MIS 416 Study Guide questions with accurate answers
___________ is the negative result if the risk occurs.
A. risk
B. probability
C. value
D. impact Ans✓✓✓ D
____________ assessments are objective, while ___________
assessments are subjective.
A. Risk, threat
B. Qualitative, quantitative
C. Quantitative, qualitative
D. Threat, risk Ans✓✓✓ C
_____________ is the likelihood that a threat will exploit a
vulnerability.
A. assessment
B. probability
C. risk
D. impact Ans✓✓✓ B
,A BIA typically identifies the customers & how the organization plans
to serve them.
True
False Ans✓✓✓ False
A business impact analysis is concerned with identifying and
implementing recovery methods.
True
False Ans✓✓✓ False
A business impact analysis is intended to include all IT functions.
True
False Ans✓✓✓ False
A relative measurement of a resource's tolerance for risk exposure is:
A. Threat landscape
B. Risk aversion
C. Vulnerability score
,D. Risk sensitivity Ans✓✓✓ D
A risk assessment is the same as a risk management program.
True
False Ans✓✓✓ False
A Risk Assessment team should focus both on critical areas and on what
management might consider important.
True
False Ans✓✓✓ False
A security risk assessment which is technically accurate is still a failure
if it what?
A. doesn't include an assignment of blame for specific security failings
B. Fails to provide detailed mitigation strategies
C. Includes un-actionable positive findings
D. Alienates those who receive the information Ans✓✓✓ D
, A Security Scan and a Risk Assessment are the same.
True
False Ans✓✓✓ True
A threat event where loss materializes and/or where liability increases.
A. loss event
B. risk event
C. liability event Ans✓✓✓ A
A(n) __________ is a common type of attack to deny service on
Internet-facing servers.
A. SQL injection
B. DDOS
C. DMZ
D. database server Ans✓✓✓ B
A(n) ___________________ is performed to identify the most serious
risks, help you manage risks, and identify the best methods to control
risks.
___________ is the negative result if the risk occurs.
A. risk
B. probability
C. value
D. impact Ans✓✓✓ D
____________ assessments are objective, while ___________
assessments are subjective.
A. Risk, threat
B. Qualitative, quantitative
C. Quantitative, qualitative
D. Threat, risk Ans✓✓✓ C
_____________ is the likelihood that a threat will exploit a
vulnerability.
A. assessment
B. probability
C. risk
D. impact Ans✓✓✓ B
,A BIA typically identifies the customers & how the organization plans
to serve them.
True
False Ans✓✓✓ False
A business impact analysis is concerned with identifying and
implementing recovery methods.
True
False Ans✓✓✓ False
A business impact analysis is intended to include all IT functions.
True
False Ans✓✓✓ False
A relative measurement of a resource's tolerance for risk exposure is:
A. Threat landscape
B. Risk aversion
C. Vulnerability score
,D. Risk sensitivity Ans✓✓✓ D
A risk assessment is the same as a risk management program.
True
False Ans✓✓✓ False
A Risk Assessment team should focus both on critical areas and on what
management might consider important.
True
False Ans✓✓✓ False
A security risk assessment which is technically accurate is still a failure
if it what?
A. doesn't include an assignment of blame for specific security failings
B. Fails to provide detailed mitigation strategies
C. Includes un-actionable positive findings
D. Alienates those who receive the information Ans✓✓✓ D
, A Security Scan and a Risk Assessment are the same.
True
False Ans✓✓✓ True
A threat event where loss materializes and/or where liability increases.
A. loss event
B. risk event
C. liability event Ans✓✓✓ A
A(n) __________ is a common type of attack to deny service on
Internet-facing servers.
A. SQL injection
B. DDOS
C. DMZ
D. database server Ans✓✓✓ B
A(n) ___________________ is performed to identify the most serious
risks, help you manage risks, and identify the best methods to control
risks.