ISA 3300 Chapter 5 Exam Questions With
Correct Answers
Small organizations spend more per user on security than medium or
| | | | | | | | | | |
large sized organizations.
| |
True
False - CORRECT ANSWER✔✔-True
| | |
Legal assessment for the implementation of the information security
| | | | | | | | |
program is almost always done by the information security or IT
| | | | | | | | | | |
department. |
True
False - CORRECT ANSWER✔✔-False
| | |
Threats from insiders are more likely in a small organization than a large
| | | | | | | | | | | | |
one.
True
,False - CORRECT ANSWER✔✔-False
| | |
Which of the following is NOT a part of an information security
| | | | | | | | | | | |
program?
a. technologies used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
b. activities used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
c. personnel used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
d. All of these are part of an information security program. - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-d. All of these are parts of an information security | | | | | | | | | |
program.
Which of the following variable is the most influential in determining
| | | | | | | | | | |
how to structure an information security program?
| | | | | |
a. security capital budget
| | | |
b. competitive environment
| | |
c. online exposure of organization
| | | | |
d. organizational culture - CORRECT ANSWER✔✔-d. Organizational
| | | | | | |
culture
, Which of the following functions includes identifying the sources of risk
| | | | | | | | | | |
and may include offering advice on controls that can reduce risk?
| | | | | | | | | |
a. risk treatment
| | |
b. risk assessment
| | |
c. systems testing
| | |
d. vulnerability assessment - CORRECT ANSWER✔✔-b. risk assessment
| | | | | | |
Which of the following is true about security staffing, budget, and needs
| | | | | | | | | | |
of a medium sized organization?
| | | | |
a. It has a larger dedicated (full-time) security staff than a small
| | | | | | | | | | | |
organization. |
b. It has a larger security budget (as percent of IT budget) than a small
| | | | | | | | | | | | | | |
organization. |
c. It has a smaller security budget (as percent of IT budget) than a large
| | | | | | | | | | | | | | |
organization. |
d. It has larger information security needs than a small organization. -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-d. It has larger information security needs than a
| | | | | | | | |
small organization.
| |
Correct Answers
Small organizations spend more per user on security than medium or
| | | | | | | | | | |
large sized organizations.
| |
True
False - CORRECT ANSWER✔✔-True
| | |
Legal assessment for the implementation of the information security
| | | | | | | | |
program is almost always done by the information security or IT
| | | | | | | | | | |
department. |
True
False - CORRECT ANSWER✔✔-False
| | |
Threats from insiders are more likely in a small organization than a large
| | | | | | | | | | | | |
one.
True
,False - CORRECT ANSWER✔✔-False
| | |
Which of the following is NOT a part of an information security
| | | | | | | | | | | |
program?
a. technologies used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
b. activities used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
c. personnel used by an organization to manage the risks to its
| | | | | | | | | | | |
information assets | |
d. All of these are part of an information security program. - CORRECT
| | | | | | | | | | | | |
ANSWER✔✔-d. All of these are parts of an information security | | | | | | | | | |
program.
Which of the following variable is the most influential in determining
| | | | | | | | | | |
how to structure an information security program?
| | | | | |
a. security capital budget
| | | |
b. competitive environment
| | |
c. online exposure of organization
| | | | |
d. organizational culture - CORRECT ANSWER✔✔-d. Organizational
| | | | | | |
culture
, Which of the following functions includes identifying the sources of risk
| | | | | | | | | | |
and may include offering advice on controls that can reduce risk?
| | | | | | | | | |
a. risk treatment
| | |
b. risk assessment
| | |
c. systems testing
| | |
d. vulnerability assessment - CORRECT ANSWER✔✔-b. risk assessment
| | | | | | |
Which of the following is true about security staffing, budget, and needs
| | | | | | | | | | |
of a medium sized organization?
| | | | |
a. It has a larger dedicated (full-time) security staff than a small
| | | | | | | | | | | |
organization. |
b. It has a larger security budget (as percent of IT budget) than a small
| | | | | | | | | | | | | | |
organization. |
c. It has a smaller security budget (as percent of IT budget) than a large
| | | | | | | | | | | | | | |
organization. |
d. It has larger information security needs than a small organization. -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-d. It has larger information security needs than a
| | | | | | | | |
small organization.
| |