MCQ Bank
Which of the following focuses on detecting potentially abnormal behavior in function of operating system or request made by application software?
- A) Biometrics
- B) Scanners
- C) Behavior blockers
- D) Passwords
Confidentiality of information system means
- A) information systems are available and usable when required
- B) data & information are easily available to everyone
- C) data and information are protected against authorized modification
- D) data and information are disclosed only to those who have a right to know it
Which of the following refers to damage caused to the software and data without any physical damage to the computers?
- A) Physical Threat
- B) Virus
- C) Worm
- D) Logical Threat
__________ site backup is an appropriate choice for organizations if fast recovery is critical.
- A) Warm
- B) Cold
- C) Cool
- D) Hot
Which of the following software performs concurrent monitoring as the system is being used?
- A) Passive Scanners
- B) Active Scanners
- C) Passive Monitors
- D) Active Monitors
Which of the following phase determines the adverse impact resulting from a successful threat exercise of vulnerability?
- A) Impact analysis
- B) Monitoring threats
- C) Risk resilience
- D) Likelihood determination
Which of the following is a logical record of computer activities, usage, processing pertaining to an operating or application system or user activities?
- A) Audit Trial
- B) Audit Control
- C) Control Log
- D) Control Trial
A bad sector on the hard drive is an example of ________ threat.
- A) Physical
- B) Logical
- C) Lexical
- D) Fatal
Which of the following is not a name used for an intruder?
- A) Hacktivist
- B) Knacker
- C) Cracker
- D) Hacker
Which of the following is a weakness that can be accidentally triggered or intentionally exploited?
- A) Audit Trial
- B) Vulnerability
- C) Threat Identification
- D) Likelihood Identification
Control assessment analysis process does not include_____________
- A) Checking of control reliability
- B) Checking of control planned
- C) Checking of control implemented
- D) Checking of control Motivation
Risk projection attempts to rate risk in two ways
- A) Likelihood and mitigation
- B) Likelihood and size
- C) Likelihood and impact
- D) Likelihood and size
Automated tools can be used to
- A) Threat identification
- B) Information elicitation
- C) On site reviews
- D) Maintain system integrity
Which of the following is responsible for ensuring that appropriate security, consistent with the organization’s security policy that is embedded in their information systems?
- A) Process Owners
- B) Executive Management
- C) Data Owners
- D) Users
Which statement describes the security program correctly?
- A) Periodic threat exposure
- B) Identification of assets
- C) Periodic reviews to check safety
- D) Series of irregular reviews
Impact Analysis in control of threat does not depend on__________
- A) System Criticality
- B) Vulnerability Analysis
- C) Data Criticality
- D) System Mission
Which of the following refers to the process of identifying attempts to penetrate a system and gain unauthorized access
- A) Control Trial
- B) Audit trial
- C) Intrusion Detection
- D) Documentation
Which of the following is a program not a virus but it installs a virus on the PC while performing another function?
- A) Worm
- B) Trojans
- C) Bug
- D) Dropper
What could be the first step in any corporate risk strategy?
- A) Characterization
- B) Control implementation
- C) Documentation
- D) Risk identification
Control effectiveness can be checked by____________
- A) System characterization
- B) High Threat Motivation
- C) Availability of Threat
- D) Threat Definition