MIS 315 Chapter 10 - Information Security and Risk
Management LATEST ALL VERSIONS ACTUAL EXAM
COMPLETE QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS) | ALREADY GRADED
A+ 2026/2027 WITH FREE PRACTICE TEST SETS.
QUESTION 1
Which of the following is considered a threat caused by human error?
a. A tsunami floods a data center causing total data loss
b. An employee inadvertently installing an old database on top of the current one
c. An employee intentionally destroying data and system components
d. A virus and worm writer infecting computer systems
- answers 100%✔✔✔ 📌b. An employee inadvertently installing an old database on
top of the current one
Rationale: Human error refers to unintentional mistakes made by employees during their
regular work activities. Inadvertently installing an old database over the current one is a classic
example of human error because it involves an accidental action that causes data loss or
corruption. Option (a) is a natural disaster, option (c) is intentional destruction (malicious act),
and option (d) involves external malicious actors creating viruses, which are deliberate acts
rather than errors.
QUESTION 2
Which of the following is considered a computer crime?
a. Failure to correctly back up customer data
b. Accidental deletion of important records
c. Poorly written programs resulting in information loss
,d. Hacking of information systems
- answers 100%✔✔✔ 📌d. Hacking of information systems
Rationale: A computer crime is a deliberate, illegal act involving computers or computer
systems. Hacking—unauthorized access to information systems—is a criminal offense
prosecuted under computer fraud and abuse laws. Options (a), (b), and (c) all describe mistakes,
negligence, or poor practices rather than intentional criminal activity. They may cause data loss,
but they are not classified as crimes because they lack criminal intent.
QUESTION 3
In the context of security threats, pretexting, sniffing, spoofing, and phishing are all examples
of ________.
a. Unauthorized data disclosure
b. SQL injection
c. Incorrect data modification
d. Loss of infrastructure
- answers 100%✔✔✔ 📌a. Unauthorized data disclosure
Rationale: Pretexting (creating a fabricated scenario to obtain information), sniffing
(intercepting network traffic), spoofing (disguising communication as coming from a trusted
source), and phishing (deceiving users to reveal confidential data) are all methods used to gain
unauthorized access to and disclosure of sensitive information. They are not examples of SQL
injection, data modification, or infrastructure loss—they are information-gathering and
deception techniques aimed at data disclosure.
QUESTION 4
Email spoofing is a synonym for ________.
a. Sniffing
b. Baiting
c. Usurping
d. Phishing
,- answers 100%✔✔✔ 📌d. Phishing
Rationale: Email spoofing involves forging an email header so the message appears to come
from someone other than the actual sender. This technique is most commonly used in phishing
attacks, where attackers impersonate legitimate organizations to trick recipients into revealing
personal information. While sniffing involves intercepting traffic and usurping involves taking
over a system, email spoofing is specifically associated with phishing campaigns.
QUESTION 5
Which of the following is a sniffing technique?
a. Caches
b. Adware
c. Port scanner
d. IP spoofing
- answers 100%✔✔✔ 📌b. Adware
Rationale: Adware is a type of spyware that monitors user behavior and can act as a sniffing
technique by tracking browsing habits, keystrokes, and online activities without the user's
knowledge or consent. Port scanners are used for network reconnaissance, IP spoofing is an
address forgery technique, and caches are temporary storage mechanisms—none of these are
classified as sniffing techniques in the context of information security threats.
QUESTION 6
Which of the following is most likely to be a result of hacking?
a. Slowing of network speed
b. Pop-up ads appearing frequently
c. Small amounts of spam in a user's inbox
d. Certain Web sites being censored for hurting sentiments
- answers 100%✔✔✔ 📌a. Slowing of network speed
, Rationale: When hackers breach a network, they often install malicious tools, launch attacks
from compromised systems, or exfiltrate large amounts of data—all of which can significantly
slow network performance. While pop-up ads may indicate adware and spam may indicate
email list compromise, network slowdown is a direct and common consequence of an active
hacking intrusion. Censorship is a policy decision, not a hacking result.
QUESTION 7
Which of the following usually happens in a malicious denial-of-service attack?
a. A phisher pretends to be a legitimate company and requests confidential data
b. A hacker identifies vulnerabilities in network hosts
c. A hacker floods a Web server with many millions of bogus service requests
d. An intruder uses another site's IP address to masquerade as that other site
- answers 100%✔✔✔ 📌c. A hacker floods a Web server with many millions of bogus
service requests
Rationale: A denial-of-service (DoS) attack is specifically designed to make a service unavailable
by overwhelming it with traffic. The attacker sends massive volumes of bogus requests to
exhaust the server's resources, preventing legitimate users from accessing the service. Option
(a) describes phishing, option (b) describes vulnerability scanning, and option (d) describes IP
spoofing—none of which are the defining characteristic of a DoS attack.
QUESTION 8
Which of the following statements is TRUE about losses due to computer security threats?
a. Surveys on computer crimes provide accurate results since they use standard parameters to
measure and tally computer crime costs
b. Losses due to natural disasters can be measured accurately
c. Losses due to human error are insignificant
d. Surveys suggest that some organizations do not report all their computer crime losses, and
some will not report such losses at all
- answers 100%✔✔✔ 📌d. Surveys suggest that some organizations do not report all
their computer crime losses, and some will not report such losses at all
Management LATEST ALL VERSIONS ACTUAL EXAM
COMPLETE QUESTIONS AND CORRECT DETAILED
ANSWERS (VERIFIED ANSWERS) | ALREADY GRADED
A+ 2026/2027 WITH FREE PRACTICE TEST SETS.
QUESTION 1
Which of the following is considered a threat caused by human error?
a. A tsunami floods a data center causing total data loss
b. An employee inadvertently installing an old database on top of the current one
c. An employee intentionally destroying data and system components
d. A virus and worm writer infecting computer systems
- answers 100%✔✔✔ 📌b. An employee inadvertently installing an old database on
top of the current one
Rationale: Human error refers to unintentional mistakes made by employees during their
regular work activities. Inadvertently installing an old database over the current one is a classic
example of human error because it involves an accidental action that causes data loss or
corruption. Option (a) is a natural disaster, option (c) is intentional destruction (malicious act),
and option (d) involves external malicious actors creating viruses, which are deliberate acts
rather than errors.
QUESTION 2
Which of the following is considered a computer crime?
a. Failure to correctly back up customer data
b. Accidental deletion of important records
c. Poorly written programs resulting in information loss
,d. Hacking of information systems
- answers 100%✔✔✔ 📌d. Hacking of information systems
Rationale: A computer crime is a deliberate, illegal act involving computers or computer
systems. Hacking—unauthorized access to information systems—is a criminal offense
prosecuted under computer fraud and abuse laws. Options (a), (b), and (c) all describe mistakes,
negligence, or poor practices rather than intentional criminal activity. They may cause data loss,
but they are not classified as crimes because they lack criminal intent.
QUESTION 3
In the context of security threats, pretexting, sniffing, spoofing, and phishing are all examples
of ________.
a. Unauthorized data disclosure
b. SQL injection
c. Incorrect data modification
d. Loss of infrastructure
- answers 100%✔✔✔ 📌a. Unauthorized data disclosure
Rationale: Pretexting (creating a fabricated scenario to obtain information), sniffing
(intercepting network traffic), spoofing (disguising communication as coming from a trusted
source), and phishing (deceiving users to reveal confidential data) are all methods used to gain
unauthorized access to and disclosure of sensitive information. They are not examples of SQL
injection, data modification, or infrastructure loss—they are information-gathering and
deception techniques aimed at data disclosure.
QUESTION 4
Email spoofing is a synonym for ________.
a. Sniffing
b. Baiting
c. Usurping
d. Phishing
,- answers 100%✔✔✔ 📌d. Phishing
Rationale: Email spoofing involves forging an email header so the message appears to come
from someone other than the actual sender. This technique is most commonly used in phishing
attacks, where attackers impersonate legitimate organizations to trick recipients into revealing
personal information. While sniffing involves intercepting traffic and usurping involves taking
over a system, email spoofing is specifically associated with phishing campaigns.
QUESTION 5
Which of the following is a sniffing technique?
a. Caches
b. Adware
c. Port scanner
d. IP spoofing
- answers 100%✔✔✔ 📌b. Adware
Rationale: Adware is a type of spyware that monitors user behavior and can act as a sniffing
technique by tracking browsing habits, keystrokes, and online activities without the user's
knowledge or consent. Port scanners are used for network reconnaissance, IP spoofing is an
address forgery technique, and caches are temporary storage mechanisms—none of these are
classified as sniffing techniques in the context of information security threats.
QUESTION 6
Which of the following is most likely to be a result of hacking?
a. Slowing of network speed
b. Pop-up ads appearing frequently
c. Small amounts of spam in a user's inbox
d. Certain Web sites being censored for hurting sentiments
- answers 100%✔✔✔ 📌a. Slowing of network speed
, Rationale: When hackers breach a network, they often install malicious tools, launch attacks
from compromised systems, or exfiltrate large amounts of data—all of which can significantly
slow network performance. While pop-up ads may indicate adware and spam may indicate
email list compromise, network slowdown is a direct and common consequence of an active
hacking intrusion. Censorship is a policy decision, not a hacking result.
QUESTION 7
Which of the following usually happens in a malicious denial-of-service attack?
a. A phisher pretends to be a legitimate company and requests confidential data
b. A hacker identifies vulnerabilities in network hosts
c. A hacker floods a Web server with many millions of bogus service requests
d. An intruder uses another site's IP address to masquerade as that other site
- answers 100%✔✔✔ 📌c. A hacker floods a Web server with many millions of bogus
service requests
Rationale: A denial-of-service (DoS) attack is specifically designed to make a service unavailable
by overwhelming it with traffic. The attacker sends massive volumes of bogus requests to
exhaust the server's resources, preventing legitimate users from accessing the service. Option
(a) describes phishing, option (b) describes vulnerability scanning, and option (d) describes IP
spoofing—none of which are the defining characteristic of a DoS attack.
QUESTION 8
Which of the following statements is TRUE about losses due to computer security threats?
a. Surveys on computer crimes provide accurate results since they use standard parameters to
measure and tally computer crime costs
b. Losses due to natural disasters can be measured accurately
c. Losses due to human error are insignificant
d. Surveys suggest that some organizations do not report all their computer crime losses, and
some will not report such losses at all
- answers 100%✔✔✔ 📌d. Surveys suggest that some organizations do not report all
their computer crime losses, and some will not report such losses at all