MCQ Bank
Which of the following is responsible for ensuring that appropriate security, consistent with the organization’s security policy that is embedded in their information systems?
- A) Process Owners
- B) Executive Management
- C) Data Owners
- D) Users
Which statement describes the security program correctly?
- A) Periodic threat exposure
- B) Identification of assets
- C) Periodic reviews to check safety
- D) Series of irregular reviews
Impact Analysis in control of threat does not depend on__________
- A) System Criticality
- B) Vulnerability Analysis
- C) Data Criticality
- D) System Mission
Which of the following refers to the process of identifying attempts to penetrate a system and gain unauthorized access
- A) Control Trial
- B) Audit trial
- C) Intrusion Detection
- D) Documentation
Which of the following is a program not a virus but it installs a virus on the PC while performing another function?
- A) Worm
- B) Trojans
- C) Bug
- D) Dropper
What could be the first step in any corporate risk strategy?
- A) Characterization
- B) Control implementation
- C) Documentation
- D) Risk identification
Control effectiveness can be checked by____________
- A) System characterization
- B) High Threat Motivation
- C) Availability of Threat
- D) Threat Definition
_____ is an example of Trojan horse.
- A) Worm
- B) Dropper
- C) Scanner
- D) Logic Bomb
Which statement is INCORRECT about a BUG?
- A) It can never create a virus in the system.
- B) It is an internal malfunctioning of the system.
- C) It is caused by improper application of programming logic.
- D) It is an unintentional fault in the program.
Which of the following can be used together with access controls to identify and provide information about users suspected of improper modification of data.
- A) Audit control
- B) Audit Trial
- C) Control Trial
- D) Control Log
Which of the following is the process of measuring, or assessing risk and then developing strategies to manage the risk?
- A) None of the given options
- B) Risk Management
- C) Executive management
- D) Audit Trial
Which of the following is NOT true about risk management?
- A) Process of assessing risk
- B) Process of measuring risk
- C) Process of developing strategies to manage risk
- D) Process of logical intrusion
_________ refer to the sudden increase in power supply.
- A) Spikes
- B) Black out
- C) Brown outs
- D) Sags
Which one of the following is not classified as biometrics?
- A) Digital Password
- B) Finger Prints
- C) Sound of your voice
- D) Blood vessels in the retina of your eye
Which of the following is an expression of an intention to inflict pain, injury, evil or punishment, and an indication of impending danger or harm?
- A) Damage
- B) None of these options
- C) Intrusion
- D) Threat
________ site backup is an appropriate choice for organizations if they can bear some downtime.
- A) Cool
- B) Warm
- C) Cold
- D) Hot
What would affect the impact’s scope if a risk does occur?
- A) Risk resources
- B) Risk scope
- C) Risk timing
- D) Risk cost
Damage caused to the software without physical presence is the outcome of _______________ threat.
- A) Privacy
- B) Physical
- C) Logical
- D) Security
The first step after threat attacks the system would be
- A) Threat analysis
- B) Data sensitivity analysis
- C) Control analysis
- D) Impact analysis
An effective risk management strategy will need to address _______
- A) Risk monitoring
- B) Risk avoidance
- C) All of these
- D) Business continuity planning