ANSWERS GRADED A+
✔✔monitoring - ✔✔____ is not a risk response identified in the COSO enterprise risk
management framework
✔✔residual risk - ✔✔____ remains after management implements internal controls
✔✔impact times likelihood - ✔✔how is expected loss calculated when performing risk
assessment
✔✔avoid - ✔✔as a result of an internal risk assessment allstate insurance decided it
was not profitable to provide hurricane insurance in the state of florida. allstate
apparently chose to ___ the risk of paying hurricane claims in florida
✔✔reduce - ✔✔upon getting into your new car, you suddenly become worried that you
might become injured in an auto accident. you decided to buckle you seat belt in
response you chose to ___ the risk of being injured in an auto accident
✔✔make sure that different people handle different parts of the same transaction -
✔✔one of the key objectives of segregating duties is to
✔✔Mike issues credit cards to him and Maxine, and when the credit card balances ae
just under $1000 maxine writes off the accounts as bad debt Mike then issues new
cards. - ✔✔of the following examples of fraud which will be the most difficult to prevent
and detect?
✔✔sequentially pre-numbering sales invoices - ✔✔which of the following is a control
related to design and use of documents and records
✔✔effective - ✔✔if the time an attacker takes to break through the organizations
preventive controls is greater than the sum of the time required to detect the attack and
the time required to respond to the attack then security is
✔✔authorization - ✔✔restricting access of users to specific portions of the system as
well as specific tasks is an example of
✔✔encryption - ✔✔____ is/are an example of a preventive control
✔✔log analysis - ✔✔___ is/are an example of a detective control
✔✔incident response teams - ✔✔Which of the following is an example of a corrective
control?
, ✔✔passwords should be no more than 8 characters in length - ✔✔which of the
following is not a requirement of effective passwords
✔✔involves the use of two or more basic authentication methods - ✔✔multifactor
authentication
✔✔is a table specifying which portions of the system users are permitted to access -
✔✔identify the best description of an access control matrix below
✔✔internet protocol - ✔✔this protocol specifies the structure of packets sent over the
internet and the route to get them to the proper destination
✔✔the information needs to be classified in terms of its value to the organization -
✔✔after the information that needs to be protected has been identified what step should
be completed next
✔✔data loss prevention software - ✔✔which type of software blocks outgoing
messages containing key words or phrases associated with an organization's sensitive
data
✔✔a digital watermark - ✔✔a tool that embeds a code into all of its digital documents
✔✔internet voice conversations can be intercepted - ✔✔what confidentiality and
security risk does using VoIP present to organizations
✔✔provide free credit report monitoring for customers - ✔✔which of the following is not
one of the 10 internationally recognized best practices for protecting the privacy of
customers' personal information
✔✔privacy - ✔✔in developing policies related to personal information about customers,
folding squis technologies adhered to the trust services framework the standard
applicable to these policies is
✔✔an encryption system with digital signatures - ✔✔a client approached Paxton Uffe
and said " i need for my customers to make payments online using credit cards, bit I
want to make sure that the credit card data isnt intercepted. What do you suggest?"
✔✔spam - ✔✔Cindy logged into her email and saw she had 50 emails from the same
company she was a victim of
✔✔10 - ✔✔under CAN-SPAM legislation an organization that receives an opt-out
request from and individual has ___ days to implement steps to ensure they do not
send out any additional unsolicited email to the individual again