Quiz: Information Security and Continuity Planning — 32 questions

Detailed questions and answers

1. What is the primary purpose of information security within an organization?

To eliminate every security issue before it can affect resources
To evaluate business decisions that remain after controls are applied
To protect valuable resources and keep them available when needed
To assign operational tasks to users who access organizational systems

To protect valuable resources and keep them available when needed

Explanation

Information security protects an organization’s valuable resources and helps ensure that they are available when needed. Risk management, rather than information security itself, addresses security issues that cannot be completely eliminated.

2. Which set correctly identifies the three basic requirements of information security?

Classification, custody, and regulatory compliance
Availability, integrity, and confidentiality
Identification, authentication, and authorization
Privacy, accountability, and risk management

Availability, integrity, and confidentiality

Explanation

The core requirements are availability, integrity, and confidentiality. Identification, authentication, and authorization are related security functions but are not the three basic requirements.

3. A company ensures that authorized employees can reach a required system during working hours; which security requirement is being addressed?

Availability
Accountability
Integrity
Confidentiality

Availability

Explanation

Availability means that a computer system can be accessed by authorized users whenever it is needed. Confidentiality would instead address preventing unauthorized people from viewing protected information.

4. Which control objective is concerned with preventing intentional or accidental unauthorized changes to system information?

Availability
Identification
Confidentiality
Integrity

Integrity

Explanation

Integrity protects information from unauthorized modification, whether the change is deliberate or accidental. Availability concerns access to systems, while confidentiality concerns unauthorized disclosure.

5. Why does an organization classify information instead of applying identical protection to every data set?

Classification directs stronger controls toward information with greater value or risk
Classification replaces privacy and regulatory obligations with internal labels
Classification assigns every data set the same level of protection for consistency
Classification allows users to determine controls without owner or supervisor involvement

Classification directs stronger controls toward information with greater value or risk

Explanation

Classification focuses protection and control on data that needs it most because information does not have equal organizational value. Treating every data set as equally important is the uniform-protection approach that classification avoids.

6. Which description best distinguishes private information from confidential information in a private-sector classification scheme?

Private information concerns regulatory records, while confidential information describes employee identity claims
Private information supports company use, while confidential information is highly sensitive and harmful if disclosed
Private information requires the strongest controls, while confidential information has limited business value
Private information is available publicly, while confidential information is intended for routine company use

Private information supports company use, while confidential information is highly sensitive and harmful if disclosed

Explanation

Private information is intended for company use, such as salary levels, whereas confidential information is highly sensitive and unauthorized disclosure could seriously harm the company. Public information is the category associated with broad availability.

7. Which activity belongs in a complete information-classification procedure?

Assigning protection duties to custodians without identifying information owners
Applying one control set to all information and omitting exception records
Defining controls for each classification level and procedures for declassification or custody transfer
Allowing each user to choose a label and changing it whenever the data is accessed

Defining controls for each classification level and procedures for declassification or custody transfer

Explanation

A complete procedure specifies controls for each level and defines declassification or custody-transfer processes, along with ownership, labeling, exceptions, and awareness. Letting users freely choose labels would undermine consistent classification governance.

8. Who determines the required classification of information and delegates protection duties to the custodian?

The information owner
The routine information user
The information custodian
The enterprise awareness coordinator

The information owner

Explanation

The information owner determines the required classification and delegates protection responsibilities to the custodian. The custodian carries out protection, while the user typically accesses the information for work.

9. What is the defining role of a security policy in an organization’s documentation hierarchy?

It gives detailed steps for completing a particular operational task
It provides high-level direction and serves as the basis for security implementation
It recommends optional technologies that departments may adopt independently
It records audit events generated by users and system administrators

It provides high-level direction and serves as the basis for security implementation

Explanation

A security policy is generally the first and highest level of security documentation and contains broad statements that guide implementation. Detailed task instructions belong in procedures rather than policies.

