# Top 20 ISI Quiz Questions With Answers

So, let’s move on to the quiz questions with answers.

Select one:
a. True
b. False

Select one:
a. True
b. False

Select one:
a. True
b. False

Select one:
a. True
b. False

5. ##### Q5. Which of the following is not true of information security and information systems?

Select one:
a. An IT security assessment is a key activity that involves the management of risk.
b. Loss is an uncertainty that might lead to a risk.
c. A risk-based approach to security includes identifying and categorizing information and information systems.
d. Monitoring security controls is a continual cycle as organizations evolve.

Select one:
a. True
b. False

7. ##### Q7. _ by itself does not reduce __; it must be implemented and maintained.

Select one:
a. Accountability; attack vectors
b. Risk; compliance gaps
c. A policy; risk
d. A risk; accountability

8. ##### Q8. A policy requiring enhanced security measures is not effective unless it is fully implemented. During a compliance audit, which of the following is least likely to ensure that policies are enforced?

Select one:
a. Documentation of the compliance governance structure and ensuring that it is understood
b. Incentive structures that create a conflict of interest
c. Measurement and timely reporting on policy outcomes
d. Clear accountability

9. ##### Q9. An IT security assessment is a key activity that involves the management of:

Select one:
a. compliance with federal regulations.
b. risk.
c. IT governance.
d. controls.

10. ##### Q10. What refers to the need or desire for an organization to follow rules and guidelines set forth by external organizations and initiatives?

Select one:
a. Internal compliance
b. Compliance with an organization's control objectives
c. Compliance with an organization's security policy
d. External compliance

Select one:
a. True
b. False

Select one:
a. True
b. False

13. ##### Q13. An organization's ability to follow its own rules, which are typically based on defined policies, is called:

Select one:
a. regulatory compliance.
b. internal compliance.
c. meeting contractual obligations.
d. external compliance.

14. ##### Q14. What is the act or process of doing what you have been asked or ordered to do?

a. Compliance
b. Accountability
c. Auditing
d. Assurance

15. ##### Q15. What ensures that only authorized users can modify data?

a. Confidentiality
b. Integrity
c. Availability
d. Accountability

Select one:
a. True
b. False

17. ##### Q17. Which of the following is not true of compliance, risk, and governance?

Select one:
a. Compliance is closely related to risk management and governance at the technical, procedural, and strategic levels.
b. Assurance seeks to mitigate risk through controls.
c. Compliance helps risk management by verifying that the desired controls are in place.
d. Governance seeks to better run an organization using complete and accurate information and management processes or controls.

Select one:
a. True
b. False

19. ##### Q19. Which of the following is a general step to meeting regulatory compliance?

Select one:
a. Interpret the regulation and how it applies to the federal government.
b. Identify accountability at the governance, department, and executive levels of the regulatory body.
c. Identify any gaps in controls or determine where the organization stands with the compliance mandate.
d. Ensure management devises a plan to maintain any gaps in controls.

Select one:
a. True
b. False

1. b
2. b
3. b
4. b
5. b
6. a
7. d
8. b
9. b
10. d
11. b
12. b
13. b
14. a
15. b
16. b
17. d
18. b
19. c
20. a