Quick review

CLEP Information Systems Quick Review

High-impact topic boxes for a focused review session before you take the practice test.

1. Productivity Software Suites

The big idea

Productivity software (word processors, spreadsheets, presentation programs, and desktop databases) automates the core information-creation tasks of an office, and most vendors bundle them into a single suite.

Must know

Word processing = formatting/editing text documents (styles, mail merge, track changes). Spreadsheets = grid-based calculation with formulas, functions, and what-if analysis (e.g., Excel). Presentation software = slide-based visual communication. Desktop database software (e.g., Access) = storing and querying structured records. A ``suite'' (e.g., Microsoft 365, Google Workspace) bundles these with shared file formats and cloud sync.

Don't confuse

A spreadsheet (calculation-oriented, one flat grid of cells) vs. a database (relationship-oriented, multiple linked tables with enforced data types) --- spreadsheets are for computation, databases are for structured, related record-keeping.

Exam trap

A scenario describing linked customer, order, and product tables with enforced relationships is testing database software, not a spreadsheet, even though a spreadsheet could technically hold the same numbers.

5-second recall

Word = text; Spreadsheet = numbers/formulas; Database = related records; Suite = all bundled together.

2. Office Systems and Collaboration Tools

The big idea

Office systems extend individual productivity software into shared, organization-wide communication and document workflows.

Must know

Email = asynchronous written messaging. Web/video conferencing = real-time audio-visual meetings. Collaborative work software (e.g., shared docs, project wikis) = simultaneous multi-user editing. Document imaging + OCR (optical character recognition) = scanning paper documents and converting the image into editable/searchable text. Voice recognition software converts spoken audio into text commands or documents.

Don't confuse

Document imaging (capturing a picture of a page) vs. OCR (the separate process of reading that image and converting it into actual machine-readable text) --- imaging alone does not make a scanned page searchable; OCR is required.

Exam trap

A question describing a scanned PDF that ``looks like text but can't be searched or copied'' is testing that OCR was never applied --- the document was only imaged, not converted to text.

5-second recall

Imaging = picture of the page; OCR = picture $arrow$ searchable text.

3. Specialized Information Systems by Management Level

The big idea

Different levels of management need different kinds of information systems, ranging from routine daily transaction records to unstructured executive-level dashboards.

Must know

Transaction processing system (TPS) = records routine day-to-day business transactions (sales, payroll). Management information system (MIS) = summarizes TPS data into routine reports for middle managers. Decision support system (DSS) = interactive, model-based tools for semi-structured decisions. Executive information system (EIS) = high-level dashboards/summaries for top executives. Expert system (ES) = uses a knowledge base and rules to mimic human expert reasoning. Geographic information system (GIS) = maps and analyzes location-based data. Business intelligence/OLAP (online analytical processing) = multidimensional analysis of large data sets for strategic insight.

Don't confuse

A decision support system (interactive ``what-if'' modeling tool for semi-structured problems) vs. an expert system (rule/knowledge-base-driven system that mimics a human expert's judgment on a narrow, specific problem) --- a DSS supports a human decision-maker; an expert system can render a recommendation on its own.

Exam trap

A question describing a tool that gives loan officers ``what-if'' interest-rate scenarios is testing DSS; a tool that automatically diagnoses a loan applicant's risk using coded expert rules is testing an expert system --- these are frequently swapped as distractors.

5-second recall

TPS (transactions) $arrow$ MIS (reports) $arrow$ DSS (what-if) $arrow$ EIS (exec dashboard); ES = coded expert rules.

4. E-Commerce Models and EDI

The big idea

E-commerce is the buying and selling of goods/services electronically, and it is classified by which type of parties are transacting.

Must know

B2B (business-to-business), B2C (business-to-consumer), C2C (consumer-to-consumer, e.g., online marketplaces/auctions), B2G/C2G (business/consumer-to-government). Electronic data interchange (EDI) = standardized, computer-to-computer exchange of structured business documents (purchase orders, invoices) between organizations, without human re-keying.

Don't confuse

EDI (a structured, standards-based document exchange directly between two organizations' computer systems) vs. ordinary e-commerce/web ordering (a human-facing storefront transaction) --- EDI is business-to-business and largely automated end to end.

Exam trap

A question describing an online marketplace where individuals resell used goods to each other is testing C2C, not B2C --- the key is which two parties are on each end of the transaction.

5-second recall

B2B/B2C/C2C = who's trading; EDI = computer-to-computer document exchange between businesses.

5. Enterprise Systems: ERP, CRM, and SCM

The big idea

Large organizations use integrated enterprise systems to unify data and processes across departments instead of relying on isolated, disconnected systems.

Must know

ERP (enterprise resource planning) = integrates core internal processes (finance, HR, manufacturing, inventory) into one shared database. CRM (customer relationship management) = manages interactions and data across the customer lifecycle (sales, marketing, service). SCM (supply chain management) = coordinates the flow of materials, information, and finances from suppliers through production to the end customer.

Don't confuse

ERP (internal, cross-department integration) vs. SCM (external, coordinating with suppliers/logistics partners) vs. CRM (external, coordinating with customers) --- all three can share data with each other, but each has a different primary focus.

Exam trap

A question about a system that tracks a customer's purchase history and support tickets is testing CRM, not ERP, even though both may live inside the same enterprise software package.

5-second recall

ERP = inside the company; CRM = toward customers; SCM = toward suppliers.

6. Business Process Strategy

The big idea

Organizations use structured strategies to redesign or continuously improve how work gets done, not just to buy new software.

Must know

Business process reengineering (BPR) = radical, top-down redesign of core processes for dramatic improvement. Total quality management (TQM) = continuous, incremental, organization-wide improvement of quality involving all employees. Workflow management = software-defined routing of tasks/approvals through a process. Project management = planning, scheduling, and controlling resources to complete a defined project (scope, time, cost, quality).

Don't confuse

BPR (radical, one-time redesign ``from scratch'') vs. TQM (gradual, continuous, incremental improvement) --- these represent opposite philosophies of change (revolutionary vs. evolutionary).

Exam trap

A scenario describing a company that ``starts over'' and completely redesigns its order-fulfillment process is testing BPR; a company that runs ongoing small-improvement teams is testing TQM --- watch for the pace/scope of change described.

5-second recall

BPR = radical redesign; TQM = continuous small improvements.

7. Information Processing Methods

The big idea

Data can be processed as it arrives or accumulated and processed together, and the choice affects how current the resulting information is.

Must know

Real-time/transaction processing = each transaction is processed immediately as it occurs (e.g., ATM withdrawal, credit-card authorization), keeping records instantly current. Batch processing = transactions are collected over a period and processed together at a scheduled time (e.g., nightly payroll run).

Don't confuse

Real-time processing (immediate, one at a time) vs. batch processing (delayed, grouped) --- a system can look ``fast'' to the user yet still be batch if updates are only posted periodically behind the scenes.

Exam trap

A question describing a bank that updates account balances only once overnight is testing batch processing, even if customers submit transactions throughout the day in real time.

5-second recall

Real-time = instantly; Batch = collected, then processed later together.

8. Internet Infrastructure: Intranets, Extranets, and Governance

The big idea

Organizations use restricted versions of internet technology to control who can access shared information, ranging from fully internal to selectively shared with outside partners.

Must know

Intranet = a private network using internet technologies, accessible only to an organization's own members. Extranet = a controlled extension of an intranet that gives selected outside parties (partners, vendors) limited access. The public internet itself is governed collaboratively (no single owner); organizations such as ICANN coordinate naming/addressing, while technical standards bodies define protocols.

Don't confuse

Intranet (internal only) vs. extranet (internal plus selected external partners) vs. the public internet (open to anyone) --- the difference is who is allowed in, not the underlying technology, which is the same web/TCP-IP technology in all three.

Exam trap

A question describing a supplier being given limited login access to a manufacturer's private ordering system is testing extranet, not intranet, because an outside party is involved.

5-second recall

Intranet = us only; Extranet = us + invited outsiders; Internet = everyone.

9. Internet Communication and Web 2.0

The big idea

The internet relies on standardized communication protocols, and the modern ``Web 2.0'' era shifted the web from static pages toward interactive, user-generated content.

Must know

Common protocols: HTTP/HTTPS (web page transfer; HTTPS is encrypted), FTP (file transfer), SMTP (sending email), POP3/IMAP (retrieving email). ``Push'' technology sends content to the user automatically (e.g., notifications); ``pull'' technology requires the user to request content (e.g., loading a page). Web 2.0 = the shift toward social media, blogs, wikis, and user-generated/interactive content, contrasted with the earlier static, read-only ``Web 1.0.''

Don't confuse

Push technology (content is sent to you) vs. pull technology (you request the content) --- a news app alert is push; manually refreshing a webpage is pull.

Exam trap

A question describing a static, brochure-like company website with no user comments or interaction is testing ``Web 1.0'' characteristics, not Web 2.0, even if it is a currently-running site.

5-second recall

HTTP/HTTPS = web pages; FTP = files; SMTP/POP3/IMAP = email; Push = sent to you; Pull = you request it.

10. Web Browsers and Client-Side Technology

The big idea

The web browser is the client-side software that requests, renders, and manages a user's interaction with web content and keeps track of session information.

Must know

A URL (uniform resource locator) specifies protocol + domain + path (e.g., https://www.example.com/page). Cookies = small text files a website stores in the browser to remember session data, preferences, or login state. Browser cache = temporarily stored local copies of page resources to speed up future loads. Browser history = a log of previously visited pages.

Don't confuse

Cookies (small data files that persist user-specific information across visits) vs. browser cache (temporary stored copies of page files themselves, used purely for faster loading) --- clearing cache affects load speed; clearing cookies affects logins/preferences.

Exam trap

A question about a website that ``remembers you're logged in'' between visits is testing cookies, not cache, even though both are stored locally by the browser.

5-second recall

URL = address; Cookie = remembers you; Cache = stores files for speed.

11. Web Development Languages and Architecture

The big idea

Websites are built from markup, styling, and scripting languages that separate content, appearance, and interactivity, delivered through a client-server architecture.

Must know

HTML (hypertext markup language) = structures page content. CSS (cascading style sheets) = controls visual presentation/layout, separately from content. XML (extensible markup language) = a flexible markup language for structuring and exchanging data (not primarily for display). JavaScript = a scripting language that adds interactivity/dynamic behavior on the client side. Client-server architecture = the browser (client) requests resources from a remote web server, which processes/returns the response.

Don't confuse

HTML (structures the content) vs. CSS (styles the content) vs. JavaScript (adds behavior/interactivity) --- these three layers are deliberately kept separate in modern web design.

Exam trap

A question describing data being exchanged between two different systems in a structured, tagged format (not for visual display) is testing XML, not HTML, even though both use angle-bracket tags.

5-second recall

HTML = structure; CSS = style; JavaScript = behavior; XML = data exchange.

12. Website Design, Usability, and Accessibility

The big idea

Effective website development requires analyzing user needs and designing for usability and accessibility, not just writing working code.

Must know

Site development process: requirements analysis $arrow$ design (navigation, layout, content structure) $arrow$ development/coding $arrow$ testing $arrow$ deployment $arrow$ maintenance. Usability = how easily users can accomplish tasks on the site. Accessibility = designing so users with disabilities (visual, motor, hearing) can still use the site (e.g., alt text for images, keyboard navigation, sufficient color contrast).

Don't confuse

Usability (how easy the site is to use for a typical user) vs. accessibility (whether the site can be used by people with disabilities/assistive technology) --- a site can be highly usable for most people yet still be inaccessible to a screen-reader user.

Exam trap

A question describing missing image alt text or a site that cannot be navigated by keyboard is testing accessibility, not general usability, even though both concepts affect the user experience.

5-second recall

Usability = easy for typical users; Accessibility = usable with assistive technology/disabilities.

13. Malware Categories

The big idea

Malicious software is classified by how it spreads and what it does once it infects a system, and knowing the distinguishing behavior of each type is the key testable skill.

Must know

Virus = attaches to a host file/program and requires a user action (e.g., opening a file) to spread. Worm = self-replicating, spreads across networks on its own without needing a host file or user action. Trojan horse = disguised as legitimate/useful software but carries a hidden malicious payload; does not self-replicate. Ransomware = encrypts a victim's files and demands payment for the decryption key. Spyware = secretly monitors/collects user activity or data. Adware = automatically displays unwanted advertisements. Scareware = uses fake alarming warnings (e.g., ``your PC is infected'') to trick users into installing malware or paying for fake fixes.

Don't confuse

A virus (needs a host file and user action to spread) vs. a worm (self-replicates and spreads across a network with no user action required) --- worms are typically far faster-spreading because they don't wait on a human.

Exam trap

A question describing malware that spread across a whole corporate network overnight with no employee opening anything is testing a worm, not a virus, because no host file/user action was needed.

5-second recall

Virus = needs a host $+$ a click; Worm = spreads itself; Trojan = disguised payload; Ransomware = encrypts $+$ demands payment.

14. Denial-of-Service Attacks and Network Threats

The big idea

Some attacks aim not to steal data but to make a system or service unavailable to its legitimate users by overwhelming it.

Must know

Denial of service (DoS) attack = flooding a server/network with excessive traffic or requests so it cannot respond to legitimate users. Distributed denial of service (DDoS) = the same attack launched simultaneously from many compromised machines (a botnet), making it harder to block. Firewalls, intrusion detection systems, and traffic filtering are common countermeasures.

Don't confuse

A DoS attack (aims to disrupt availability by overwhelming a system) vs. malware like a virus or spyware (aims to infect, steal, or damage data/files) --- a successful DoS attack doesn't necessarily breach or steal any data at all.

Exam trap

A question describing a website that ``goes down'' because it is flooded with traffic from thousands of compromised computers at once is testing DDoS, not a virus outbreak.

5-second recall

DoS/DDoS $arrow$ flood traffic $arrow$ deny access, not steal data.

15. Authentication, Authorization, and Access Control

The big idea

Securing a system requires first verifying who a user is, and then separately controlling what that verified user is allowed to do.

Must know

Authentication = proving identity (something you know: password/PIN; something you have: security token/smart card; something you are: biometrics). Authorization = the separate step of granting/restricting permissions and access rights for an already-authenticated user (what files, systems, or actions they may access). Access control also covers secure remote data access and device/application-level permissions.