10. What does a senior management statement of policy primarily demonstrate?

Flexible recommendations that departments may follow according to local preferences
Detailed instructions for configuring systems and completing daily security tasks
Enterprise-wide commitment to information security and oversight of lower-level documents
Technical requirements that mandate uniform technologies across every system

Enterprise-wide commitment to information security and oversight of lower-level documents

Explanation

The senior management statement recognizes the importance of computing resources, supports security across the enterprise, and commits management to authorizing and overseeing lower-level documents. Detailed implementation instructions belong in standards, procedures, or guidelines.

11. Which pairing correctly distinguishes standards, guidelines, and procedures?

Standards give task instructions, guidelines establish mandatory technologies, and procedures document optional practices
Standards state broad direction, guidelines record audit trails, and procedures assign information classifications
Standards offer flexible advice, guidelines mandate technologies, and procedures state broad management commitments
Standards mandate uniform technologies, guidelines offer flexible advice, and procedures give detailed task steps

Standards mandate uniform technologies, guidelines offer flexible advice, and procedures give detailed task steps

Explanation

Standards specify compulsory technologies uniformly, guidelines provide flexible non-compulsory recommendations, and procedures describe detailed steps for a task. Broad management direction belongs to policy rather than to these lower-level document types.

12. Which role determines how organizational data should be classified?

The data owner
The security auditor
The system operator
The information custodian

The data owner

Explanation

The owner decides the classification assigned to data, such as its sensitivity or required protection level. The custodian is responsible for preserving confidentiality, integrity, and availability rather than setting the classification.

13. Why are both security awareness and role-specific training important in an organization?

Awareness assigns data classifications, while training audits security controls
Awareness explains protection responsibilities, while training develops secure job skills
Awareness calculates annual losses, while training selects insurance coverage
Awareness approves access privileges, while training determines business impact

Awareness explains protection responsibilities, while training develops secure job skills

Explanation

Awareness helps employees understand why enterprise information must be protected, while training builds the skills needed to perform duties securely. The other choices assign unrelated security-management tasks to awareness and training.

14. What is the proper relationship between risk analysis and risk assessment?

Analysis examines risk conditions, while assessment assigns values to them
Analysis assigns asset values, while assessment identifies vulnerable systems
Analysis transfers risk, while assessment eliminates every identified threat
Analysis approves safeguards, while assessment performs security operations

Analysis examines risk conditions, while assessment assigns values to them

Explanation

Risk analysis examines conditions such as vulnerabilities, affected assets, and possible consequences, whereas risk assessment assigns values to those elements. Assigning asset values is therefore part of assessment rather than the defining role of analysis.

15. During risk analysis, what should an analyst do after identifying vulnerabilities in a target environment?

Convert them directly into annualized monetary losses
Associate them with affected assets and determine undesirable results
Classify every affected asset according to business ownership
Assign each vulnerability a personnel training requirement

Associate them with affected assets and determine undesirable results

Explanation

Risk analysis links vulnerabilities to affected assets, determines potential undesirable results, and evaluates countermeasures that could reduce risk. Converting findings into annualized monetary losses belongs to quantitative assessment rather than this analysis step.

16. Which activity is characteristic of risk assessment rather than risk analysis?

Identifying vulnerabilities in the target environment
Linking vulnerabilities to the assets they could affect
Assigning values to assets, threat frequencies, and consequences
Evaluating countermeasures that could reduce identified risk

Assigning values to assets, threat frequencies, and consequences

Explanation

Risk assessment assigns values to assets, threat frequency, consequences, and other chance-related elements to characterize risk. Identifying vulnerabilities and linking them to assets are activities performed during risk analysis.

17. A threatened event could cause a $200,000 asset to lose 30% of its value in one occurrence. What is the Single Loss Expectancy?

