• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 19 pages
Exam (elaborations)

MIS 416 Exam 1(All answered)

Document preview thumbnail
Preview 3 out of 19 pages

Which of the following can be calculated using the values from an annualized rate of occurrence multiplied by the values from a single loss expectancy? A) cost benefit analysis B) annualized loss expectancy C) asset valuation D) operational feasibility correct answers B What is an indirect objective of a business impact analysis? A) to evaluate the effectiveness of controls B) to justify funding C) to calculate MAOs D) to identify an impact that can result from disruptions in a business correct answers B An organization should implement as many controls as possible. T/F? correct answers F A business impact analysis is intended to include all IT functions. T/F? correct answers F The value of an assessment is only as valuable as the expertise of the experts. T/F? correct answers T Some recovery point objectives require you to recover data up to a moment in time. T/F? correct answers T When should you perform a risk assessment? A) when eliminating a threat B) continuously C) when mitigating a threat D) periodically correct answers D It is often useful to categorize an organization's environments by risk sensitivity and then go deeper into the specific sensitive resources in each environment. T/F? correct answers T

Content preview

MIS 416 Exam 1(All answered)
Which of the following can be calculated using the values from an annualized rate of occurrence
multiplied by the values from a single loss expectancy?
A) cost benefit analysis
B) annualized loss expectancy
C) asset valuation
D) operational feasibility correct answers B


What is an indirect objective of a business impact analysis?
A) to evaluate the effectiveness of controls
B) to justify funding
C) to calculate MAOs
D) to identify an impact that can result from disruptions in a business correct answers B


An organization should implement as many controls as possible. T/F? correct answers F


A business impact analysis is intended to include all IT functions. T/F? correct answers F


The value of an assessment is only as valuable as the expertise of the experts. T/F? correct answers T


Some recovery point objectives require you to recover data up to a moment in time. T/F? correct answers
T


When should you perform a risk assessment?
A) when eliminating a threat
B) continuously
C) when mitigating a threat
D) periodically correct answers D


It is often useful to categorize an organization's environments by risk sensitivity and then go deeper into
the specific sensitive resources in each environment. T/F? correct answers T

,Which of the following is NOT an example of what type of document a risk assessor could request during
a risk assessment?
A) Asset Inventories
B) Previously considered IT Security Recommendations
C) Current Security Policies, Standards and Procedures
D) Previous Information Security Risk Assessments
E) Copy of the BIA correct answers B


When using the RIIOT method for data gathering, it is essential to inspect security controls prior to
interviewing key personnel in order to understand the systems that employees are operating and
potentially putting at risk. T/F? correct answers F


What is the key principal element of an information security risk assessment?
A) vulnerability
B) threat agent
C) asset
D) threat correct answers C


Objectives during the interview phase of the RIIOT technique include all the following except:
A) Measurement of security awareness among staff
C) Identification of vulnerabilities in the area of the interviewee's expertise
C) Confirmation of managerial involvement in risk assessment process
D) Confirmation of security procedure execution
E) Confirmation of threat identification, asset valuation and critical systems identification correct answers
C


The objective of the "inspect security controls" approach in the RIIOT technique is to present alternative
methods of potentially reducing risks to an organization. T/F? correct answers F


A threat event where loss materializes and/or where liability increases.
A) Threat Event

, B) Vulnerability Event
C) Loss Event
D) Primary Event
E) Risk Event correct answers C


According to the CIA triad, which of the following is a desirable characteristic for computer security?
A) transparency
B) accountability
C) availability
D) decoupling correct answers C


All companies face the same set of vulnerabilities. T/F? correct answers F


When risk is reduced to an acceptable level, the remaining risk is referred to as _________.
A) remaining risk
B) acceptable risk
C) low-impact risk
D) residual risk correct answers D


Uncertainty level indicates how valid data is. T/F? correct answers T


Asset valuation is NOT a major priority of risk management. T/F? correct answers F


CBA stands for Cost Benefit Authorization. T/F? correct answers F


What may occur if you do NOT include the scope of the RA when defining it?
A) attacks
B) missed deadlines
C) exploited threats
D) losses correct answers B

Document information

Uploaded on
November 20, 2024
Number of pages
19
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.79

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
23
Followers
6
Items
4026
Last sold
6 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions