MCQ Bank
Small organizations usually have ____________________ management structure.
- A) Simple
- B)
- C)
- D)
Threat likelihoods are determine to define
- A) Threat source
- B) Current controls
- C) Vulnerability scope
- D) Information security
__________ is used to record transactions of routine and repetitive nature.
- A) Transaction Processing System
- B)
- C)
- D)
When a customer enters the card and the pin code in an Automatic Teller Machine (ATM), which of the following controls are exercised by the system to block unwanted or illegitimate access?
- A) Input Controls
- B) Database Controls
- C) Communication Controls
- D) Access Controls
In _________________ organizational structure, there are usually less number of management levels.
- A) Flat
- B)
- C)
- D)
Which of the following is the process of converting data into codes (cryptograms)?
- A) Decoding
- B) Decryption
- C) Coding
- D) Encryption
Human being is the example of ______________.
- A) open system
- B)
- C)
- D)
When voltage that is received does not stay stable is referred as:
- A) power factor
- B) power game
- C) power dissipation
- D) power fluctuation
"Regulatory Authorities" come under ___________ source of information.
- A) External
- B)
- C)
- D)
Risk Management does NOT include _________ phase.
- A) Likelihood Determination
- B) Control Analysis
- C) Understanding Business Process
- D) System Characterization
What-if analysis technique is used in _________.
- A) Model Driven DSS
- B)
- C)
- D)
Threat likelihood is determined to use in ______
- A) Control recommendation
- B) Assessment process
- C) Vulnerability identification
- D) Impact analysis
Which of the following is not an external source of information to an organization?
- A) Formal reporting system
- B)
- C)
- D)
Risks are rated by ______
- A) Probability and impact
- B) Probability and cost
- C) Probability and exposure
- D) Probability and size
___________ is /are subset of data which adds to the knowledge.
- A) Information
- B)
- C)
- D)
Which of the following are responsible for providing independent assurance to management on the appropriateness of the security objectives?
- A) Information Systems Auditors
- B) Executive Management
- C) Security Managers
- D) Data owners
Providing independent assurance to management regarding the appropriateness of the security objectives is the responsibility of _________.
- A) Information systems auditors
- B) Process owners
- C) Data owners
- D) End users
PIN is a secret shared between a user and a system that can be used to authenticate the user to the system. In this context, what does PIN stands for?
- A) Personal Identification Number
- B) Personal Information Node
- C) Password Indicating Null
- D) Password Indicator Number
Controls can be technical and non-technical. Which of the following is an example of non-technical control?
- A) Application Programs
- B) Software
- C) Hardware
- D) Management
Threat identification can be verified using
- A) Threat source
- B) Threat statement
- C) Threat impact analysis
- D) Threat action plan