Information Systems Security
Final Exam — Complete Study Guide
Edition | Verified Answers
About This Study Guide
This document is a complete, professionally organized duplicate of the MISY 5325 Information Systems
Security Final Exam Q&A set. All questions and verified correct answers from the original exam are
preserved and restructured into clearly labeled topic sections for efficient study.
Coverage: Access controls and identity management, risk management and threat assessment, compliance
and regulatory frameworks, business continuity planning (BCP), disaster recovery planning (DRP), incident
response and CIRT, NIST Cybersecurity Framework, and forensics.
Format: Each section begins with key concept definitions and summaries, followed by exam Q&A pairs with
answers clearly highlighted in green, and True/False statements with answers color-coded (green = TRUE,
red = FALSE).
Sections: 8 | Questions: 150+ | Source: Verified 2025/2026 actual final exam
Section 1: Access Controls & Identity Management
Access controls govern how users and processes communicate and interact with systems and resources. Every
access control system has three common attributes: an identification scheme, an authentication method, and an
authorization model.
1.1 Key Definitions
Identification: The process of the subject supplying an identifier to the object (e.g., a username). Used to identify
unique records in a set.
Authentication: The process of the subject supplying verifiable credentials to the object — proving you are who
you claim to be. The METHOD used to prove identification is genuine. Requires the subject to supply verifiable
credentials called FACTORS.
Authorization: The process of assigning authenticated subjects permission to carry out a specific operation. The
MODEL defines how access rights and permissions are granted.
Identity Management: The process of identifying, authenticating, and authorizing users or groups to access
applications, systems, or networks.
Subject: The ACTIVE entity that requests access to a resource or data.
Object: The PASSIVE entity being accessed or acted upon.
Least Privilege: All users should be granted only the level of privilege they need to do their jobs, and no more.
Need to Know: A subject should be granted access to an object only if the access is needed to carry out the job.
Shares with least privilege: both specify users be granted access only to what they need to perform their jobs.
Security Posture: An organization's approach to access controls based on information about an object, such as
a host or network.
Right: Grants the authority to perform an action on a system.
Permission: Grants access to a resource.
Security Labels: Mandatory access controls embedded in object and subject properties.
,Object Capability: Used programmatically; based on a combination of an unforgeable reference and an
operational message.
Access Control Lists (ACLs): Used to determine access based on criteria such as user ID, group membership,
classification, location, address, and date.
Faraday Cage: Built out of a mesh of conducting material that prevents electromagnetic energy from entering or
escaping.
1.2 Authentication Factors — Three Categories
• Something you KNOW (e.g., password)
• Something you HAVE (e.g., token, smart card)
• Something you ARE (e.g., biometrics)
• NOT a category: Role (something the user does)
1.3 Authorization Models
Three Primary Models: Discretionary Access Control (DAC), Mandatory Access Control (MAC), Role-Based
Access Control (RBAC).
NOT a primary model: Multilayer authorization
Multifactor Authentication: When TWO OR MORE DIFFERENT TYPES of factors are presented (NOT one or
more — that is just single-factor).
Multilayer Authentication: When two or more of the SAME type of factors are presented.
1.4 Network Access Control (NAC)
• Can provide: device compliance checking, network segmentation, guest access, quarantine
• Cannot provide: password management
1.5 Exam Q&A — Access Controls
Q: What is the process of the subject supplying an identifier to the object?
A: Identification
Q: What is the process of the subject supplying verifiable credentials to the object?
A: Authentication
Q: What is the process of assigning authenticated subjects permission to carry out a specific operation?
A: Authorization
Q: The __ method is how identification is proven to be genuine.
A: Authentication
Q: The __ model defines how access rights and permissions are granted.
A: Authorization
Q: A right grants the authority to perform an action on a system. A __ grants access to a resource.
A: Permission
Q: The active entity that requests access to a resource is called the __.
A: Subject
Q: The passive entity being accessed or acted upon is called the __.
A: Object
Q: A subject should be granted access only if needed to carry out the job — this is called __.
A: Need To Know
, Q: The principle of __ states that all users should be granted only the level of privilege they need.
A: Least privilege
Q: In terms of authorization, security labels are based on:
A: Object/subject classification properties — mandatory access controls
Q: In the three categories of identification factors, which is NOT included?
A: Role (something the user does)
Q: The three primary authorization models include all EXCEPT:
A: Multilayer authorization
Q: Network Access Control (NAC) can provide all EXCEPT:
A: Password management
Q: An identification scheme, an authentication method, and an authorization model are the three common
attributes of all access controls.
A: TRUE
Statement: Access controls can be technical or administrative but never physical.
Answer: FALSE — access controls can be technical, administrative, OR physical.
Statement: Authentication is about establishing who you are, whereas identification is about proving you are the
entity you claim to be.
Answer: FALSE — these are reversed. Identification establishes who you are; authentication proves it.
Statement: The security posture of an organization determines the custom settings for access controls.
Answer: FALSE
Statement: Multifactor authentication is when one or more factors are presented.
Answer: FALSE — multifactor requires two or more DIFFERENT types of factors.
Statement: Multilayer authentication is when two or more of the same type of factors are presented.
Answer: TRUE
Section 2: Risk Management & Threat Assessment
Risk management involves identifying, analyzing, and responding to threats and vulnerabilities. The goal is to
reduce risk to an acceptable level through controls and countermeasures.
2.1 Core Formulas & Definitions
Risk Formula: Risk = Vulnerability x Threat
Vulnerability: A weakness in a system or process.
Threat: Any activity that represents a possible danger — circumstances or events with the potential to cause
adverse impact.
Exploit: An exploit assessment attempts to identify vulnerabilities that can be exploited.
Mitigate: To reduce or neutralize threats or vulnerabilities to an acceptable level.
Scope Creep: The biggest problem you can face if you do not identify the scope of your risk management project.
Countermeasure Value (CBA): Projected benefit minus cost of control. Example: $50,000 benefit - $1,500 cost =
$48,500 control value.
Overlapping Countermeasures: Different countermeasures that attempt to mitigate the SAME risk.
Implicit Deny: A firewall approach that starts by blocking ALL traffic, then adds rules to allow approved traffic.