MIS 416 Exam 2 Questions With Complete Solutions
_____ monitoring results gives organizations the capability to
maintain awareness of the risk being incurred, highlight the need
to revisit other steps in the risk management process, and initiate
process improvement activities as needed. Correct Answers
Analyzing
____________ mitigate(s) risk. Correct Answers Controls
A best practice for enabling a risk mitigation plan from your risk
assessment is prioritizing countermeasures. Correct Answers
True
A business impact analysis (BIA) is an output of the risk
assessment process. Correct Answers False
A decision is made to accept, avoid, transfer, or mitigate a risk is
done in the risk evaluation stage. Correct Answers True
A gap analysis report documents differences between what is
mitigated and what is NOT mitigated, resulting in a gap in
security. Correct Answers True
A KPx is a summary of one or more KPIs. Correct Answers
False
A risk ____ could be a simple listing of identified risks, some of
which are already assessed and others of which are still in the
process of being qualified Correct Answers Inventory
,A risk assessment ends with a report. Correct Answers True
A risk assessment ends with a report. Correct Answers True
A risk assessment provides a point-in-time report. Correct
Answers True
A risk assessment provides a point-in-time report. Correct
Answers True
A threshold KPI is significant when an index falls into a set
range. Correct Answers True
Access controls testing verifies user rights and permissions.
Correct Answers True
Action plans are a necessary output of the risk assessment
process so that recommendations can be acted upon quickly
once the assessment is approved. Correct Answers True
After you collect data on risks and recommendations, you
include that information in a report, and you give that report to
management. Why do you do this? Correct Answers to help
management decide which recommendations to use
After you collect data on risks and recommendations, you
include that information in a report, and you give that report to
management. Why do you do this? Correct Answers to help
management decide which recommendations to use
ALE is: Correct Answers SLE x ARO
, All of the following are KPI types except: Correct Answers
Esoteric
All of the following are risk treatments in different frameworks
except? Correct Answers Control
All of the following are risk treatments in different frameworks
except? Correct Answers Ignore
Another term for data range and reasonableness checks is
______________. Correct Answers Input validation
Asset valuation is a listing or grouping of assets under an
assessment. Correct Answers False
Change management ensures that similar systems have the
same, or at least similar, configurations. Correct Answers False
Change management is a process that ensures that changes are
made only after a review process. Correct Answers True
Clear and effective security risk assessment reporting requires
that the contents of the report be perceived as Correct Answers
relevant, unambiguous, nonthreatening, accurate
COBIT worked with ISACA to develop ITGI. Correct Answers
False
Configuration management is the same as change management.
Correct Answers False
_____ monitoring results gives organizations the capability to
maintain awareness of the risk being incurred, highlight the need
to revisit other steps in the risk management process, and initiate
process improvement activities as needed. Correct Answers
Analyzing
____________ mitigate(s) risk. Correct Answers Controls
A best practice for enabling a risk mitigation plan from your risk
assessment is prioritizing countermeasures. Correct Answers
True
A business impact analysis (BIA) is an output of the risk
assessment process. Correct Answers False
A decision is made to accept, avoid, transfer, or mitigate a risk is
done in the risk evaluation stage. Correct Answers True
A gap analysis report documents differences between what is
mitigated and what is NOT mitigated, resulting in a gap in
security. Correct Answers True
A KPx is a summary of one or more KPIs. Correct Answers
False
A risk ____ could be a simple listing of identified risks, some of
which are already assessed and others of which are still in the
process of being qualified Correct Answers Inventory
,A risk assessment ends with a report. Correct Answers True
A risk assessment ends with a report. Correct Answers True
A risk assessment provides a point-in-time report. Correct
Answers True
A risk assessment provides a point-in-time report. Correct
Answers True
A threshold KPI is significant when an index falls into a set
range. Correct Answers True
Access controls testing verifies user rights and permissions.
Correct Answers True
Action plans are a necessary output of the risk assessment
process so that recommendations can be acted upon quickly
once the assessment is approved. Correct Answers True
After you collect data on risks and recommendations, you
include that information in a report, and you give that report to
management. Why do you do this? Correct Answers to help
management decide which recommendations to use
After you collect data on risks and recommendations, you
include that information in a report, and you give that report to
management. Why do you do this? Correct Answers to help
management decide which recommendations to use
ALE is: Correct Answers SLE x ARO
, All of the following are KPI types except: Correct Answers
Esoteric
All of the following are risk treatments in different frameworks
except? Correct Answers Control
All of the following are risk treatments in different frameworks
except? Correct Answers Ignore
Another term for data range and reasonableness checks is
______________. Correct Answers Input validation
Asset valuation is a listing or grouping of assets under an
assessment. Correct Answers False
Change management ensures that similar systems have the
same, or at least similar, configurations. Correct Answers False
Change management is a process that ensures that changes are
made only after a review process. Correct Answers True
Clear and effective security risk assessment reporting requires
that the contents of the report be perceived as Correct Answers
relevant, unambiguous, nonthreatening, accurate
COBIT worked with ISACA to develop ITGI. Correct Answers
False
Configuration management is the same as change management.
Correct Answers False