1/249
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?
A. Security policy
B. Risk management framework
C. Security standards
D. Risk appetite
D
When an organization decides to accept a risk, it should mean the cost to mitigate:
A. exceeds budget allocation.
B. is higher than the cost to transfer risk.
C. is less than the residual risk.
D. is greater than the residual risk.
D
Which of the following is the MOST important reason to conduct interviews as part of the business impact analysis (BIA) process?
A. To facilitate a qualitative risk assessment following the BIA
B. To obtain input from as many relevant stakeholders as possible
C. To ensure the stakeholders providing input own the related risk
D. To increase awareness of information security among key stakeholders
B
Due to changes in an organization’s environment, security controls may no longer be adequate. What is the information security manager’s BEST course of action?
A. Perform a new risk assessment.
B. Review the previous risk assessment and countermeasures.
C. Transfer the new risk to a third party.
D. Evaluate countermeasures to mitigate new risks.
A
What is the PRIMARY benefit to an organization when information security program requirements are aligned with employment and staffing processes?
A. Access is granted based on task requirements.
B. Information assets are classified appropriately.
C. Security staff turnover is reduced.
D. Security incident reporting procedures are followed.
A
When developing an asset classification program, which of the following steps should be completed FIRST?
A. Implement a data loss prevention (DLP) system.
B. Categorize each asset.
C. Create a business case for a digital rights management tool.
D. Create an inventory.
D
Which of the following is the PRIMARY reason to monitor key risk indicators (KRIs) related to information security?
A. To alert on unacceptable risk
B. To identity residual risk
C. To reassess risk appetite
D. To benchmark control performance
A
Which of the following is the BEST indicator of an emerging incident?
A. A weakness identified within an organization's information systems
B. Attempted patching of systems resulting in errors
C. Customer complaints about lack of website availability
D. A recent security incident at an industry competitor
C
An organization has discovered a recurring problem with unsecure code being released into production. Which of the following is the information security manager action?
A. Implement segregation of duties between development and production.
B. Increase the frequency of penetration testing.
C. Review existing configuration management processes.
D. Review existing change management processes.
A
When developing a categorization method for security incidents, the categories MUST:
A. be created by the incident hander.
B. align with reporting requirements.
C. have agreed-upon definitions.
D. align with industry standards.
C
Which of the following is MOST likely to be impacted when emerging technologies are introduced to an organization?
A. Risk profile
B. Security policies
C. Control effectiveness
D. Risk assessment approach
A
An organization's main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated risk?
A. The data owner
B. The information security manager
C. The security engineer
D. The application owner
D
Which of the following is the MOST important criterion when deciding whether to accept residual risk?
A. Cost of replacing the asset
B. Annual loss expectancy (ALE)
C. Cost of additional mitigation
D. Annual rate of occurrence
B
An information security manager finds that a soon-to-be deployed online application will increase risk beyond acceptable levels, and necessary controls have not been included. Which of the following is the BEST course of action for the information security manager?
A. Recommend a different application.
B. Instruct IT to deploy controls based on urgent business needs.
C. Solicit bids for compensating control products.
D. Present a business case for additional controls to senior management.
D
When developing a business case to justify an information security investment, which of the following would BEST enable an informed decision by senior management?
A. The information security strategy
B. Security investment trends in the industry
C. Losses due to security incidents
D. The results of a risk assessment
D
A data-hosting organization's data center houses servers, applications, and data for a large number of geographically dispersed customers. Which of the following strategies is the BEST approach for developing a physical access control policy for the organization?
A. Review customers’ security policies.
B. Design single sign-on (SSO) or federated access.
C. Develop access control requirements for each system and application.
D. Conduct a risk assessment to determine security risks and mitigating controls.
D
Which of the following is a PRIMARY benefit of managed security solutions?
A. Easier implementation across an organization
B. Greater ability to focus on core business operations
C. Wider range of capabilities
D. Lower cost of operations
B
Which of the following is an example of risk mitigation?
A. Improving security controls
B. Discontinuing the activity associated with the risk
C. Performing a cost-benefit analysis
D. Purchasing insurance
A
Which of the following BEST enables an organization to provide ongoing assurance that legal and regulatory compliance requirements can be met?
A. Engaging external experts to provide guidance on changes in compliance requirements
B. Assigning the operations manager accountability for meeting compliance requirements
C. Embedding compliance requirements within operational processes
D. Performing periodic audits for compliance with legal and regulatory requirements
C
Following a successful attack, an information security manager should be confident the malware has not continued to spread at the completion of which incident response phase?
A. Recovery
B. Eradication
C. Identification
D. Containment
D
Which of the following is the BEST method to align an information security strategic plan to the corporate strategy?
A. Ensuring the plan complies with business unit expectations
B. Involving industry experts in the development of the plan
C. Involving senior management in the development of the plan
D. Obtaining adequate funds from senior management
C
Which of the following would BEST ensure that security is integrated during application development?
A. Performing application security testing during acceptance testing
B. Introducing security requirements during the initiation phase
C. Employing global security standards during development processes
D. Providing training on secure development practices to programmers
B
Which of the following is MOST important in increasing the effectiveness of incident responders?
A. Integrating staff with the IT department
B. Testing response scenarios
C. Communicating with the management team
D. Reviewing the incident response plan annually
B
Which of the following should be the PRIMARY objective of the information security incident response process?
A. Classifying incidents
B. Conducting incident triage
C. Communicating with internal and external parties
D. Minimizing negative impact to critical operations
D
An incident response team has been assembled from a group of experienced individuals. Which type of exercise would be MOST beneficial for the team at the first drill?
A. Tabletop exercise
B. Red team exercise
C. Disaster recovery exercise
D. Black box penetration test
A
In violation of a policy prohibiting the use of cameras at the office, employees have been issued smartphones and tablet computers with enabled web cameras. Which of the following should be the information security manager's FIRST course of action?
A. Revise the policy.
B. Conduct a risk assessment.
C. Communicate the acceptable use policy.
D. Perform a root cause analysis.
B
When performing a business impact analysis (BIA), who should calculate the recovery time and cost estimates?
A. Business process owner
B. Business continuity coordinator
C. Information security manager
D. Senior management
A
A PRIMARY purpose of creating security policies is to:
A. implement management's security governance strategy.
B. establish the way security tasks should be executed.
C. communicate management's security expectations.
D. define allowable security boundaries.
C
The MAIN benefit of implementing a data loss prevention (DLP) solution is to:
A. enhance the organization's antivirus controls.
B. reduce the need for a security awareness program.
C. complement the organization's detective controls.
D. eliminate the risk of data loss.
C
Which of the following is the MOST important detail to capture in an organization's risk register?
A. Risk acceptance criteria
B. Risk severity level
C. Risk ownership
D. Risk appetite
C
Which of the following is the GREATEST benefit of information asset classification?
A. Supporting segregation of duties
B. Defining resource ownership
C. Providing a basis for implementing a need-to-know policy
D. Helping to determine the recovery point objective (RPO)
C
While classifying information assets, an information security manager notices that several production databases do not have owners assigned to them. What the information security manager address this situation?
A. Assign the highest classification level to those databases.
B. Assign responsibility to the database administrator (DBA).
C. Prepare a report of the databases for senior management.
D. Review the databases for sensitive content.
C
An organization’s research department plans to apply machine learning algorithms on a large data set containing customer names and purchase history. The risk leakage is considered high impact. Which of the following is the BEST risk treatment option in this situation?
A. Accept the risk, as the benefits exceed the potential consequences.
B. Mitigate the risk by applying anonymization on the data set.
C. Transfer the risk by purchasing insurance.
D. Mitigate the risk by encrypting the customer names in the data set.
B
IT projects have gone over budget with too many security controls being added post-production. Which of the following would MOST help to ensure that relevant to a project?
A. Involving information security at each stage of project management
B. Creating a data classification framework and providing it to stakeholders
C. Identifying responsibilities during the project business case analysis
D. Providing stakeholders with minimum information security requirements
A
Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?
A. Integration of assurance efforts
B. Automation of controls
C. Documentation of control procedures
D. Standardization of compliance requirements
A
Which of the following BEST helps to ensure a risk response plan will be developed and executed in a timely manner?
A. Establishing risk metrics
B. Training on risk management procedures
C. Reporting on documented deficiencies
D. Assigning a risk owner
D
An information security manager learns that IT personnel are not adhering to the information security policy because it creates process inefficiencies. What should the information security manager do FIRST?
A. Propose that IT update information security policies and procedures.
B. Request that internal audit conduct a review of the policy development process.
C. Conduct user awareness training within the IT function.
D. Determine the risk related to noncompliance with the policy.
D
Which of the following is MOST important to include in a report to key stakeholders regarding the effectiveness of an information security program?
A. Security incident details
B. Security metrics
C. Security risk exposure
D. Security baselines
B
An organization is increasingly using Software as a Service (SaaS) to replace in-house hosting and support of IT applications. Which of the following would be the MOST effective way to help ensure procurement decisions consider information security concerns?
A. Integrate information security risk assessments into the procurement process.
B. Invite IT members into regular procurement team meetings to influence best practice.
C. Enforce the right to audit in procurement contracts with SaaS vendors.
D. Provide regular information security training to the procurement team.
A
Which of the following should be the KEY consideration when creating an information security communication plan with industry peers?
A. Reducing the costs associated with information sharing by automating the process
B. Balancing the benefits of information sharing with the drawbacks of sharing sensitive information
C. Notifying the legal department whenever incident-related information is shared
D. Ensuring information is detailed enough to be of use to other organizations
B
Which of the following is MOST effective for communicating forward-looking trends within security reporting?
A. Key risk indicators (KRIs)
B. Key performance indicators (KPIs)
C. Key control indicators (KCIs)
D. Key goal indicators (KGIs)
A
An organization recently purchased data loss prevention (DLP) software but soon discovered the software fails to detect or prevent data loss.
Which of the following should the information security manager do FIRST?
A. Revise the data classification policy.
B. Review the contract.
C. Review the configuration
D. Implement stricter data loss controls.
C
Network isolation techniques are immediately implemented after a security breach to.
A. allow time for key stakeholder decision making.
B. reduce the extent of further damage.
C. enforce zero trust architecture principles.
D. preserve evidence as required for forensics.
B
Which of the following incident response phases involves actions to help safeguard critical systems while maintaining business operations?
A. Containment
B. Identification
C. Preparation
D. Recovery
A
An organization has received complaints from users that some of their files have been encrypted. These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?
A. Isolate the affected systems.
B. Conduct an impact assessment.
C. Initiate incident response.
D. Rebuild the affected systems.
C
Which of the following has the GREATEST positive impact on the ability to execute a disaster recovery plan (DRP)?
A. Updating the plan periodically
B. Conducting a walk-through of the plan
C. Storing the plan at an offsite location
D. Communicating the plan to all stakeholders.
B
Which of the following is MOST important to include in monthly information security reports to the board?
A. Root cause analysis of security incidents
B. Threat intelligence
C. Risk assessment results
D. Trend analysis of security metrics
D
Which of the following activities is designed to handle a control failure that leads to a breach?
A. Vulnerability management
B. Incident management
C. Root cause analysis
D. Risk assessment
B
Which of the following is MOST important to consider when aligning a security awareness program with the organization's business strategy?
A. Processes and technology
B. People and culture
C. Regulations and standards
D. Executive and board directives
B
Which of the following BEST indicates that information assets are classified accurately?
A. An accurate and complete information asset catalog
B. Appropriate assignment of information asset owners
C. Appropriate prioritization of information risk treatment
D. Increased compliance with information security policy
C
Reevaluation of risk is MOST critical when there is:
A. a management request for updated security reports.
B. resistance to the implementation of mitigating controls.
C. a change in the threat landscape.
D. a change in security policy.
C
Which of the following BEST supports investments in an information security program?
A. Business impact analysis (BIA)
B. Risk assessment results
C. Gap analysis results
D. Business cases
D
Which of the following is MOST important to ensure when developing escalation procedures for an incident response plan?
A. Minimum regulatory requirements are maintained.
B. The contact list regularly updated.
C. Each process is assigned to a responsible party.
D. Senior management approval has been documented.
C
Which of the following is the PRIMARY benefit of implementing a vulnerability assessment process?
A. Compliance status is improved.
B. Threat management is enhanced.
C. Security metrics are enhanced.
D. Proactive risk management is facilitated.
D
An organization is implementing an information security governance framework. To communicate the program's effectiveness to stakeholders, it is MOST important to establish:
A. a control self-assessment (CSA) process.
B. metrics for each milestone.
C. automated reporting to stakeholders.
D. a monitoring process for the security policy.
B
Which of the following would be the MOST effective way to present quarterly reports to the board on the status of the information security program?
A. Detailed analysis of security program KPIs
B. An information security risk register
C. An information security dashboard
D. A capability and maturity assessment
C
Which of the following is the BEST way to obtain support for a new organization-wide information security program?
A. Deliver an information security awareness campaign.
B. Publish an information security RACI chart.
C. Benchmark against similar industry organizations.
D. Establish an information security strategy committee.
D
To confirm that a third-party provider complies with an organization's information security requirements, it is MOST important to ensure:
A. contract clauses comply with the organization's information security policy.
B. security metrics are included in the service level agreement (SLA).
C. the information security policy of the third-party service provider is reviewed.
D. right to audit is included in the service level agreement (SLA).
D
Which of the following BEST enables an organization to transform its culture to support information security?
A. Strong management support
B. Robust technical security controls
C. Periodic compliance audits
D. Incentives for security incident reporting
A
An organization is close to going live with the implementation of a cloud-based application. Independent penetration test results have been received that show a high-rated vulnerability. Which of the following would be the BEST way to proceed?
A. Postpone the implementation until the vulnerability has been fixed.
B. Commission further penetration tests to validate initial test results.
C. Assess whether the vulnerability is within the organization's risk tolerance levels.
D. Implement the application and request the cloud service provider to fix the vulnerability.
C
Which of the following is the BEST way to achieve compliance with new global regulations related to the protection of personal information?
A. Review contracts and statements of work (SOWs) with vendors.
B. Determine current and desired state of controls.
C. Execute a risk treatment plan.
D. Implement data regionalization controls.
B
Which of the following should be given the HIGHEST priority during an information security post-incident review?
A. Evaluating incident response effectiveness
B. Documenting actions taken in sufficient detail
C. Evaluating the performance of incident response team members
D. Updating key risk indicators (KRIs)
A
Which of the following is the BEST course of action when an online company discovers a network attack in progress?
A. Shut off all network access points.
B. Isolate the affected network segment.
C. Dump all event logs to removable media.
D. Enable trace logging on all events.
B
Which of the following is the BEST reason for an organization to use Disaster Recovery as a Service (DRaaS)?
A. It transfers the risk associated with recovery to a third party.
B. It eliminates the need for the business to perform testing.
C. It eliminates the need to maintain offsite facilities.
D. It lowers the annual cost to the business.
C
When properly implemented, secure transmission protocols protect transactions:
A. from eavesdropping.
B. in the server's database.
C. from denial of service (DoS) attacks.
D. on the client desktop.
A
An organization is in the process of acquiring a new company. Which of the following would be the BEST approach to determine how to protect newly acquired data assets prior to integration?
A. Review data architecture.
B. Include security requirements in the contract.
C. Perform a risk assessment.
D. Assess security controls.
C
The PRIMARY objective of a post-incident review of an information security incident is to:
A. minimize impact.
B. determine the impact.
C. prevent recurrence.
D. update the risk profile.
C
The MOST appropriate time to conduct a disaster recovery test would be after:
A. the security risk profile has been reviewed.
B. major business processes have been redesigned.
C. the business continuity plan (BCP) has been updated.
D. noncompliance incidents have been filed.
C
Which of the following methods is the BEST way to demonstrate that an information security program provides appropriate coverage?
A. Gap assessment
B. Vulnerability scan report
C. Maturity assessment
D. Security risk analysis
D
Which of the following is an information security manager's MOST important course of action when responding to a major security incident that could disrupt the business?
A. Notify law enforcement.
B. Contact forensic investigators.
C. Follow the escalation process.
D. Identify the indicators of compromise.
C
An information security manager determines there are a significant number of exceptions to a newly released industry-required security standard. Which of the following should be done NEXT?
A. Document risk acceptances.
B. Conduct an information security audit.
C. Assess the consequences of noncompliance.
D. Revise the organization's security policy.
C
Which of the following BEST facilitates effective incident response testing?
A. Including all business units in testing
B. Testing after major business changes
C. Simulating realistic test scenarios
D. Reviewing test results quarterly
C
Which of the following is the BEST indication of effective information security governance?
A. Information security is considered the responsibility of the entire information security team.
B. Information security is integrated into corporate governance.
C. Information security governance is based on an external security framework.
D. Information security controls are assigned to risk owners.
B
The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization. Which of the following should be done FIRST?
A. Re-evaluate the risk.
B. Ask the business owner for the new remediation plan.
C. Inform senior management.
D. Implement compensating controls.
A
Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?
A. Require vendors to complete information security questionnaires.
B. Request customer references from the vendor.
C. Verify that information security requirements are included in the contract.
D. Review the results of the vendor's independent control reports.
D
Security administration efforts will be greatly reduced following the deployment of which of the following techniques?
A. Access control lists
B. Distributed access control
C. Discretionary access control
D. Role-based access control
D
Which of the following would be the BEST way for an information security manager to improve the effectiveness of an organization's information security program?
A. Focus on addressing conflicts between security and performance.
B. Obtain assistance from IT to implement automated security controls.
C. Include information security requirements in the change control process.
D. Collaborate with business and IT functions in determining controls.
D
Which of the following should an information security manager do FIRST upon learning of noncompliance with an impending information security regulatory change?
A. Conduct a business impact and vulnerability analysis.
B. Report the noncompliance to senior management.
C. Assess the risk and cost of noncompliance.
D. Implement the correct measures to become compliant.
C
Which of the following is MOST critical when creating an incident response plan?
A. Identifying what constitutes an incident
B. Identifying vulnerable data assets
C. Documenting incident notification and escalation processes
D. Aligning with the risk assessment process
A
Which of the following would BEST help to ensure appropriate security controls are built into software?
A. Integrating security throughout the development process
B. Performing security testing prior to deployment
C. Providing standards for implementation during development activities
D. Providing security training to the software development team
A
Which of the following will BEST facilitate the integration of information security governance into enterprise governance?
A. Implementing an information security awareness program
B. Documenting the information security governance framework
C. Developing an information security policy based on risk assessments
D. Establishing an information security steering committee
D
Which of the following should an information security manager do FIRST when noncompliance with security standards is identified?
A. Validate the noncompliance
B. Include the noncompliance in the risk register
C. Report the noncompliance to senior management
D. Implement compensating controls to mitigate the noncompliance
A
Which of the following should be considered FIRST when recovering a compromised system that needs a complete rebuild?
A. Network system logs
B. Intrusion detection system (IDS) logs
C. Patch management files
D. Configuration management files
D
When deciding to move to a cloud-based model, the FIRST consideration should be:
A. data classification
B. physical location of the data
C. storage in a shared environment
D. availability of the data
A
Which of the following is the PRIMARY objective of incident triage?
A. Containment of threats
B. Coordination of communications
C. Categorization of events
D. Mitigation of vulnerabilities
C
Who is accountable for ensuring risk mitigation is effective?
A. Application owner
B. Business owner
C. Risk owner
D. Control owner
C
Which of the following BEST enables an information security manager to obtain organizational support for the implementation of security controls?
A. Conducting periodic vulnerability assessments
B. Defining the organization's risk management framework
C. Communicating business impact analysis (BIA) results
D. Establishing effective stakeholder relationships
D
To support effective risk decision making, which of the following is MOST important to have in place?
A. An audit committee consisting of mid-level management
B. Risk reporting procedures
C. Well-defined and approved controls
D. Established risk domains
B
Which of the following parties should be responsible for determining access levels to an application that processes client information?
A. The identity and access management team
B. The business client
C. The information security team
D. Business unit management
D
What should be an information security manager's MOST important consideration when developing a multi-year plan?
A. Ensuring contingency plans are in place for potential information security risks
B. Ensuring alignment with the plans of other business units
C. Demonstrating projected budget increases year after year
D. Allowing the information security program to expand its capabilities
B
When performing a business impact analysis (BIA), who should be responsible for determining the initial recovery time objective (RTO)?
A. Information security manager
B. External consultant
C. Business continuity coordinator
D. Information owner
D
Which of the following will ensure confidentiality of content when accessing an email system over the Internet?
A. Digital encryption
B. Multi-factor authentication
C. Digital signatures
D. Data masking
A
Who is BEST suited to determine how the information in a database should be classified?
A. Information security analyst
B. Database analyst
C. Database administrator (DBA)
D. Data owner
D
Which of the following is an incident containment method?
A. Reviewing system logs and audit trails
B. Removing compromised systems from the network
C. Analyzing systems for impact from the incident
D. Mapping the scope of the incident on the network
B
A CISO learns that a third-party service provider did not notify the organization of a data breach that affected the service provider's data center. Which of the following should the CISO do FIRST?
A. Determine the extent of the impact to the organization.
B. Request an independent review of the provider's data center.
C. Notify affected customers of the data breach.
D. Recommend canceling the outsourcing contract.
A
Which of the following is MOST important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals?
A. Skills required for the incident response team
B. A detailed incident notification process
C. A list of external resources to assist with incidents
D. Service level agreements (SLAs)
B
Which of the following is the PRIMARY role of an information security manager in a software development project?
A. To identify software security weaknesses
B. To identify noncompliance in the early design stage
C. To assess and approve the security application architecture
D. To enhance awareness for secure software design
C
Which of the following MOST effectively identifies issues related to noncompliance with legal, regulatory, and contractual requirements?
A. Compliance maturity assessment
B. Compliance benchmarking data
C. Compliance gap analysis
D. Independent compliance audit
D
Which of the following is MOST helpful for fostering an effective information security culture?
A. Obtaining support from key organizational influencers
B. Implementing comprehensive technical security controls
C. Conducting regular information security awareness training
D. Developing procedures to enforce the information security policy
A
Which of the following is MOST important to convey to employees in building a security risk-aware culture?
A. Employee access should be based on the principle of least privilege.
B. Personal information requires different security controls than sensitive information.
C. The responsibility for security rests with all employees.
D. Understanding an information asset's value is critical to risk management.
C