Information Systems Security Final Exam Prep
INFORMATION SYSTEMS SECURITY FINAL EXAM PREP NEWEST
2026/2027 ACTUAL EXAM COMPLETE 200 QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY GRADED
A+||BRAND NEW VERSION!!
Which of the following is another term for statutory law?
A) Legislation
B) Regulation
C) Policy
D) Governance - Correct Answer-A
Which of the following federal legislations, also known as the Financial
Modernization Act of 1999, was created to reform and modernize the banking
industry by eliminating existing barriers between banking and commerce?
A) HITECH
B) HIPAA
C) FERPA
D) GLBA - Correct Answer-D
Which major regulation entity within the European Union (EU) was created to
maintain a single standard for data protection among all member states in the EU?
A) Directive on Security of Network and Information Systems (the NIS Directive)
B) EU General Data Protection Regulation (GDPR)
C) European Union Agency for Network and Information Security (ENISA)
1|Page
, Information Systems Security Final Exam Prep
D) The Consumer Credit Regulations 2010 - Correct Answer-B
Which key task in the policy development phase requires the authors to consult
with internal and external experts, including legal counsel, human resources,
compliance, cybersecurity and technology professionals, auditors, and regulators?
A) Writing
B) Authorizing
C) Vetting
D) Planning - Correct Answer-C
Which key task in the policy adoption phase is the busiest and most challenging
task of all?
A) Implementation
B) Enforcement
C) Monitoring
D) Education - Correct Answer-A
Which of the following is not an example of a standard?
A) Passwords must include at least one special character.
B) Passwords must not include repeating characters.
C) Pass phrases make good passwords.
D) Passwords must not include the user's name. - Correct Answer-C
Which of the following version numbers is an example of a major policy revision?
2|Page
, Information Systems Security Final Exam Prep
A) 3.5
B) 4.0
C) 4.1
D) 5.1 - Correct Answer-B
Which of the following version numbers would indicate a minor revision?
A) IV
B) 2.0
C) 2.1
D) 3.0 - Correct Answer-C
Where is the policy introduction located in a consolidated policy document?
A) In a separate document
B) Before the version control table
C) At the beginning of the document
D) After the version control table - Correct Answer-D
What is the purpose of the administrative notations section of a policy?
A) To refer the reader to additional information
B) To explain terms, abbreviations, and acronyms used in the policy
C) To provide the policy version number
D) To provide information about policy exceptions - Correct Answer-A
3|Page
, Information Systems Security Final Exam Prep
What is the purpose of the policy definition section?
A) To provide information about policy exceptions
B) To refer the reader to additional information
C) To explain terms, abbreviations, and acronyms used in the policy
D) To provide the policy version number - Correct Answer-C
Which of the following statements about standards and guidelines is true?
A) Standards are mandatory, whereas guidelines are not.
B) Guidelines are mandatory, whereas standards are not.
C) Both standards and guidelines are mandatory.
D) Neither standards nor guidelines are mandatory. - Correct Answer-A
Which of the following procedure formats is best suited when there is a decision-
making process associated with a task?
A) Simple Step
B) Flowchart
C) Hierarchical
D) Graphic - Correct Answer-B
Which of the following best describes a baseline?
A) Specifications for implementation of a policy
B) Instructions on how a policy is carried out
C) Application of a standard to a specific category or grouping
4|Page
INFORMATION SYSTEMS SECURITY FINAL EXAM PREP NEWEST
2026/2027 ACTUAL EXAM COMPLETE 200 QUESTIONS AND CORRECT
DETAILED ANSWERS (VERIFIED ANSWERS) |ALREADY GRADED
A+||BRAND NEW VERSION!!
Which of the following is another term for statutory law?
A) Legislation
B) Regulation
C) Policy
D) Governance - Correct Answer-A
Which of the following federal legislations, also known as the Financial
Modernization Act of 1999, was created to reform and modernize the banking
industry by eliminating existing barriers between banking and commerce?
A) HITECH
B) HIPAA
C) FERPA
D) GLBA - Correct Answer-D
Which major regulation entity within the European Union (EU) was created to
maintain a single standard for data protection among all member states in the EU?
A) Directive on Security of Network and Information Systems (the NIS Directive)
B) EU General Data Protection Regulation (GDPR)
C) European Union Agency for Network and Information Security (ENISA)
1|Page
, Information Systems Security Final Exam Prep
D) The Consumer Credit Regulations 2010 - Correct Answer-B
Which key task in the policy development phase requires the authors to consult
with internal and external experts, including legal counsel, human resources,
compliance, cybersecurity and technology professionals, auditors, and regulators?
A) Writing
B) Authorizing
C) Vetting
D) Planning - Correct Answer-C
Which key task in the policy adoption phase is the busiest and most challenging
task of all?
A) Implementation
B) Enforcement
C) Monitoring
D) Education - Correct Answer-A
Which of the following is not an example of a standard?
A) Passwords must include at least one special character.
B) Passwords must not include repeating characters.
C) Pass phrases make good passwords.
D) Passwords must not include the user's name. - Correct Answer-C
Which of the following version numbers is an example of a major policy revision?
2|Page
, Information Systems Security Final Exam Prep
A) 3.5
B) 4.0
C) 4.1
D) 5.1 - Correct Answer-B
Which of the following version numbers would indicate a minor revision?
A) IV
B) 2.0
C) 2.1
D) 3.0 - Correct Answer-C
Where is the policy introduction located in a consolidated policy document?
A) In a separate document
B) Before the version control table
C) At the beginning of the document
D) After the version control table - Correct Answer-D
What is the purpose of the administrative notations section of a policy?
A) To refer the reader to additional information
B) To explain terms, abbreviations, and acronyms used in the policy
C) To provide the policy version number
D) To provide information about policy exceptions - Correct Answer-A
3|Page
, Information Systems Security Final Exam Prep
What is the purpose of the policy definition section?
A) To provide information about policy exceptions
B) To refer the reader to additional information
C) To explain terms, abbreviations, and acronyms used in the policy
D) To provide the policy version number - Correct Answer-C
Which of the following statements about standards and guidelines is true?
A) Standards are mandatory, whereas guidelines are not.
B) Guidelines are mandatory, whereas standards are not.
C) Both standards and guidelines are mandatory.
D) Neither standards nor guidelines are mandatory. - Correct Answer-A
Which of the following procedure formats is best suited when there is a decision-
making process associated with a task?
A) Simple Step
B) Flowchart
C) Hierarchical
D) Graphic - Correct Answer-B
Which of the following best describes a baseline?
A) Specifications for implementation of a policy
B) Instructions on how a policy is carried out
C) Application of a standard to a specific category or grouping
4|Page