MIS Information Security Management 2 — Questions and Answers
Question 1: What is the purpose of encryption in information security?
- To speed up data transmission
- To convert data into an unreadable format for unauthorized users (Correct answer)
- To compress files for storage efficiency
- To authenticate user identities
Correct answer: To convert data into an unreadable format for unauthorized users
Encryption converts readable data (plaintext) into an unreadable format (ciphertext) that can only be decoded by authorized parties with the correct key.
Question 2: A risk assessment in information security involves:
- Installing security software on all workstations
- Identifying, analyzing, and evaluating potential threats to information assets (Correct answer)
- Hiring security guards for the data center
- Creating backup copies of all data daily
Correct answer: Identifying, analyzing, and evaluating potential threats to information assets
A risk assessment systematically identifies potential threats, analyzes their likelihood and impact, and evaluates appropriate mitigation strategies.
Question 3: Which security control type is a password policy?
- Physical control
- Technical control
- Administrative control (Correct answer)
- Operational control
Correct answer: Administrative control
Password policies are administrative controls — documented rules and procedures that govern how people behave to maintain security.
Question 4: What is social engineering in the context of information security?
- Managing social media accounts for the organization
- Manipulating people psychologically to divulge confidential information (Correct answer)
- Engineering software for social networking platforms
- Analyzing employee social interactions
Correct answer: Manipulating people psychologically to divulge confidential information
Social engineering exploits human psychology rather than technical vulnerabilities to manipulate individuals into revealing sensitive information or granting unauthorized access.
Question 5: What does the principle of least privilege mean in information security?
- Executives have the most system access
- Users are granted only the minimum access needed to perform their job (Correct answer)
- New employees have no system access initially
- System administrators have unlimited access to all data
Correct answer: Users are granted only the minimum access needed to perform their job
The principle of least privilege limits user access rights to only what is strictly necessary to perform their specific job functions.
Question 6: What is a security audit?
- A financial audit focused on IT spending
- A systematic evaluation of an organization's security controls and practices (Correct answer)
- A physical inspection of server hardware
- An employee background check process
Correct answer: A systematic evaluation of an organization's security controls and practices
A security audit systematically reviews an organization's security policies, controls, and practices to identify vulnerabilities and ensure compliance.
What is the purpose of encryption in information security?