MISY 5325 EXAM QUESTIONS & ANSWERS | 2026
__________ provide the detailed steps needed to carry out ___________. - Answers -
Procedures, policies
A __________ grants the authority to perform an action on a system. A __________
grants access to a resource. - Answers - right, permission
A business continuity plan (BCP) is an example of a(n): - Answers - security plan
A hacker wants to launch an attack on an organization. The hacker uses a tool to
capture data sent over the network in cleartext, hoping to gather information that will
help make the attack successful. What tool is the hacker using? - Answers - a packet
analyzer
A threat is any activity that represents a possible danger, which includes any
circumstances or events with the potential to cause an adverse impact on all of the
following, except: - Answers - assessments
A(n) ____________ assessment attempts to identify vulnerabilities that can be
exploited. - Answers - exploit
An access control such as a firewall or intrusion prevention system cannot protect
against which of the following? - Answers - Social engineering
Another term for data range and reasonableness checks is: - Answers - input validation
Background checks, software testing, and awareness training are all categories of: -
Answers - procedural controls.
Bill is a security professional. He is in a meeting with co-workers and describes a
system that will make web sessions more secure. He says when a user connects to the
web server and starts a secure session, the server sends a certificate to the user. The
certificate includes a public key. The user can encrypt data with the public key and send
it to the server. Because the server holds the private key, it can decrypt the data.
Because no other entity has the private key, no one else can decrypt the data. What is
Bill describing? - Answers - Public key infrastructure (PKI)
Bonding is a type of __________ that covers against losses by theft, fraud, or
dishonesty. - Answers - Insurance
Complete the equation for the relationship between risk, vulnerabilities, and threats:
Risk equals: - Answers - Vulnerability × Threat .
Functionality testing is primarily used with: - Answers - Software Development
, Ideally, when should you perform threat modeling? - Answers - Before writing an
application or deploying a system
In a SQL injection attack, an attacker can: - Answers - read sections of a database or a
whole database without authorization.
Piggybacking is also known as: - Answers - Tailgating
Primary considerations for assessing threats based on historical data in your local area
are __________ and ___________. - Answers - Weather Conditions; Natural Disasters
Purchasing insurance is the primary way for an organization to __________ or
___________ risk. - Answers - share, transfer
Some controls are identified based on the function they perform. What are the broad
classes of controls based on function? - Answers - Preventative, detective, corrective
System logs and audit trails are a type of ________ control. - Answers - technical
The actual methods used to protect against data loss are __________ controls, but the
program that identifies which data to protect is a ___________ control. - Answers -
technical, procedural
The National Institute of Standards and Technology (NIST) publishes SP 800-53. This
document describes a variety of IT security controls, such as access control, incident
response, and configuration management. Controls are grouped into families. Which
NIST control family helps an organization recover from failures and disasters? -
Answers - Contingency Planning(CP)
To _________ risk means to reduce or neutralize threats or vulnerabilities to an
acceptable level. - Answers - Mitigate
What changes plaintext data to ciphered data? - Answers - encryption
What characteristic is common to risk assessments and threat assessments? - Answers
- They are both performed for a specific time.
What does the principle of least privilege have in common with the principle of need to
know? - Answers - They both specify that users be granted access only to what they
need to perform their jobs.
What is a transaction in a database? - Answers - A group of statements that either
succeed or fail as a whole
__________ provide the detailed steps needed to carry out ___________. - Answers -
Procedures, policies
A __________ grants the authority to perform an action on a system. A __________
grants access to a resource. - Answers - right, permission
A business continuity plan (BCP) is an example of a(n): - Answers - security plan
A hacker wants to launch an attack on an organization. The hacker uses a tool to
capture data sent over the network in cleartext, hoping to gather information that will
help make the attack successful. What tool is the hacker using? - Answers - a packet
analyzer
A threat is any activity that represents a possible danger, which includes any
circumstances or events with the potential to cause an adverse impact on all of the
following, except: - Answers - assessments
A(n) ____________ assessment attempts to identify vulnerabilities that can be
exploited. - Answers - exploit
An access control such as a firewall or intrusion prevention system cannot protect
against which of the following? - Answers - Social engineering
Another term for data range and reasonableness checks is: - Answers - input validation
Background checks, software testing, and awareness training are all categories of: -
Answers - procedural controls.
Bill is a security professional. He is in a meeting with co-workers and describes a
system that will make web sessions more secure. He says when a user connects to the
web server and starts a secure session, the server sends a certificate to the user. The
certificate includes a public key. The user can encrypt data with the public key and send
it to the server. Because the server holds the private key, it can decrypt the data.
Because no other entity has the private key, no one else can decrypt the data. What is
Bill describing? - Answers - Public key infrastructure (PKI)
Bonding is a type of __________ that covers against losses by theft, fraud, or
dishonesty. - Answers - Insurance
Complete the equation for the relationship between risk, vulnerabilities, and threats:
Risk equals: - Answers - Vulnerability × Threat .
Functionality testing is primarily used with: - Answers - Software Development
, Ideally, when should you perform threat modeling? - Answers - Before writing an
application or deploying a system
In a SQL injection attack, an attacker can: - Answers - read sections of a database or a
whole database without authorization.
Piggybacking is also known as: - Answers - Tailgating
Primary considerations for assessing threats based on historical data in your local area
are __________ and ___________. - Answers - Weather Conditions; Natural Disasters
Purchasing insurance is the primary way for an organization to __________ or
___________ risk. - Answers - share, transfer
Some controls are identified based on the function they perform. What are the broad
classes of controls based on function? - Answers - Preventative, detective, corrective
System logs and audit trails are a type of ________ control. - Answers - technical
The actual methods used to protect against data loss are __________ controls, but the
program that identifies which data to protect is a ___________ control. - Answers -
technical, procedural
The National Institute of Standards and Technology (NIST) publishes SP 800-53. This
document describes a variety of IT security controls, such as access control, incident
response, and configuration management. Controls are grouped into families. Which
NIST control family helps an organization recover from failures and disasters? -
Answers - Contingency Planning(CP)
To _________ risk means to reduce or neutralize threats or vulnerabilities to an
acceptable level. - Answers - Mitigate
What changes plaintext data to ciphered data? - Answers - encryption
What characteristic is common to risk assessments and threat assessments? - Answers
- They are both performed for a specific time.
What does the principle of least privilege have in common with the principle of need to
know? - Answers - They both specify that users be granted access only to what they
need to perform their jobs.
What is a transaction in a database? - Answers - A group of statements that either
succeed or fail as a whole