100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

ISOL 533Midterm_2.

Rating
-
Sold
-
Pages
30
Grade
A+
Uploaded on
30-05-2022
Written in
2020/2021

What are the elements of the security triad? Risk is the practice of identifying, assessing, controlling, and mitigating risks. Another term for risk mitigation is . What is NOT a step in risk management? Companies use risk management techniques to differentiate from ? Total risk = What is a major type of vulnerability for the user domain? What are often the weakest links in IT security? What is the area that is inside the firewall? What is the primary reason to avoid risk? What is one source of risk reduction? What is NOT an example of unintentional threat? damage for the sake of doing damage, and they often choose targets of opportunity. are acts that are hostile to an organization. A(n) is a computer joined to a botnet. What is the most commonly seen attack? What can you control about threat/vulnerability pairs? A policy governs how patches are understood, tested, and rolled out to systems and clients. What is a security policy? A teenager learning about computers and programming for the first time writes a simple program meant to disrupt the function of his sister’s computer. While she’s hanging out with friends at the mall, he enters his sister’s IP address, launches the program, and waits to see what will happen. The teenager is an example of a . What is a publicly traded company? What are the seven COBIT enablers? FERPA applies to all of the following, EXCEPT . 0.25 out of 0.25 points What ensures that federal agencies protect their data and assigns specific responsibilities for federal agencies? CIPA is . When a fiduciary does not exercise due diligence, it can be considered . HIPAA requires that your insurance company sets standards for the protection of your data and the systems that handle that data’s . When your bank or credit card company sends you a notification of changes in how it collects or shares data, it is sending that notification in compliance with . What is NOT one of the three primary bureaus of the FTC? When companies are expected to adhere to the laws that they are affected by, this is commonly known as . Choose the most accurate statement with respect to creating a risk management plan. You are creating objectives for your risk management plan. What do you NOT include at this stage? 0.25 out of 0.25 points In a CBA, if the benefits of a control outweigh the costs of implementing that control, then the control can be implemented to reduce risk. However, if the cost outweighs the benefit, then . Selected POAM stands for . When a stakeholder’s involvement in a project helps that stakeholder have ownership of the project, the ownership is also known as a(n) . What are the four major categories of reporting requirements? All of the following are steps involved in creating an affinity diagram, EXCEPT: You use to communicate a risk and the resulting impact. A(n) is a process used to determine how to manage risk. After you collect data on risks and recommendations, you include that information in a report, and you give that report to management. Why do you do this? is the likelihood that a threat will exploit a vulnerability. Selected What is the Delphi Method? Qualitative RAs determine the level of risk based on the and of risk. 0.25 out of 0.25 points If you know an SLE is $100 and the associated ARO is 5 months, then what is the ALE? What is NOT a benefit of a quantitative RA? All of the following are major components of RAs, EXCEPT: What does RAID stand for? You run a bank and wish to update your physical security at each branch of your bank and to update the technological security of the bank’s private financial data. What is the best way to determine whether physical security or technological security has a higher priority of protection? When should you perform a risk assessment? is the negative result if the risk occurs. The define(s) what the system does. An exploit assessment is also known as a(n) . What is NOT something to consider when determining the value of an asset? value is the cost to purchase a new asset. What is NOT a way that you can determine the value of an asset? What may occur if you do NOT include the scope of the RA when defining it? How do you start a risk assessment? A cold site is . All of the following are reasons why configuration management is an important risk management process, EXCEPT: Threat is a process used to identify possible threats on a system. A(n) provides access to a private network over a public network such as the internet. The two categories of IP are and . refer(s) to when users or customers need a system or service.

Show more Read less
Institution
ISOL 533 / ISOL533
Course
ISOL 533 / ISOL533










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
ISOL 533 / ISOL533
Course
ISOL 533 / ISOL533

Document information

Uploaded on
May 30, 2022
Number of pages
30
Written in
2020/2021
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

CA$21.27
Get access to the full document:

100% satisfaction guarantee
Immediately available after payment
Both online and in PDF
No strings attached


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Lima222 American Intercontinental University
Follow You need to be logged in order to follow users or courses
Sold
50
Member since
5 year
Number of followers
45
Documents
439
Last sold
1 month ago

3.5

8 reviews

5
5
4
0
3
0
2
0
1
3

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions