CHAPTER 14 ASSESSMENT

1. A parallel test uses current processing data to test IT system operation.

A. True

B. False

2. Which item is not part of the risk management process?

A. Risk analysis

B. Risk response

C. Continuous monitoring

D. Training employees

E. All of these are parts of the risk management process.

3. What does a risk assessment do?

4. Which type of contingency plan test is the least expensive?

A. Full interruption test

B. Parallel test

C. Simulation test

D. Checklist test

E. None of these is correct.

5. Which type of risk analysis uses real numbers to calculate risk?

A. Quantitative

B. Qualitative

C. Quasi-quantitative

D. Quasi-qualitative

E. None of these is correct.

6. The ________ is the percentage of asset loss that is likely to be caused by an identified threat.

7. How is annualized loss expectancy calculated?

8. What is the main benefit of a qualitative risk assessment?

A. Measures the money cost of a risk

B. Scope of the assessment can be easily changed

C. Easy to administer

D. All of these are correct.

E. None of these is correct.

9. Which of the following is a qualitative risk assessment methodology?

A. OCTAVE

B. ARO

C. MTD

D. BIA

E. None of these is correct.

10. Which risk response eliminates all risk of harm posted by a threat or vulnerability?

A. Risk transfer

B. Risk mitigation

C. Risk acceptance

D. Risk avoidance

E. None of these is correct.

11. Which type of contingency plan reacts to attacks against an organization’s IT infrastructure?

A. BC plan

B. DR plan

C. IR plan

D. BC and DR plans

E. None of these is correct.

12. A(n) ________ is an event that adversely affects the confidentiality, integrity, and/or availability of an organization’s data and IT systems.

13. A(n) ________ is a sudden, unplanned event that negatively affects the organization’s critical business functions for an unknown period.

14. Which backup site is a fully operational backup site?

A. Mirrored site

B. Hot site

C. Warm site

D. Cold site

E. None of these is correct.

15. A business impact analysis identifies key business operations and resources.

A. True

B. False

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset