Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

MISY 5325 MIDTERM ACTUAL EXAM NEWEST 2025/2026 COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |BRAND NEW VERSION!!

Beoordeling
-
Verkocht
-
Pagina's
34
Cijfer
A+
Geüpload op
13-10-2025
Geschreven in
2025/2026

MISY 5325 MIDTERM ACTUAL EXAM NEWEST 2025/2026 COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS (VERIFIED ANSWERS) |BRAND NEW VERSION!! The formulas used in a quantitative risk assessment typically look at a single year. The calculations can become quite complex if other costs are included. Which of the following is not usually included in the calculations? A. Annualized Rate of Occurrence (ARO) B. Single Loss Expectancy (SLE) C. Annualized Loss Expectancy (ALE) D. Cost to maintain a control The cost to maintain a control In a risk assessment, which of the following refers to how responsibilities are assigned? a. Operational characteristics b. Management operations c. Configuration management d. Management structure Management structure Which of the following is not true of data and information assets? a. Access controls protect data from unauthorized disclosure. b. Backups protect data when it becomes corrupted or accidentally deleted. c. Data classified at different levels, such as public and private, receives the same levels of protection. d. Many organizations don't recognize the value of their data until it is lost. 2 | Page Misy 5325 Midterm Actual Exam Data classified at different levels, such as public and private, receives the same levels of protection. _________ are acts that are hostile to an organization. A) Intentional threats B) Unintentional threats C) Human threats D) All threats Intentional threats Which of the following is often the weakest link in IT security? A. physical security B. people C. use of pass-phrases D. use of computer firewalls People A new company does not have a lot of revenue for the first year. Installing antivirus software for all the company's computers would be very costly, so the owners decide to forgo purchasing antivirus software for the first year of the business. In what domain of a typical IT infrastructure is a vulnerability created? A) workstation domain B) malware domain C) LAN domain D) WAN domain Workstation Domain Companies use risk assessment strategies to differentiate ___________ from _________. A) vulnerabilities, weaknesses B) vulnerabilities, threats 3 | Page Misy 5325 Midterm Actual Exam C) risks, threats D) severe risks, minor risks Severe risks, minor risks What is the primary reason security professionals automate some processes? A) To create security policies B) To enforce the principle of least privilege C) To enforce the principle of need to know D) To reduce human error To reduce human error Which of the following is not a risk management step? A. eliminating all risks B. identifying risks C. taking steps to reduce risk to an accepted level D. assessing risks Eliminating all risks What are the elements of the security triad? A.cooperation, installation, and acquisition b. confidence, intelligence, and assessment C. coordination, implementation, and authorization D. confidentiality, integrity, and availability Confidentiality, integrity, and availability

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

Misy 5325 Midterm Actual Exam


MISY 5325 MIDTERM ACTUAL EXAM NEWEST 2025/2026
COMPLETE QUESTIONS AND CORRECT DETAILED ANSWERS
(VERIFIED ANSWERS) |BRAND NEW VERSION!!
The formulas used in a quantitative risk assessment typically look at a single year.
The calculations can become quite complex if other costs are included. Which of
the following is not usually included in the calculations?

A. Annualized Rate of Occurrence (ARO)
B. Single Loss Expectancy (SLE)
C. Annualized Loss Expectancy (ALE)
D. Cost to maintain a control

The cost to maintain a control

In a risk assessment, which of the following refers to how responsibilities are
assigned?

a. Operational characteristics
b. Management operations
c. Configuration management
d. Management structure

Management structure

Which of the following is not true of data and information assets?

a. Access controls protect data from unauthorized disclosure.
b. Backups protect data when it becomes corrupted or accidentally deleted.
c. Data classified at different levels, such as public and private, receives the same
levels of protection.
d. Many organizations don't recognize the value of their data until it is lost.

1|Page

, Misy 5325 Midterm Actual Exam

Data classified at different levels, such as public and private, receives the same
levels of protection.

_________ are acts that are hostile to an organization.
A) Intentional threats
B) Unintentional threats
C) Human threats
D) All threats

Intentional threats

Which of the following is often the weakest link in IT security?

A. physical security
B. people
C. use of pass-phrases
D. use of computer firewalls

People

A new company does not have a lot of revenue for the first year. Installing
antivirus software for all the company's computers would be very costly, so the
owners decide to forgo purchasing antivirus software for the first year of the
business. In what domain of a typical IT infrastructure is a vulnerability created?
A) workstation domain
B) malware domain
C) LAN domain
D) WAN domain

Workstation Domain

Companies use risk assessment strategies to differentiate ___________ from
_________.
A) vulnerabilities, weaknesses
B) vulnerabilities, threats

2|Page

, Misy 5325 Midterm Actual Exam

C) risks, threats
D) severe risks, minor risks

Severe risks, minor risks

What is the primary reason security professionals automate some processes?
A) To create security policies
B) To enforce the principle of least privilege
C) To enforce the principle of need to know
D) To reduce human error

To reduce human error

Which of the following is not a risk management step?
A. eliminating all risks
B. identifying risks
C. taking steps to reduce risk to an accepted level
D. assessing risks

Eliminating all risks

What are the elements of the security triad?
A.cooperation, installation, and acquisition
b. confidence, intelligence, and assessment
C. coordination, implementation, and authorization
D. confidentiality, integrity, and availability

Confidentiality, integrity, and availability

Another term for risk mitigation is:
A) risk reduction.
B) risk assessment.
C) risk management.
D) risk evaluation.

Risk reduction
3|Page

, Misy 5325 Midterm Actual Exam

What can you control about threat/vulnerability pairs?
A) the vulnerability
b) the threat
c) the loss
d) the cost

The vulnerability only

Isabella works as a risk specialist for her company. She wants to determine which
risks should be managed and which should not by applying a test to each risk.
Risks that don't meet the test are accepted. What type of test does she apply?
A.Cost assessment
B.reasonableness test
C.control test
D.vulnerability test

Reasonableness test

Which of the following is a division of the U.S. Department of Commerce and
publishes the Risk Management Framework (RMF) 800 special publications series?
A. Department of Homeland security (DHS)
B. MITRE corporation
C. National Institute of standards and technology (NIST)
D. United States computer emergency readiness team (US-CERT)

National Institute of Standards and Technology (NIST)

Rodrigo is a network security specialist. He wants to perform real-time analysis of
security data gathered from networked systems. Which of the following is the best
solution for Rodrigo to implement?
A. Intrusion prevention system (IPS)
B. vulnerability scanning
C. security information and event management (SIEM)
D. configuration management


4|Page

Geschreven voor

Vak

Documentinformatie

Geüpload op
13 oktober 2025
Aantal pagina's
34
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$13.99
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
SophiaBennettRN Teachme2-tutor
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
24
Lid sinds
1 jaar
Aantal volgers
1
Documenten
2322
Laatst verkocht
1 week geleden
TopGrade Tutor: Expert Psychology, Nursing, Pharmacology & Computer and Math Resources

Welcome to my academic support store, your trusted destination for top-tier homework help and tutoring services! Specializing in key subjects like Psychology, Nursing, Human Resource Management, and Mathematics, I’m dedicated to helping students excel with high-quality, meticulously crafted resources. My mission is to deliver scholarly, reliable content that guarantees excellent grades, earning me a reputation as one of Stuvia’s BEST GOLD RATED TUTORS. Whether you need assistance with quizzes, exams, or detailed study materials, I prioritize your success with a commitment to academic excellence and results you can count on

Lees meer Lees minder
3.9

7 beoordelingen

5
4
4
1
3
0
2
1
1
1

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen