NEW
Font size
WorksheetsSecurity Domain
Total questions: 20
Worksheet time: 2hrs 40mins
All of the following items should be included in a Business Impact Analysis (BIA) questionnaire EXCEPT questions that
determine the risk of a business interruption occurring
determine the technological dependence of the business processes
Identify the operational impacts of a business interruption
Identify the financial impacts of a business interruption
Which of the following represents the GREATEST risk to data confidentiality?
Network redundancies are not implemented
Security awareness training is not completed
Backup tapes are generated unencrypted
Users have administrative privileges
A While investigating a malicious event, only six days of audit logs from the last month were available. Whatpolicy should be updated to address this problem
Retention
Reporting
Recovery
Remediation
When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?
Only when assets are clearly defined
Only when standards are defined
Only when controls are put in place
Only procedures are defined
An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?
Development, testing, and deployment
Prevention, detection, and remediation
People, technology, and operations
Certification, accreditation, and monitoring
A control to protect from a Denial-of-Service (DoS) attach has been determined to stop 50% of attacks, and additionally reduces the impact of an attack by 50%. What is the residual risk?
25%
50%
75%
100%
Which of the following entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership responsibilities?
Security Governance
Risk Management
Security Portfolio Management
Risk Assessment
Which of the following mandates the amount and complexity of security controls applied to a security risk?
Security Vulnerability
Risk Tolerate
Risk Mitigation
Security Staff
A security professional determines that a number of outsourcing contracts inherited from a previous merger do not adhere to the current security requirements. Which of the following BEST minimizes the risk of this happening again?
Define additional security controls directly after the merger
Include a procurement officer in the merger team
Verify all contracts before a merger occurs
Assign a compliancy officer to review the merger conditions
Which of the following is a direct monetary cost of a security incident?
Morale
Reputation
Equipment
Information
An effective information security policy should include:
Detailed technical instructions for device configuration.
General guidelines and security objectives for the organization.
A list of approved and prohibited software.
Specific technical standards for each department.
Risk management in information security should:
Eliminate all risks to protect organizational information.
Reduce risks to an acceptable level in line with the organization's risk tolerance.
Ignore risks that are deemed small or insignificant.
Be solely the responsibility of the IT team.
Under ISO 31000, the first step in the risk management cycle is:
Evaluating the effectiveness of existing controls.
Assessing the impact of each risk.
Identifying relevant risks.
Developing a risk mitigation plan.
In the context of information security, what does Due Diligence mean?
Taking proactive steps to reduce risk.
Periodically reviewing policies and procedures.
Legal responsibility to implement reasonable security practices.
Ignoring risks based on low impact.
In a legal framework, compliance refers to:
An organization's obligation to meet internal technical standards.
Meeting external standards and regulations applicable to the organization.
Enforcing policies on individuals who violate them.
Fulfilling all customer requests without exception.
The concept of risk transference in risk management can be applied by:
A. Ignoring risks that are too costly to manage.
Insuring organizational assets against certain losses.
Moving high-risk assets to a safer location.
Enhancing hardware security across the board.
Which of the following is a part of the CIA Triad?
Non-repudiation
Audit Control
Incident Response
Accounting
In the context of information security governance, who is responsible for setting policy direction?
IT managers.
The board of directors or senior leaders.
External security auditors.
The information security team.
Residual risk is:
The risk that remains after all controls are applied.
A risk that can be ignored due to minimal impact.
A new risk that emerges after policy changes.
A risk that only applies to financial planning.
Which of the following is an example of a preventive control in information security?
A. Intrusion Detection System (IDS)
Strict password policies.
User activity monitoring logs.
D. Disaster recovery plan.
