Font size
S
M
L
XL
WorksheetsRev Test 3 - DISA
Total questions: 155
Worksheet time: 2hrs 56mins
Name
Class
Date
1.
Which function identify policy exception
a)
Weekend Payment
b)
Splitting vouchers
c)
Rounding off
d)
All of the above
2.
Which of the following is an attribute of the control self-assessment (CSA) approach?
a)
Broad stakeholder involvement
b)
Auditors are the primary control analysts
c)
Limited employee participation
d)
Policy driven
3.
The area of AI that investigates methods of facilitating communication between people and computers is
a)
Natural language processing
b)
Symbolic processing
c)
Decision support
d)
Robotics
4.
At what level an incident if not solved is considered as problem
a)
Level 2
b)
Level 3
c)
Level 4
d)
Level 5
5.
Pareto analysis involved in which step of data analytics
a)
Investigate
b)
Analyze
c)
Profile
d)
None of them
6.
In …......... Schema, the logical design of database is mapped to physical schema
a)
External Schema
b)
Conceptual Schema
c)
Physical Schema
d)
None of the Option
7.
The single most reliable system backup strategy is to have fully redundant systems called an active recovery.It is also known as
a)
Mirror Site
b)
Near site
c)
Warm Site
d)
Cold Site
8.
BENEFITS OF IOT?
a)
INTEGRATE AND ADAPT BUSINESS MODELS
b)
AUTOMATIC SOFTWARE INTEGRATION
c)
SHARING OF RESPONSIBILITIES AMONG THE ORGANIZATIONS.
d)
HIGHER AUTOMATIONS POSSIBLE
9.
Neural Networks and Fuzzy Logics are classified under which category of Artificial intelligence?
a)
Cognitive Science
b)
Robotics
c)
Natural Sciences
d)
Virtual Reality
10.
Which of the following should an IS auditor consider while auditing data warehousing systems
a)
Network capacity for speedy access
b)
Accuracy and correctness of outputs generated
c)
Validation of receivers details for correctness and completeness
d)
Review of exceptional transaction logs
11.
List some applications of AI
a)
Natural language processing
b)
Sentiment analysis
c)
Self-driving cars
d)
All of the above
12.
…...... Is the layer which converts data into bits and puts it to copper wire or fiber wire for further transmission
a)
Application Layer
b)
Application Programming Interface
c)
Link Layer
d)
Internet Layer
13.
Backup type wherein 1st time a full backup is taken & then whenever change takes place, it is updated
a)
Full backup
b)
Incremental backup
c)
Differential backup
d)
Virtual full backups
14.
Which of the following business purposes can be met by implementing Data warehouse in an organisation?
a)
Business continuity can be ensured in case of disaster.
b)
Data in the data ware house can work as a backup
c)
The data in the warehouse can be used for meeting regulatory requirements
d)
Business decisions can be taken and future policies can be framed based on actual transactional data.
15.
Which is the best system development methodology for developing regular system
a)
Traditional Approach
b)
Prototype
c)
Spiral
d)
RAD
16.
Which of the following audit tools is MOST useful to an IS auditor when an audit trail is required?
a)
ntegrated test facility (ITF)
b)
Continuous and intermittent simulation (CIS)
c)
Audit hooks
d)
Snapshots
17.
The cashier of a company has rights to create bank master in TALLY. This error is a reflection of poor definition for which type of control:
a)
User Controls
b)
Application Control
c)
Input Control
d)
Output Control
18.
The programming languague commonly used are <br />
a)
COBOL
b)
JAVA
c)
VB SCRIPT
d)
All of these
19.
What is the term used for describing the judgmental or commonsense part of problem solving?
a)
Heuristic
b)
Critical
c)
Value based
d)
Analytical
20.
