Information Security and Risk Management

Quiz covering Information Security Management Systems, cyber laws, identity management, risk assessment methodologies, vulnerability management, and IT fundamentals including software licensing and wireless technologies.

18 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following biometric technologies are still under evolution to estalish better identification and verification?

  1. Iris Matching
  2. Retina Scan
  3. Nail bed Structure
  4. Face recognition
Question 2 Multiple Choice (Single Answer)

Which of the following listed attacks is a Wireless Access Point (WAP) most susceptible to?

  1. Lexicographer Attack
  2. Cafe Latte Attack
  3. All except A
  4. Man in the Middle attack
Question 3 Multiple Choice (Single Answer)

Which of the following IEEE standards standardizes Wireless LANs?

  1. 802.3
  2. 802.11
  3. 802.1
  4. 802.5
Question 4 Multiple Choice (Single Answer)

Mobile 3G supports which of the following?

  1. Voice calls
  2. Video calls
  3. Wireless data
  4. All of the above
Question 5 Multiple Choice (Single Answer)

Why is Vulnerability Management critical for any organization?

  1. To protect reputation and brand
  2. Ensure business continuity
  3. Protect IT infrastructure and critical data
  4. All of the above
Question 6 Multiple Choice (Single Answer)

Which of the following is the correct order of the 4 steps involved in Vulnerability Management Lifecycle?

  1. Analyze, Identify, Mitigate, Monitor
  2. Identify, Analyze, Mitigate, Manage
  3. Analyze, Identify, Manage, Mitigate
  4. Monitor, Analyze, Mitigate, Manage
Question 7 True/False

State true or false: "Patch Management is all that is to Vulnerability Management"

  1. True
  2. False
Question 8 True/False

State true or false: "Risk is assessed as a function of: a. probability of a threat b. probability of vulnerabilities c. potential impact to business."

  1. True
  2. False
Question 9 Multiple Choice (Single Answer)

Which of the following Risk Assessment Methodologies is deployed at TTSL?

  1. Fault Tree Analysis (FTA)
  2. Probability Risk Assessment (PRA)
  3. Failure Mode and Effect Analysis (FMEA)
  4. Operationally Critical Threat, Asset and Vulnerability (OCTAVE)
Question 10 Multiple Choice (Single Answer)

Which of the following options correctly states the various potential risk treatments?

  1. Risk Transfer, Risk Retention, Risk Avoidance, Risk Reduction
  2. Risk Analysis and Mitigation
  3. Risk Elimination
  4. None of the above
Question 11 Multiple Choice (Single Answer)

Software can be broadly categorized as which of the following?

  1. Application Software
  2. System Software
  3. Programming Software
  4. All of the above
Question 12 Multiple Choice (Single Answer)

Which of the following lists out correctly the various categories of software licenses?

  1. Open source and donate ware
  2. Proprietary Liences, Freeware and Cardware
  3. Proprietary Licenses, Freeware and Open Source
  4. Shareware, Donateware and Cardware
Question 13 Multiple Choice (Single Answer)

Why is a software license agreement important?

  1. It contains restrictions imposed by the creator of the software
  2. It ocntains warranty and warranty disclaimers
  3. It contains permissions granted to the user by the creator
  4. All of the above
Question 14 Multiple Choice (Single Answer)

Which of the following could be forms of identity theft?

  1. Credit Card Frauds
  2. Bank Frauds
  3. Employment Frauds
  4. All of the above
Question 15 Multiple Choice (Single Answer)

Which of the followin highlights the benefits of a Single Sign On technology?

  1. Reducing IT costs as it lowers the number of IT help desk calls about passwords
  2. Enforces uniform password policy controls against disparate and legacy systems
  3. Both A & B
  4. None of the above
Question 16 Multiple Choice (Single Answer)

What are the benefits of using an Identity and Access Management System?

  1. Automation of account management
  2. Control and delegation of elevated and least privileged accounts
  3. Establishment of strong authentication
  4. All of the above
Question 17 Multiple Choice (Single Answer)

Which of the following domains are encomapssed by Cyber Laws?

  1. Cyber Crimes and Intellectual Property
  2. Electronic and Digital Signature
  3. Data Protection and Privacy Laws
  4. All of the above
Question 18 Multiple Choice (Single Answer)

Which of the following ISO 27000 series deals with detailed information on Information Security Management System (ISMS)?

  1. ISO 27001
  2. ISO 27006
  3. ISO 27005
  4. ISO 27000 series