INMT 441 Exam 2Questions and
Answers
According to the UT policy of Acceptable Use of Information Technology Resources, users are
responsible for monitoring access to their accounts (such as log-ins to their Volmail and Canvas
accounts). - Answer-True
According to the UT policy of Acceptable Use of Information Technology Resources, students should not
share access codes or passwords that are assigned for their own use. - Answer-True
Regulations refer to the nonmandatory recommendations that the employee may use as a reference in
complying with ISP. - Answer-False
Which of the following is NOT one of the three general causes of employee violations of ISPs? - Answer-
Carelessness
According to the UT policy of Acceptable Use of Information Technology Resources, UT students can use
the University emails (e.g., Volmail) for commercial activities as long as the activities adhere to the
federal, state, and local laws.
True - Answer-False
,In developing Information Security Policies, employee input should not be considered because it makes
the process too complex. - Answer-False
According to the UT policy of Acceptable Use of Information Technology Resources, University owned IT
resources are for University business only. Any type of personal use is prohibited. - Answer-False
The UT policy of Acceptable Use of Information Technology Resources specifies that if a user suspects
unauthorized activity on their account, or that their account has been compromised, they must report
the compromise to the University authority. - Answer-True
An organization's policy regarding IT investment, management, and use is called ____. - Answer-IT
policy
ISP __________ means the employee must agree to the policy. - Answer-Compliance
Which of the following cybersecurity standards particularly specifies the handling of credit, debit, and
specialty payment cards in an effort to reduce credit card fraud? - Answer-PCI DSS
Which policy is the highest level of policy and is usually created first? - Answer-EISP
Technology is the essential foundation of an effective information security program. - Answer-False
The UT policy of Acceptable Use of Information Technology Resources prohibits the monitoring, logging,
and reviewing of user activities on UT systems and networks by any party. - Answer-False
Cybersecurity: Three headed Janus Randcom security policies assessment - Answer-The information
security processes were ineffective as can be seen by the lack of changes to the processes over the
years, no separation of duties, access privileges were not revoked, everything was on paper, and not
many employees were well taught in the processes. Also did not have necessary policies such as an
incident response plan.
,Randcom organizational culture that led to incidents - Answer-Some of the aspects of the organizational
culture in Randcom that led to the security incidents were things like the managers just not caring, the
employees being allowed to share passwords, leaving passwords in the open, un-checked copying of
files, using personal tech for work purposes, and no formal cybersecurity education for employees.
Certified Information Security Auditor (CISA) is a certification program provided by ____. - Answer-
ISACA
The main purpose of gamification for cybersecurity is to ____. - Answer-engage employees
Which of the following is NOT a sign that your organization is at risk of cybersecurity incidents? -
Answer-Highly confidential data are stored in a secured location in the cloud.
An effective security awareness program should do all of the following EXCEPT ___. - Answer-focus on it
workforce
Of the following four industries, which faces the least amount of cybersecurity threats? - Answer-
Education
SETA may help achieve the followings goals EXCEPT ___. - Answer-Reducing the reliance on
employeees' responsibilities
According to a Harvard Business Review paper (van Zadelhoff, 2016), the biggest cybersecurity threat is
___. - Answer-Insider threat
According to the slides, which security training method is most prefered by employees? - Answer-
Online modules
, Why is gamification a prefered way of cybersecurity training? - Answer-People like competition / People
can make decisions and test the consequence of those decisions / People can receive feedback from the
gameified system
Security awareness aims to ___. - Answer-Make employees aware of security risks.
SETA is designed to ___. - Answer-x
A gamified environment contains all of the following except ___. - Answer-A real, operational system
Which of the following groups of people are not usually included in a SETA program? - Answer-
Shareholders
Security awareness can be delivered through all of the following channels except ____. - Answer-All are
valid ( Newsletters, Flyers, Website)
Insider threat includes ____. - Answer-Intentional and Accidental security breaches
All of the following are indicators of probable incidents except ____. - Answer-Scheduled system
maintenance
A computer system that uses special software routines or self-checking logic built into their circuitry to
detect hardware failures and automatically switch to backup devices is called a ___. - Answer-Fault-
tolerant computer system
Which of the following is included in the post-incident phase of business continuity? - Answer-Insurance
settlement
Disaster recovery plan includes all of the following except ___. - Answer-Business impact analysis
Answers
According to the UT policy of Acceptable Use of Information Technology Resources, users are
responsible for monitoring access to their accounts (such as log-ins to their Volmail and Canvas
accounts). - Answer-True
According to the UT policy of Acceptable Use of Information Technology Resources, students should not
share access codes or passwords that are assigned for their own use. - Answer-True
Regulations refer to the nonmandatory recommendations that the employee may use as a reference in
complying with ISP. - Answer-False
Which of the following is NOT one of the three general causes of employee violations of ISPs? - Answer-
Carelessness
According to the UT policy of Acceptable Use of Information Technology Resources, UT students can use
the University emails (e.g., Volmail) for commercial activities as long as the activities adhere to the
federal, state, and local laws.
True - Answer-False
,In developing Information Security Policies, employee input should not be considered because it makes
the process too complex. - Answer-False
According to the UT policy of Acceptable Use of Information Technology Resources, University owned IT
resources are for University business only. Any type of personal use is prohibited. - Answer-False
The UT policy of Acceptable Use of Information Technology Resources specifies that if a user suspects
unauthorized activity on their account, or that their account has been compromised, they must report
the compromise to the University authority. - Answer-True
An organization's policy regarding IT investment, management, and use is called ____. - Answer-IT
policy
ISP __________ means the employee must agree to the policy. - Answer-Compliance
Which of the following cybersecurity standards particularly specifies the handling of credit, debit, and
specialty payment cards in an effort to reduce credit card fraud? - Answer-PCI DSS
Which policy is the highest level of policy and is usually created first? - Answer-EISP
Technology is the essential foundation of an effective information security program. - Answer-False
The UT policy of Acceptable Use of Information Technology Resources prohibits the monitoring, logging,
and reviewing of user activities on UT systems and networks by any party. - Answer-False
Cybersecurity: Three headed Janus Randcom security policies assessment - Answer-The information
security processes were ineffective as can be seen by the lack of changes to the processes over the
years, no separation of duties, access privileges were not revoked, everything was on paper, and not
many employees were well taught in the processes. Also did not have necessary policies such as an
incident response plan.
,Randcom organizational culture that led to incidents - Answer-Some of the aspects of the organizational
culture in Randcom that led to the security incidents were things like the managers just not caring, the
employees being allowed to share passwords, leaving passwords in the open, un-checked copying of
files, using personal tech for work purposes, and no formal cybersecurity education for employees.
Certified Information Security Auditor (CISA) is a certification program provided by ____. - Answer-
ISACA
The main purpose of gamification for cybersecurity is to ____. - Answer-engage employees
Which of the following is NOT a sign that your organization is at risk of cybersecurity incidents? -
Answer-Highly confidential data are stored in a secured location in the cloud.
An effective security awareness program should do all of the following EXCEPT ___. - Answer-focus on it
workforce
Of the following four industries, which faces the least amount of cybersecurity threats? - Answer-
Education
SETA may help achieve the followings goals EXCEPT ___. - Answer-Reducing the reliance on
employeees' responsibilities
According to a Harvard Business Review paper (van Zadelhoff, 2016), the biggest cybersecurity threat is
___. - Answer-Insider threat
According to the slides, which security training method is most prefered by employees? - Answer-
Online modules
, Why is gamification a prefered way of cybersecurity training? - Answer-People like competition / People
can make decisions and test the consequence of those decisions / People can receive feedback from the
gameified system
Security awareness aims to ___. - Answer-Make employees aware of security risks.
SETA is designed to ___. - Answer-x
A gamified environment contains all of the following except ___. - Answer-A real, operational system
Which of the following groups of people are not usually included in a SETA program? - Answer-
Shareholders
Security awareness can be delivered through all of the following channels except ____. - Answer-All are
valid ( Newsletters, Flyers, Website)
Insider threat includes ____. - Answer-Intentional and Accidental security breaches
All of the following are indicators of probable incidents except ____. - Answer-Scheduled system
maintenance
A computer system that uses special software routines or self-checking logic built into their circuitry to
detect hardware failures and automatically switch to backup devices is called a ___. - Answer-Fault-
tolerant computer system
Which of the following is included in the post-incident phase of business continuity? - Answer-Insurance
settlement
Disaster recovery plan includes all of the following except ___. - Answer-Business impact analysis