveforms of human speech.

Q4) In which cipher method are values rearranged within a block to create the ciphertext?

A) Permutation

B) Vernam

C) Substitution

D) Monoalphabetic

Q5) Briefly describe how biometric technologies are generally evaluated.

Q6) List the most common firewall implementation architectures.

Q7) A(n)____________________ is a secret word or combination of characters known only by the user.

Q8) What are NAT and PAT?Describe these technologies.

To view all questions and flashcards with answers, click on the resource link above. Page 14

Turn static files into dynamic content formats.

Create a flipbook
IT Security Management Midterm Exam - 696 Verified Questions by Quizplus - Issuu