NEW
Font size
Worksheetsisc2 sample questions
Total questions: 14
Worksheet time: 7mins
What is the primary goal of the risk management process?
To identify the Assess and mitigate risks
Which module of security principles focuses on establishing guidelines for security behavior within an organization?
Module 1: Understand the Security Concepts of Information Assurance
Module 2: Understand the Risk Management Process
Module 3: Understand Security Controls
Module 5: Understand ISC2 Code of Ethics
What is the primary focus of the module that involves the identification, analysis, and prioritization of incidents in incident response?
Module 1: Understand Incident Response
Module 2: Understand Business Continuity
Module 3: Understand Disaster Recovery
What is the primary purpose of physical access controls?
To restrict access to computer systems and networks
To secure physical locations and assets
To encrypt data transmissions
To prevent malware infections
Which of the following is NOT one of the CIA triad principles of information security?
Confidentiality
Integrity
Availability
Reliability
What is the first step in the risk management process?
Implement risk mitigation strategies.
Identify and assess risks
Monitor and review risks.
Develop risk acceptance criteria.
Which type of control is most effective in preventing unauthorized physical access to a data center?
Preventive control
Detective control
Corrective control
Recovery control
What is the primary objective of an organization's security policy?
To define network architecture.
To outline ethical guidelines for employees.
To establish clear expectations for security practices.
To specify incident response procedures.
A security professional discovers a critical vulnerability in a client's system. According to the ISC2 code of ethics, what is the MOST appropriate action?
Inform the public immediately.
Ignore the vulnerability if it doesn't affect their own systems.
Report the vulnerability to the client responsibly.
Exploit the vulnerability for personal gain.
Which of the following is NOT a typical component of a disaster recovery plan?
Data backup and restoration procedures
Communication protocols
Employee training and testing
Marketing strategies
What is the key difference between business continuity and disaster recovery?
Business continuity focuses on data recovery, while disaster recovery addresses physical infrastructure.
Business continuity is proactive, while disaster recovery is reactive.
Business continuity focuses on technology, while disaster recovery focuses on personnel.
There is no significant difference.
The primary objective of an incident response plan is to
Assign blame for the incident
Contain the incident and minimize damage
Train employees on incident prevention
Update security policies
What is the primary purpose of the ISC2 Code of Ethics?
Define security standards
Guide professional conduct
Outline certification requirements
Specify security controls
Which type of control aims to prevent unauthorized access to information?
Preventive
Detective
Corrective
Recovery
