UTK INMT 341 - Final Exam 230+ (2026/2027
Updated) Solved Exams + 100% Verified
Solutions Complete Q&A
Comprehensive Examination Question Bank • In-Depth Rationales • Concept Mapping
TOTAL QUESTIONS EXAM TOPICS RATIONALES
239 Questions 12 Modules 100% Verified
DOCUMENT OVERVIEW
This document contains 239 verified questions with correct answers and explanations focused on various
aspects of information technology risk management and security. It serves as a comprehensive resource for
understanding key concepts related to data protection, network security, and compliance regulations. This
document guide is suitable for students preparing for certifications, course reviews, and in-depth study of IT
security frameworks.
EXAM BLUEPRINT & TOPIC DISTRIBUTION
Systematic breakdown of subject domains and exam coverage.
Topic Module Scope & Core Focus
Explores the identification, assessment, and mitigation of risks associated with information
IT Risk Management technology.
Data Protection Regulations Covers laws and regulations concerning the protection of personal and sensitive data.
Focuses on strategies and tools to safeguard network infrastructure from unauthorized
Network Security access and attacks.
Examines methods to protect applications from vulnerabilities and threats throughout their
Application Security lifecycle.
Cybersecurity Frameworks Discusses established frameworks and best practices for managing cybersecurity risks.
Disaster Recovery Planning Covers the processes and strategies for recovering IT systems and data after a disaster.
Focuses on technologies and methodologies for detecting and preventing unauthorized
Intrusion Detection and Prevention access to systems.
Encryption and Data Security Explores various encryption methods and their role in securing data at rest and in transit.
Confidential • Student Study Edition • Practice & Review Guide Page 1 of 52
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
Examines tactics used by attackers to manipulate individuals into divulging confidential
Social Engineering Threats information.
Discusses strategies to ensure essential business functions continue during and after a
Business Continuity Management crisis.
Focuses on the processes and policies that organizations implement to safeguard assets and
Internal Controls ensure accurate financial reporting.
Examines the various compliance standards that organizations must adhere to in the realm of
Compliance Standards information technology.
Total Exam Coverage 12 Integrated Topic Modules • 239 Examination Questions
Confidential • Student Study Edition • Practice & Review Guide Page 2 of 52
,STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
QUESTION 1
Hacking attacks that exploit software or hardware vulnerabilities
Correct Answer: SQL Injection/Insertion
- Cross-site Scripting (XSS)
- Buffer (cache) overflow.
QUESTION 2
Decision points (Diamond Shape)
Correct Answer: A decision symbol would display the decision, and a description of the decision would
appear in the symbol (e.g. "Is the document complete?"). Two labeled flow lines would exit from the decision
symbol to illustrate the indicated course of action.
QUESTION 3
FERPA
Correct Answer: Family Educational Rights and Privacy Act
- Protected Personally Identifiable Information (Grades)
QUESTION 4
Examples of application controls
Correct Answer: Application understanding
- Access control (authentication)
- Authorization
- Input controls
- Processing controls
- Output controls
- Other controls.
Confidential • Student Study Edition • Practice & Review Guide Page 3 of 52
, STUDENT STUDY & MASTERY EDITION PRACTICE & REVIEW GUIDE
QUESTION 5
Authorization Controls
Correct Answer: Access control lists, ensure different user levels created
- Job roles/job descriptions match to ACL
- Privileges identified for each job role/description
- Enforcement of privileges provided to each job role/description
- Application hardening to remove possibility of bypassing authorization mechanisms to elevate user levels
- Job change/termination policies and procedures.
QUESTION 6
Network risks
Correct Answer: System administrators having unlimited direct access to the database
- Developers not being adequately trained in secure coding techniques for web application development
- Failure to implement an effective Bring your own device(BYOD) policy.
QUESTION 7
DMZ (demilitarized zone)
Correct Answer: A sub-network that separates an internal local area network (LAN) from other untrusted
networks, usually the Internet.
External-facing servers, resources and services are located in the DMZ so they are accessible from the
Internet but the rest of the internal LAN remains unreachable.
This provides an additional layer of security to the LAN as it restricts the ability of hackers to directly access
internal servers and data via the Internet.
QUESTION 8
Network risks
Correct Answer: Incorrect router/firewall configurations (not according to organization specifications)
- Inadequate configurations (do not work as designed)
- Ability for remote users to bypass the border router and firewall and get direct access to the database
server
- Ability to spoof the internal IP (internet protocol) Address and bypass the web server
- Internal users who have malicious intent and by being internal do not go through the firewall and/or border
router.
Confidential • Student Study Edition • Practice & Review Guide Page 4 of 52