Don't confuse

Authentication (verifying WHO you are) vs. authorization (determining WHAT you're allowed to do once verified) --- a user can be successfully authenticated (correct password) yet still be denied authorization to a specific restricted file.

Exam trap

A question describing an employee who logs in successfully but then is blocked from opening the payroll database is testing authorization, not authentication, since the login itself already succeeded.

5-second recall

Authentication = prove who you are; Authorization = what you're allowed to do.

16. Privacy and Identity Theft

The big idea

Information systems raise privacy concerns for both individuals and businesses, and identity theft is the most tested individual-level harm.

Must know

Individual privacy concerns: tracking of personal data, location, and online behavior. Business privacy concerns: protecting customer/employee records and complying with data-protection obligations. Identity theft = illegally obtaining and using someone else's personal/financial information (e.g., Social Security number, credit card data) to commit fraud.

Don't confuse

Privacy (control over who can see/collect your personal information) vs. security (the technical measures, like encryption and access control, used to protect that information from unauthorized access) --- weak security can cause a privacy violation, but the two concepts are not identical.

Exam trap

A question describing someone using a stolen Social Security number to open a fraudulent credit account is testing identity theft specifically, not just a generic ``privacy violation.''

5-second recall

Privacy = control over your info; Identity theft = someone else using your info to commit fraud.

17. Disaster Recovery Planning

The big idea

Organizations must plan in advance for how to restore information systems after a major disruption, because reactive planning after the fact is too late.

Must know

Disaster recovery plan (DRP) = a documented strategy for restoring IT systems/data after disasters (natural: fire, flood; man-made: cyberattack, hardware failure, human error). Key elements: regular data backups (on-site and off-site), a backup/alternate processing site, a clear recovery priority order for critical systems, and periodic testing of the plan itself.

Don't confuse

A disaster recovery plan (focused specifically on restoring IT systems/data/infrastructure) vs. a general business continuity plan (the broader plan for keeping the whole organization operating, of which IT recovery is one part) --- IS disaster recovery is a subset of business continuity.

Exam trap

A question describing a company that has backups but has never actually tested restoring from them is testing a key disaster-recovery weakness --- an untested plan cannot be assumed to work when actually needed.

5-second recall

DRP = backups $+$ alternate site $+$ recovery priorities $+$ regular testing.

18. Core Hardware Components

The big idea

Every computer system relies on the same basic categories of hardware to process, store, and move data, regardless of the device's size or purpose.

Must know

Processing devices: the CPU (central processing unit) executes instructions. Storage devices: primary/volatile memory (RAM, lost on power-off) vs. secondary/non-volatile storage (hard drives, SSDs, holds data long-term). Input devices (keyboard, mouse, scanner) capture data; output devices (monitor, printer) present results. Telecommunications/networking hardware (routers, modems, network interface cards) connect devices to networks.

Don't confuse

RAM (temporary, volatile working memory that is erased when power is lost) vs. secondary storage like an SSD/hard drive (permanent, non-volatile storage that keeps data after shutdown) --- more RAM speeds up active tasks, while more storage capacity holds more saved files long-term.

Exam trap

A question describing data that is ``lost after a power outage'' is testing RAM/volatile memory, not the hard drive/SSD, which retains its data regardless of power.

5-second recall

RAM = temporary/volatile; Storage (HDD/SSD) = permanent/non-volatile.

19. Operating Systems and System Software

The big idea

System software (led by the operating system) manages a computer's hardware resources and provides the platform on which application software runs.

Must know

The operating system (OS) manages memory, processes, file storage, and input/output devices, and provides the user interface. Functions performed by system software include computer/hardware management, running the telecommunications stack, and coordinating network hardware. Examples: Windows, macOS, Linux, mobile OSes (iOS, Android).

Don't confuse

System software (the OS and utility programs that manage the hardware and support all other software) vs. application software (productivity tools like word processors or spreadsheets that the user directly uses to accomplish tasks) --- the OS runs first and application software runs ``on top of'' it.

Exam trap

A question describing a program that ``manages memory allocation and schedules which programs get CPU time'' is testing the operating system, not any single application.

5-second recall

OS = manages hardware $+$ resources; Applications = run on top of the OS.

20. Network Architectures

The big idea

Networks are classified primarily by their geographic scope and by whether they use public or private/secured connections.

Must know

PAN (personal area network) = very short range, connecting an individual's own nearby devices (e.g., Bluetooth). LAN (local area network) = confined to one building/campus. WAN (wide area network) = spans large geographic areas, connecting multiple LANs (the internet is the largest WAN). VPN (virtual private network) = creates a secure, encrypted ``tunnel'' over a public network (like the internet) so remote users can access a private network safely. Enterprise networks integrate multiple LANs/WANs across an organization.

Don't confuse

A LAN (small, single-site network) vs. a WAN (large network spanning multiple sites/geographic areas, often connecting several LANs together) --- an office building's network is a LAN; the network connecting that company's offices across several states is a WAN.

Exam trap

A question describing a remote employee securely connecting to the office network over the public internet is testing VPN, not a LAN, because the connection is encrypted and travels over a public network.

5-second recall

PAN = you, personal devices; LAN = one building; WAN = many sites; VPN = secure tunnel over a public network.

21. Computer Classifications

The big idea

Computers are grouped into categories based on processing power, size, and intended use, from massive supercomputers down to personal devices.

Must know

Supercomputer = fastest, most powerful, used for massive scientific/complex calculations. Mainframe = large, powerful system built for high-volume, reliable transaction processing (e.g., banking) serving many simultaneous users. Server = a computer that provides services/resources to other computers (clients) in a client/server architecture. Workstation = a high-performance single-user computer for demanding tasks. Personal computer (PC) = a general-purpose computer for individual use.

Don't confuse

A mainframe (built for extremely high-volume, reliable transaction throughput for many simultaneous users, e.g., a bank's core system) vs. a supercomputer (built for raw computational speed on massive, complex scientific calculations, e.g., climate modeling) --- mainframes prioritize reliable transaction volume; supercomputers prioritize raw processing speed.

Exam trap

A question describing a system processing millions of daily ATM/banking transactions reliably is testing a mainframe, not a supercomputer, even though both sound like ``huge, powerful'' computers.

5-second recall

Supercomputer = fastest calculations; Mainframe = high-volume reliable transactions; Server = serves clients.

22. Wireless and Mobile Technologies

The big idea

Multiple wireless technologies coexist because each is optimized for a different range, purpose, and power/data tradeoff.

Must know

Wi-Fi (IEEE 802.11) = wireless LAN access, moderate range (tens to a few hundred feet). Bluetooth = very short-range (about 30 feet/10 meters) wireless connection between nearby personal devices (a PAN technology). RFID (radio-frequency identification) = tags that transmit identifying data to a nearby reader/scanner (used in inventory tracking, access badges). GPS (global positioning system) = satellite-based location/navigation. Cellular networks (e.g., 4G/5G) = wide-area mobile voice/data. Internet of Things (IoT) = everyday physical devices/objects embedded with sensors and network connectivity so they can collect and exchange data.

Don't confuse

Bluetooth (very short range, connects a small number of nearby personal devices, e.g., a phone to a headset) vs. Wi-Fi (longer range, connects many devices to a shared local network, typically through a router) --- Bluetooth is device-to-device; Wi-Fi is device-to-network.

Exam trap

A question describing a wireless mouse or headset paired directly to one nearby laptop is testing Bluetooth, not Wi-Fi, because it is a short-range, direct device pairing rather than a network connection.

5-second recall

Wi-Fi = network access; Bluetooth = short-range device pairing; RFID = tag + scanner; GPS = location.

23. SDLC and Development Methodologies

The big idea

Software is built using a defined life-cycle process, and different methodologies trade off speed, structure, and user involvement differently.

Must know

The systems development life cycle (SDLC) is the traditional structured sequence of phases used to build information systems (see Power Box 7 for the full pathway). Prototyping = quickly building a working mockup for early user feedback before full development. Rapid application development (RAD) = compressed, iterative development emphasizing speed and prototyping over extensive upfront planning. Joint application development (JAD) = structured workshops bringing users and developers together to define requirements collaboratively. CASE (computer-aided software engineering) tools = software that automates parts of the development process (diagramming, code generation). Agile = iterative, incremental development in short cycles (sprints) with continuous user feedback. Spiral model = risk-driven, iterative model that repeats through planning, risk analysis, prototyping, and evaluation in expanding cycles.

Don't confuse

The traditional/waterfall-style SDLC (sequential, phase-by-phase, extensive upfront planning) vs. Agile (iterative, incremental, short cycles with continuous feedback and flexible requirements) --- SDLC assumes requirements are mostly known upfront; Agile assumes they will evolve.

Exam trap

A question describing a project built in short, repeated two-week cycles with continuously evolving requirements is testing Agile, not a traditional linear SDLC approach, even though Agile projects still pass through analysis, design, and testing activities.

5-second recall

Waterfall/SDLC = sequential phases; Agile = short iterative sprints; RAD/Prototyping = fast mockups; JAD = user-developer workshops.

24. Systems Analysis and Design

The big idea

Before any code is written, developers must formally study the current problem/system (analysis) and then specify exactly how the new system will work (design).

Must know

Feasibility analysis = an early study of whether a proposed project is technically, economically, and operationally achievable. Systems analysis = studying the current system and gathering/documenting requirements for the new one (what the system must do). Systems design = specifying how the new system will meet those requirements (inputs, outputs, processes, interfaces, data structures). End-user development = business users themselves building simple applications/tools (e.g., an advanced spreadsheet macro) without going through the full formal IT development process.

Don't confuse

Systems analysis (defining WHAT the new system must do, based on requirements) vs. systems design (defining HOW the system will be built to meet those requirements) --- analysis comes first and is requirement-focused; design comes second and is solution-focused.

Exam trap

A question describing a document listing the specific screen layouts, file structures, and interfaces to be built is testing the design phase, not the analysis phase, since analysis produces requirements, not blueprints.

5-second recall

Analysis = what's needed; Design = how it will be built.

25. Implementation, Testing, and Conversion Strategies

The big idea

Rolling out a new system safely requires deliberate testing, user training, and a chosen strategy for switching over from the old system to the new one.

Must know

Testing types include unit testing (individual components) and system/integration testing (the whole system working together). Data conversion = migrating existing data into the new system's format. Conversion strategies: direct/plunge cutover (old system stops and new system starts all at once --- fastest but riskiest), parallel conversion (old and new systems run simultaneously for a period --- safest but most costly/duplicative), phased conversion (the new system is rolled out gradually, module by module or function by function), and pilot conversion (the new system is tried in one location/department first before wider rollout). Post-implementation activities include ongoing maintenance and documentation.

Don't confuse

Parallel conversion (both old and new systems run at the same time so results can be cross-checked, minimizing risk but doubling workload/cost) vs. direct/plunge conversion (the old system is shut off immediately as the new one goes live, minimizing cost but maximizing risk if something goes wrong) --- these are opposite ends of the risk/cost tradeoff.

Exam trap

A question describing a hospital that tests a new records system in a single department first before expanding it hospital-wide is testing pilot conversion, not phased conversion, since phased conversion rolls out by function/module rather than by a single site/department.

5-second recall

Direct = risky, all at once; Parallel = safe, both run together; Phased = gradual by module; Pilot = one site first.

26. Software Standards and Licensing

The big idea

Software is distributed under different licensing models that determine who may view, modify, and redistribute the underlying source code.

Must know

Proprietary software = source code is closed/owned by a company; users typically buy a license to use it but cannot legally modify or redistribute it (e.g., Microsoft Office). Open-source software = source code is publicly available, and users can view, modify, and often redistribute it, usually under a specific open-source license (e.g., Linux). Purpose-based standards ensure interoperability (e.g., a common file format or protocol that multiple vendors' software can read).

Don't confuse

Proprietary software (closed source code, restricted use/modification rights, typically paid) vs. open-source software (source code publicly viewable/modifiable, often free, though not all open-source software is free of cost) --- ``free'' and ``open-source'' are related but not identical concepts.

Exam trap

A question describing software that is free to download but whose source code cannot be viewed or altered is testing proprietary freeware, not open source --- being free of charge does not automatically make software open source.

5-second recall

Proprietary = closed source, restricted; Open source = source code open to view/modify.

27. Data Hierarchy and Digital Representation

The big idea

Computers represent all information as binary data, which is organized into increasingly larger, more meaningful units, from a single bit up to a full database.

Must know

Data hierarchy, smallest to largest: bit (single binary 0/1) $arrow$ byte (8 bits, represents one character) $arrow$ field (a single data element, e.g., last name) $arrow$ record (a complete set of related fields, e.g., one customer's full record) $arrow$ file/table (a collection of related records) $arrow$ database (a collection of related files/tables). Storage capacity units scale by powers of approximately 1,000/1,024: kilobyte (KB), megabyte (MB), gigabyte (GB), terabyte (TB).

Don't confuse

A field (one single piece of data, like a phone number) vs. a record (the complete collection of related fields describing one entity, like an entire customer's information) --- a record is made up of multiple fields, not the reverse.

Exam trap

A question describing ``all the information about one specific customer'' is testing the term record, not field, since it refers to the complete set of that customer's data, not just one data point.

5-second recall

Bit $arrow$ byte $arrow$ field $arrow$ record $arrow$ file $arrow$ database (small to large).

28. File Organization and Access Methods

The big idea

How records are physically arranged in a file determines how quickly and in what order they can later be retrieved.

Must know

Sequential file organization = records are stored and must be read in physical order, one after another (efficient for processing entire files, slow for finding one specific record). Indexed(-sequential) organization = an index (like a book's index) allows direct lookup of a record's location without scanning the whole file. Direct/random access organization = a record's storage location is calculated directly (e.g., via a hashing algorithm), allowing immediate access to any record without reading others first.

Don't confuse

Sequential access (must read records in order, one by one, to reach a target record) vs. direct/random access (can jump immediately to any specific record's location) --- direct access is far faster for looking up a single specific record; sequential is efficient only when processing an entire file in order.

Exam trap

A question describing a system that must scan every prior record to find one specific customer is testing sequential access, not direct/random access, which could locate that same record instantly.