170,000170{,}000
600,000600{,}000
60,00060{,}000
6,0006{,}000

$$60{,}000$$

Explanation

Single Loss Expectancy is calculated as asset value multiplied by exposure factor, so 200,000×0.30=60,000200{,}000 \times 0.30 = 60{,}000. The exposure factor is the percentage loss, whereas SLE is the resulting monetary loss for one occurrence.

18. A threat is expected to occur once every ten years. What is its Annualized Rate of Occurrence?

11
0.10.1
1010
100100

$$0.1$$

Explanation

An occurrence once every ten years corresponds to an annualized frequency of 1÷10=0.11 \div 10 = 0.1. An ARO of 11 would represent one expected occurrence per year, not one per decade.

19. An asset has a Single Loss Expectancy of 40,00040{,}000 and an Annualized Rate of Occurrence of 0.250.25. What is its Annualized Loss Expectancy?

40,02540{,}025
10,00010{,}000
160,000160{,}000
39,75039{,}750

$$10{,}000$$

Explanation

Annualized Loss Expectancy equals Single Loss Expectancy multiplied by Annualized Rate of Occurrence, giving 40,000×0.25=10,00040{,}000 \times 0.25 = 10{,}000. The SLE represents one event, while ALE incorporates the expected frequency across a year.

20. A safeguard reduces annualized loss expectancy from 75,00075{,}000 to 25,00025{,}000 and costs 15,00015{,}000 annually. What is its value?

40,00040{,}000
50,00050{,}000
65,00065{,}000
35,00035{,}000

$$35{,}000$$

Explanation

The safeguard value is calculated as ALEbeforeALEafterannual safeguard costALE_{before} - ALE_{after} - annual\ safeguard\ cost, so 75,00025,00015,000=35,00075{,}000 - 25{,}000 - 15{,}000 = 35{,}000. Subtracting the safeguard cost is necessary because the reduction in expected loss is not the net value by itself.

21. What is the primary purpose of Business Continuity Planning during an emergency?

To analyze threats and vulnerabilities affecting organizational assets
To maintain business operations through a structured continuity framework
To authorize the use of a newly developed recovery plan
To restore damaged facilities after the emergency has ended

To maintain business operations through a structured continuity framework

Explanation

Business Continuity Planning establishes a framework for keeping the business operating during an emergency. Disaster Recovery Planning is more specifically concerned with restoring operations after disruption, making the second option a related but incorrect distinction.

22. Which activity is a stated objective of Business Continuity Planning?

Identifying threats, vulnerabilities, and countermeasures
Approving enterprise-wide recovery procedures
Determining the longest tolerable interruption for critical processes
Reducing financial loss caused by disruptive events

Reducing financial loss caused by disruptive events

Explanation

BCP aims to reduce financial loss, prevent interruptions, resume processes, and limit the costs of disruptive events. Determining tolerable interruption periods belongs to Business Impact Analysis, not the objective list of BCP.

23. Which event is classified as a man-made disruption rather than a natural disruption?

A flood that damages the organization’s facilities
An earthquake that interrupts regional operations
A strike that makes employees unavailable for work
A storm that causes extended power failures

A strike that makes employees unavailable for work

Explanation

Strikes and employee unavailability are identified as man-made disruptive events. Floods, earthquakes, and storms are natural events, even when they produce similar operational consequences.

24. What is the main purpose of a Business Impact Analysis?

To authorize recovery capabilities for enterprise-wide deployment
To document the effects a disruptive event could have on the business
To identify threats, vulnerabilities, assets, and countermeasures
To define the parameters and management practices of the continuity plan

To document the effects a disruptive event could have on the business

Explanation

A Business Impact Analysis produces a document describing the potential business impact of a disruptive event. The third option describes risk analysis, while defining plan parameters belongs to scope and plan initiation.

