Security courses attract students who like the technical half and tolerate the managerial half, and the assessment is usually built the other way around. Information Security and IT Risk Management, 1st Edition by Manish Agrawal treats security as a risk problem before it treats it as a technology problem, so a question may hand you an asset value, an exposure factor and an incident frequency and ask whether a proposed control is worth buying. Reading about firewalls does not prepare anyone for that.
Why this test bank helps
Risk questions fail quietly: the arithmetic is short enough that a wrong assumption still produces a tidy number. The rationale under each item here shows the calculation line by line and names the concept it rests on — why an annualized figure is not a single-incident figure, why a control is justified only against the loss it actually removes, why a recovery objective is a business decision rather than a technical one. Following that working is how the ideas become usable.
What’s inside
- Questions covering the text chapter by chapter, from security fundamentals through to incident response and compliance.
- Multiple choice, true/false and short calculation items matching the mix this course sets.
- A rationale under every question, including the full working for the quantitative risk items.
- Emphasis on the managerial chapters — risk assessment, policy and continuity — that technically minded students skim.
- One organized PDF, delivered instantly at checkout.
Topics covered
- Security fundamentals — confidentiality, integrity and availability, and the vocabulary of threats and vulnerabilities.
- Asset identification and classification — valuing information assets and setting handling requirements.
- Quantitative risk assessment — exposure factor, single loss expectancy, annualized rate of occurrence and annualized loss.
- Control selection and cost justification — preventive, detective and corrective controls and defense in depth.
- Identity and access management — authentication factors, authorization models and least privilege.
- Incident response — preparation, detection, containment, eradication, recovery and lessons learned.
- Business continuity and disaster recovery — impact analysis, recovery time and recovery point objectives.
- Policy, compliance and audit — security policy structure, regulatory drivers and the role of the audit function.
- People and awareness — social engineering, training programs and the human element in security failures.
Who it’s for
Undergraduate information systems, computing and business students taking a first course in information security or IT risk management from this text, and IT staff studying the managerial side of security formally for the first time.
How to use it (the right way)
Read the chapter, then attempt a block closed-book and write out each risk calculation on paper before you look at the options; the distractors are built from the specific errors that arise when you do it in your head. Read every rationale, including on correct answers. This is a study aid, to be used in line with your institution’s academic-integrity policy — for revision and self-assessment, never as a shortcut around the coursework or in a graded assessment.
Sample question (shows the format — your download contains the full set)
Q. A firm values a customer database at $500,000. Analysts estimate that a ransomware incident would destroy 20 percent of that value, and that such an incident occurs about once every four years. What is the annualized loss expectancy?
- A. $100,000
- B. $25,000
- C. $125,000
- D. $20,000
Answer: B. The single loss expectancy is asset value multiplied by the exposure factor, or $500,000 times 0.20, which is $100,000. The annualized rate of occurrence is one incident in four years, or 0.25. Multiplying the two gives an annualized loss expectancy of $25,000, which is also the ceiling on what a control that fully removes this risk can be worth each year. A stops at the single loss expectancy and never annualizes it. C adds the two figures instead of multiplying. D applies the exposure factor to the frequency rather than to the asset value.
Edition & format
- Matches: Information Security and IT Risk Management, 1st Edition, by Manish Agrawal (ISBN 9781118335895).
- Format: Digital PDF, delivered instantly after checkout.
- Access: Lifetime — re-download from your account whenever you need it.
Chapter order and the worked examples change between printings and editions of this title. Please confirm the edition and ISBN above match the book your course assigned before you buy.
Frequently asked questions
Which edition does this cover? The first edition, ISBN 9781118335895. If your syllabus names a different edition, choose that listing instead, because the chapter sequence differs.
How do I receive it? As an immediate download once checkout completes; the file also remains in your account for repeat access.
Do all the questions include rationales? Yes. Calculation items show the full working, and conceptual items explain why each incorrect option fails.
Is using a test bank allowed? Used as practice it is an ordinary study resource. Follow your institution’s academic-integrity policy and keep it out of graded assessments.
You will find related subjects in Management Test Banks.








Reviews
There are no reviews yet.