MCQ Bank
The output of threat identification phase is_____________
- A) Threat Definition
- B) Threat Measuring
- C) Threat Resolution
- D) Threat Control
Threat likelihoods are determine to define
- A) Threat source
- B) Current controls
- C) Vulnerability scope
- D) Information security
When a customer enters the card and the pin code in an Automatic Teller Machine (ATM), which of the following controls are exercised by the system to block unwanted or illegitimate access?
- A) Input Controls
- B) Database Controls
- C) Communication Controls
- D) Access Controls
Which of the following is the process of converting data into codes (cryptograms)?
- A) Decoding
- B) Decryption
- C) Coding
- D) Encryption
When voltage that is received does not stay stable is referred as:
- A) power factor
- B) power game
- C) power dissipation
- D) power fluctuation
Risk Management does NOT include _________ phase.
- A) Likelihood Determination
- B) Control Analysis
- C) Understanding Business Process
- D) System Characterization
Threat likelihood is determined to use in ______
- A) Control recommendation
- B) Assessment process
- C) Vulnerability identification
- D) Impact analysis
Risks are rated by ______
- A) Probability and impact
- B) Probability and cost
- C) Probability and exposure
- D) Probability and size
Which of the following are responsible for providing independent assurance to management on the appropriateness of the security objectives?
- A) Information Systems Auditors
- B) Executive Management
- C) Security Managers
- D) Data owners
Providing independent assurance to management regarding the appropriateness of the security objectives is the responsibility of _________.
- A) Information systems auditors
- B) Process owners
- C) Data owners
- D) End users
PIN is a secret shared between a user and a system that can be used to authenticate the user to the system. In this context, what does PIN stands for?
- A) Personal Identification Number
- B) Personal Information Node
- C) Password Indicating Null
- D) Password Indicator Number
Controls can be technical and non-technical. Which of the following is an example of non-technical control?
- A) Application Programs
- B) Software
- C) Hardware
- D) Management
Threat identification can be verified using
- A) Threat source
- B) Threat statement
- C) Threat impact analysis
- D) Threat action plan
______________are the key people who will have to ensure that security is effective and smoothly operated
- A) executive management
- B) technology providers
- C) users
- D) IS security professionals
Logical intrusion is also known as_____________
- A) Wrecking
- B) Hacking
- C) Firewalls
- D) Antivirus
An IT enabled organization that involves the radical re-conceptualization of the business needs _____ for possible threat invasion
- A) Data backup
- B) Control recommendation
- C) Business continuity plan
- D) Impact analysis plan
Risk impact assessment should focus on consequences affecting _______
- A) Marketing, costing, staffing
- B) Planning, resources, cost, schedule
- C) Business, technology, process
- D) Performance, cost, schedule
The protection of information from unauthorized disclosure explains the concept of system and data ______________.
- A) Confidentiality
- B) Reliability
- C) Completeness
- D) Consistency
Which of the following phase determines that a potential vulnerability could be exercised by a given threat source?
- A) Impact analysis
- B) Risk resilience
- C) Likelihood determination
- D) Intelligence
Under which of the following agreement, two or more organizations agree to provide backup facilities to each other in case of one suffering from a disaster.
- A) Joint
- B) Cooperative
- C) Mutual
- D) Reciprocal