Font size
WorksheetsISC2 Certified in CyberSecurity Quiz - 2
Total questions: 20
Worksheet time: 10mins
What is the primary goal when it comes to hacking according to the ISC2 Code of Ethics?
To gain personal benefits
To protect society and infrastructure
To cause chaos and disruption
To prove one's technical skills
Who is eligible to file a complaint for violations related to acting honorably, justly, and within laws?
Only employers and clients
Anyone
Other ISC2 professionals
Professionals and employers
An information security professional, Alex, is aware of a colleague who consistently violates the organization's security policies. According to the (ISC)² Code of Ethics, what should Alex consider before filing a complaint?
The colleague's job performance
Whether the violation is intentional or unintentional
The popularity of the security policies within the organization
Alex's personal relationship with the colleague
In the context of fulfilling one's duties diligently and competently, who has the authority to file a complaint?
Anyone
Only employers and clients
Other professionals
Professionals and employers
What is the consequence if you fail to report a witnessed violation of the Code of Ethics?
Verbal warning
Mandatory training
Suspension of certification
Revocation of certification
What does "Standing" mean in the context of making a complaint under the ISC2 Code of Ethics?
The complainant's reputation in the industry
The alleged behavior must harm the complainant or their profession in some way
The complainant's financial status
The complainant's years of experience in the field
Who is responsible for setting policies in a Security Policy Framework?
Employees
Senior Management
IT Department
External Consultants
What is the primary purpose of Guidelines in a Security Policy Framework?
Provide a foundation for the organization's information security program
Describe specific details of security controls
Offer advice on best practices
Outline step-by-step procedures
what is the nature of compliance with Guidelines?
Mandatory
Optional
Depends on Senior Management
Advisory
What is the primary focus of an Acceptable Use Policy (AUP) within the Best Practice of Security Policies?
Password security practices
Protection of sensitive information
Authorized uses of technology
Documentation of technology changes
In the context of Security Policy Framework, what is the role of Password Policies?
Provide advice on best practices
Set the foundation for information security program
Describe specific details of security controls
Enforce password security practices
How are Compliance and Guidelines related in a Security Policy Framework?
Compliance with Guidelines is mandatory
Compliance with Guidelines is optional
Guidelines are not part of compliance
Compliance with Guidelines is determined by the IT department
What is the primary goal of Business Continuity Planning (BCP)?
Confidentiality
Availability
Integrity
Authentication
What does SPOF stand for in the context of system analysis?
Single Point of Failure
Systematic Program of Functions
Secure Point of Focus
Systematic Protection of Files
How does Load Balancing contribute to ensuring the continued operation of systems?
By spreading demand across available systems
By creating redundancy in power supply
By eliminating single points of failure
By providing fault-tolerance to storage media
In Business Impact Assessment (BIA), what is the first step?
Identifying critical IT systems
Conducting a risk assessment
Identifying mission essential functions
Tracing critical systems forward to business activities
What is the purpose of Uninterruptible Power Supplies (UPS) in the context of Business Continuity?
To provide additional power during normal operation
To prevent power disruptions during brief interruptions
To generate power in case of complete power failure
To regulate power distribution across the network
What is the primary function of RAID in the context of storage media?
Backup strategy
Networking redundancy
Fault-Tolerance technique
Data encryption strategy
Maria, an infosec professional, proposes a policy to monitor personal social media for security risks. According to the (ISC)² Code of Ethics, what ethical considerations should she weigh, and how might it impact governance?
Proceed with the policy.
Revise for privacy rights alignment
Escalate to senior management.
Implement selectively for high-security departments
John, a CISO, prioritizes RAID for data storage redundancy in a business continuity plan. The CFO questions the cost, suggesting traditional backups. How should John justify RAID, considering governance processes and critical information protection?
Emphasize RAID cost-effectiveness.
Explain RAID as fault-tolerance, not backup
Remove RAID to cut costs
Propose an alternative tech to the CFO