As part of auditing Information Security of a multinational bank, an auditor wants to assess the security of information in ATM facilities. Under which privacy policy should he look for details pertaining to security guards and CCTV surveillance of ATM’s?
a)
Physical Access and Security Policy
b)
Acceptable use of Information Assets Policy
c)
Asset Management Policy
d)
Business Continuity Management Policy Key
21.
Risk where an outsourced vendor further outsources job to their vendor is known as _____________
a)
Counter Party Risk
b)
Third Party Risk
c)
Fourth Party Risk
d)
Sub contractual Risk
22.
Which of the following BEST describes the purpose or character of an audit charter?
a)
An audit charter should be dynamic and change often to coincide with the changing nature of technology and the audit profession.
b)
An audit charter should early state audit's objectives for the delegation of authority for the maintenance and review of internal controls.
c)
An audit charter should document the audit procedures designed to achieve the planned audit objectives
d)
An audit charter should outline the overall authority, scope and responsibilities of the audit function
23.
…........... Defines authority, scope and responsibility of IS audit function
a)
Engagement Letter
b)
Audit control framework
c)
Audit Charter
d)
Audit Universe
24.
Which is the best system development methodology involve joint development workshop
a)
Traditional Approach
b)
Prototype
c)
Spiral
d)
RAD
25.
In an inter school competition on Artificial Intelligence, four children develop software which performs the following different functions respectively. Which of them is a correct example of the use of basic Artificial Intelligence?
a)
Predictive & self-learning word-processing software
b)
A calculation software which arrives at the arithmetic total of figures keyed in
c)
A password system which allows access based upon keying in of the correct password
d)
A software which rejects invalid dates like 32nd March 2019
26.
---------------- is a Central Repository of clean, consistent, integrated & summarized information, extracted from multiple operational systems, for on-line query processing
a)
Data Warehouse
b)
Data Mart
c)
Data Lake
d)
None of the above
27.
------- are information systems that provide interactive information support to middle management through analytical models
a)
DSS
b)
TPS
c)
ESS
d)
None of the above
28.
Virtual reality is an important application that can be classified under
a)
Cognitive Science
b)
Robotics
c)
Natural Languages
d)
Intelligent Agents
29.
SEM is used to provide
a)
in depth analysis
b)
real time monittoring
c)
Logs collection
d)
All of the above
30.
How should an organization include third-party suppliers in the continual improvement of services?
a)
Ensure suppliers include details of their approach to service improvement in contracts
b)
Require evidence that the supplier uses agile development methods
c)
Require evidence that the supplier implements all improvements using project management practices
d)
?Ensure that all supplier problem management activities result in improvements
31.
Which of the following sentences are true about RFP (Request for Proposal)?
a)
It is a standard solicitation document used by various organisations to compete for contract opportunities
b)
It is often used to acquire services, although it may be used in some circumstances to acquire goods
c)
IS Auditor can play an important role in preparation and evaluation of responses to RFP
d)
All of the above
32.
Which of the following is the most important element in the design of a data warehouse?
a)
Quality of the metadata
b)
Speed of the transaction
c)
Volatility of the data
d)
Vulnerability of the system
33.
protection of information asset includes the key components that ensure
a)
confidentiality
b)
integrity
c)
availability
d)
All of the above
34.
project management process begins with
a)
Project charter
b)
Business case
c)
Project sponser
d)
project manager
35.
Which of the following is not a Advance tools for Analytics
a)
Matlab
b)
Julia
c)
Pareto
d)
Hadoop
36.
IS auditor should review adequecy of the following proect management activities
a)
Levels of oversight by project committee
b)
risk management methods
c)
cost management
d)
process for planning and dependency management
e)
All of above
37.
WHICH OF THE FOLLOWING CHALLANGES TO OVERCOME,IT ORGANIZATION MUST
a)
DEFINE YOUR IOT GOVERNANCE PROCESSES AND POLICIES
b)
LEGAL AND COMPLIANCE
c)
INSUFFICIENT SECURITY CONFIGURABILITY
d)
ALL OF ABOVE
38.
