D489 ITAS 6320
Cybersecurity Management
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following is considered a framework for
managing cybersecurity risks?
a) NIST SP 800-53
b) ITIL
c) ISO 27001
d) All of the above
Correct Answer: d) All of the above
Rationale: All these frameworks provide structured
approaches to managing cybersecurity risks.
2. What is the primary objective of an incident response plan?
a) To prevent all incidents from occurring
b) To ensure swift and effective resolution of incidents
c) To assign blame for incidents
d) To notify law enforcement
Correct Answer: b) To ensure swift and effective resolution
of incidents
Rationale: The main goal of an incident response plan is to
manage and mitigate harm caused by incidents.
©2024/2025
, 3. Which of the following is a key function of a Security
Information and Event Management (SIEM) system?
a) Data backup
b) Real-time analysis of security alerts
c) Network virtualization
d) Cloud storage
Correct Answer: b) Real-time analysis of security alerts
Rationale: SIEM systems are designed to aggregate and
analyze security data in real-time.
4. In cybersecurity, what does the acronym "CIA" stand for?
a) Central Intelligence Agency
b) Confidentiality, Integrity, Availability
c) Cyber Intelligence Assessment
d) Critical Infrastructure Assurance
Correct Answer: b) Confidentiality, Integrity, Availability
Rationale: The CIA triad is fundamental to information
security and encapsulates the three core principles.
5. Which of the following best describes 'phishing'?
a) Malware that encrypts files
©2024/2025
Cybersecurity Management
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. Which of the following is considered a framework for
managing cybersecurity risks?
a) NIST SP 800-53
b) ITIL
c) ISO 27001
d) All of the above
Correct Answer: d) All of the above
Rationale: All these frameworks provide structured
approaches to managing cybersecurity risks.
2. What is the primary objective of an incident response plan?
a) To prevent all incidents from occurring
b) To ensure swift and effective resolution of incidents
c) To assign blame for incidents
d) To notify law enforcement
Correct Answer: b) To ensure swift and effective resolution
of incidents
Rationale: The main goal of an incident response plan is to
manage and mitigate harm caused by incidents.
©2024/2025
, 3. Which of the following is a key function of a Security
Information and Event Management (SIEM) system?
a) Data backup
b) Real-time analysis of security alerts
c) Network virtualization
d) Cloud storage
Correct Answer: b) Real-time analysis of security alerts
Rationale: SIEM systems are designed to aggregate and
analyze security data in real-time.
4. In cybersecurity, what does the acronym "CIA" stand for?
a) Central Intelligence Agency
b) Confidentiality, Integrity, Availability
c) Cyber Intelligence Assessment
d) Critical Infrastructure Assurance
Correct Answer: b) Confidentiality, Integrity, Availability
Rationale: The CIA triad is fundamental to information
security and encapsulates the three core principles.
5. Which of the following best describes 'phishing'?
a) Malware that encrypts files
©2024/2025