Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 6 pages
Exam (elaborations)

MIS 360 MODULES 1&2 EXAM QUESTIONS WITH VERIFIED SOLUTIONS LATEST UPDATE 2026

Document preview thumbnail
Preview 2 out of 6 pages

MIS 360 MODULES 1&2 EXAM QUESTIONS WITH VERIFIED SOLUTIONS LATEST UPDATE 2026 Accounting - Answers The ability that provides tracking of events Advanced Persistent Threat - Answers A class of attacks by state actors that use innovative attack tools to silently extract data over an extended period Asset - Answers An item that has value Attack vector - Answers The pathway for an attack Authentication - Answers Proof of genuineness Authorization - Answers The act of providing permission or approval to technology resources Availability - Answers Security actions that ensure that data is accessible to authorized users Brokers - Answers An attacker who sells knowledge of a vulnerability to other attackers or governments Confidentiality - Answers Security actions that ensure that only authorized parties can view the information Cybercriminals - Answers An attacker whose goal is financial gain Cybersecurity - Answers The tasks of protecting the integrity, confidentiality, and availability of information on the devices that store, manipulate, and transmit the information through products, people, and procedures Cyberterrorism - Answers A politically motivated cyberattack designed to cause disruption and panic Cyberterrorists - Answers An attacker whose motivation may be defined as ideological, or attacking for the sake of principals and beliefs General Data Protection Regulation - Answers A directive that requires companies that perform business in the European Union to inform the EU's Information Commissioner's Office if they suffer a breach involving the personal information of customers or employees Gramm-Leach-Bliley Act - Answers A U.S. law that requires banks and financial institutions to alert customers of their policies and practices in disclosing customer information Hactivists - Answers An attacker who attacks for ideological reasons Hacker - Answers An older term that referred to a person who used advanced computer skills to attack computers HIPAA - Answers A U.S. law designed to guard protected health information and implement policies and procedures to safeguard it Identity theft - Answers Stealing another person's personal information, such as Social Security Number, and then using it to impersonate the victim, generally for financial gain Insiders - Answers An employee, contractor, or business partner who is responsible for an attack Integrity - Answers Security actions that ensure that the information is correct and no unauthorized person or malicious software has altered the data Payment Card Industry Data Security Standard - Answers A set of security standards that all U.S. companies processing, storing, or transmitting credit card information must follow Risk - Answers A situation that involves exposure to danger Sarbanes-Oxley Act - Answers A U.S. law designed to fight corporate corruption Script Kiddies - Answers Individual who lacks advanced knowledge of computers and networks and uses downloaded automatic attack software State Actors - Answers An attacker commissioned by the government Threat - Answers A type of action that has the potential to cause harm Threat Actor - Answers A term used to describe individuals or entities who are responsible for cyber incidents against the technology equipment of enterprises and users Threat Agent - Answers A person or element that has the power to carry out a threat Threat Likelihood - Answers The probability that a threat will actually occur Vulnerability - Answers A flaw or weakness that allows the threat agent to bypass security Fair and Accurate Credit Transactions Act - Answers A law that contains rules regarding consumer privacy Hoax - Answers A false warning, often contained in an email claiming to come from the IT department Impersonation - Answers Masquerading as a real or fictitious character and then playing out the role of that person to trick a victim in a social engineering attack Online Brute Force Attack - Answers An attack in which the same account is continuously attacked by entering different passwords Password - Answers A secret combination of letters, numbers, and/or characters known only by the user Password Crackers - Answers Sophisticated attacker software that is specifically designed to break passwords Password Spraying - Answers An attack in which one or a small number of commonly used passwords is used to attempt to log in to several different user accounts Phishing - Answers Sending an email claiming to be from a legitimate enterprise in an attempt to trick the user into surrendering private information or taking action Random Password Generator - Answers A feature in password management software to create long and unique passwords Social Engineering - Answers A means of using trickery