wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Long Quiz Lap 8 and 9 - 3B

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

What is the primary goal of risk management in a project?

a)

To eliminate all risks

b)

To identify and migrate risks

c)

To avoid all negative events

d)

To ensure project success without risks

2.

Why is risk management important in project management?

a)

It increases the probability of negative events

b)

It affects only the scope of the project

c)

It enhances project scheduling

d)

It affects all aspects of the project

3.

What is included in the risk management process?

a)

Risk Response Planning

b)

Only Risk Identification

c)

Resource Allocation

d)

Cost Estimation

4.

How can risks be effectively communicated in a project?

a)

By ignoring them

b)

By discussing them with stakeholders

c)

By only documenting them

d)

By reporting them after project completion

5.

Which analysis is used to assess the impact and likelihood of identified risks?

a)

SWOT Analysis

b)

Qualitative Risk Analysis

c)

Resource Allocation Analysis

d)

Cost-Benefit Analysis

6.

What does a Probability and Impact Matrix help with?

a)

Identifying stakeholders

b)

Risk urgency assessment

c)

Estimating project costs

d)

Scheduling tasks

7.

What technique is used in Quantitative Risk Analysis?

a)

SWOT Analysis

b)

Decision Tree Analysis

c)

Checklist Analysis

d)

Stakeholder Mapping

8.

Which of the following is a method for planning risk response to negative risks?

a)

Exploit

b)

Enhance

c)

Mitigate

d)

Share

9.

What is a contingency plan in risk management?

a)

A plan to ignore risks

b)

A plan for regular audits

c)

A plan if the risk occurs

d)

A financial backup plan

10.

What is the purpose of a risk audit?

a)

To eliminate risks

b)

To examine the effectiveness of planned risk responses

c)

To increase project costs

d)

To delay project timelines

11.

How does monitoring and controlling risks benefit a project?

a)

It prevents all risks

b)

It ensures no changes in the project

c)

It promotes continuous improvement

d)

It focuses only on internal audits

12.

Which of the following is NOT a benefit of effective risk management?

a)

Enhancing communication

b)

Increased project costs

c)

Reassuring stakeholders

d)

Strategic business planning

13.

What is the role of Primavera in risk management?

a)

Keep track of issues

b)

Only manage resources

c)

Avoid all risks

d)

Increase project costs

14.

What is the significance of stakeholder involvement in risk management planning?

a)

To provide financial support

b)

To ensure all risks are ignored

c)

To make risk management appropriate to project size and complexity

d)

To delay project completion

15.

Which method helps in identifying risks early in a project?

a)

SWOT Analysis

b)

Only qualitative analysis

c)

Budget estimation

d)

Resource assignment

16.

What is the first step in the risk management process?

a)

Plan Risk Response

b)

Identify Risk

c)

Monitor and Control Risk

d)

Schedule Risk

17.

What does qualitative risk analysis focus on?

a)

Data gathering

b)

Assessing risk impact and likelihood

c)

Financial analysis

d)

Stakeholder communication

18.

What is the purpose of a fallback plan in risk management?

a)

To avoid risks

b)

To use if contingency plans fail

c)

To increase project scope

d)

To eliminate all threats

19.

What is the benefit of risk categorization?

a)

To increase project costs

b)

To improve communication

c)

To focus on high-priority risks

d)

To delay decision-making

20.

How does risk reassessment benefit a project?

a)

It identifies new risks regularly

b)

It avoids all risks

c)

It ensures project delays

d)

It reduces stakeholder involvement

21.

What is the primary characteristic of a quality security program?

a)

Begins and ends with technical solutions

b)

Focuses on user training

c)

Begins and ends with policy

d)

Relies on advanced encryption

22.

What is the least expensive control to execute in information security?

a)

Firewalls

b)

Information security policies

c)

Antivirus software

d)

Intrusion detection systems

23.

What should information security policies never contradict?

a)

Company guidelines

b)

Employee preferences

c)

Laws

d)

Technical standards

24.

What is the most difficult aspect of implementing information security policies?

a)

Writing the policies

b)

Updating the policies

c)

Properly implementing the policies

d)

Monitoring compliance

25.

What is the role of policies within an organization?

a)

To dictate hardware specifications

b)

To convey instructions and dictate behavior

c)

To define software requirements

d)

To manage financial resources

26.

What is the primary purpose of a strategic plan in an organization?

a)

To define daily operations

b)

To move the organization toward its mission

c)

To handle customer relations

d)

To manage employee benefits

27.

What type of document is an Enterprise Information Security Policy (EISP)?

a)

Technical manual

b)

Executive level document

c)

Marketing brochure

d)

Training guide

28.

Which statement is true about Issue-Specific Security Policies (ISSP)?

a)

They never require updates

b)

They address specific areas of technology

c)

They are the same length as EISPs

d)

They are only for external use

29.

Which of the following is a component of Incident Response Planning?

a)

Financial planning

b)

Sales forecasting

c)

Incident detection

d)

Product development

30.

What is a probable indicator of an incident in information security?

a)

Presence of new accounts

b)

Normal system operation

c)

Standard log entries

d)

Routine network traffic

31.

Which of the following is considered a definite indicator of an incident?

a)

Unusual system slowdown

b)

Use of dormant accounts

c)

High network activity

d)

Increase in user queries

32.

What should a security policy support in an organization?

a)

Employee preferences

b)

The organization's mission, vision, and strategic plan

c)

External vendor requirements

d)

Government subsidies

33.

What does the term "de facto standards" refer to in information security?

a)

Informal standards

b)

Legal regulations

c)

Mandatory guidelines

d)

Technical instructions

34.

What is an example of an activity involved in incident response?

a)

Financial auditing

b)

Incident planning

c)

Marketing research

d)

Product design

35.

What is an essential characteristic of a security incident?

a)

It must be financially damaging

b)

It affects information confidentiality, integrity, or availability

c)

It involves physical damage

d)

It always involves external hackers

36.

Which of the following is a type of security policy?

a)

Financial policy

b)

System-specific policy

c)

Marketing policy

d)

Staffing policy

37.

What is a primary characteristic of standards in information security?

a)

They are optional

b)

They are not related to policies

c)

They detail what must be done to comply with policies

d)

They are used only in emergencies

38.

What does a modular plan in ISSP provide?

a)

Simplicity in procedures

b)

Balance and maintain specific issue requirements

c)

A single viewpoint

d)

A broad, general approach

39.

What is the focus of systems management in an ISSP?

a)

Developing new software

b)

Regulating the use of email and electronic documents

c)

Designing hardware

d)

Marketing strategies

40.

What dictates acceptable and unacceptable behavior within an organization?

a)

Personal preferences

b)

Information security policies

c)

External consultants

d)

Competitive analysis