MCQ Bank
Which of the following is the process of converting data into codes (cryptograms)?
- A) Decoding
- B) Decryption
- C) Coding
- D) Encryption
Human being is the example of ______________.
- A) open system
- B)
- C)
- D)
When voltage that is received does not stay stable is referred as:
- A) power factor
- B) power game
- C) power dissipation
- D) power fluctuation
"Regulatory Authorities" come under ___________ source of information.
- A) External
- B)
- C)
- D)
Risk Management does NOT include _________ phase.
- A) Likelihood Determination
- B) Control Analysis
- C) Understanding Business Process
- D) System Characterization
What-if analysis technique is used in _________.
- A) Model Driven DSS
- B)
- C)
- D)
Threat likelihood is determined to use in ______
- A) Control recommendation
- B) Assessment process
- C) Vulnerability identification
- D) Impact analysis
Which of the following is not an external source of information to an organization?
- A) Formal reporting system
- B)
- C)
- D)
Risks are rated by ______
- A) Probability and impact
- B) Probability and cost
- C) Probability and exposure
- D) Probability and size
___________ is /are subset of data which adds to the knowledge.
- A) Information
- B)
- C)
- D)
Which of the following are responsible for providing independent assurance to management on the appropriateness of the security objectives?
- A) Information Systems Auditors
- B) Executive Management
- C) Security Managers
- D) Data owners
Providing independent assurance to management regarding the appropriateness of the security objectives is the responsibility of _________.
- A) Information systems auditors
- B) Process owners
- C) Data owners
- D) End users
PIN is a secret shared between a user and a system that can be used to authenticate the user to the system. In this context, what does PIN stands for?
- A) Personal Identification Number
- B) Personal Information Node
- C) Password Indicating Null
- D) Password Indicator Number
Controls can be technical and non-technical. Which of the following is an example of non-technical control?
- A) Application Programs
- B) Software
- C) Hardware
- D) Management
Threat identification can be verified using
- A) Threat source
- B) Threat statement
- C) Threat impact analysis
- D) Threat action plan
______________are the key people who will have to ensure that security is effective and smoothly operated
- A) executive management
- B) technology providers
- C) users
- D) IS security professionals
Logical intrusion is also known as_____________
- A) Wrecking
- B) Hacking
- C) Firewalls
- D) Antivirus
An IT enabled organization that involves the radical re-conceptualization of the business needs _____ for possible threat invasion
- A) Data backup
- B) Control recommendation
- C) Business continuity plan
- D) Impact analysis plan
Risk impact assessment should focus on consequences affecting _______
- A) Marketing, costing, staffing
- B) Planning, resources, cost, schedule
- C) Business, technology, process
- D) Performance, cost, schedule
The protection of information from unauthorized disclosure explains the concept of system and data ______________.
- A) Confidentiality
- B) Reliability
- C) Completeness
- D) Consistency