PRINCIPLES OF INFORMATION SYSTEMS
CERTIFICATION EVALUATION COMPLETE
QUESTIONS AND SOLUTIONS GRADED
APLUS
●● Which of the following is NOT one of the four main components in
Leavitt's Diamond?
A. People
B. Systems
C. Processes
D. Technology Infrastructure
Answer: Systems
●● Why would Claire, who has a Certified Information Systems
Security Professional credential, object to shadow IT efforts at her
company?
A. Issues can arise over the responsibility to fix shadow IT solutions
when they break
B. Shadow IT provides the opportunity to evaluate and test many more
information system initiatives.
C. Shadow IT systems and processes may lack necessary levels of
security required to meet compliance standards.
D. Shadow IT delays testing of quick solutions to business needs.
,Answer: Shadow IT systems and processes may lack necessary levels of
security required to meet compliance standards.
●● Clive completes specific coursework provided by a vendor to help
him prepare to take an examination so that he can obtain _____.
A. Retirement benefits
B. enterprise IS access
C. a shadow IT position
D. a certification
Answer: a certification
●● Even legitimate organizations sometimes use worms, unsolicited
email messages sent to large numbers of people, to promote their
products.
A. True
B. False
Answer: False
●● What is an attack vector?
A. a person who attacks a computer system or network for financial gain
B. the technique used to gain unauthorized access to a device or a
network
C. a large group of computers controlled from one or more remote
locations by hackers
, D. a vulnerable communications protocol or system
Answer: the technique used to gain unauthorized access to a device or a
network
●● Many organizations outsource their network security operations to
a(n) _____.
A. VPN
B. HIPAA
C. MSSP
D. CSFA
Answer: MSSP
●● Samantha owns a small business that handles a lot of sensitive
customer data and would be devastated by a data breach. Her IS
department, which consists of one part-time consultant named Nikki, is
overwhelmed by the number of alerts and false alarms constantly issued
by her security-monitoring systems, and expresses concerns about their
data security. What should Samantha do about this?
A. consider a managed security service provider
B. ask Nikki to disable the alerts and alarms
C. research different security software options
D. change her passwords more often
Answer: consider a managed security service provider
CERTIFICATION EVALUATION COMPLETE
QUESTIONS AND SOLUTIONS GRADED
APLUS
●● Which of the following is NOT one of the four main components in
Leavitt's Diamond?
A. People
B. Systems
C. Processes
D. Technology Infrastructure
Answer: Systems
●● Why would Claire, who has a Certified Information Systems
Security Professional credential, object to shadow IT efforts at her
company?
A. Issues can arise over the responsibility to fix shadow IT solutions
when they break
B. Shadow IT provides the opportunity to evaluate and test many more
information system initiatives.
C. Shadow IT systems and processes may lack necessary levels of
security required to meet compliance standards.
D. Shadow IT delays testing of quick solutions to business needs.
,Answer: Shadow IT systems and processes may lack necessary levels of
security required to meet compliance standards.
●● Clive completes specific coursework provided by a vendor to help
him prepare to take an examination so that he can obtain _____.
A. Retirement benefits
B. enterprise IS access
C. a shadow IT position
D. a certification
Answer: a certification
●● Even legitimate organizations sometimes use worms, unsolicited
email messages sent to large numbers of people, to promote their
products.
A. True
B. False
Answer: False
●● What is an attack vector?
A. a person who attacks a computer system or network for financial gain
B. the technique used to gain unauthorized access to a device or a
network
C. a large group of computers controlled from one or more remote
locations by hackers
, D. a vulnerable communications protocol or system
Answer: the technique used to gain unauthorized access to a device or a
network
●● Many organizations outsource their network security operations to
a(n) _____.
A. VPN
B. HIPAA
C. MSSP
D. CSFA
Answer: MSSP
●● Samantha owns a small business that handles a lot of sensitive
customer data and would be devastated by a data breach. Her IS
department, which consists of one part-time consultant named Nikki, is
overwhelmed by the number of alerts and false alarms constantly issued
by her security-monitoring systems, and expresses concerns about their
data security. What should Samantha do about this?
A. consider a managed security service provider
B. ask Nikki to disable the alerts and alarms
C. research different security software options
D. change her passwords more often
Answer: consider a managed security service provider