MISY 5325 EXAM 1 QUESTIONS AND ANSWERS | 2026
_______ are acts that are hostile to an organization. - Answers - Intentional threats
_________ is the process of creating a list of threats. - Answers - Threat identification
__________ damage for the sake of doing damage, and they often choose targets of
opportunity. - Answers - Vandals
A __________ is a computer joined to a botnet. - Answers - zombie
A______policy governs how patches are understood ,tested ,and rolled out to systems
and clients. - Answers - patch management
A(n) _________ is the likelihood that something unexpected is going to occur. -
Answers - risk
Alice is an aspiring hacker. She wants to get information on computer and network
vulnerabilities and ways to exploit applications. Which of the following is the best
source? - Answers - Dark web
All of the following terms have the same meaning, except: - Answers - Internal network
zone
Companies use risk assessment strategies to differentiate ___________ from
_________. - Answers - severe risks, minor risks
Hajar is a security professional for a government contractor. Her company recently hired
three new employees for a special project, all of whom have a security clearance for
Secret data. Rather than granting the employees access to all files and folders in the
data repository, she is granting them access only to the data they need for the project.
What principle is Hajar following? - Answers - Principle of need to know
Hardening a server refers to: - Answers - the combination of all the steps that it takes to
protect a vulnerable system and make it more secure than the default installation.
In which of the following domains does the IT infrastructure link to a wide area network
(WAN) and the Internet? - Answers - LAN-to-WAN Domain
Isabella works as a risk specialist for her company. She wants to determine which risks
should be managed and which should not by applying a test to each risk. Risks that
don't meet the test are accepted. What type of test does she apply? - Answers -
Reasonableness test
, Kevin is a disgruntled employee who was recently laid off from a major technology
company. He wants to launch an attack on the company. Where might Kevin learn
about vulnerabilities that he can exploit? - Answers - A blog
Total risk equals: - Answers - threat × vulnerability × asset value.
True or False? The formula for calculating residual risk is Total Risk - Controls. -
Answers - TRUE
True or False? A security policy provides details of how to implement security
techniques. - Answers - FALSE
True or False? All companies face the same set of vulnerabilities. - Answers - False
True or False? Aserver's attack surface refers to how many services can be attacked on
a server. - Answers - TRUE
True or False? Companies purchase insurance to reduce the impact of threats. -
Answers - TRUE
True or False? Data is a tangible asset. - Answers - TRUE
True or False? If the likelihood of a risk occurring is low, the impact would be low as
well. - Answers - FALSE
True or False? Implementing a backup plan is an example of a risk mitigation. -
Answers - TRUE
True or False? Malware cannot threaten the Workstation Domain of a typical IT security
infrastructure if the other domains are secure. - Answers - FALSE
True or False? Outsourcing an activity, such as having a third party host your website,
is an example of risk avoidance. - Answers - FALSE
True or False? Ransomware is an attack in which criminals restrict access to an
infected system and display messages to the user demanding payment to get access to
their computer and/or files. - Answers - TRUE
True or False? Regarding the security triad, integrity is ensuring data or an IT system is
not modified or destroyed. - Answers - TRUE
True or False? Related to security policies, standards describe what should be
implemented and how. - Answers - TRUE
True or False? Residual risk is the risk that remains before controls have been applied.
- Answers - FALSE
_______ are acts that are hostile to an organization. - Answers - Intentional threats
_________ is the process of creating a list of threats. - Answers - Threat identification
__________ damage for the sake of doing damage, and they often choose targets of
opportunity. - Answers - Vandals
A __________ is a computer joined to a botnet. - Answers - zombie
A______policy governs how patches are understood ,tested ,and rolled out to systems
and clients. - Answers - patch management
A(n) _________ is the likelihood that something unexpected is going to occur. -
Answers - risk
Alice is an aspiring hacker. She wants to get information on computer and network
vulnerabilities and ways to exploit applications. Which of the following is the best
source? - Answers - Dark web
All of the following terms have the same meaning, except: - Answers - Internal network
zone
Companies use risk assessment strategies to differentiate ___________ from
_________. - Answers - severe risks, minor risks
Hajar is a security professional for a government contractor. Her company recently hired
three new employees for a special project, all of whom have a security clearance for
Secret data. Rather than granting the employees access to all files and folders in the
data repository, she is granting them access only to the data they need for the project.
What principle is Hajar following? - Answers - Principle of need to know
Hardening a server refers to: - Answers - the combination of all the steps that it takes to
protect a vulnerable system and make it more secure than the default installation.
In which of the following domains does the IT infrastructure link to a wide area network
(WAN) and the Internet? - Answers - LAN-to-WAN Domain
Isabella works as a risk specialist for her company. She wants to determine which risks
should be managed and which should not by applying a test to each risk. Risks that
don't meet the test are accepted. What type of test does she apply? - Answers -
Reasonableness test
, Kevin is a disgruntled employee who was recently laid off from a major technology
company. He wants to launch an attack on the company. Where might Kevin learn
about vulnerabilities that he can exploit? - Answers - A blog
Total risk equals: - Answers - threat × vulnerability × asset value.
True or False? The formula for calculating residual risk is Total Risk - Controls. -
Answers - TRUE
True or False? A security policy provides details of how to implement security
techniques. - Answers - FALSE
True or False? All companies face the same set of vulnerabilities. - Answers - False
True or False? Aserver's attack surface refers to how many services can be attacked on
a server. - Answers - TRUE
True or False? Companies purchase insurance to reduce the impact of threats. -
Answers - TRUE
True or False? Data is a tangible asset. - Answers - TRUE
True or False? If the likelihood of a risk occurring is low, the impact would be low as
well. - Answers - FALSE
True or False? Implementing a backup plan is an example of a risk mitigation. -
Answers - TRUE
True or False? Malware cannot threaten the Workstation Domain of a typical IT security
infrastructure if the other domains are secure. - Answers - FALSE
True or False? Outsourcing an activity, such as having a third party host your website,
is an example of risk avoidance. - Answers - FALSE
True or False? Ransomware is an attack in which criminals restrict access to an
infected system and display messages to the user demanding payment to get access to
their computer and/or files. - Answers - TRUE
True or False? Regarding the security triad, integrity is ensuring data or an IT system is
not modified or destroyed. - Answers - TRUE
True or False? Related to security policies, standards describe what should be
implemented and how. - Answers - TRUE
True or False? Residual risk is the risk that remains before controls have been applied.
- Answers - FALSE