MIS 416 Exam 1 questions with accurate answers
_________ negatively affect(s) the CIA triad. Ans✓✓✓ Threats
_____________ is the likelihood that a threat will exploit a
vulnerability. Ans✓✓✓ Probability
A business impact analysis is concerned with identifying and
implementing recovery methods. Ans✓✓✓ False
A key step in managing risk is to first understand and manage the
source. Ans✓✓✓ True
A Risk rating calculation = Ans✓✓✓ likelihood of vulnerability x value
of asset - % mitigated risks + uncertainty
A threat event where loss materializes and/or where liability increases.
Ans✓✓✓ Loss Event
A(n) ___________________ is performed to identify the most serious
risks, help you manage risks, and identify the best methods to control
risks. Ans✓✓✓ RA
A(n) ____________________ is an act against an asset that could result
in a loss. Ans✓✓✓ Attack
, According to Landoll, which of the following is NOT a type of security
test? Ans✓✓✓ Threat Testing
According to Talabis, what is the function of a BIA? Ans✓✓✓ To
assess and identify critical and non-critical organizational functions and
activities.
According to Talabis, what is the most rigorous and most encompassing
activity in the information security risk assessment process? Ans✓✓✓
Data Collection
According to the CIA triad, which of the following is a desirable
characteristic for computer security? Ans✓✓✓ Availability
An asset has a value of 50 and 1 vulnerability. The vulnerability has a
probability of 1.0. There are no controls. It is estimated this information
is 90% accurate. What is the risk rating? Ans✓✓✓ 55
An IT asset inventory is a list of IT assets that are vulnerable to a
specific threat that is under assessment. Ans✓✓✓ False
An organization should implement as many controls as possible.
Ans✓✓✓ False
_________ negatively affect(s) the CIA triad. Ans✓✓✓ Threats
_____________ is the likelihood that a threat will exploit a
vulnerability. Ans✓✓✓ Probability
A business impact analysis is concerned with identifying and
implementing recovery methods. Ans✓✓✓ False
A key step in managing risk is to first understand and manage the
source. Ans✓✓✓ True
A Risk rating calculation = Ans✓✓✓ likelihood of vulnerability x value
of asset - % mitigated risks + uncertainty
A threat event where loss materializes and/or where liability increases.
Ans✓✓✓ Loss Event
A(n) ___________________ is performed to identify the most serious
risks, help you manage risks, and identify the best methods to control
risks. Ans✓✓✓ RA
A(n) ____________________ is an act against an asset that could result
in a loss. Ans✓✓✓ Attack
, According to Landoll, which of the following is NOT a type of security
test? Ans✓✓✓ Threat Testing
According to Talabis, what is the function of a BIA? Ans✓✓✓ To
assess and identify critical and non-critical organizational functions and
activities.
According to Talabis, what is the most rigorous and most encompassing
activity in the information security risk assessment process? Ans✓✓✓
Data Collection
According to the CIA triad, which of the following is a desirable
characteristic for computer security? Ans✓✓✓ Availability
An asset has a value of 50 and 1 vulnerability. The vulnerability has a
probability of 1.0. There are no controls. It is estimated this information
is 90% accurate. What is the risk rating? Ans✓✓✓ 55
An IT asset inventory is a list of IT assets that are vulnerable to a
specific threat that is under assessment. Ans✓✓✓ False
An organization should implement as many controls as possible.
Ans✓✓✓ False