• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 12 pages
Exam (elaborations)

Misy 5325 Final Exam Questions And Answers

Document preview thumbnail
Preview 2 out of 12 pages

MISY 5325 FINAL EXAM QUESTIONS AND ANSWERS

Content preview

MISY 5325 FINAL EXAM QUESTIONS AND ANSWERS |
2026

Another term for data range and reasonableness checks is: - Answers - input validation

Which of the following is not one of the three primary objectives of controls? - Answers -
Eliminate

What changes plaintext data to ciphered data? - Answers - Encryption

A hacker wants to launch an attack on an organization. The hacker uses a tool to
capture data sent over the network in cleartext, hoping to gather information that will
help make the attack successful. What tool is the hacker using? - Answers - A packet
analyzer

Primary considerations for assessing threats based on historical data in your local area
are __________ and ___________. - Answers - weather conditions, natural disasters

In a SQL injection attack, an attacker can: - Answers - read sections of a database or a
whole database without authorization.

What does the principle of least privilege have in common with the principle of need to
know? - Answers - They both specify that users be granted access only to what they
need to perform their jobs.

An access control such as a firewall or intrusion prevention system cannot protect
against which of the following? - Answers - Social engineering

What is the purpose of nonrepudiation techniques? - Answers - To prevent people from
denying they took actions

Background checks, software testing, and awareness training are all categories of: -
Answers - procedural controls.

Ideally, when should you perform threat modeling? - Answers - Before writing an
application or deploying a system

You receive an email from someone named Bob in the IT department who needs to
access your login information for a scheduled internal vulnerability assessment. You
know an assessment is taking place because your manager notified your group last
week. Normally, you wouldn't give your password or other login information to anybody,
but doing so seems appropriate in this situation. Which of the following could be taking
place? - Answers - Social engineering attack

, What is a transaction in a database? - Answers - A group of statements that either
succeed or fail as a whole

Why is system testing performed? - Answers - To test individual systems for
vulnerabilities

What is the primary determination as to whether an incident is included in a business
continuity plan (BCP)? - Answers - Probability of occurrence and impact

A business continuity plan (BCP) program manager within a large organization: -
Answers - Usually manages multiple BCP projects.

What step of a business continuity plan (BCP) comes after providing training? -
Answers - Testing and exercising plans

Having supplies on hand for continued production: - Answers - may conflict with other
organizational planning principles.

Which term is defined as "an element necessary to perform the mission of an
organization"? - Answers - CSF

What is the primary purpose of identifying critical resources in the business impact
analysis (BIA) process? - Answers - Identify all IT assets that support critical business
functions (CBFs).

Lower recovery time objectives (RTOs) are __________ but __________. - Answers -
achievable, costly

What are critical resources? - Answers - Those that are required to support critical
business functions (CBFs)

Functionality testing is primarily used with: - Answers - Software development

A(n) ____________ assessment attempts to identify vulnerabilities that can be
exploited. - Answers - Exploit

A business continuity plan (BCP) is an example of a(n): - Answers - Security Plan

Which of the following is most likely to describe how to perform test restores? - Answers
- A backup plan

Which of the following is not a common category of control implementation? - Answers -
Functional

What characteristic is common to risk assessments and threat assessments? - Answers
- They are both performed for a specific time.

Document information

Uploaded on
April 23, 2026
Number of pages
12
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$14.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
GEEKA
3.8
(367)
Sold
2191
Followers
1449
Items
61605
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions