Corporate3Computer3Security,35e3(Boyle/Panko)3Chap
ter323 Planning3and3Policy
1) Which3of3the3following3is3FALSE3about3security3management?
A) Management3is3abstract;3technology3is3visible.
B) Security3technology3is3far3more3important3than3security3management.
C) There3are3fewer3general3principles3in3security3management3than3technology.
D) It3is3generally3a3mistake3to3focus3too3heavily3on3security3technology3compared3to3securit
y3management.
Answer:3 B3
Page3Ref:349
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Difficult
2) Comprehensive3security3pertains3to3 .
A) closing3all3routes3of3attack3to3their3systems3to3attackers
B) closing3all3Internet-linked3servers3to3attackers
C) lessening3security3issues3in3an3entire3company
D) decreasing3the3risk3of3all3computer3systems3in3a3compan
y3Answer:3 A
Page3Ref:349
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
3) If3a3failure3of3a3single3element3of3a3system3will3ruin3security,3this3is3called3a(n)3 .
A) weakest-link3failure
B) hybrid3solution
C) internal3audit
D) risk3analysis
3Answer: 3 A3Pa
ge3Ref:349
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
4) Process3pertains3to3 .
A) the3plan-protect-respond3cycle
B) the3systems3life3cycle
C) a3planned3series3of3actions
D) recovery3according3to3plan
3Answer: 3 C
Page3Ref:350
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
1
Copyright3©320213Pearson3Education,3Inc
.
mynursytest.store
,DOWNLOAD3THE3Test3Bank3for3Corporate3Computer3Security35th3Edition3Boyle
5) Which3of3the3following3is3NOT3part3of3the3highest-
level3security3management3process3that3most3firms3use3today3to3protect3against3threats?
A) Plan
B) Process
C) Protect
D) Respond3
Answer:3 B3
Page3Ref:351
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
6) The3systems3development3life3cycle3is3most3connected3to3the3 of3the3plan-protect-
3respond3cycle 3of3security3management.
A) plan
B) process
C) protect
D) respond3
Answer:3 C3
Page3Ref:352
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
7) Response3is3 .
A) the3second3phase3of3the3systems3life3cycle
B) the3plan-based3creation3and3operation3of3countermeasures
C) a3planned3series3of3actions
D) recovery3according3to3plan
3Answer: 3 D
Page3Ref:353
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
8) A3firm's3primary3objective3is3to3make3a3profit
.3Answer:3 TRUE
Page3Ref:348
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
9) A3firewall3administrator3should3check3the3log3file3in3a3company3each3wee
k.3Answer:3 FALSE
Page3Ref:349
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Moderate
2
Copyright3©320213Pearson3Education,3Inc
.
mynursytest.store
, DOWNLOAD3THE3Test3Bank3for3Corporate3Computer3Security35th3Edition3Boyle
10) One3reason3why3security3management3is3difficult3is3that3companies3need3to3protect3a3larg
e3number3of3resources.
Answer:3 TRUE3Pag
e3Ref:350
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
11) Security3is3too3complicated3to3be3managed3informally
.3Answer:3 TRUE
Page3Ref:350
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
12) In3the3plan-protect-
respond3cycle,3the3three3activities3always3take3place3in3sequential3order.3Answer:3 FALSE
Page3Ref:350
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
13) One3key3to3making3security3an3enabler3is3to3get3security3involved3near3the3end3of3mo
st3projects.
Answer:3 FALSE3Pa
ge3Ref:354
Learning3Objective:3 2.13Justify3the3need3for3formal3management3processes
3Difficulty: 3 Easy
14) are3things3that3require3a3firm3to3change3its3security3planning,3protections,3an
d3response.
A) Responses
B) Protections
C) MSSPs
D) Driving3forces
3Answer: 3 D
Page3Ref:358
Learning3Objective:3 2.23Describe3compliance3laws3and3regulations3Difficu
lty:3 Moderate
15) Which3of3the3following3produced3the3greatest3change3in3financial3reporting3requirement3sinc
e3the3Great3Depression?
A) The3Sarbanes-Oxley3Act
B) The3General3Data3Protection3Regulation
C) The3Gramm-Leach-Bliley3Act
D) The3Health3Insurance3Portability3and3Accountability3Ac
t3Answer:3 A
Page3Ref:358
Learning3Objective:3 2.23Describe3compliance3laws3and3regulations3Difficu
lty:3 Moderate
3
Copyright3©320213Pearson3Education,3Inc
.
mynursytest.store