1|Page
MISY 5325 FINAL EXAM 2026 UPDATED ACTUAL
EXAM WITH CORRECT SOLUTIONS.
Another term for data range and reasonableness checks is:
input validation
Which of the following is not one of the three primary objectives of
controls?
Eliminate
What changes plaintext data to ciphered data?
Encryption
A hacker wants to launch an attack on an organization. The hacker uses
a tool to capture data sent over the network in cleartext, hoping to
gather information that will help make the attack successful. What tool
is the hacker using?
A packet analyzer
,2|Page
Primary considerations for assessing threats based on historical data in
your local area are __________ and ___________.
weather conditions, natural disasters
In a SQL injection attack, an attacker can:
read sections of a database or a whole database without authorization.
What does the principle of least privilege have in common with the
principle of need to know?
They both specify that users be granted access only to what they need
to perform their jobs.
An access control such as a firewall or intrusion prevention system
cannot protect against which of the following?
Social engineering
What is the purpose of nonrepudiation techniques?
To prevent people from denying they took actions
,3|Page
Background checks, software testing, and awareness training are all
categories of:
procedural controls.
Ideally, when should you perform threat modeling?
Before writing an application or deploying a system
You receive an email from someone named Bob in the IT department
who needs to access your login information for a scheduled internal
vulnerability assessment. You know an assessment is taking place
because your manager notified your group last week. Normally, you
wouldn't give your password or other login information to anybody, but
doing so seems appropriate in this situation. Which of the following
could be taking place?
Social engineering attack
What is a transaction in a database?
A group of statements that either succeed or fail as a whole
, 4|Page
Why is system testing performed?
To test individual systems for vulnerabilities
What is the primary determination as to whether an incident is included
in a business continuity plan (BCP)?
Probability of occurrence and impact
A business continuity plan (BCP) program manager within a large
organization:
Usually manages multiple BCP projects.
What step of a business continuity plan (BCP) comes after providing
training?
Testing and exercising plans
Having supplies on hand for continued production:
may conflict with other organizational planning principles.
MISY 5325 FINAL EXAM 2026 UPDATED ACTUAL
EXAM WITH CORRECT SOLUTIONS.
Another term for data range and reasonableness checks is:
input validation
Which of the following is not one of the three primary objectives of
controls?
Eliminate
What changes plaintext data to ciphered data?
Encryption
A hacker wants to launch an attack on an organization. The hacker uses
a tool to capture data sent over the network in cleartext, hoping to
gather information that will help make the attack successful. What tool
is the hacker using?
A packet analyzer
,2|Page
Primary considerations for assessing threats based on historical data in
your local area are __________ and ___________.
weather conditions, natural disasters
In a SQL injection attack, an attacker can:
read sections of a database or a whole database without authorization.
What does the principle of least privilege have in common with the
principle of need to know?
They both specify that users be granted access only to what they need
to perform their jobs.
An access control such as a firewall or intrusion prevention system
cannot protect against which of the following?
Social engineering
What is the purpose of nonrepudiation techniques?
To prevent people from denying they took actions
,3|Page
Background checks, software testing, and awareness training are all
categories of:
procedural controls.
Ideally, when should you perform threat modeling?
Before writing an application or deploying a system
You receive an email from someone named Bob in the IT department
who needs to access your login information for a scheduled internal
vulnerability assessment. You know an assessment is taking place
because your manager notified your group last week. Normally, you
wouldn't give your password or other login information to anybody, but
doing so seems appropriate in this situation. Which of the following
could be taking place?
Social engineering attack
What is a transaction in a database?
A group of statements that either succeed or fail as a whole
, 4|Page
Why is system testing performed?
To test individual systems for vulnerabilities
What is the primary determination as to whether an incident is included
in a business continuity plan (BCP)?
Probability of occurrence and impact
A business continuity plan (BCP) program manager within a large
organization:
Usually manages multiple BCP projects.
What step of a business continuity plan (BCP) comes after providing
training?
Testing and exercising plans
Having supplies on hand for continued production:
may conflict with other organizational planning principles.