ISA 3300 Chapter 6 Exam Questions With
Correct Answers
Having an established risk management program means that an
| | | | | | | | |
organization's assets are completely protected.
| | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
The IT community often takes on the leadership role in addressing risk.
| | | | | | | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
MAC addresses are considered a reliable identifier for devices with
| | | | | | | | | |
network interfaces because they are essentially foolproof.
| | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
,Likelihood is the overall rating of the probability that a specific
| | | | | | | | | | |
vulnerability will be exploited or attacked.
| | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-*a. True
| | | | | |
b. False
|
Some threats can manifest in multiple ways, yielding multiple
| | | | | | | | |
vulnerabilities for an asset-threat pair. | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-*a. True
| | | | | |
b. False
|
When operating any kind of organization, a certain amount of debt is
| | | | | | | | | | | |
always involved. |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
Risk identification, risk analysis, and risk evaluation are part of a single
| | | | | | | | | | | |
function known as risk protection.
| | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
, *b. False |
Some threats can manifest in multiple ways, yielding multiple exploits
| | | | | | | | | |
for an asset-threat pair.
| | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |
The recognition, enumeration and documentation of risks to an
| | | | | | | | |
organization's information assets is known as risk control.
| | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |
An evaluation of the threats to information assets, including a
| | | | | | | | | |
determination of their potential to endanger the organization, is known
| | | | | | | | | |
as exploit assessment.
| |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |
Correct Answers
Having an established risk management program means that an
| | | | | | | | |
organization's assets are completely protected.
| | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
The IT community often takes on the leadership role in addressing risk.
| | | | | | | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
MAC addresses are considered a reliable identifier for devices with
| | | | | | | | | |
network interfaces because they are essentially foolproof.
| | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
,Likelihood is the overall rating of the probability that a specific
| | | | | | | | | | |
vulnerability will be exploited or attacked.
| | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-*a. True
| | | | | |
b. False
|
Some threats can manifest in multiple ways, yielding multiple
| | | | | | | | |
vulnerabilities for an asset-threat pair. | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-*a. True
| | | | | |
b. False
|
When operating any kind of organization, a certain amount of debt is
| | | | | | | | | | | |
always involved. |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False
|
Risk identification, risk analysis, and risk evaluation are part of a single
| | | | | | | | | | | |
function known as risk protection.
| | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
, *b. False |
Some threats can manifest in multiple ways, yielding multiple exploits
| | | | | | | | | |
for an asset-threat pair.
| | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |
The recognition, enumeration and documentation of risks to an
| | | | | | | | |
organization's information assets is known as risk control.
| | | | | | |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |
An evaluation of the threats to information assets, including a
| | | | | | | | | |
determination of their potential to endanger the organization, is known
| | | | | | | | | |
as exploit assessment.
| |
a. True
| |
b. False - CORRECT ANSWER✔✔-a. True
| | | | | |
*b. False |