to cause the victim to act in the attacker's favor Social Networking - Answers The use of Internet-based social media platforms that allow users to stay connected with friends, family, and peers Weak security update distribution - Answers Which of the following is not a reason why it is difficult to defend against today's attackers? a. Faster detection of vulnerabilities b. Complexity of attack tools c. Weak security update distribution d. Greater sophistication of attacks Distributed attacks - Answers Which of the following accounts for the greatest difficulty in preventing attacks? a. Availability and simplicity of attack tools b. Delays in security updating c. Distributed attacks d. User confusion It is the steps necessary to protect a person or property from harm - Answers In a general sense, what is security? a. It is only available on specialized computers b. It is protection from only direct actions c. It is the steps necessary to protect a person or property from harm d. It is both an art and a science Confidentiality - Answers Which of the following ensures that only authorized parties can view information? a. Confidentiality b. Authorization c. Integrity d. Availability The vulnerability they uncover was previously unknown and is unlikely to be patched quickly - Answers Why can brokers command such a high price for what they sell? a. Brokers are licensed professionals b. The attack targets are always wealthy corporations c. The vulnerability they uncover was previously unknown and is unlikely to be patched quickly d. Brokers work in teams and all the members must be compensated Purposes - Answers Which of the following is not a successive layer in which information security is achieved? a. Products b. People c. Policies and procedures d. Purposes APT - Answers What is a class of attacks by state actors that use innovative attack tools to silently extract data over an extended period of time? a. RPP b. XLX c. APT d. GOR Threat actor - Answers What is a person or element that has the power to carry out a threat? a. Threat actor b. Agent c. Risk exploiter d. Cyber invader Vulnerability - Answers In cybersecurity, what is a flaw or weakness that allows an attacker to bypass security protections? a. Access b. Vulnerability c. Worm hole d. Access control Authentication - Answers Which of the following ensures that individuals are who they claim to be? a. Demonstration b. Authentication c. Accounting d. Certification Health Insurance Portability and Accountability Act - Answers Which of the following requires that enterprises must guard protected health information and implement policies and procedures to safeguard it? a. Hospital Protection and Insurance Association Agreement b. Sarbanes-Oxley Act c. Gramm-Leach-Bliley Act d. Health Insurance Portability and Accountability Act Cyberterrorists - Answers Which of the following is motivated for the sake of their principles or beliefs? a. Cyberterrorists b. Insiders c. Script kiddies d. Computer spies The aim of a hacktivist is not to incite panic like cyberterrorists - Answers What is the difference between a hacktivist and a cyberterrorist? a. A hacktivist is motivated by ideology while a cyberterrorist is not. b. Cyberterrorists always work in groups while hacktivists work alone c. The aim of a hacktivist is not to incite panic like cyberterrorists d. Cyberterrorists are better funded than hacktivists Minimizing losses - Answers Lorenzo has decided to make regular backup copies of information from his laptop and store it in a safe place. Which of the following principles is he following? a. Minimizing losses b. Blocking attacks c. Updating defenses d. Using layers Cybercriminals - Answers Which of the following is not classified as an insider? a. Business partners b. Contractors c. Cybercriminals d. Employees To spy on citizens - Answers What is the objective of state actors? a. To right a perceived wrong b. To spy on citizens c. To sell vulnerabilities to the highest bidder d. To earn fortune over fame Gramm-Leach-Bliley Act - Answers Which of the following requires banks and financial institutions to protect all electronic and paper containing personally identifiable financial information? a. California Savings and Loan Security Act b. Sarbanes-Oxley Act c. Gramm-Leach-Bliley Act d. USA Patriot Act Integrity - Answers Which of the following ensures that the information is correct and no unauthorized person or malicious software has altered that data? a. Integrity b. Obscurity c. Layering d. Confidentiality Threat - Answers Which of the following is a type of action that has the potential to cause harm? a. Hazard b. Risk c. Threat d. Peril Attack vector - Answers Bella is explaining to her friend that her new role at work requires her to block the pathways for an attack. Which of the following terms would she use to explain what this pathway is? a. Interception b. Attack vector c. Cybersecurity intrusion d. Asset roadway

