MIS 416 Exam 1 Questions With Complete Solutions
_________ negatively affect(s) the CIA triad.
A) Threats
B) NNTP
C) Vulnerabilities
D) Risks Correct Answers A
__________ is the negative result if the risk occurs.
A) Value
B) Probability
C) Risk
D) Impact Correct Answers D
____________ assessments are objective, while ___________
assessments are subjective.
A) Quantitative, qualitative
B) Qualitative, quantitative
C) Risk, threat
D) Threat, risk Correct Answers A
_____________ is the likelihood that a threat will exploit a
vulnerability.
A) Risk
B) Probability
C) Impact
D) Assessment Correct Answers B
A _________ is the likelihood that a loss will occur.
A) vulnerability
B) threat
,C) risk
D) assessment Correct Answers C
A business impact analysis is intended to include all IT
functions. T/F? Correct Answers F
A key step in managing risk is to first understand and manage
the source. T/F? Correct Answers T
A relative measurement of a resource's tolerance for risk
exposure is:
A) Risk aversion
B) Threat landscape
C) Risk sensitivity
D) Vulnerability score Correct Answers C
A risk assessment is the same as a risk management program.
T/F? Correct Answers F
A Risk Assessment team should focus both on critical areas and
on what management might consider important. T/F? Correct
Answers T
A Security Scan and a Risk Assessment are the same. T/F?
Correct Answers F
A threat event where loss materializes and/or where liability
increases.
A) Threat Event
B) Vulnerability Event
C) Loss Event
, D) Primary Event
E) Risk Event Correct Answers C
A threat is a weakness, but a vulnerability is an activity that
represents a possible danger. T/F? Correct Answers F
According to Landoll, which of the following is NOT a type of
security test?
A) Threat Testing
B) Penetration Testing
C) Vulnerability Testing
D) Information Accuracy Testing Correct Answers A
According to Talabis, what is the function of a BIA?
A) To assess and identify critical and non-critical organizational
functions and activities.
B) To determine which business processes cannot be modified
regardless of recommendations from the risk assessment team.
C) To identify what business processes are going to be most
impacted by a specific threat.
D) To evaluate what threats are specific to each business
organization unit in a company and how these threats will
specifically impact the business unit. Correct Answers A
According to Talabis, what is the most rigorous and most
encompassing activity in the information security risk
assessment process?
A) Interviewing Personnel
B) Data Collection
C) Creating Valid Risk Profiles
D) Testing Controls
_________ negatively affect(s) the CIA triad.
A) Threats
B) NNTP
C) Vulnerabilities
D) Risks Correct Answers A
__________ is the negative result if the risk occurs.
A) Value
B) Probability
C) Risk
D) Impact Correct Answers D
____________ assessments are objective, while ___________
assessments are subjective.
A) Quantitative, qualitative
B) Qualitative, quantitative
C) Risk, threat
D) Threat, risk Correct Answers A
_____________ is the likelihood that a threat will exploit a
vulnerability.
A) Risk
B) Probability
C) Impact
D) Assessment Correct Answers B
A _________ is the likelihood that a loss will occur.
A) vulnerability
B) threat
,C) risk
D) assessment Correct Answers C
A business impact analysis is intended to include all IT
functions. T/F? Correct Answers F
A key step in managing risk is to first understand and manage
the source. T/F? Correct Answers T
A relative measurement of a resource's tolerance for risk
exposure is:
A) Risk aversion
B) Threat landscape
C) Risk sensitivity
D) Vulnerability score Correct Answers C
A risk assessment is the same as a risk management program.
T/F? Correct Answers F
A Risk Assessment team should focus both on critical areas and
on what management might consider important. T/F? Correct
Answers T
A Security Scan and a Risk Assessment are the same. T/F?
Correct Answers F
A threat event where loss materializes and/or where liability
increases.
A) Threat Event
B) Vulnerability Event
C) Loss Event
, D) Primary Event
E) Risk Event Correct Answers C
A threat is a weakness, but a vulnerability is an activity that
represents a possible danger. T/F? Correct Answers F
According to Landoll, which of the following is NOT a type of
security test?
A) Threat Testing
B) Penetration Testing
C) Vulnerability Testing
D) Information Accuracy Testing Correct Answers A
According to Talabis, what is the function of a BIA?
A) To assess and identify critical and non-critical organizational
functions and activities.
B) To determine which business processes cannot be modified
regardless of recommendations from the risk assessment team.
C) To identify what business processes are going to be most
impacted by a specific threat.
D) To evaluate what threats are specific to each business
organization unit in a company and how these threats will
specifically impact the business unit. Correct Answers A
According to Talabis, what is the most rigorous and most
encompassing activity in the information security risk
assessment process?
A) Interviewing Personnel
B) Data Collection
C) Creating Valid Risk Profiles
D) Testing Controls