ISSC 451 Week 5 Practice Exam with
multiple choice questions with
correct answers and rationale
graded A+ new!!
Multiple Choice Questions with Answers and Rationales
1. What is the primary purpose of an information security policy?
A. To eliminate all business risk
B. To define management’s intent, direction, and rules for security
C. To replace all technical controls
D. To provide legal advice only
Correct Answer: B
Rationale: Security policies establish management’s expectations, direction, and required behaviors
for protecting information assets.
2. Which type of policy provides broad management guidance and organizational direction?
A. Issue-specific policy
B. System-specific policy
C. Enterprise information security policy
D. User configuration policy
Correct Answer: C
Rationale: The enterprise information security policy is the highest-level policy that sets the strategic
direction for the entire organization.
3. A policy that addresses acceptable use of email is best classified as a:
A. Regulatory policy
,B. Issue-specific policy
C. Disaster recovery plan
D. Business continuity framework
Correct Answer: B
Rationale: Issue-specific policies address specific topics such as internet usage, email usage, remote
access, or social media.
4. Which of the following is most likely part of a system-specific policy?
A. Corporate ethics statement
B. Password length configuration for a server
C. Mission statement
D. Company holiday schedule
Correct Answer: B
Rationale: System-specific policies focus on technical or operational rules for a specific system, such
as password settings or access control configurations.
5. Standards are best described as:
A. Optional recommendations
B. Mandatory requirements that support policies
C. Temporary workarounds
D. High-level mission goals
Correct Answer: B
Rationale: Standards are compulsory rules that help enforce policies consistently across the
organization.
6. Guidelines differ from standards because guidelines are:
A. Legally binding
B. Mandatory in all situations
C. Recommended but not mandatory
, D. Written only for executives
Correct Answer: C
Rationale: Guidelines provide recommended practices and flexibility, unlike standards, which are
required.
7. Procedures are important because they:
A. Replace the need for policies
B. Describe step-by-step instructions for implementing controls
C. Eliminate human error entirely
D. Only apply during an incident
Correct Answer: B
Rationale: Procedures provide detailed operational steps to carry out policies and standards.
8. The confidentiality, integrity, and availability model is commonly known as the:
A. AAA model
B. CIA triad
C. CISO model
D. Risk cube
Correct Answer: B
Rationale: The CIA triad is the foundational information security model that focuses on
confidentiality, integrity, and availability.
9. Which security principle ensures that data is not disclosed to unauthorized individuals?
A. Availability
B. Integrity
C. Confidentiality
D. Accountability
Correct Answer: C
multiple choice questions with
correct answers and rationale
graded A+ new!!
Multiple Choice Questions with Answers and Rationales
1. What is the primary purpose of an information security policy?
A. To eliminate all business risk
B. To define management’s intent, direction, and rules for security
C. To replace all technical controls
D. To provide legal advice only
Correct Answer: B
Rationale: Security policies establish management’s expectations, direction, and required behaviors
for protecting information assets.
2. Which type of policy provides broad management guidance and organizational direction?
A. Issue-specific policy
B. System-specific policy
C. Enterprise information security policy
D. User configuration policy
Correct Answer: C
Rationale: The enterprise information security policy is the highest-level policy that sets the strategic
direction for the entire organization.
3. A policy that addresses acceptable use of email is best classified as a:
A. Regulatory policy
,B. Issue-specific policy
C. Disaster recovery plan
D. Business continuity framework
Correct Answer: B
Rationale: Issue-specific policies address specific topics such as internet usage, email usage, remote
access, or social media.
4. Which of the following is most likely part of a system-specific policy?
A. Corporate ethics statement
B. Password length configuration for a server
C. Mission statement
D. Company holiday schedule
Correct Answer: B
Rationale: System-specific policies focus on technical or operational rules for a specific system, such
as password settings or access control configurations.
5. Standards are best described as:
A. Optional recommendations
B. Mandatory requirements that support policies
C. Temporary workarounds
D. High-level mission goals
Correct Answer: B
Rationale: Standards are compulsory rules that help enforce policies consistently across the
organization.
6. Guidelines differ from standards because guidelines are:
A. Legally binding
B. Mandatory in all situations
C. Recommended but not mandatory
, D. Written only for executives
Correct Answer: C
Rationale: Guidelines provide recommended practices and flexibility, unlike standards, which are
required.
7. Procedures are important because they:
A. Replace the need for policies
B. Describe step-by-step instructions for implementing controls
C. Eliminate human error entirely
D. Only apply during an incident
Correct Answer: B
Rationale: Procedures provide detailed operational steps to carry out policies and standards.
8. The confidentiality, integrity, and availability model is commonly known as the:
A. AAA model
B. CIA triad
C. CISO model
D. Risk cube
Correct Answer: B
Rationale: The CIA triad is the foundational information security model that focuses on
confidentiality, integrity, and availability.
9. Which security principle ensures that data is not disclosed to unauthorized individuals?
A. Availability
B. Integrity
C. Confidentiality
D. Accountability
Correct Answer: C