Content preview

MIS 360 MODULES 1&2 EXAM QUESTIONS WITH VERIFIED SOLUTIONS LATEST UPDATE 2026


Accounting - Answers The ability that provides tracking of events
Advanced Persistent Threat - Answers A class of attacks by state actors that use innovative attack
tools to silently extract data over an extended period
Asset - Answers An item that has value
Attack vector - Answers The pathway for an attack
Authentication - Answers Proof of genuineness
Authorization - Answers The act of providing permission or approval to technology resources
Availability - Answers Security actions that ensure that data is accessible to authorized users
Brokers - Answers An attacker who sells knowledge of a vulnerability to other attackers or
governments
Confidentiality - Answers Security actions that ensure that only authorized parties can view the
information
Cybercriminals - Answers An attacker whose goal is financial gain
Cybersecurity - Answers The tasks of protecting the integrity, confidentiality, and availability of
information on the devices that store, manipulate, and transmit the information through products,
people, and procedures
Cyberterrorism - Answers A politically motivated cyberattack designed to cause disruption and panic
Cyberterrorists - Answers An attacker whose motivation may be defined as ideological, or attacking
for the sake of principals and beliefs
General Data Protection Regulation - Answers A directive that requires companies that perform
business in the European Union to inform the EU's Information Commissioner's Office if they suffer a
breach involving the personal information of customers or employees
Gramm-Leach-Bliley Act - Answers A U.S. law that requires banks and financial institutions to alert
customers of their policies and practices in disclosing customer information
Hactivists - Answers An attacker who attacks for ideological reasons
Hacker - Answers An older term that referred to a person who used advanced computer skills to
attack computers
HIPAA - Answers A U.S. law designed to guard protected health information and implement policies
and procedures to safeguard it
Identity theft - Answers Stealing another person's personal information, such as Social Security
Number, and then using it to impersonate the victim, generally for financial gain
Insiders - Answers An employee, contractor, or business partner who is responsible for an attack
Integrity - Answers Security actions that ensure that the information is correct and no unauthorized
person or malicious software has altered the data
Payment Card Industry Data Security Standard - Answers A set of security standards that all U.S.
companies processing, storing, or transmitting credit card information must follow
Risk - Answers A situation that involves exposure to danger
Sarbanes-Oxley Act - Answers A U.S. law designed to fight corporate corruption
Script Kiddies - Answers Individual who lacks advanced knowledge of computers and networks and
uses downloaded automatic attack software
State Actors - Answers An attacker commissioned by the government
Threat - Answers A type of action that has the potential to cause harm
Threat Actor - Answers A term used to describe individuals or entities who are responsible for cyber
incidents against the technology equipment of enterprises and users
Threat Agent - Answers A person or element that has the power to carry out a threat
Threat Likelihood - Answers The probability that a threat will actually occur
Vulnerability - Answers A flaw or weakness that allows the threat agent to bypass security
Fair and Accurate Credit Transactions Act - Answers A law that contains rules regarding consumer
privacy
Hoax - Answers A false warning, often contained in an email claiming to come from the IT
department
Impersonation - Answers Masquerading as a real or fictitious character and then playing out the role
of that person to trick a victim in a social engineering attack

, Online Brute Force Attack - Answers An attack in which the same account is continuously attacked by
entering different passwords
Password - Answers A secret combination of letters, numbers, and/or characters known only by the
user
Password Crackers - Answers Sophisticated attacker software that is specifically designed to break
passwords
Password Spraying - Answers An attack in which one or a small number of commonly used passwords
is used to attempt to log in to several different user accounts
Phishing - Answers Sending an email claiming to be from a legitimate enterprise in an attempt to trick
the user into surrendering private information or taking action
Random Password Generator - Answers A feature in password management software to create long
and unique passwords
Social Engineering - Answers A means of using trickery to cause the victim to act in the attacker's
favor
Social Networking - Answers The use of Internet-based social media platforms that allow users to stay
connected with friends, family, and peers
Weak security update distribution - Answers Which of the following is not a reason why it is difficult
to defend against today's attackers?
a. Faster detection of vulnerabilities
b. Complexity of attack tools
c. Weak security update distribution
d. Greater sophistication of attacks
Distributed attacks - Answers Which of the following accounts for the greatest difficulty in preventing
attacks?
a. Availability and simplicity of attack tools
b. Delays in security updating
c. Distributed attacks
d. User confusion
It is the steps necessary to protect a person or property from harm - Answers In a general sense,
what is security?
a. It is only available on specialized computers
b. It is protection from only direct actions
c. It is the steps necessary to protect a person or property from harm
d. It is both an art and a science
Confidentiality - Answers Which of the following ensures that only authorized parties can view
information?
a. Confidentiality
b. Authorization
c. Integrity
d. Availability
The vulnerability they uncover was previously unknown and is unlikely to be patched quickly -
Answers Why can brokers command such a high price for what they sell?
a. Brokers are licensed professionals
b. The attack targets are always wealthy corporations
c. The vulnerability they uncover was previously unknown and is unlikely to be patched quickly
d. Brokers work in teams and all the members must be compensated
Purposes - Answers Which of the following is not a successive layer in which information security is
achieved?
a. Products
b. People
c. Policies and procedures
d. Purposes
APT - Answers What is a class of attacks by state actors that use innovative attack tools to silently
extract data over an extended period of time?
a. RPP
b. XLX
c. APT

Document information

Uploaded on
August 1, 2026
Number of pages
6
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
joshuawesonga22
3.4
(12)
Sold
114
Followers
2
Items
14959
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions