WorksheetsLong Quiz Lap 8 and 9 - 3B
Total questions: 40
Worksheet time: 20mins
What is the primary goal of risk management in a project?
To eliminate all risks
To identify and migrate risks
To avoid all negative events
To ensure project success without risks
Why is risk management important in project management?
It increases the probability of negative events
It affects only the scope of the project
It enhances project scheduling
It affects all aspects of the project
What is included in the risk management process?
Risk Response Planning
Only Risk Identification
Resource Allocation
Cost Estimation
How can risks be effectively communicated in a project?
By ignoring them
By discussing them with stakeholders
By only documenting them
By reporting them after project completion
Which analysis is used to assess the impact and likelihood of identified risks?
SWOT Analysis
Qualitative Risk Analysis
Resource Allocation Analysis
Cost-Benefit Analysis
What does a Probability and Impact Matrix help with?
Identifying stakeholders
Risk urgency assessment
Estimating project costs
Scheduling tasks
What technique is used in Quantitative Risk Analysis?
SWOT Analysis
Decision Tree Analysis
Checklist Analysis
Stakeholder Mapping
Which of the following is a method for planning risk response to negative risks?
Exploit
Enhance
Mitigate
Share
What is a contingency plan in risk management?
A plan to ignore risks
A plan for regular audits
A plan if the risk occurs
A financial backup plan
What is the purpose of a risk audit?
To eliminate risks
To examine the effectiveness of planned risk responses
To increase project costs
To delay project timelines
How does monitoring and controlling risks benefit a project?
It prevents all risks
It ensures no changes in the project
It promotes continuous improvement
It focuses only on internal audits
Which of the following is NOT a benefit of effective risk management?
Enhancing communication
Increased project costs
Reassuring stakeholders
Strategic business planning
What is the role of Primavera in risk management?
Keep track of issues
Only manage resources
Avoid all risks
Increase project costs
What is the significance of stakeholder involvement in risk management planning?
To provide financial support
To ensure all risks are ignored
To make risk management appropriate to project size and complexity
To delay project completion
Which method helps in identifying risks early in a project?
SWOT Analysis
Only qualitative analysis
Budget estimation
Resource assignment
What is the first step in the risk management process?
Plan Risk Response
Identify Risk
Monitor and Control Risk
Schedule Risk
What does qualitative risk analysis focus on?
Data gathering
Assessing risk impact and likelihood
Financial analysis
Stakeholder communication
What is the purpose of a fallback plan in risk management?
To avoid risks
To use if contingency plans fail
To increase project scope
To eliminate all threats
What is the benefit of risk categorization?
To increase project costs
To improve communication
To focus on high-priority risks
To delay decision-making
How does risk reassessment benefit a project?
It identifies new risks regularly
It avoids all risks
It ensures project delays
It reduces stakeholder involvement
What is the primary characteristic of a quality security program?
Begins and ends with technical solutions
Focuses on user training
Begins and ends with policy
Relies on advanced encryption
What is the least expensive control to execute in information security?
Firewalls
Information security policies
Antivirus software
Intrusion detection systems
What should information security policies never contradict?
Company guidelines
Employee preferences
Laws
Technical standards
What is the most difficult aspect of implementing information security policies?
Writing the policies
Updating the policies
Properly implementing the policies
Monitoring compliance
What is the role of policies within an organization?
To dictate hardware specifications
To convey instructions and dictate behavior
To define software requirements
To manage financial resources
What is the primary purpose of a strategic plan in an organization?
To define daily operations
To move the organization toward its mission
To handle customer relations
To manage employee benefits
What type of document is an Enterprise Information Security Policy (EISP)?
Technical manual
Executive level document
Marketing brochure
Training guide
Which statement is true about Issue-Specific Security Policies (ISSP)?
They never require updates
They address specific areas of technology
They are the same length as EISPs
They are only for external use
Which of the following is a component of Incident Response Planning?
Financial planning
Sales forecasting
Incident detection
Product development
What is a probable indicator of an incident in information security?
Presence of new accounts
Normal system operation
Standard log entries
Routine network traffic
Which of the following is considered a definite indicator of an incident?
Unusual system slowdown
Use of dormant accounts
High network activity
Increase in user queries
What should a security policy support in an organization?
Employee preferences
The organization's mission, vision, and strategic plan
External vendor requirements
Government subsidies
What does the term "de facto standards" refer to in information security?
Informal standards
Legal regulations
Mandatory guidelines
Technical instructions
What is an example of an activity involved in incident response?
Financial auditing
Incident planning
Marketing research
Product design
What is an essential characteristic of a security incident?
It must be financially damaging
It affects information confidentiality, integrity, or availability
It involves physical damage
It always involves external hackers
Which of the following is a type of security policy?
Financial policy
System-specific policy
Marketing policy
Staffing policy
What is a primary characteristic of standards in information security?
They are optional
They are not related to policies
They detail what must be done to comply with policies
They are used only in emergencies
What does a modular plan in ISSP provide?
Simplicity in procedures
Balance and maintain specific issue requirements
A single viewpoint
A broad, general approach
What is the focus of systems management in an ISSP?
Developing new software
Regulating the use of email and electronic documents
Designing hardware
Marketing strategies
What dictates acceptable and unacceptable behavior within an organization?
Personal preferences
Information security policies
External consultants
Competitive analysis
