CSIA 300 – Midterm UPDATED ACTUAL Questions and CORRECT Answers
0 view 0 purchase
Course
CSIA 300
Institution
CSIA 300
CSIA 300 – Midterm UPDATED ACTUAL
Questions and CORRECT Answers
Within the realm of IT security, which of the following combinations best defines risk? -
CORRECT ANSWER- Threat coupled with a vulnerability
When determining the value of an intangible asset which is the BEST approach? -
CORRE...
CSIA 300 – Midterm UPDATED ACTUAL
Questions and CORRECT Answers
Within the realm of IT security, which of the following combinations best defines risk? -
CORRECT ANSWER✔✔- Threat coupled with a vulnerability
When determining the value of an intangible asset which is the BEST approach? -
CORRECT ANSWER✔✔- With the assistance of a finance of accounting professional
determine how much profit the asset has returned
Qualitative risk assessment is earmarked by which of the following? - CORRECT
ANSWER✔✔- Ease of implementation and it can be completed by personnel with a limited
understanding of the risk assessment process
Single loss expectancy (SLE) is calculated by using: - CORRECT ANSWER✔✔- Asset
value and exposure factor
Consideration for which type of risk assessment to perform includes all of the following: -
CORRECT ANSWER✔✔- Culture of the organization, budget, capabilities and resources
Security awareness training includes: - CORRECT ANSWER✔✔- Security roles and
responsibilities for staff
What is the minimum and customary practice of responsible protection of assets that affects a
community or societal norm? - CORRECT ANSWER✔✔- Due care
Effective security management: - CORRECT ANSWER✔✔- Reduces risk to an acceptable
level
Availability makes information accessible by protecting from: - CORRECT ANSWER✔✔-
Denial of services, fires, floods, and hurricanes and unreadable backup tapes
, Which phrase best defines a business continuity/disaster recover plan? - CORRECT
ANSWER✔✔- The adequate preparations and procedures for the continuation of all
organization functions
Which of the following steps should be performed first in a business impact analysis (BIA)? -
CORRECT ANSWER✔✔- Identify all business units within an organization
Tactical security plans are BEST used to: - CORRECT ANSWER✔✔- Deploy new security
technology
Who is accountable for implementing information security? - CORRECT ANSWER✔✔-
Security officer
Security is likely to be most expensive when addressed in which phase? - CORRECT
ANSWER✔✔- Implementation
Information systems auditors help the organization: - CORRECT ANSWER✔✔- Identify
control gaps
The Facilitated Risk Analysis Process (FRAP) - CORRECT ANSWER✔✔- makes a base
assumption that a narrow risk assessment is the most efficient way to determine risk in a
system, business segment, application or process.
Setting clear security roles has the following benefits: - CORRECT ANSWER✔✔-
Establishes personal accountability, establishes continuous improvement and reduces turf
battles
Well-written security program policies are BEST reviewed: - CORRECT ANSWER✔✔- At
least annually or at pre-determined organization changes
An organization will conduct a risk assessment to evaluate - CORRECT ANSWER✔✔-
threats to its assets, vulnerabilities present in the environment, the likelihood that a threat will
be realized by taking advantage of an exposure, the impact that the exposure being realized
will have on the organization, the residual risk
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller MGRADES. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $10.49. You're not tied to anything after your purchase.