• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 18 pages
Exam (elaborations)

MISY 5325 Information Systems Security Final Exam — Complete Study Guide 2025 / 2026 Edition | Verified Answers

Document preview thumbnail
Preview 3 out of 18 pages

This document is a complete, professionally organized duplicate of the MISY 5325 Information Systems Security Final Exam Q&A set. All questions and verified correct answers from the original exam are preserved and restructured into clearly labeled topic sections for efficient study. Coverage: Access controls and identity management, risk management and threat assessment, compliance and regulatory frameworks, business continuity planning (BCP), disaster recovery planning (DRP), incident response and CIRT, NIST Cybersecurity Framework, and forensics. Format: Each section begins with key concept definitions and summaries, followed by exam Q&A pairs with answers clearly highlighted in green, and True/False statements with answers color-coded (green = TRUE, red = FALSE). Sections: 8 | Questions: 150+ | Source: Verified 2025/2026 actual final exam

Content preview

MISY 5325
Information Systems Security
Final Exam — Complete Study Guide
Edition | Verified Answers



About This Study Guide
This document is a complete, professionally organized duplicate of the MISY 5325 Information Systems
Security Final Exam Q&A set. All questions and verified correct answers from the original exam are
preserved and restructured into clearly labeled topic sections for efficient study.
Coverage: Access controls and identity management, risk management and threat assessment, compliance
and regulatory frameworks, business continuity planning (BCP), disaster recovery planning (DRP), incident
response and CIRT, NIST Cybersecurity Framework, and forensics.
Format: Each section begins with key concept definitions and summaries, followed by exam Q&A pairs with
answers clearly highlighted in green, and True/False statements with answers color-coded (green = TRUE,
red = FALSE).
Sections: 8 | Questions: 150+ | Source: Verified 2025/2026 actual final exam




Section 1: Access Controls & Identity Management
Access controls govern how users and processes communicate and interact with systems and resources. Every
access control system has three common attributes: an identification scheme, an authentication method, and an
authorization model.


1.1 Key Definitions
Identification: The process of the subject supplying an identifier to the object (e.g., a username). Used to identify
unique records in a set.
Authentication: The process of the subject supplying verifiable credentials to the object — proving you are who
you claim to be. The METHOD used to prove identification is genuine. Requires the subject to supply verifiable
credentials called FACTORS.
Authorization: The process of assigning authenticated subjects permission to carry out a specific operation. The
MODEL defines how access rights and permissions are granted.
Identity Management: The process of identifying, authenticating, and authorizing users or groups to access
applications, systems, or networks.
Subject: The ACTIVE entity that requests access to a resource or data.
Object: The PASSIVE entity being accessed or acted upon.
Least Privilege: All users should be granted only the level of privilege they need to do their jobs, and no more.
Need to Know: A subject should be granted access to an object only if the access is needed to carry out the job.
Shares with least privilege: both specify users be granted access only to what they need to perform their jobs.
Security Posture: An organization's approach to access controls based on information about an object, such as
a host or network.
Right: Grants the authority to perform an action on a system.
Permission: Grants access to a resource.
Security Labels: Mandatory access controls embedded in object and subject properties.

,Object Capability: Used programmatically; based on a combination of an unforgeable reference and an
operational message.
Access Control Lists (ACLs): Used to determine access based on criteria such as user ID, group membership,
classification, location, address, and date.
Faraday Cage: Built out of a mesh of conducting material that prevents electromagnetic energy from entering or
escaping.


1.2 Authentication Factors — Three Categories
• Something you KNOW (e.g., password)
• Something you HAVE (e.g., token, smart card)
• Something you ARE (e.g., biometrics)
• NOT a category: Role (something the user does)


1.3 Authorization Models
Three Primary Models: Discretionary Access Control (DAC), Mandatory Access Control (MAC), Role-Based
Access Control (RBAC).
NOT a primary model: Multilayer authorization
Multifactor Authentication: When TWO OR MORE DIFFERENT TYPES of factors are presented (NOT one or
more — that is just single-factor).
Multilayer Authentication: When two or more of the SAME type of factors are presented.


1.4 Network Access Control (NAC)
• Can provide: device compliance checking, network segmentation, guest access, quarantine
• Cannot provide: password management


1.5 Exam Q&A — Access Controls
Q: What is the process of the subject supplying an identifier to the object?
A: Identification
Q: What is the process of the subject supplying verifiable credentials to the object?
A: Authentication
Q: What is the process of assigning authenticated subjects permission to carry out a specific operation?
A: Authorization
Q: The __ method is how identification is proven to be genuine.
A: Authentication
Q: The __ model defines how access rights and permissions are granted.
A: Authorization
Q: A right grants the authority to perform an action on a system. A __ grants access to a resource.
A: Permission
Q: The active entity that requests access to a resource is called the __.
A: Subject
Q: The passive entity being accessed or acted upon is called the __.
A: Object
Q: A subject should be granted access only if needed to carry out the job — this is called __.
A: Need To Know

, Q: The principle of __ states that all users should be granted only the level of privilege they need.
A: Least privilege
Q: In terms of authorization, security labels are based on:
A: Object/subject classification properties — mandatory access controls
Q: In the three categories of identification factors, which is NOT included?
A: Role (something the user does)
Q: The three primary authorization models include all EXCEPT:
A: Multilayer authorization
Q: Network Access Control (NAC) can provide all EXCEPT:
A: Password management
Q: An identification scheme, an authentication method, and an authorization model are the three common
attributes of all access controls.
A: TRUE
Statement: Access controls can be technical or administrative but never physical.
Answer: FALSE — access controls can be technical, administrative, OR physical.
Statement: Authentication is about establishing who you are, whereas identification is about proving you are the
entity you claim to be.
Answer: FALSE — these are reversed. Identification establishes who you are; authentication proves it.
Statement: The security posture of an organization determines the custom settings for access controls.
Answer: FALSE
Statement: Multifactor authentication is when one or more factors are presented.
Answer: FALSE — multifactor requires two or more DIFFERENT types of factors.
Statement: Multilayer authentication is when two or more of the same type of factors are presented.
Answer: TRUE




Section 2: Risk Management & Threat Assessment
Risk management involves identifying, analyzing, and responding to threats and vulnerabilities. The goal is to
reduce risk to an acceptable level through controls and countermeasures.


2.1 Core Formulas & Definitions
Risk Formula: Risk = Vulnerability x Threat
Vulnerability: A weakness in a system or process.
Threat: Any activity that represents a possible danger — circumstances or events with the potential to cause
adverse impact.
Exploit: An exploit assessment attempts to identify vulnerabilities that can be exploited.
Mitigate: To reduce or neutralize threats or vulnerabilities to an acceptable level.
Scope Creep: The biggest problem you can face if you do not identify the scope of your risk management project.
Countermeasure Value (CBA): Projected benefit minus cost of control. Example: $50,000 benefit - $1,500 cost =
$48,500 control value.
Overlapping Countermeasures: Different countermeasures that attempt to mitigate the SAME risk.
Implicit Deny: A firewall approach that starts by blocking ALL traffic, then adds rules to allow approved traffic.

Document information

Uploaded on
February 26, 2026
Number of pages
18
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
8
Followers
0
Items
93
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions