100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.6 TrustPilot
logo-home
Exam (elaborations)

Infosec Final 2 Exam Questions and Answers Already Passed Latest Update

Rating
-
Sold
-
Pages
25
Grade
A+
Uploaded on
29-09-2025
Written in
2025/2026

Infosec Final 2 Exam Questions and Answers Already Passed Latest Update If an organization deals successfully with change and has created procedures and systems that can be adjusted to the environment, the existing security improvement program will probably continue to work well. a. True b. False - Answers True Over time, policies and procedures may become inadequate due to changes in the organization's mission and operational requirements, threats, or the environment. a. True b. False - Answers True An effective information security governance program requires no ongoing review once it is well established. a. True b. False - Answers False A general guideline for performance of hard drives suggests that when the amount of data stored on a particular hard drive averages 95% of available capacity for a prolonged period, you should consider an upgrade for the drive. a. True b. False - Answers False Documentation procedures are not required for configuration and change management processes. a. True b. False - Answers False management model such as the ISO 27000 series deals with methods to maintain systems. a. True b. False - Answers False External monitoring entails forming intelligence from various data sources and then giving that intelligence context and meaning for use by decision makers within the organization. - Answers True US-CERT is generally viewed as the definitive authority for computer emergency response teams. a. True b. False - Answers True Intelligence for external monitoring can come from a number of sources: vendors, CERT organizations, public network sources, and membership sites. a. True b. False - Answers True Over time, external monitoring processes should capture information about the external environment in a format that can be referenced across the organization as threats emerge and for historical use. a. True b. False - Answers True The internal monitoring domain is the component of the maintenance model that focuses on identifying, assessing, and managing the physical security of assets in an organization. a. True b. False - Answers False Inventory characteristics for hardware and software assets that record the manufacturer and versions are related to technical functionality, and should be highly accurate and updated each time there is a change. a. True b. False - Answers True The target selection step of Internet vulnerability assessment involves using the external monitoring intelligence to configure a test engine (such as Nessus) for the tests to be performed. a. True b. False - Answers False An intranet vulnerability scan starts with the scan of the organization's default Internet search engine. a. True b. False - Answers False All systems that are mission critical should be enrolled in platform security validation (PSV) measurement. a. True b. False - Answers True Wireless vulnerability assessment begins with the planning, scheduling, and notification of all Internet connections, using software such as Wireshark. a. True b. False - Answers False Remediation of vulnerabilities can be accomplished by accepting or transferring the risk, removing the threat, or repairing the vulnerability. a. True b. False - Answers True The vulnerability database, like the risk, threat, and attack database, both stores and tracks information. a. True b. False - Answers True In some instances, risk is acknowledged as being part of an organization's business process. a. True b. False - Answers True Threats cannot be removed without requiring a repair of the vulnerability. a. True b. False - Answers False Policy needs to be reviewed and refreshed from time to time to ensure that it's providing a current foundation for the information security program. a. True b. False - Answers True Major planning components should be reviewed on a periodic basis to ensure that they are current, accurate, and appropriate. a. True b. False - Answers True Rehearsal adds value by exercising the procedures, identifying shortcomings, and providing security personnel the opportunity to improve the security plan before it is needed. a. True b. False - Answers True An effective information security governance program requires constant change. __________ - Answers False - review

Show more Read less
Institution
Infosec
Course
Infosec










Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
Infosec
Course
Infosec

Document information

Uploaded on
September 29, 2025
Number of pages
25
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

Infosec Final 2 Exam Questions and Answers Already Passed Latest Update 2025-2026

If an organization deals successfully with change and has created procedures and systems that
can be adjusted to the environment, the existing security improvement program will probably
continue to work well.

a. True

b. False - Answers True

Over time, policies and procedures may become inadequate due to changes in the
organization's mission and operational requirements, threats, or the environment.

a. True

b. False - Answers True

An effective information security governance program requires no ongoing review once it is well
established.

a. True

b. False - Answers False

A general guideline for performance of hard drives suggests that when the amount of data
stored on a particular hard drive averages 95% of available capacity for a prolonged period, you
should consider an upgrade for the drive.

a. True

b. False - Answers False

Documentation procedures are not required for configuration and change management
processes.

a. True

b. False - Answers False

management model such as the ISO 27000 series deals with methods to maintain systems.

a. True

b. False - Answers False

External monitoring entails forming intelligence from various data sources and then giving that
intelligence context and meaning for use by decision makers within the organization. - Answers
True

,US-CERT is generally viewed as the definitive authority for computer emergency response
teams.

a. True

b. False - Answers True

Intelligence for external monitoring can come from a number of sources: vendors, CERT
organizations, public network sources, and membership sites.

a. True

b. False - Answers True

Over time, external monitoring processes should capture information about the external
environment in a format that can be referenced across the organization as threats emerge and
for historical use.

a. True

b. False - Answers True

The internal monitoring domain is the component of the maintenance model that focuses on
identifying, assessing, and managing the physical security of assets in an organization.

a. True

b. False - Answers False

Inventory characteristics for hardware and software assets that record the manufacturer and
versions are related to technical functionality, and should be highly accurate and updated each
time there is a change.

a. True

b. False - Answers True

The target selection step of Internet vulnerability assessment involves using the external
monitoring intelligence to configure a test engine (such as Nessus) for the tests to be
performed.

a. True

b. False - Answers False

An intranet vulnerability scan starts with the scan of the organization's default Internet search
engine.

, a. True

b. False - Answers False

All systems that are mission critical should be enrolled in platform security validation (PSV)
measurement.

a. True

b. False - Answers True

Wireless vulnerability assessment begins with the planning, scheduling, and notification of all
Internet connections, using software such as Wireshark.

a. True

b. False - Answers False

Remediation of vulnerabilities can be accomplished by accepting or transferring the risk,
removing the threat, or repairing the vulnerability.

a. True

b. False - Answers True

The vulnerability database, like the risk, threat, and attack database, both stores and tracks
information.

a. True

b. False - Answers True

In some instances, risk is acknowledged as being part of an organization's business process.

a. True

b. False - Answers True

Threats cannot be removed without requiring a repair of the vulnerability.

a. True

b. False - Answers False

Policy needs to be reviewed and refreshed from time to time to ensure that it's providing a
current foundation for the information security program.

a. True

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
joshuawesonga22 Liberty University
View profile
Follow You need to be logged in order to follow users or courses
Sold
34
Member since
8 months
Number of followers
1
Documents
11081
Last sold
7 hours ago
Tutor Wes

Hi there! I'm Tutor Wes, a dedicated tutor with a passion for sharing knowledge and helping others succeed academically. All my notes are carefully organized, detailed, and easy to understand. Whether you're preparing for exams, catching up on lectures, or looking for clear summaries, you'll find useful study materials here. Let’s succeed together!

3.3

3 reviews

5
1
4
0
3
1
2
1
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions