MISY 5325 FINAL EXAM REVIEW STUDY NOTES
◉ A(n) _________ is the likelihood that something unexpected is going
to occur.
Answer: risk
◉ A(n) _________ provides secure access to a private network over a
public network such as the Internet.
Answer: virtual private network (VPN)
◉ A(n) _____________ is a process used to determine how to manage
risk.
Answer: cost-benefit analysis (CBA)
◉ A(n) ___________________ is performed to identify and evaluate risks.
Answer: risk assessment
◉ According to the World Intellectual Property Organization
(WIPO), the two categories of intellectual property (IP) are
_______________ and _______________.
Answer: industrial property, copyright
,◉ Aditya is assessing the value of IT systems. His company sells
sporting goods online. One factor of his evaluation is the required
availability of each system. Some systems must be available 24/7,
while others must be available during regular business hours
Monday through Friday. Which of the following would have the
highest availability requirements?
Answer: E-commerce website server
◉ Alice is an aspiring hacker. She wants to get information on
computer and network vulnerabilities and ways to exploit
applications. Which of the following is the best source?
A. Common Vulnerabilities and Exposures (CVE) list
B. Dark web
C. United States Computer Emergency Readiness Team (US-CERT)
website
D. National Institute of Standards and Technology (NIST) website
Answer: Dark web
◉ All of following are examples of hardware assets, except:
Answer: operating system.
◉ All of the following are reasons why configuration management is
an important risk management process, except:
, Answer: it reduces unintended outages.
◉ All of the following are true of risk assessment critical area
identification, except:
A. identifying critical areas helps the risk assessment team focus on
what's important.
B. when critical areas are identified, areas that are least critical to
the business should be the first priority.
C. the risk assessment needs to balance potential profits and losses.
D. losses that threaten an organization's survivability are critical.
Answer: when critical areas are identified, areas that are least
critical to the business should be the first priority.
◉ All of the following are true of risk assessment scope
identification, except:
A. the scope identifies the boundary of a risk assessment.
B. when participants understand the scope, they are less likely to
change it.
C. identifying the scope of a risk assessment helps keep it on track.
D. the system or network administrator ultimately decides what is
included in the scope of a risk assessment.
◉ A(n) _________ is the likelihood that something unexpected is going
to occur.
Answer: risk
◉ A(n) _________ provides secure access to a private network over a
public network such as the Internet.
Answer: virtual private network (VPN)
◉ A(n) _____________ is a process used to determine how to manage
risk.
Answer: cost-benefit analysis (CBA)
◉ A(n) ___________________ is performed to identify and evaluate risks.
Answer: risk assessment
◉ According to the World Intellectual Property Organization
(WIPO), the two categories of intellectual property (IP) are
_______________ and _______________.
Answer: industrial property, copyright
,◉ Aditya is assessing the value of IT systems. His company sells
sporting goods online. One factor of his evaluation is the required
availability of each system. Some systems must be available 24/7,
while others must be available during regular business hours
Monday through Friday. Which of the following would have the
highest availability requirements?
Answer: E-commerce website server
◉ Alice is an aspiring hacker. She wants to get information on
computer and network vulnerabilities and ways to exploit
applications. Which of the following is the best source?
A. Common Vulnerabilities and Exposures (CVE) list
B. Dark web
C. United States Computer Emergency Readiness Team (US-CERT)
website
D. National Institute of Standards and Technology (NIST) website
Answer: Dark web
◉ All of following are examples of hardware assets, except:
Answer: operating system.
◉ All of the following are reasons why configuration management is
an important risk management process, except:
, Answer: it reduces unintended outages.
◉ All of the following are true of risk assessment critical area
identification, except:
A. identifying critical areas helps the risk assessment team focus on
what's important.
B. when critical areas are identified, areas that are least critical to
the business should be the first priority.
C. the risk assessment needs to balance potential profits and losses.
D. losses that threaten an organization's survivability are critical.
Answer: when critical areas are identified, areas that are least
critical to the business should be the first priority.
◉ All of the following are true of risk assessment scope
identification, except:
A. the scope identifies the boundary of a risk assessment.
B. when participants understand the scope, they are less likely to
change it.
C. identifying the scope of a risk assessment helps keep it on track.
D. the system or network administrator ultimately decides what is
included in the scope of a risk assessment.