ITM 375 FINAL EXAM UPDATED ACTUAL Questions And Correct Answers
Terms in this set (35)
As an information systems security manager (ISSM), how A brief, high-level statement defining what is and is not permitted during the
would you explain the purpose for a system security operation of the system.
policy?
Which answer lists the proper steps required to develop Project initiation, business impact analysis, strategy development, plan
a disaster recovery and business continuity plan development, testing, and maintenance.
(DRP/BCP)?
An information security program should include the Security policy, implementation, assignment of roles and responsibilities, and
following elements: information assist classification.
Before powering off a computer system, a computer dump the memory contents to a disk.
crime investigator should record contents of the monitor
and...?
What is a set of step-by-step instructions used to satisfy Procedure
control requirements called?
What principle recommends division of responsibilities so Separation of duties
that one person cannot commit an undetected fraud?
The likelihood fo a threat source taking advantage of a Risk
vulnerability is called?
An instance of being exposed to losses is called? Exposure
Which of the following describes the activities that assure Due diligence
protection mechanisms are maintained and operational?
When there is a "separation of duties", parts of tasks are Collusion is required to perform an unauthorized act.
assigned to different people so that:
Which of the following is not a generally accepted A security awareness and training program will help prevent natural disasters from
benefit of security awareness, training, and education? occuring.
In a typical information security program, who would be Auditors
responsible for providing reports to the corporate
executives and senior management on the effectiveness
of the instituted program controls?
If risk is defined as "the potential that a given threat will Controls addressing the threats.
exploit vulnerabilities of an asset or group of assets to
cause loss or damage to the assets" the risk has all of the
following elements except?
Terms in this set (35)
As an information systems security manager (ISSM), how A brief, high-level statement defining what is and is not permitted during the
would you explain the purpose for a system security operation of the system.
policy?
Which answer lists the proper steps required to develop Project initiation, business impact analysis, strategy development, plan
a disaster recovery and business continuity plan development, testing, and maintenance.
(DRP/BCP)?
An information security program should include the Security policy, implementation, assignment of roles and responsibilities, and
following elements: information assist classification.
Before powering off a computer system, a computer dump the memory contents to a disk.
crime investigator should record contents of the monitor
and...?
What is a set of step-by-step instructions used to satisfy Procedure
control requirements called?
What principle recommends division of responsibilities so Separation of duties
that one person cannot commit an undetected fraud?
The likelihood fo a threat source taking advantage of a Risk
vulnerability is called?
An instance of being exposed to losses is called? Exposure
Which of the following describes the activities that assure Due diligence
protection mechanisms are maintained and operational?
When there is a "separation of duties", parts of tasks are Collusion is required to perform an unauthorized act.
assigned to different people so that:
Which of the following is not a generally accepted A security awareness and training program will help prevent natural disasters from
benefit of security awareness, training, and education? occuring.
In a typical information security program, who would be Auditors
responsible for providing reports to the corporate
executives and senior management on the effectiveness
of the instituted program controls?
If risk is defined as "the potential that a given threat will Controls addressing the threats.
exploit vulnerabilities of an asset or group of assets to
cause loss or damage to the assets" the risk has all of the
following elements except?