MIS 416 Exam 1 Questions With Complete Solutions
_________ negatively affect(s) the CIA triad. Correct Answers
Threats
_____________ is the likelihood that a threat will exploit a
vulnerability. Correct Answers Probability
A business impact analysis is concerned with identifying and
implementing recovery methods. Correct Answers False
A key step in managing risk is to first understand and manage
the source. Correct Answers True
A Risk rating calculation = Correct Answers likelihood of
vulnerability x value of asset - % mitigated risks + uncertainty
A threat event where loss materializes and/or where liability
increases. Correct Answers Loss Event
A(n) ___________________ is performed to identify the most
serious risks, help you manage risks, and identify the best
methods to control risks. Correct Answers RA
A(n) ____________________ is an act against an asset that
could result in a loss. Correct Answers Attack
According to Landoll, which of the following is NOT a type of
security test? Correct Answers Threat Testing
, According to Talabis, what is the function of a BIA? Correct
Answers To assess and identify critical and non-critical
organizational functions and activities.
According to Talabis, what is the most rigorous and most
encompassing activity in the information security risk
assessment process? Correct Answers Data Collection
According to the CIA triad, which of the following is a desirable
characteristic for computer security? Correct Answers
Availability
An asset has a value of 50 and 1 vulnerability. The vulnerability
has a probability of 1.0. There are no controls. It is estimated
this information is 90% accurate. What is the risk rating?
Correct Answers 55
An IT asset inventory is a list of IT assets that are vulnerable to
a specific threat that is under assessment. Correct Answers
False
An organization should implement as many controls as possible.
Correct Answers False
Another term for risk mitigation is _______. Correct Answers
Risk Reduction
Asset valuation is NOT a major priority of risk management.
Correct Answers False
_________ negatively affect(s) the CIA triad. Correct Answers
Threats
_____________ is the likelihood that a threat will exploit a
vulnerability. Correct Answers Probability
A business impact analysis is concerned with identifying and
implementing recovery methods. Correct Answers False
A key step in managing risk is to first understand and manage
the source. Correct Answers True
A Risk rating calculation = Correct Answers likelihood of
vulnerability x value of asset - % mitigated risks + uncertainty
A threat event where loss materializes and/or where liability
increases. Correct Answers Loss Event
A(n) ___________________ is performed to identify the most
serious risks, help you manage risks, and identify the best
methods to control risks. Correct Answers RA
A(n) ____________________ is an act against an asset that
could result in a loss. Correct Answers Attack
According to Landoll, which of the following is NOT a type of
security test? Correct Answers Threat Testing
, According to Talabis, what is the function of a BIA? Correct
Answers To assess and identify critical and non-critical
organizational functions and activities.
According to Talabis, what is the most rigorous and most
encompassing activity in the information security risk
assessment process? Correct Answers Data Collection
According to the CIA triad, which of the following is a desirable
characteristic for computer security? Correct Answers
Availability
An asset has a value of 50 and 1 vulnerability. The vulnerability
has a probability of 1.0. There are no controls. It is estimated
this information is 90% accurate. What is the risk rating?
Correct Answers 55
An IT asset inventory is a list of IT assets that are vulnerable to
a specific threat that is under assessment. Correct Answers
False
An organization should implement as many controls as possible.
Correct Answers False
Another term for risk mitigation is _______. Correct Answers
Risk Reduction
Asset valuation is NOT a major priority of risk management.
Correct Answers False