| Questions and Answers Rated A+ |
2025/2026 Guide
An evaluation of whether an organization has a well-considered security
policy in place and if it is being followed.
- Correct Answer - security audit
An organization's security requirements, as well as the controls and
sanctions needed to meet those requirements.
- Correct Answer - security policy
The concept of having different aspects of a process handled by different
people to prevent fraud.
- Correct Answer - separation of duties
The estimated loss that would be incurred if a risk event occurs.
- Correct Answer - single loss expectancy (SLE)
An oral defamatory statement.
- Correct Answer - slander
,Another variation of phishing that involves the use of texting.
- Correct Answer - smishing
A process whereby an organization reviews how well it is meeting its
ethical and social responsibility goals and communicates its new goals
for the upcoming year.
- Correct Answer - social audit
A trade group that represents the world's largest software and hardware
manufacturers.
- Correct Answer - Software & Information Industry Association (SIIA)
A form of copyright infringement that involves making copies of software
or enabling others to access software to which they are not entitled.
- Correct Answer - software piracy
A variation of phishing in which the phisher sends fraudulent emails to a
certain organization's employees.
- Correct Answer - spear phishing
An auditing standard issued by the Auditing Standards Board of the
American Institute of Certified Public Accountants (AICPA). It
demonstrates that an outsourcing firm has effective internal controls in
accordance with the Sarbanes-Oxley Act of 2002.
,- Correct Answer - SSAE No. 16 audit report
A cell phone spy software that can be loaded onto someone's cell phone
or smartphone within minutes, making it possible for the user to perform
location tracking, record calls, view every text message or pic turesent or
received, and record the URLs of any website visited on the phone.
- Correct Answer - stalking app
A software-testing technique in which software is tested without actually
executing the code. It consists of two steps—review and static analysis. -
Correct Answer - static testing
The acquiring of data, sound, images, and video from a patient and then
transmitting everything to a medical specialist for later evaluation.
- Correct Answer - store-and-forward telemedicine
A lawsuit filed by corporations, government officials, and others against
citizens and community groups who oppose them on matters of concern.
The lawsuit is typically without merit and is used to intimidate critics out
of fear of the cost and effort associated with a major legal battle.
- Correct Answer - strategic lawsuit against public participation (SLAPP)
, A situation in which the defendant is held responsible for injuring another
person, regardless of negligence or intent. - Correct Answer - strict
liability
A component of corporate social responsibility (CSR) that focuses on
developing and maintaining a supply chain that meets the needs of the
present without compromising the ability of future generations to meet
their needs. - Correct Answer - supply chain sustainability
Someone who has explicit responsibility for ensuring that a system will
operate in a safe and reliable manner while meeting its users' needs. -
Correct Answer - system safety engineer
Software testing done after successful integration testing, where the
various subsystems are combined to test the entire system as a
complete entity. - Correct Answer - system testing
Employs electronic information processing and telecommunications to
support at-a-distance health care, provide professional and patient
health-related training, and support healthcare administration. - Correct
Answer - telehealth
A component of telehealth that provides medical care to people at a
location different from the healthcare providers. - Correct Answer -
telemedicine