2.1.7

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/9

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:56 PM on 9/21/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

10 Terms

1
New cards

An IT professional is responsible for ensuring the security of a company's information systems. The professional wants to implement a cybersecurity framework that covers personal data and privacy.

Which of the following industry standard publishers should the IT professional choose?

International Organization for Standardization (ISO)

2
New cards

As a security analyst for a U.S. federal agency, you have been asked by management to make sure that the company meets all requirements for FISMA (the Federal Information Security Modernization Act) in a practical and applicable way for your organization.

At the moment, these requirements are not focused on personal data and privacy.

Which of the following resources would MOST likely provide the guidance that you need to meet the FISMA regulations?

NIST

3
New cards

A cybersecurity team at a large financial organization that uses various operating systems, applications, and hardware devices is responsible for configuring these systems securely to prevent potential security breaches.

As part of their research, they came across a set of global data protection standards maintained by a consortium that help prevent fraud and protect transactions for card transactions.

Which of the following standards is designed to meet these protection requirements?

PCI DSS

4
New cards

A mid-sized company wants to incorporate e-commerce to improve sales. The company has decided to hire an information security consultant to assist in bolstering security measures in preparation for the company's new changes.

The consultant is focusing on the potential risk associated with storing and processing bank information.

What information security standard is the consultant concentrating efforts on?

Payment Card Industry Data Security Standard (PCI DSS)

5
New cards

A compliance team keeps a record of the time between issuing and applying a security patch.

Who would MOST likely be interested in analyzing this type of information on a regular basis?

Risk managers

6
New cards

The Chief Information Security Officer (CISO) for a large pharmaceutical corporation receives a report that a hacktivist has vandalized one of the company's web servers due to an authentication flaw at the server level.

As an organizational leader working to prevent future incidents, what should be the CISO's top priority?

Reviewing the company's service-level objectives and incident response plan to ensure they are in keeping with industry best practices.

7
New cards

An organization has tasked an IT team with implementing vulnerability scanning methods and concepts. They are considering different industry frameworks to use.

Which of the following frameworks focuses on user interaction to prioritize vulnerabilities?

OWASP

8
New cards

A web developer at a startup company is building a new web application. The developer wants to ensure that the application is secure from various types of attacks.

Which of the following frameworks would be the most appropriate for the web developer to use?

Open Web Application Security Project (OWASP)

9
New cards

Which of the following are true statements about CIS Benchmarks? (Select two.)

They can be used to assess the protection of individual systems and configurations.
They are designed to be flexible and scalable.

10
New cards

The solutions architect is in charge of assembling the initial security configuration of various systems on the network, such as Mac, Windows, UNIX, and Linux.

Where would the architect look for configuration guidelines to cover these different systems?

Center for Internet Security (CIS) benchmarks