5-second recall

Sequential = read in order; Indexed = look up via an index; Direct/random = jump straight to it.

29. Database Management Models and Keys

The big idea

Databases organize related data according to one of a few classic structural models, and relational databases (the dominant modern model) link tables using key fields.

Must know

Relational model = data stored in multiple related tables (rows/records and columns/fields), linked by shared key values; uses SQL for queries. Hierarchical model = data organized in a strict parent-child tree structure (each child has only one parent). Network model = similar to hierarchical but more flexible, allowing a record to have multiple parent/owner relationships. Primary key = a field that uniquely identifies each record in a table. Foreign key = a field in one table that refers to the primary key of another table, creating the link/relationship between them.

Don't confuse

A primary key (uniquely identifies each record within its own table) vs. a foreign key (a field that references another table's primary key, in order to establish a relationship between the two tables) --- a foreign key value can repeat across records; a primary key value cannot.

Exam trap

A question describing a ``CustomerID'' field appearing in an Orders table to link each order back to a specific customer is testing foreign key, not primary key, because it is referencing another table's identifier.

5-second recall

Relational = tables linked by keys; Primary key = unique ID in its own table; Foreign key = link to another table's key.

30. Data Warehousing, Mining, and Big Data

The big idea

Organizations collect and consolidate huge volumes of historical data specifically to analyze it for patterns and business insight, separate from day-to-day operational databases.

Must know

Data warehouse = a large, centralized repository that consolidates historical data from multiple operational systems for analysis/reporting, rather than for daily transaction processing. Data mining = analyzing large data sets to discover hidden patterns, trends, and relationships (e.g., market-basket analysis). Big data = extremely large, fast-growing, and often unstructured/varied data sets that exceed the capacity of traditional database tools to process, typically described by volume, velocity, and variety.

Don't confuse

A data warehouse (a centralized, historical store built specifically for analysis/reporting) vs. an operational transaction database (built for fast, real-time, day-to-day recording of individual transactions) --- running heavy analytical queries directly against a live operational database can slow it down, which is exactly why warehouses exist separately.

Exam trap

A question describing analysts running complex historical trend reports against a separate consolidated repository (not the live sales system) is testing a data warehouse, not the operational TPS database.

5-second recall

Data warehouse = consolidated history for analysis; Data mining = finding hidden patterns; Big data = huge, fast, varied data.

31. Programming Logic, Boolean Operators, and SQL

The big idea

Programs and database queries are built from simple logical building blocks, and SQL is the standard language for retrieving and managing data in relational databases.

Must know

Boolean logic operators: AND (both conditions must be true), OR (at least one condition true), NOT (negates a condition) --- used in both programming conditionals and search/query filtering. Structured Query Language (SQL) core commands: SELECT (retrieve data), FROM (specify table), WHERE (filter rows by condition), INSERT (add a record), UPDATE (modify a record), DELETE (remove a record). Object-oriented programming = organizes code around ``objects'' that bundle data and behavior together, using classes, encapsulation, and inheritance. Structured/procedural programming = organizes code as a sequence of procedures/functions that act on separate data.

Don't confuse

Structured/procedural programming (organized around sequential steps/procedures operating on data kept separate from the code) vs. object-oriented programming (organized around self-contained objects that bundle data and the behavior/methods that act on it together) --- object-oriented design emphasizes reusable, encapsulated objects rather than a strict top-down sequence.

Exam trap

A question showing a query filter requiring a record to match category A AND price under a set amount is testing the AND operator, not OR --- with AND, both conditions must hold, which is stricter/returns fewer results than OR.

5-second recall

AND = both true; OR = either true; SELECT/FROM/WHERE = the core of a SQL query.

32. Outsourcing, Offshoring, Insourcing, and Green Computing

The big idea

Organizations make strategic decisions about where and by whom IT work gets done, and increasingly must also weigh the environmental impact of their technology use.

Must know

Outsourcing = contracting IT work or services to an external company (which may be domestic or foreign). Offshoring = relocating business processes/operations to another country (which could be handled by the company's own foreign subsidiary or by an outsourced foreign vendor). Insourcing = performing work using internal staff/resources, including bringing previously outsourced work back in-house. Green computing = using computing resources in an environmentally responsible way (energy-efficient hardware, reduced power consumption, e-waste recycling).

Don't confuse

Outsourcing (contracting work to an external company, which may or may not be in another country) vs. offshoring (relocating work to another country, which may or may not involve an external company) --- the two concepts overlap but describe different dimensions (who does the work vs. where it's done).

Exam trap

A company opening its own wholly-owned support center in another country (not hiring an outside vendor) is testing offshoring without outsourcing, since the work stayed in-house but simply moved to a different country.

5-second recall

Outsourcing = who does it (external); Offshoring = where it's done (another country); Insourcing = bring it back in-house.

33. Intellectual Property and Software Licensing Ethics

The big idea

Legal protections for creative and technical work give owners exclusive rights, and unauthorized copying/use of software raises both legal and ethical issues.

Must know

Copyright = protects original creative/expressive works (including software code) from unauthorized copying/distribution. Patent = protects a novel invention or process (can apply to software algorithms/business methods in some cases). Trademark = protects brand identifiers (names, logos). Software piracy = unauthorized copying or distribution of licensed software, an ongoing ethical/legal issue. Open-source licensing offers an alternative model that legally permits viewing, modifying, and sharing code.

Don't confuse

Copyright (protects the specific expression/code of a creative or technical work from copying) vs. patent (protects a novel invention, process, or method itself, which is a higher legal bar to obtain) --- most commercial software is protected primarily by copyright, while only certain novel algorithms/processes may also be patentable.

Exam trap

A question describing employees installing unlicensed copies of paid software on multiple computers is testing software piracy/copyright infringement, not a patent issue.

5-second recall

Copyright = protects the expression/code; Patent = protects the invention/process; Trademark = protects the brand.

34. IT Workforce Trends

The big idea

Information technology has reshaped where, how, and under what physical conditions employees do their jobs.

Must know

Telecommuting = employees work remotely (often from home) using IT rather than commuting to a central office. Virtual teams = groups of employees who collaborate on shared work while being geographically dispersed, relying on communication/collaboration technology. Ergonomics = designing workspaces/equipment (chairs, keyboards, monitor height) to reduce physical strain and injury from computer use. Job design/staffing = how IT changes the structure, requirements, and availability of jobs within an organization.

Don't confuse

Telecommuting (an individual employee working remotely rather than commuting) vs. a virtual team (a group of employees, who may or may not each be telecommuting, collaborating across distance using technology) --- a virtual team can include members who telecommute from home as well as members working from different physical offices.

Exam trap

A question describing several employees in different countries collaborating on one project entirely through video calls and shared documents is testing virtual teams, not merely telecommuting, since the focus is on distributed collaboration, not one worker's location.

5-second recall

Telecommuting = one person works remotely; Virtual team = a distributed group collaborating via technology.

35. IS Careers, Certifications, and Social Networking Ethics

The big idea

Information systems work spans a range of specialized career roles, many supported by professional certifications, and social networking technology raises its own set of ethical/social tradeoffs.

Must know

Common IS roles: systems analyst (studies/designs systems), database administrator/DBA (manages and secures databases), network administrator (manages network infrastructure), web developer (builds websites/web applications), and CIO/CTO (executive-level technology leadership). Certifications validate specific skills (e.g., vendor-neutral hardware/networking/security certifications, or vendor-specific credentials). Social networking benefits: connection, information sharing, marketing reach. Social networking risks: privacy exposure, misinformation, cyberbullying, and reduced face-to-face interaction.

Don't confuse

A systems analyst (focuses on studying requirements and designing how a system should work) vs. a database administrator (focuses on the ongoing management, performance, and security of an existing database) --- these are two distinct IS career roles with different day-to-day responsibilities.

Exam trap

A question describing a professional whose main job is granting/restricting user access to a company's database and monitoring its performance is testing the database administrator role, not the systems analyst role.

5-second recall

Systems analyst = designs the system; DBA = manages the database; Network admin = manages the network.

POWER BOX 1 --- Key Numbers and Reference Sheet

5-second recall

100 questions / 90 minutes / scaled 20--80 / ACE-recommended passing score = 50.

POWER BOX 2 --- Terms Students Always Confuse

POWER BOX 3 --- Information Systems Taxonomy by Management Level

5-second recall

Operational (TPS) $arrow$ middle management (MIS/DSS) $arrow$ executive (EIS); ES $=$ automated expert judgment.

POWER BOX 4 --- Standards and Protocols Reference List

POWER BOX 5 --- How to Analyze a Systems-Development Scenario Question

5-second recall

Phase keyword $arrow$ methodology keyword $arrow$ conversion-strategy keyword $arrow$ match the risk/cost tradeoff.

POWER BOX 6 --- Exam Format and Question-Type Playbook

5-second recall

$$100 questions / 90 minutes / all multiple choice --- terminology precision and scenario recognition both matter.

POWER BOX 7 --- Pathway: The Systems Development Life Cycle (SDLC)

5-second recall

Planning $arrow$ Analysis $arrow$ Design $arrow$ Implementation (build/test/train/convert) $arrow$ Maintenance.

POWER BOX 8 --- Database and File Organization Decision Guide

5-second recall

One record fast $arrow$ direct/indexed; whole file in order $arrow$ sequential; linked tables $arrow$ relational; strict tree $arrow$ hierarchical.

POWER BOX 9 --- CLEP Trap Statements

POWER BOX 10 --- Final 15-Minute Review