IS3110 CHAP 4 Flashcards

1
Q

What are valid contents of a risk management plan?

  1. Objectives
  2. Scopes
  3. Recommendations
  4. POAM
  5. All the above
A
ALL
 Objectives
 Scopes
 Recommendations
 POAM
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What should be included in the objectives of a risk management plan?

  1. A list of threats
  2. A list of vulnerabilities
  3. Costs associated with risks
  4. Cost-benefit analysis
  5. All the above
A
ALL
 A list of threats
 A list of vulnerabilities
 Costs associated with risks
 Cost-benefit analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What will the scope of a risk management plan define?

  1. Objectives
  2. POAM
  3. Recommendations
  4. Boundaries
A

Boundaries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What problem can occur if the scope of a risk management plan is not defined?

  1. Excess boundaries
  2. Stakeholder loss
  3. Scope creep
  4. SSCP
A

Scope creep

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a stakeholder?

  1. A mark that identifies critical steps
  2. An individual or group that has an interest in the project
  3. A critical process or procedure
  4. Another name for the risk management plan project manager
A

An individual or group that has an interest in the project

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A key stake holder should have authority to make decisions about a project. This includes authority to provide additional resources.
TRUE OR FALSE

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A risk management plan project manager oversees the entire plan. what is the project manager responsible for? (Select two)

  1. Ensuring costs are controlled
  2. Ensuring the project stays on schedule
  3. Ensuring stakeholders have adequate funds
  4. Ensuring recommendations are adopted
A

Ensuring costs are controlled

Ensuring the project stays on schedule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A risk management plan includes steps to mitigate risks. Who is responsible for choosing what steps to implement?

  1. The project manager
  2. Management
  3. Risk management team
  4. The POAM manager
A

Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A risk management plan includes a list of findings in a report. The findings identify threats and vulnerabilities. What type of diagram can document some of the findings?

  1. Gantt chart
  2. Critical path chart
  3. POAM diagram
  4. Cause and effect diagram
A

POAM diagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What elements should be included in the findings of the risk management report?

  1. Causes, criteria, and effects
  2. Threats, causes, and effects
  3. Criteria, vulnerabilities, and effects
  4. Causes, criteria, and milestones
A

Causes, criteria, and effects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a primary tool used to identify the financial significance of a mitigation tool?

  1. Ishikawa diagram
  2. Fishbone diagram
  3. CBA
  4. POAM
A

CBA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A fishbone diagram can link causes with effects.

TRUE OR FALSE

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

You present management with recommendations from a risk management plan. What can management choose to do?

  1. Accept or reject the recommendations
  2. Adjust, defer, or modify the recommendations
  3. Accept, defer, or modify the recommendations
  4. Allow or deny the recommendations
A

Accept, defer, or modify the recommendations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a POAM?

  1. Project objectives and milestones
  2. Planned objectives and milestones
  3. Project of action milestone
  4. Plan of action and milestones
A

Plan of action and milestones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A POAM is used to track the progress of a project. What type of chart is commonly used to assist with tracking?

  1. Fishbone chart
  2. Cause and effect chart
  3. GANTT chart
  4. POAM chart
A

GANTT chart

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A method used to create lists of threats, vulnerabilities, or respond plans. It starts with a large topic such as a problem statement. It then narrows the problem to individual sources.

A

Affinity diagram

17
Q

A creative method used to generate a large number of ideas on a topic. Participants are encouraged to mention any idea that comes to mind. Ideas are recorded without judgements.

A

Brainstorming

18
Q

AKA ISHIKAWA diagram or FISHBONE diagram. It is used to show the relationships between causes and problems.

A

Cause and effect diagram

19
Q

A chart of critical tasks in a project. If any task in the critical path is delayed, the entire project will be delayed.

A

Critical path chart

20
Q

Filters traffic; rules are configured to define what traffic is allowed and what traffic is blocked. A network system is a combination of hardware and software. Individual systems can include a single software-based filter.

A

Firewall

21
Q

A self-contained solution. It includes hardware and software to provide security protection for a network.

A

Firewall appliance

22
Q

A document that identifies what traffic to allow or block. A firewall policy is often used to implement rules.

A

Firewall policy

23
Q

A bar chart used to show a project schedule. This is commonly used in project management and can be used in risk management plans.

A

Gantt chart

24
Q

A scheduled event for a project. It indicates the completion of a major task or group or tasks. They are used to track the progress of a project.

A

Milestone

25
Q

A graphical representation of major milestones. It shows the time relationship of milestones to each other. It also show dependencies, if any.

A

Milestone Plan Chart

26
Q

A document used to track activities in a risk management plan. A POAM assigns responsibility for specific tasks. It also makes it easier for management to follow-up on the tasks.

A

Plan of action and milestones (POAM)

27
Q

A statement used to summarize a risk. They often use an “if/then” format. The “if” part of the statement identifies the elements of the risk. The “then portion of the statement identifies the result.

A

Risk statement

28
Q

The boundaries of a risk management plan. It defines what the plan should cover. Defining the scope helps prevent scope creep.

A

Scope

29
Q

A problem with projects resulting from uncontrolled changes. It should be avoided and can result in cost overruns and missed deadlines.

A

Scope creep

30
Q

An individual or group that has a stake, or interest, in the success of a project. They have some authority over the project. Additionally, they can provide resources for the project.

A

Stakeholder