MISY 5325 QUIZ 1 QUESTIONS AND
VERIFIED ANSWERS
\.Which of the following is not a risk management step? - ANSWERS✔-Eliminating
all risks
\._______ are acts that are hostile to an organization. - ANSWERS✔-Intentional
threats
\._________ is the process of creating a list of threats. - ANSWERS✔-Threat
identification
\.__________ damage for the sake of doing damage, and they often choose
targets of opportunity. - ANSWERS✔-Vandals
\.A __________ is a computer joined to a botnet. - ANSWERS✔-zombie
\.A _____________ policy governs how patches are understood, tested, and rolled
out to systems and clients. - ANSWERS✔-patch management
\.A(n) _________ is the likelihood that something unexpected is going to occur. -
ANSWERS✔-risk
, \.Alice is an aspiring hacker. She wants to get information on computer and
network vulnerabilities and ways to exploit applications. Which of the following is
the best source? - ANSWERS✔-Dark web
\.All of the following terms have the same meaning, except: - ANSWERS✔-Internal
network zone
\.Companies use risk assessment strategies to differentiate ___________ from
_________. - ANSWERS✔-severe risks, minor risks
\.Hajar is a security professional for a government contractor. Her company
recently hired three new employees for a special project, all of whom have a
security clearance for Secret data. Rather than granting the employees access to
all files and folders in the data repository, she is granting them access only to the
data they need for the project. What principle is Hajar following? - ANSWERS✔-
Principle of need to know
\.Hardening a server refers to: - ANSWERS✔-the combination of all the steps that
it takes to protect a vulnerable system and make it more secure than the default
installation.
\.In which of the following domains does the IT infrastructure link to a wide area
network (WAN) and the Internet? - ANSWERS✔-LAN-to-WAN Domain
\.Isabella works as a risk specialist for her company. She wants to determine which
risks should be managed and which should not by applying a test to each risk.
VERIFIED ANSWERS
\.Which of the following is not a risk management step? - ANSWERS✔-Eliminating
all risks
\._______ are acts that are hostile to an organization. - ANSWERS✔-Intentional
threats
\._________ is the process of creating a list of threats. - ANSWERS✔-Threat
identification
\.__________ damage for the sake of doing damage, and they often choose
targets of opportunity. - ANSWERS✔-Vandals
\.A __________ is a computer joined to a botnet. - ANSWERS✔-zombie
\.A _____________ policy governs how patches are understood, tested, and rolled
out to systems and clients. - ANSWERS✔-patch management
\.A(n) _________ is the likelihood that something unexpected is going to occur. -
ANSWERS✔-risk
, \.Alice is an aspiring hacker. She wants to get information on computer and
network vulnerabilities and ways to exploit applications. Which of the following is
the best source? - ANSWERS✔-Dark web
\.All of the following terms have the same meaning, except: - ANSWERS✔-Internal
network zone
\.Companies use risk assessment strategies to differentiate ___________ from
_________. - ANSWERS✔-severe risks, minor risks
\.Hajar is a security professional for a government contractor. Her company
recently hired three new employees for a special project, all of whom have a
security clearance for Secret data. Rather than granting the employees access to
all files and folders in the data repository, she is granting them access only to the
data they need for the project. What principle is Hajar following? - ANSWERS✔-
Principle of need to know
\.Hardening a server refers to: - ANSWERS✔-the combination of all the steps that
it takes to protect a vulnerable system and make it more secure than the default
installation.
\.In which of the following domains does the IT infrastructure link to a wide area
network (WAN) and the Internet? - ANSWERS✔-LAN-to-WAN Domain
\.Isabella works as a risk specialist for her company. She wants to determine which
risks should be managed and which should not by applying a test to each risk.