Who ensures that system controls and supporting processes provide an effective level of protection, based on the data classification set in accordance with corporate security policies and procedures
a)
Security Officer
b)
Programmers/Developers
c)
Technology Specialist
d)
Systems Analyst
39.
ISO/IEC 27001:2013 formally specifies an Information Security Management System (ISMS), a suite of activities concerning the management of information security risks. Which of the following are true about this ISO/IEC 27001:2013?
a)
It is a formalized specification for an Information System Management System (ISMS)
b)
It lays out, at a high level, what an organization can do in order to implement an ISMS.
c)
It can (optionally) be used as the basis for formal compliance assessment by accredited (certified) IS Auditors in order to certify an organization.
d)
All of the above
40.
The first blockchain was conceptualized by a<br />person (or group of people) known as Satoshi<br />Nakamoto in?
a)
2004
b)
2005
c)
2006
d)
2008
41.
Who owns the data in a department?
a)
System owner
b)
Process owner
c)
Data custodian
d)
Data owner
42.
Which of the following best helps in classifying the information within the organization
a)
using minimum classes in classification schema
b)
conduct training on classification schema
c)
labelling all information based on classification schema
d)
determining the stroage based on classification schema
43.
Who of the following would approve or reject Major changes in cofiguration
a)
Management
b)
Change control Board
c)
User
d)
System Administrator
44.
discipilary actions for non compliance must be defined & communicated with
a)
middle level management
b)
lower level management
c)
senior level management
d)
All of the above
45.
Which of the following is defined as independent,objective assurance andconsulting activity designed to add value and improve organisation's operations
a)
IS Audit
b)
Internal Auditing
c)
CAAT
d)
Risk Based Audit
e)
Option A and B
46.
who is facilitator in implementing security across organization
a)
CISO
b)
senior management
c)
Board of Director
d)
All of the above
47.
Which of the following is central storage of all kind of data
a)
Data Lake
b)
Database
c)
Data Marts
d)
Data Warehouse
48.
Which of the situation directly affect the business drivers
a)
New service delivery opportunity
b)
issue & problem with existing system / business process
c)
use of automation by competitors to enchance quality of service
d)
All of these
49.
what is four eyes (Two-Person) principle
a)
Maker and Checker
b)
Maker-Checker-Approver
c)
both a and b
d)
None of the above
50.
key man is a term is used specifically for an important employee executive
a)
true
b)
false
51.
Which policy deals with that organization shall hold non- public personal information in strict confidance
a)
Acceptable use of policy
b)
Asset management Poicy
c)
Network & security policy
d)
Data classification & privacy polcy
52.
Configuration mgt is planning, identifying and managing the configuration with proper procedure so as to maintain -------------
a)
Confidentiality, Integrity, Availabilty
b)
Authenticity, Accountibility and Integrity
c)
Confidentiality , Authenticity and Accountibility
d)
None of the above
53.
All company developed software code whether used internally or sold to clients is classified under which Information category
a)
client confidential data
b)
company confidential data
c)
sensitive
d)
unclassified/above
54.
Which function displays the variation between highest value and 2nd highest value
a)
Max Variance factor
b)
Relative size factor
c)
3 way Matching factor
d)
Quadrant size factor
55.
SIM provide information or result to
a)
Level 3 manpower
b)
Level 1 manpower
c)
Level 2 manpower
d)
level 4 manpower
56.
Classification of information is primarily based on
a)
Where the information is stored?
b)
Who has access to information?
c)
What will happen if information is not available?
d)
Why attachement to mail are encrypted
57.
Which of the following is not an ITIL service lifecycle
a)
Service Strategy
b)
Service Feasibility
c)
Service Transition
d)
Service Design
58.
Which of the following is primary purpose of information classification
a)
comply with regulatory requirement
b)
Assign owner to information asset
c)
Provide appropriate level of protection
d)
Reduce costs od Data Protection
59.
Protecting integrity of data primarily focuses on
a)
intentional leakege of data
b)
Accidentional loss of data
c)
Accuracy and Completeness
d)
Data back up procedure
60.
Which of the following statement is correct
a)
Log provide information related to all events with some exception
b)
It is very easy for SOC team to read logs of all the devices installed in an organisation
c)
The event usually indicate the vulnerability in the system
d)
SOC tools collects Logs from all devices an darrange them in a common format
61.
Which of the following are NON_PROCEDURAL LANGUAGES?
a)
Query and Report Generators
b)
Embedded Database Languages
c)
Relational Database Languages
d)
All of the above
62.
MS office is an example of which type of Application software
a)
Commercial use Package Software
b)
Technical use Package Software
c)
Communication software
d)
Knowledge Software
63.
Information security "triad" is best described as
a)
Integrity, Authenticity, Confidentiality
b)
Integrity, Availability, Confidentiality
c)
Availability, Confidentiality, Utility
d)
Security, Sustainibility, Integrity
64.
…............ Is a component of SQL which can Insert, Update, Select and Delete records in a Table
a)
Data Manipulation Language (DML)
b)
Data Control Language (DCL)
c)
Data Definition Language (DDL)
d)
None of the Option
65.
Risk Mitigation primarily focuses on
a)
Designing and Implementing Controls to prevent incidents due to risk materialisation
b)
Detect when incident happens/likely to happen
c)
Define process to recover from incidence
d)
All of the above
66.
Which of the following represents the GREATEST risk created by a reciprocal agreement for disaster recovery made between two companies?
a)
Developments may result in hardware and software incompatibility.
b)
Resources may not be available when needed
c)
The recovery plan cannot be tested.
d)
The security infrastructures in each company may be different
67.
Under DREAD Modelling, category Exploitability refers to
a)
How many assets can be affected?
b)
How easily the vulnerability can be found?
c)
How easily the attack can be launched?
d)
None of the above
68.
Who is responsible for the overall direction, costs, and timetables for systems-development projects
a)
The project sponsor
b)
The project steering committee
c)
Senior management
d)
The project team leader
69.
Major function of SIEM is : i.) security information management ii) Security Log collection iii) Security event management iv) Support the development of content
a)
i&ii
b)
i&iii
c)
ii&iii
d)
i&iv
70.
Clustering is which type of control
a)
Preventive control
b)
Detective Control
c)
Reactive Control
d)
None of the above
71.
First step in Control Assessment is to
a)
Prioritize the controls to be tested
b)
Review the risk register
c)
Measuring the effectiveness of controls
d)
Ensure that associated risk is responded appropriately
72.
Following are the types of risk responses, except
a)
Mitigate
b)
Transfer
c)
Accept
d)
Control
73.
Which version of ITIL framework is used to implement Information System Service Management
a)
Version 3
b)
Version 4
c)
Version 5
d)
Version 2
74.
IS Audit can be carried out by external auditors as a part of statutory audit to review internal controls in automated information system
a)
true
b)
False,as it is carried out by Internal Audit team
75.
Strategies for recovery of LANs are
a)
Eliminating Single Points of Failure (SPOC)
b)
Redundant Cabling and Devices
c)
Remote Access
d)
All of the above
76.
What does study of history, structure and culture of information involve?
a)
Identifying stakeholder expectations
b)
Types of useful systems, issues that have not been addressed and require attention
c)
Identifying how the system needs to interact with its environment
d)
Study of business processes, underlying activities, and actors that perform these activities
77.
Data warehouse is also known as
a)
Transactional db or management information system
b)
Decision support db or Executive information System
c)
both of them
d)
None of them
78.
Key role/s that an auditor can perform is/are
a)
To give assurance on risk management process
b)
To give assurance that the risks are being evaluated correctly
c)
Evaluate Risk Management process
d)
Review the management of key risks
e)
All of the above
79.
With the changes business environment it is necessary for organiation to make changes to ------- continue its operation
a)
Management
b)
existing infrastructure
c)
IT staff
d)
All of them
80.
Which of the following shall BEST help in deciding upon the protection level for information asset?
a)
Location of asset
b)
Impact of risk
c)
Vulnerabilities in asset
d)
Inventory of threats
81.
After a Tsunami, a business decides to shift the location of data centre from coastal area to mid land. Which type of risk response option it has exercised?
a)
Accept
b)
Avoid
c)
Mitigate
d)
Transfer
82.
Under STRIDE Model of Threat modelling, the threats "Spoofing" and "Elevation of Priviledges" are violation which of the desirable property for a system
a)
Non-repudiation & Confidentiality
b)
Authenticity & Authorization
c)
Authenticity & Confidentiality
d)
Availability & Authorization
83.
Which control can be most appropriately used to prevent Denial of Service (DoS) Attack
a)
Use of Patch updates
b)
Debugging functions
c)
Web Application Firewall Software
d)
Anti-malware software
84.
The quantum of risk after enterprise has implemented controls based on risk<br />mitigation plan is
a)
Accepted risk
b)
Residual risk
c)
Inherent risk
d)
Current risk
85.
The ______ is provided to cyber security team of the organisation as a feedback
a)
Security Picture
b)
Secutiy Logs
c)
Security Report
d)
Security Posture
86.
Database normalization is
a)
Data redundancy optimization
b)
Data logging and accountability
c)
Streamlining data process
d)
Deleting temp files
87.
Which of the following is a mitigation plan for risk associated with compromising on quality and testing?
a)
Understand organisation baseline for infrastructure and incorporate in design
b)
Ensure standard coding practices are adopted
c)
Ensure completion of documentation along with design and development
d)
Ensure documentation experts and technical writers are part of team
88.
This questions refers to the following information. An IS auditor conducting a review of disaster recovery planning at a financial processing organization has discovered the following: The existing disaster recovery plan was compiled two years earlier by a systems <br />analyst in the organization's IT department using transaction flow projections <br />from the operations department.<br /> The plan was presented to the deputy CEO for approval and formal issue, but it <br />is still awaiting his/her attention.<br /> The plan has never been updated, tested or circulated to key management and <br />staff, though interviews show that each would know what action to take for its <br />area in the event of a disruptive incident.<br />The IS auditor's report should recommend that:
a)
the deputy CEO be censured for his/her failure to approve the plan
b)
a board of senior managers is set up to review the existing plan
c)
the existing plan is approved and circulated to all key management and staff
d)
a manager coordinates the creation of a new or revised plan within a defined time limit
89.
Half way through a project development, on which phase should an IS auditor focus in order to ensure that there is no deviation from the primary objectives of the projects?<br />
a)
Project Planning
b)
Project Controlling
c)
Resource Management
d)
Risk Management
90.
What is not a property of database transactions
a)
Consistency
b)
Atomicity
c)
Insulation
d)
Durability
91.
What does P2P technology stand for
a)
Password to Password
b)
Peer to Peer
c)
Product to Product
d)
Private Key to Public Key
92.
Auditing around the computer is also called
a)
White box approach
b)
Black box approach
c)
Yellow Box approach
d)
Red Box approach
93.
Organizations capacity to sustain loss due to uncertainty and expressed in<br />monetary terms is best known as:
a)
Risk appetite
b)
Risk tolerance
c)
Risk acceptance
d)
Risk mitigation
94.
IT Security policy is:
a)
Preventive control
b)
Detective control
c)
corrective control
d)
compensating control
95.
Main use of maintaining and updating risk register is to
a)
Define controls
b)
Identify risk owner
c)
Built risk profile
d)
Maintain evidence
96.
Which of the following considers overall business objectives,Business process and their dependencies throughout the enterprise
a)
IT Risk
b)
Risk Management
c)
Risk Universe
d)
Audit Universe
97.
The responsibility, authority and accountability of the information systems audit functions is appropriately documented in an audit charter and MUST be:
a)
approved by the highest level of management.
b)
approved by audit department management.
c)
approved by user department management
d)
changed every year before commencement of IS audits
98.
During risk management process, how is risk assessed and evaluated?
a)
Creating an inventory of possible risk
b)
Quantify the likelihood and impact of risk
c)
Create a risk management plan
d)
Discover risk that materializes
99.
Which of the following is concerned for compliance with information security policy
a)
Decrease in low risk findings in audit report
b)
high number of approved and open policy exceptions
c)
Security policy is reviewed once in two years
d)
Security policy is signed by chief information officer
100.
which of the following is primary function of information security policies
a)
Communicate intend of management to stake holders
b)
perform risk assessment of IT operations and assets
c)
Ensure compliance with requirements of standards
101.
Self-service assistance to users provided by<br />help-desk such as resetting passwords etc. is<br />considered which level of assistance?
a)
Level 4
b)
Level 0
c)
Lever 2
d)
Level 1
102.
.............. refers to managing the application software and other computer software to improve it for Functionality, Security and Usability
a)
Configuration Management
b)
Version Management
c)
Patch Management
d)
Change Management
103.
Which of the following methods of results analysis, during the testing of the business continuity plan (BCP), provides the BEST assurance that the plan is workable?
a)
Quantitatively measuring the results of the test
b)
Measurement of accuracy
c)
Elapsed time for completion of prescribed tasks
d)
Evaluation of the observed test results
104.
Which is key role of an auditor to perform
a)
Give assurance on risk management process
b)
evaluate risk management process
c)
Review of management of key risk
d)
A and B both
e)
All of the above
105.
Change management processes should proactively review the possible risks and ensure that they are part of risk register
a)
true
b)
false
c)
Depends
106.
WHICH OF THE FOLLOWING VULNERABILITIES IN (OWASP)?
a)
IRREVERSIBILITY OF RECORDS
b)
WEAK CREDENTIALS
c)
SUSCEPTIBILITY TO BEING HACKED
d)
TECHNICAL ISSUES
107.
----- strategy of data back up works in conjunction with periodic dump.
a)
Dual recording of data
b)
Logging input transactions
c)
Logging changes to the data
d)
None of the above
108.
Static electricity comes under which threat
a)
Natural Threats
b)
Man Made threats
c)
Both A and B
109.
Pandamic due to carona comes under
a)
Man Made threat
b)
Natural Threat
c)
Both A and B
110.
Which of the following is not key principle of Governance and Management of Entrerprise information and Technology in COBIT
a)
Provide Stakeholder Value
b)
Hoslistic Approach
c)
Dynamic Governance System
d)
Open and Flexible
111.
Choose Man Made threats
a)
Equipment Failure,Food Particles,Residues,Pandemic due to virus
b)
Black out,Filure of AC,Gas Leak,Static Electricity
c)
EMI,Radiation,Equipment Failure
d)
All the above
112.
Data Cables must be enclosed in
a)
Metal conduit
b)
Race ways
c)
A or B
d)
A and B
113.
IPF ,ideally should be located in which floor
a)
Ground floor
b)
Top Floor
c)
In between floors
d)
A or B or C
114.
Which of the following is not a type of entity in DBMS
a)
Name
b)
Place
c)
People
d)
Object
e)
Concept
115.
Sag Means
a)
Prolonged low voltage
b)
Momentary High Voltage
c)
Prolonged high voltage
d)
None of the above
116.
Which of the following should an IS auditor review to gain an understanding of the effectiveness of controls over the management of multiple projects
a)
Project database
b)
Policy documents
c)
Project portfolio database
d)
Program organization
117.
Within an Incident Response Management program, the Containment phase aims to
a)
Block the event
b)
Reduce the impact
c)
Remove the event
d)
Rise the event
118.
The level at which the previously described established process operates within defined limits to achieve its process outcomes
a)
Level 5
b)
Level 3
c)
Level 2
d)
Level 4
119.
……in power system refers to presence of electrical radiation in the system
a)
Sag
b)
Spike
c)
Brown out
d)
Noise
120.
-----site is a fully equipped computer facility with electrical <br />power, heating, ventilation and air conditioning (HVAC) available for use in the event of a <br />subscriber’s computer outage.
a)
Warm
b)
Hot
c)
Cold
d)
Near
121.
Smoke detectors acts as
a)
Prevetive comtrols
b)
Corrective control
c)
Detective control
d)
Both B and C
122.
A project manager of a project that is scheduled to take 18 months to complete announces that the project is in a healthy financial position because, after 6 months, only one-sixth of the budget has been spent. The IS auditor should FIRST determine:
a)
what amount of progress against schedule has been achieved.
b)
if the project budget can be reduced
c)
if the project could be brought in ahead of schedule
d)
if the budget savings can be applied to increase the project scope
123.
If fire is caused by CLASS-C combustibles which type of extinguishing system or agent is used
a)
Soda Acid or FM 200
b)
Dry Powder or Co
c)
Dry Powder or FM 200
d)
FM 200 or CO
124.
A use case provide ___________ to interface a device
a)
Standard Procedure
b)
General Procedure
c)
Prescibed/Laid down Procedure
d)
All of the above
125.
-----------works by storing data to local disk so that the backup can be <br />captured at high speed, and then either the backup software or a D2D2C (Disk to Disk to <br />Cloud) appliance encrypts and transmits data to a service provider
a)
Hybrid Online Backup
b)
Underground vaults
c)
Insulated chambers sharing facilities
d)
Free-standing dedicated vaults
126.
Which of the should not be used in manned computer facilities
a)
Soda Acid
b)
FM 200,CO
c)
Dry Powder
d)
All the above
127.
Which of the following is first action when a fire detection system raises the alarm?
a)
Turn off the air conditioner
b)
Determine type of fire
c)
Evacuate the facility
d)
Turn off power supply
128.
Which of the following is not an example for AI Platform?
a)
Watson
b)
Tensor Flow
c)
AWS AI
d)
Microsoft Power BI
129.
Which of the following are most important controls for unmanned data center?
a)
Access control for entry and exit for all doors
b)
The humidity levels need not be maintained
c)
The temperature must be at sub-zero level
d)
Halon gas-based fire suppression system
130.
Strong artificial intelligence is
a)
The embodiment of human intellectual capabilities within a computer
b)
A set of computer programs that produce output that would be considered to reflect intelligence if it were generated by humans
c)
The study of mental faculties through the use of mental models implemented on a computer
d)
The study of mental faculties through the use of mental models implemented on a computer
131.
Cognitive analytics provide
a)
foresight by identifying pattern
b)
assist in understanding the future
c)
proactive action and recognize patterns
d)
insight based on past information
132.
In achieving the objectives of requirement analysis, the process of understanding the present system and its related problems comes under which of the following steps?
a)
Fact finding
b)
Analysis
c)
Requirements of proposed systems
d)
Identifying rationale and objectives
133.
Which is the correct order of Phases of Disaster?
a)
Crisis phase,Emergency response phase,Recovery phase,Restoration phase
b)
Crisis phase,Emergency response phase,Restoration phase ,Recovery phase
c)
Crisis phase,Recovery phase,Emergency response phase,Restoration phase
d)
Emergency phase,Crisis phase,Recovery phase,Restoration phase
134.
Which of the following is a key feature of Rapid Application Development?
a)
fast development and delivery of a high quality system at a relatively low investment cost,
b)
Use of small, time-boxed subprojects or iterations where each iteration forms basis for planning next iteration
c)
Customer satisfaction by rapid delivery of useful software;
135.
Primary purpose of access controlled dead man door, turnstile, mantrap is to
a)
Prevent unauthorized entry
b)
Detect perpetrators
c)
Meet compliance requirement
d)
Reduce cost of guard
136.
An organization having a number of offices across a wide geographical area has developed a disaster recovery plan (DRP). Using actual resources, which of the following is the MOST cost-effective test of the DRP?
a)
Full operational test
b)
Preparedness test
c)
Paper test
d)
Regression test
137.
--------------------- is the property that enables a system (often computer-based) to continue operating properly in the event of the failure of (or one or more faults within) some of its components.
a)
Fault Tolerance
b)
RAID
c)
Both of the above
d)
None of the above
138.
Which software category of maintenance is a proactive approach?
a)
Corrective
b)
Adaptive
c)
Preventive
d)
All of the above
139.
What is to be included in Quality Assurance Testing except the one
a)
Unit testing
b)
Interface testing
c)
Integrating testing
d)
User acceptance testing
140.
which statement is correct about sotware reengineering
a)
it emphasis on putting in the efforts to make it easier to maintain
b)
applicable when all of the subsystems of a larger system require frequent maintenance
c)
Both a and b
d)
None of above
141.
Which of the following helps in keep track of new release
a)
Change management
b)
Version Control
c)
Configuration management
d)
All of them
142.
Out of the tests performed on a program unit, what does a performance test check?
a)
whether programs do, what they are supposed to do or not
b)
verify the expected performance criteria of program
c)
determines the stability of a given system or entity
d)
examines the internal processing logic of a software system
143.
Although BCP and DRP are often implemented and tested by middle management and end users, the ultimate responsibility and accountability for the plans remain with executive management, such as the _______________. (fill-in-the-blank)
a)
Security administrator
b)
Systems auditor
c)
Board of directors
d)
Financial auditor
144.
Which of the following is the main reason for appointing human guards at main entrance of facilities?
a)
Address visitors’ requirements to visit
b)
Issue the access cards to visitors
c)
Cost of automation exceeds security budget
d)
Deter the unauthorized persons
145.
Which of the followng ia not a part of SIEM tools
a)
Sensor
b)
Agents
c)
Collector
d)
Log
146.
The MOST significant level of BCP program development effort is generally required during the:
a)
Early stages of planning.
b)
Evaluation stage.
c)
Maintenance stage.
d)
Testing Stage.
147.
What is a reliable technique for estimating the scope and cost of a software-development project
a)
Function point analysis (FPA
b)
Feature point analysis (FPA)
c)
GANTT
d)
PERT
148.
Which of the following is a major concern associated with biometric physical access control?
a)
High acceptability
b)
High false positives
c)
High false negatives
d)
High cost
149.
…....... is not a type of DBMS
a)
Relational
b)
Object Oriented
c)
Hierarchial
d)
Network
e)
None of the Option
150.
The two most common types of physical perimeter detectors are based on
a)
Photoelectric Sensors
b)
Dry Contact Switches
c)
Both of the above
d)
None of the above
151.
Organisational Control techniques includes documentation of
a)
Defining responsibility and objectives
b)
Defining IT Infra requirment
c)
Defining IT policy
d)
None of the above
152.
User Account information have information in
a)
Clear Text
b)
Hashed
c)
Both of above
d)
None of them
153.
Types of alternate processing sites are
a)
Mirror Site
b)
Near site
c)
Warm Site
d)
All of the above
154.
Why should service desk staff detect recurring issues?
a)
To help identify problems
b)
To escalate incidents to the correct support team
c)
?To ensure effective handling of service requests
d)
To engage the correct change authority
155.
In CMMI,In which level implemented process acheives its process purpose
a)
Established
b)
Optimized
c)
Performed
d)
Managed
Reset
