Governance, Risk, Compliance and Audit ManagementSecurity Program Management and OperationsSecurity Risk Management, Controls and Audit ManagementInformation Security Core CompetenciesStrategic Planning, Finance, Procurement and Vendor Management
Scenario: An organization has recently appointed a CISO. This is a new role within the organization and signals the growing need to address security consistently at the enterprise level. Although confident in their skills and experience, the new CISO is continually defensive and cannot advance an IT-security-centric agenda.
From an Information Security Leadership perspective, which of the following is a MAJOR concern regarding the CISO's approach to security?
AIT security centric agenda
BLack of risk management process
CLack of risk management process
DCompliance centric agenda
The Information Security Governance program MUST:
Aintegrate with other organizational governance processes
Bshow a return on investment for the organization
Cintegrate with other organizational governance processes
Dsupport user choice for Bring Your Own Device (BYOD)
According to the National Institute of Standards and Technology (NIST) SP 800-30 standard, what is the SECOND step in creating a risk management methodology?
AMitigate risk
BPerform a risk assessment
CDetermine appetite
DEvaluate risk avoidance criteria
Which organizational function typically establishes risk appetite?
ABusiness units
BBoard of Directors
CAudit and compliance
DSecurity
QuestionQ6
Security Risk Management, Controls and Audit Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Security Risk Management, Controls and Audit Management
QuestionQ8
Information Security Core Competencies
QuestionQ9
Governance, Risk, Compliance and Audit Management
QuestionQ10
Security Risk Management, Controls and Audit Management
QuestionQ12
Information Security Core Competencies
QuestionQ13
Security Program Management and Operations
QuestionQ14
Security Risk Management, Controls and Audit Management
QuestionQ15
Security Risk Management, Controls and Audit Management
QuestionQ16
Security Program Management and Operations
QuestionQ17
Security Risk Management, Controls and Audit Management
QuestionQ18
Strategic Planning, Finance, Procurement and Vendor Management
QuestionQ19
Strategic Planning, Finance, Procurement and Vendor Management
QuestionQ20
Information Security Core Competencies
QuestionQ21
Strategic Planning, Finance, Procurement and Vendor Management
QuestionQ22
Strategic Planning, Finance, Procurement and Vendor Management
QuestionQ23
Security Program Management and Operations
QuestionQ24
Security Risk Management, Controls and Audit Management
QuestionQ25
Security Risk Management, Controls and Audit Management
QuestionQ26
Governance, Risk, Compliance and Audit Management
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Which of the following could the company implement to prevent this type of security issue in the future?
ANetwork based intrusion detection systems
BAn audit management process
CA security training program for developers
DA risk management process
When addressing risk, the information security practitioner may elect to:
Aacknowledge
Btransfer
Cassign
Ddefer
The process of identifying, collecting, and producing digital information to support legal proceedings is called _____________________________.
Achain of custody
Belectronic review
Cevidence tampering
Delectronic discovery
Which of the following has the GREATEST effect on implementing an information security governance model?
AComplexity of organizational structure
BDistance between physical locations
COrganizational budget
DNumber of employees
Creating an additional authentication process for network access would be an example of?
ADefense in depth cost enumerated costs
BNonlinearities in physical security performance metrics
CSystem hardening and patching requirements
DAnti-virus for mobile devices
The network administrator wants to enhance the organization’s physical security, specifically by implementing a solution that prevents people from entering certain restricted areas without appropriate credentials. Which of the following physical security measures should the administrator use?
AVideo surveillance
BMantrap
CBollards
DFence
As the Business Continuity Coordinator for a financial services organization, you are responsible for ensuring that assets are recovered on time following a disaster.
Which is the BEST Disaster Recovery performance indicator for validating disaster preparedness?
ARecovery Point Objective (RPO)
BDisaster Recovery Plan
CRecovery Time Objective (RTO)
DBusiness Continuity Plan
Which of the following is used to entice attackers into false environments so they can be monitored, contained, or prevented from reaching critical systems?
ASegmentation controls.
BShadow applications.
CDeception technology.
DVulnerability management.
As the CISO, you have been assigned responsibility for executing the company's key management program. You MUST ensure encryption-key integrity at the point of generation. Which principle of encryption-key control ensures that no single individual can constitute or reconstitute a key?
ADual Control
BSeparation of Duties
CSplit Knowledge
DLeast Privilege
Which of the following best characterizes an access-control process that verifies the identity of an entity requesting entry to a logical or physical area?
AIdentification
BAuthorization
CAuthentication
DAccountability
Simon had all system administrators deploy hardware and software firewalls to ensure network security. They implemented IDS/IPS systems throughout the network to inspect and stop any unauthorized traffic attempting to enter. Although Simon and his administrators believed they were secure, a hacker group was able to enter the network and modify files hosted on the company website. After reviewing the firewall and server logs, no one could determine how the attackers gained access. He decides that the entire network must be monitored for changes to critical and essential files. This monitoring tool alerts administrators when a critical file is modified. What tool could Simon and his administrators implement to accomplish this?
AThey need to use Nessus.
BThey can implement Wireshark.
CSnort is the best tool for their situation.
DThey could use Tripwire.
A newly appointed CISO needs to understand the organization’s financial-management standards for its business units and operations. Which of the following is the best source for this information?
AThe internal accounting department
BThe Chief Financial Officer (CFO)
CThe external financial audit service
DThe managers of the accounts payables and accounts receivables teams
Which of the following statements accurately describes capital expenses?
AThey are easily reduced through the elimination of usage, such as reducing power for lighting of work areas during off-hours
BCapital expenses can never be replaced by operational expenses
CCapital expenses are typically long-term investments with value being realized through their use
DThe organization is typically able to regain the initial cost by selling this type of asset
What does password aging mean?
AAn expiration date set for passwords
BA Single Sign-On requirement
CTime in seconds a user is allocated to change a password
DThe amount of time it takes for a password to activate
Which option best defines revenue?
ANon-operating financial liabilities minus expenses
BThe true profit-making potential of an organization
CThe sum value of all assets and cash flow into the business
DThe economic benefit derived by operating a business
Where does bottom-up financial planning mainly obtain the information used to create budgets?
ABy adding all capital and operational costs from the prior budgetary cycle, and determining potential financial shortages
BBy reviewing last year's program-level costs and adding a percentage of expected additional portfolio costs
CBy adding the cost of all known individual tasks and projects that are planned for the next budgetary cycle
DBy adding all planned operational expenses per quarter then summarizing them in a budget request
Which of the following is a primary way to apply consistent configurations across IT systems?
AAudits
BAdministration
CPatching
DTemplates
Which of the following should be identified when defining risk management strategies?
AOrganizational objectives and risk tolerance
BEnterprise disaster recovery plans
CRisk assessment criteria
DIT architecture complexity
A global retail organization intends to implement a uniform Disaster Recovery and Business Continuity Process across all its business units.
Which of the following standards and guidelines can BEST meet this organization's need?
AInternational Organization for Standardizations ג€" 22301 (ISO-22301)
Community Discussion