NEW
Font size
WorksheetsSec+ Day 7
Total questions: 49
Worksheet time: 25mins
Which of the following is NOT included in governance for security policies?
Clearly defining roles and responsibilities
Setting security standards
Ensuring compliance with legal and regulatory requirements
Configuring Dynamic Routing Protocols
What is the primary responsibility of Governance Boards?
Implementing marketing strategies
Overseeing an organization's security policies and practices
Managing financial accounts
Developing new products
Who typically makes up Governance Boards?
Junior employees and interns
Marketing and sales teams
Senior executives and stakeholders
CIRT Team & Legal Representatives
What do Governance Boards ensure regarding security measures?
They are cost-effective
They align with the organization's objectives and regulatory requirements
They are innovative and unique
They are easy to implement
Who are strategic plans primarily defined by?
Junior employees
Middle management
Senior management
External consultants
What is the main purpose of strategic plans?
To address short-term issues
To meet long-term goals
To increase daily productivity
To reduce costs immediately
Which of the following might be included in a strategic security plan?
Increase sales by 10%
Ensure our customers know their data is safe
Hire more staff
Transfer sensitive databases into a secure cloud environment
What are tactical plans designed to meet?
Specific strategic objectives
Long-term goals
Personal development goals
Financial targets
To whom may tactical plans be delegated?
Mid-level management
Entry-level employees
External consultants
Customers
What is an example of a tactical plan?
Assuring the public that all HIPAA and PCI DSS regulations will be strictly adhered to
Increasing annual revenue by 20%
Bringing the customer database into compliance with new privacy law
Expanding into international markets
What do operational plans describe?
How to perform day-to-day operations in ways that meet higher-level plans
How to create long-term strategic goals
How to manage financial resources
How to develop marketing strategies
Who typically creates or administers operational plans?
Top-level management
Low-level management
External consultants
Middle-level management
What is an example of an operational plan?
Updating database software
Setting company vision
Developing a new product line
Conducting market research
What is the primary purpose of organizational policies?
To increase profits
To guide operations, decision-making, and behaviors
To reduce employee workload
To enhance marketing strategies
What is governance in the context of organizational policies?
The process of hiring new employees
The processes used to direct and control an organization
The method of increasing sales
The strategy for increasing network uptime and reducing maintenance window times
Which of the following is an example of a common organizational policy?
Marketing Strategy Policy
Acceptable Use Policy (AUP)
Employee Satisfaction Policy
Product Development Policy
What does compliance ensure in an organization?
Increased profits
Adherence to regulations, policies, standards, and laws
Better customer service
Faster product development
What is the purpose of Information Security Policies?
To ensure IT users comply with security rules and guidelines.
To focus on critical processes during and after disruptions.
To detail steps for recovering from catastrophic events.
To govern software development processes.
What does Business Continuity & Continuity of Operations Plans (COOP) focus on?
Critical processes during and after disruptions.
Software development processes.
Steps for recovering from catastrophic events.
How IT system and software changes are managed.
What is the main goal of Disaster Recovery?
To restore operations quickly and efficiently.
To protect information within the organization’s control.
To ensure software meets efficiency, reliability, and security standards.
To outline processes after security breaches or cyber-attacks.
What does Incident Response outline?
Processes after security breaches or cyber-attacks.
How IT system and software changes are managed.
Steps for recovering from catastrophic events.
Software development processes.
What is the purpose of the Software Development Life Cycle (SDLC)?
To govern software development processes.
To ensure operations remain functional during events like natural disasters.
To detail steps for identifying, investigating, controlling, and mitigating incidents.
To outline how IT system and software changes are managed.
What does Change Management outline?
How IT system and software changes are managed.
Steps for recovering from catastrophic events.
How network devices are deployed during peak hours
Critical processes during and after disruptions.
What are Information Security Policies?
Informal guidelines for IT users
Formal documents outlining rules and procedures
Technical manuals for software installation
Marketing strategies for IT companies
What do Information Security Policies define?
Secure device configurations and patching schedules
Acceptable use of resources, security measures, and responsibilities of employees
Tactical goals for encrypting PII
Customer service protocols
What does BCP stand for in the context of business operations?
Business Continuity Plan
Business Communication Plan
Business Compliance Plan
Business Coordination Plan
What is the primary focus of COOP?
Long-term business growth
Maintaining mission-essential functions during emergencies
Enhancing customer satisfaction
Reducing operational costs
Which of the following is a characteristic of BCP?
Short-term continuity focus
Covers all critical business operations
Primarily for emergency situations
Focuses on customer service
What is the main difference between BCP and COOP?
BCP is for short-term, COOP is for long-term
BCP covers all operations, COOP focuses on mission-essential functions
BCP is for emergencies, COOP is for regular operations
BCP is more specific, COOP is broader
What is the primary goal of change management in IT systems?
To increase the speed of system updates
To minimize disruptions and ensure security
To reduce the cost of system changes
To eliminate the need for documentation
Which of the following is a key component of change management?
Change Elimination
Change Request
Change Ignorance
Change Delay
What does the Change Control Board (CCB) do?
Implement changes directly
Review and approve change requests
Apply best practices and increase delays for change requests
Delay change implementation
Why is testing important before implementing a change?
To ensure it works as expected
To increase the complexity of the system
To reduce the number of stakeholders
To eliminate the need for documentation
What is the final step in the change management process?
Planning
Documentation
Implementation
Review
What is the purpose of a back-out plan in change management?
To ensure all changes are documented
To reverse changes due to unforeseen issues
To test changes in a sandbox environment
To implement changes during maintenance
Why is documentation important in the change management process?
It reduces the time it takes for future changes on newly acquired systems
It keeps detailed records of the change process
It speeds up the implementation of changes
It eliminates the need for testing
Which of the following is NOT a step in the change management process for updating firmware on a router?
Submitting a change request
Implementing the update without testing
Testing the update in a sandbox environment
Documenting the entire process
What is one of the benefits of effective change management?
It increases the frequency of changes
It prevents unauthorized changes
It eliminates the need for maintenance
It reduces the need for documentation
What are guidelines primarily used for in a job role or department?
To enforce strict rules and regulations
To provide recommendations that steer actions
To replace policies entirely
To eliminate the need for discretion
How do guidelines differ from policies?
Guidelines are more rigid than policies
Guidelines are mandatory rules
Guidelines allow for flexibility and individual discretion
Guidelines eliminate the need for policies
What is one purpose of guidelines?
To enforce penalties for non-compliance
To provide best practices and suggestions for achieving goals
To replace all existing policies
To restrict individual judgment
Which of the following is an example of a guideline for help desk support?
Mandatory use of a specific software
Recommended response times
Strict adherence to a single communication method
Elimination of email support
What is the primary goal of security policies?
To increase company profits
To ensure the organization follows best practices to protect its informational assets
To reduce employee workload
To expand the organization's market reach
What are external requirements in a governance-based approach?
Preferences of the CEO
Requirements set by outside stakeholders
Suggestions from employees
Feedback from customers
What is often the most complex and time-consuming regulatory challenge?
Internal audits
Regulations imposed by governmental agencies or industry bodies
Employee training programs
Customer satisfaction surveys
What must organizations comply with according to compliance obligations?
Only local laws
All relevant national, state, or territory laws
Only international laws
Only industry standards
What is the purpose of step-by-step instructions and checklists?
To ensure tasks are completed quickly
To ensure consistency, compliance, and repeatability
To reduce the number of employees needed
To increase the complexity of tasks
What do playbooks typically serve as in Security Operations Centers (SOC)?
A guide for financial planning
A guide for responding to various scenarios and incidents
A guide for recovering from a honeynet breach
A guide for employee training
Which of the following is an example of a procedure?
Marketing Analysis
Onboarding/Offboarding
Product Design
Financial Auditing
