wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISC2 - CC - Chapter 1 - Module 4

Total questions: 26

Worksheet time: 13mins

Name
Class
Date
1.
What is governance?
a)
The laws imposed by the government
b)
The regulations, standards, policies y procedures accepted worldwide
c)
How organizations follow protocols imposed by the government
d)
How organizations make decisions in order to fulfill their purposes
2.
Which governance element comes usually in form of laws?
a)
Policy
b)
Standard
c)
Procedure
d)
Regulation
3.
Governments can impose financial penalties as a consequence of breaking a:?
a)
Policy
b)
Standard
c)
Procedure
d)
Regulation
4.
Which regulation provides a framework for the protection of personal data and privacy within the European Union?
a)
HIPAA
b)
PCI-DSS
c)
GDPR
d)
ISO 27001
5.
Which regulation requires organizations to notify individuals affected by a data breach?
a)
GDPR
b)
HIPAA
c)
ISO 27001
d)
PCI-DSS
6.
Which regulation requires organizations to establish controls to protect electronic protected health information (ePHI)?
a)
GDPR
b)
HIPAA
c)
ISO 27001
d)
PCI-DSS
7.
Which regulation is focused on safeguarding healthcare information and sets standards for the privacy and security of patient data?
a)
GDPR
b)
HIPAA
c)
ISO 27001
d)
PCI-DSS
8.
Which governance element guide organizations to operate with widely accepted best practices?
a)
Regulations
b)
Procedures
c)
Standards
d)
Policies
9.
Frameworks, often offered by third-party organizations, that cover specific advisory or compliance objectives are:?
a)
Regulations
b)
Procedures
c)
Standards
d)
Policies
10.
Which standard provides best practices for securing payment card data within the payment card industry?
a)
ISO 27002
b)
PCI-DSS
c)
ISO 27001
d)
NIST SP 800-53
11.
Which standard provides guidelines for implementing an information security management system (ISMS)?
a)
ISO 27002
b)
NIST SP 800-53
c)
ISO 27001
d)
CIS Controls
12.
Which standard provides guidelines for implementing security controls?
a)
GDPR
b)
PCI-DSS
c)
ISO 27001
d)
ISO 27002
13.

Which standard provides a catalog of security and privacy controls for all U.S. federal information systems?

a)

ISO 27002

b)

NIST SP 800-53

c)

ISO 27001

d)

HIPAA

14.
Which of the following governance elements are broad statements that establish context and sets out strategic direction and priorities of the organization?
a)
Regulations
b)
Procedures
c)
Standards
d)
Policies
15.
Which of the following are the highest-level governance documents within an organization?
a)
Regulations
b)
Procedures
c)
Standards
d)
Policies
16.
Who dictates high-level policies?
a)
The security manager
b)
The Human Resources office
c)
Senior management
d)
Auditors
17.
To which of the following should a security professional report violations of a security policy when working for a company?
a)
National authorities
b)
Company management
c)
A court of law
d)
Nobody
18.
Which of the following governance elements modulate the behavior of employees within an organization?
a)
Regulations
b)
Procedures
c)
Standards
d)
Policies
19.
Which policy governs the acceptable use of organizational IT resources?
a)
Password policy
b)
Incident response policy
c)
Remote access policy
d)
Acceptable use policy
20.
Which policy outlines the organization's approach to managing passwords and access credentials?
a)
Password policy
b)
Data classification policy
c)
Incident response policy
d)
Acceptable use policy
21.
Which procedure outlines the steps to be followed when responding to a cybersecurity incident?
a)
Disaster Recovery Plan (DRP)
b)
Change management procedure
c)
Incident Response Plan (IRP)
d)
Vulnerability management plan
22.
The detailed steps to complete tasks supporting departmental or organizational policies are typically documented in:?
a)
Policies
b)
Regulations
c)
Procedures
d)
Standards
23.
Which procedure outlines the steps to be followed to respond to cybersecurity incidents?
a)
Disaster Recovery Plan (DRP)
b)
Incident Response Plan (IRP)
c)
Business Continuity Plan (BCP)
d)
Vulnerability management plan
24.
Which procedure outlines the steps to be followed to maintain business operations while recovering from a cybersecurity incident?
a)
Risk assessment procedure
b)
Business Impact Analysis
c)
Business Continuity Plan (BCP)
d)
Vulnerability management plan
25.
Which procedure outlines the steps to be followed after a disaster?
a)

Business Continuity Plan (BCP)

b)

Disaster Recovery Plan (DRP)

c)

Incident Response Plan (IRP)

d)

Vulnerability management plan (VMP)

26.

The senior leadership of Triffid Corporation decides that the best way to minimize liability for the company is to demonstrate the company's commitment to adopting best practices recognized throughout the industry. Triffid management issues a document that explains that Triffid will follow the best practices published by NIST, an industry body that addresses computer and information security. The Triffid document is a ______, and the NIST document are ________?

a)

Law, policy

b)

Policy, standard

c)

Policy, law

d)

Procedure, procedure