25. What does Maximum Tolerable Downtime describe for a critical business process?

The longest interruption period before the company can no longer recover
The period needed to complete regular audits of the process
The time required to identify resources supporting the process
The interval during which management approves recovery priorities

The longest interruption period before the company can no longer recover

Explanation

Maximum Tolerable Downtime is the longest period a critical process may remain interrupted before recovery becomes impossible for the company. Identifying resources and setting recovery priorities are activities associated with Business Impact Analysis rather than the definition of this measure.

26. Which task belongs to BCP scope and plan initiation rather than to measuring disruption impacts?

Recommending recovery priorities to senior management
Recording the quantitative and qualitative effects of a disruption
Determining acceptable interruption periods for critical processes
Creating a detailed account of required work and available resources

Creating a detailed account of required work and available resources

Explanation

Scope and plan initiation examines operations and support services, details required work, lists resources, and defines management practices. Recording impacts, determining interruption periods, and recommending priorities are BIA activities.

27. How does continuity plan development use Business Impact Analysis information?

It grants senior management authority to implement the completed plan
It identifies organizational threats before evaluating business consequences
It creates and documents recovery strategies for critical business functions
It maintains one approved version through audits and assigned responsibilities

It creates and documents recovery strategies for critical business functions

Explanation

Continuity plan development uses BIA findings to create recovery strategies covering functions, computing, facilities, people, supplies, and equipment. Approval and maintenance activities authorize and control the plan rather than create its recovery strategy.

28. Which requirement belongs to plan approval and implementation?

A measurement of quantitative and qualitative disruption impacts
Senior management approval combined with training and regular audits
A determination of the longest tolerable interruption for each process
A detailed account of required work and supporting organizational resources

Senior management approval combined with training and regular audits

Explanation

Plan approval and implementation requires senior management approval, personnel training, maintenance responsibilities, regular audits, and enterprise-wide awareness. The other activities belong to scope initiation or Business Impact Analysis rather than plan authorization and implementation.

29. What is the primary purpose of maintaining a data recovery plan after it has been developed?

To verify that personnel can perform emergency duties
To transfer backup data to an off-site storage facility
To keep the plan current and relevant as conditions change
To restore the damaged primary site after a disaster

To keep the plan current and relevant as conditions change

Explanation

Plan maintenance keeps the data recovery plan current and relevant over time. Off-site backup transfer is electronic vaulting, while restoring the primary site is a salvage-team responsibility.

30. Which alternate-site type is fully configured and available for immediate operation?

A cold site
A salvage site
A hot site
A warm site

A hot site

Explanation

A hot site is a fully configured facility that can be used immediately after a disruption. A cold site provides space and utilities but requires equipment to be brought in, while a warm site may require application or workstation setup.

31. Which recovery technique processes transactions in parallel at an alternate site?

Remote journaling
Electronic vaulting
Structured walk-through testing
Database shadowing

Remote journaling

Explanation

Remote journaling processes transactions in parallel at an alternate site. Electronic vaulting transfers backup data off-site, whereas database shadowing duplicates database sets across multiple servers.

32. What is a central purpose of testing a disaster recovery plan?

To verify procedures and reveal deficiencies before an emergency
To eliminate the need for personnel training during a disaster
To replace the primary facility with a permanently new site
To transfer every transaction to an alternate site during normal operations

To verify procedures and reveal deficiencies before an emergency

Explanation

DRP testing checks the accuracy of recovery procedures, exposes deficiencies, trains personnel, and verifies alternate-site capability. It does not permanently replace the primary facility or remove the need for emergency training.

Review with flashcards

Memorize the answers with 63 flashcards on Information Security and Continuity Planning.

What does information security protect in an organization?

An organization's valuable resources.

What are the three basic information security requirements?

Availability, integrity, and confidentiality.

What does availability assure in information security?

That authorized users can access a system whenever needed.

See flashcards →

Read the study sheet

Read the complete study sheet on Information Security and Continuity Planning.

See study sheet →

Similar courses

Create your own quizzes

Import your course and AI generates quizzes with corrections in 30 seconds.

Quiz generator