<< Prev Question Next Question >>

Question 155/425

Security policies should be aligned MOST closely with:

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (425q)
Question 1: Which of the following should be determined FIRST when estab...
Question 2: The information classification scheme should:...
Question 3: Which of the following would BEST ensure that security risk ...
Question 4: The BEST time to perform a penetration test is after:...
Question 5: The PRIMARY purpose of installing an intrusion detection sys...
Question 6: The MOST appropriate individual to determine the level of in...
Question 7: A customer credit card database has been breached by hackers...
Question 8: Which of the following guarantees that data in a file have n...
Question 9: A message* that has been encrypted by the sender's private k...
Question 10: Which of the following vulnerabilities presents the GREATEST...
Question 11: If an organization considers taking legal action on a securi...
Question 12: How would an organization know if its new information securi...
Question 13: The purpose of a corrective control is to:...
Question 14: What is the MOST important reason for conducting security aw...
Question 15: To ensure that payroll systems continue on in an event of a ...
Question 16: A new e-mail virus that uses an attachment disguised as a pi...
Question 17: Security audit reviews should PRIMARILY:...
Question 18: A contract bid is digitally signed and electronically mailed...
Question 19: What is an appropriate frequency for updating operating syst...
Question 20: Which of the following would be MOST critical to the success...
Question 21: Who can BEST advocate the development of and ensure the succ...
Question 22: To reduce the possibility of service interruptions, an entit...
Question 23: Which of the following is the MOST effective type of access ...
Question 24: When creating a forensic image of a hard drive, which of the...
Question 25: Which of the following is the MOST important risk associated...
Question 26: Which of the following tools is MOST appropriate for determi...
Question 27: When application-level security controlled by business proce...
Question 28: During the restoration of several servers, a critical proces...
Question 29: There is reason to believe that a recently modified web appl...
Question 30: A web server in a financial institution that has been compro...
Question 31: Which of the following is the GREATEST risk of an inadequate...
Question 32: An organization has adopted a practice of regular staff rota...
Question 33: Which of the following is the BEST method to securely transf...
Question 34: Which of the following is MOST important to consider when de...
Question 35: The PRIMARY reason for using metrics to evaluate information...
Question 36: Successful social engineering attacks can BEST be prevented ...
Question 37: Which of the following is the BEST way to determine if an in...
Question 38: In which of the following system development life cycle (SDL...
Question 39: In a well-controlled environment, which of the following act...
Question 40: When a user employs a client-side digital certificate to aut...
Question 41: Which of the following is the BEST method to provide a new u...
Question 42: When security policies are strictly enforced, the initial im...
Question 43: The FIRST priority when responding to a major security incid...
Question 44: To address the issue that performance pressures on IT may co...
Question 45: The BEST way to ensure that security settings on each platfo...
Question 46: Which of the following activities is MOST likely to increase...
Question 47: Which of the following is the MOST important guideline when ...
Question 48: The BEST approach in managing a security incident involving ...
Question 49: The MAIN advantage of implementing automated password synchr...
Question 50: At the conclusion of a disaster recovery test, which of the ...
Question 51: Requiring all employees and contractors to meet personnel se...
Question 52: The MOST important success factor to design an effective IT ...
Question 53: Ensuring that an organization can conduct security reviews w...
Question 54: Which of the following measures is the MOST effective deterr...
Question 55: Which of the following is generally considered a fundamental...
Question 56: An organization provides information to its supply chain par...
Question 57: Which of the following provides the BKST confirmation that t...
Question 58: Which of the following controls is MOST effective in providi...
Question 59: During the security review of organizational servers, it was...
Question 60: Which of the following presents the GREATEST threat to the s...
Question 61: What is the BEST method to confirm that all firewall rules a...
Question 62: Which of the following is MOST effective in preventing the i...
Question 63: What is the BEST way to ensure data protection upon terminat...
Question 64: There is a time lag between the time when a security vulnera...
Question 65: Which of the following security activities should be impleme...
Question 66: As an organization grows, exceptions to information security...
Question 67: An organization without any formal information security prog...
Question 68: Which of the following is the BEST mechanism to determine th...
Question 69: Which of the following is MOST effective in preventing weakn...
Question 70: Which of the following are the essential ingredients of a bu...
Question 71: Which of the following is the MOST important item to conside...
Question 72: Which of the following BEST ensures timely and reliable acce...
Question 73: The FIRST step in an incident response plan is to:...
Question 74: Which of the following actions should be taken when an onlin...
Question 75: Detailed business continuity plans should be based PRIMARILY...
Question 76: Which of the following is the MOST important requirement for...
Question 77: What is the MOST appropriate change management procedure for...
Question 78: An intrusion detection system (IDS) should:...
Question 79: Which of the following is the BEST method to reduce the numb...
Question 80: An organization has a process in place that involves the use...
Question 81: Senior management has approved employees working off-site by...
Question 82: Which of the following is the MOST relevant metric to includ...
Question 83: The effectiveness of the information security process is red...
Question 84: Which of the following is the MOST immediate consequence of ...
Question 85: A root kit was used to capture detailed accounts receivable ...
Question 86: Which of the following is the MOST appropriate individual to...
Question 87: Which of the following security mechanisms is MOST effective...
Question 88: An organization has learned of a security breach at another ...
Question 89: Which of the following is the PRIMARY advantage of having an...
Question 90: An information security manager has completed a risk assessm...
Question 91: When considering whether to adopt a new information security...
Question 92: The IT function has declared that, when putting a new applic...
Question 93: An organization is already certified to an international sec...
Question 94: Which of the following is the MOST serious exposure of autom...
Question 95: What is the BEST way to alleviate security team understaffin...
Question 96: After assessing and mitigating the risks of a web applicatio...
Question 97: An information security manager has been asked to create a s...
Question 98: Of the following, retention of business records should be PR...
Question 99: A data-hosting organization's data center houses servers, ap...
Question 100: Which of the following presents the GREATEST exposure to int...
Question 101: An organization is considering moving one of its critical bu...
Question 102: The MOST important element in achieving executive commitment...
Question 103: Which of the following is the MOST important area of focus w...
Question 104: Which of the following is the BEST indicator that security a...
Question 105: Which of the following will BEST protect against malicious a...
Question 106: Data owners are normally responsible for which of the follow...
Question 107: An organization has verified that its customer information w...
Question 108: An organization is entering into an agreement with a new bus...
Question 109: When performing a qualitative risk analysis, which of the fo...
Question 110: Which of the following ensures that newly identified securit...
Question 111: When designing the technical solution for a disaster recover...
Question 112: When speaking to an organization's human resources departmen...
Question 113: The business advantage of implementing authentication tokens...
Question 114: Which of the following is the BEST approach to mitigate onli...
Question 115: Which of the following is the FIRST phase in which security ...
Question 116: Of the following, the BEST method for ensuring that temporar...
Question 117: In organizations where availability is a primary concern, th...
Question 118: Security governance is MOST associated with which of the fol...
Question 119: An information security manager has developed a strategy to ...
Question 120: Which of the following practices is BEST to remove system ac...
Question 121: Which of the following reduces the potential impact of socia...
Question 122: The PRIMARY purpose of performing an internal attack and pen...
Question 123: Who should determine the appropriate classification of accou...
Question 124: It is MOST important for an information security manager to ...
Question 125: To justify the establishment of an incident management team,...
Question 126: The PRIMARY driver to obtain external resources to execute t...
Question 127: Nonrepudiation can BEST be ensured by using:...
Question 128: Which of the following mechanisms is the MOST secure way to ...
Question 129: When implementing security controls, an information security...
Question 130: Which of the following would BEST protect an organization's ...
Question 131: A semi-annual disaster recovery test has been completed. Whi...
Question 132: Which of the following authentication methods prevents authe...
Question 133: An information security program should be sponsored by:...
Question 134: The BEST reason for an organization to have two discrete fir...
Question 135: Before engaging outsourced providers, an information securit...
Question 136: An intrusion detection system should be placed:...
Question 137: Security awareness training is MOST likely to lead to which ...
Question 138: In the process of deploying a new e-mail system, an informat...
Question 139: To ensure that all information security procedures are funct...
Question 140: Which of the following is the BEST tool to maintain the curr...
Question 141: Which of the following metrics would be the MOST useful in m...
Question 142: Following a significant change to the underlying code of an ...
Question 143: Which of the following is MOST important for a successful in...
Question 144: Which of the following is an inherent weakness of signature-...
Question 145: An account with full administrative privileges over a produc...
Question 146: Which of the following BEST ensures that information transmi...
Question 147: Which of the following is generally used to ensure that info...
Question 148: What is the BEST way to ensure that contract programmers com...
Question 149: What is the MOST important success factor in launching a cor...
Question 150: What is the BEST method for mitigating against network denia...
Question 151: Which of the following processes is critical for deciding pr...
Question 152: Which of the following is the MOST important process that an...
Question 153: A company has a network of branch offices with local file/pr...
Question 154: Primary direction on the impact of compliance with new regul...
Question 155: Security policies should be aligned MOST closely with:...
Question 156: Which of the following BEST enables an information security ...
Question 157: After obtaining commitment from senior management, which of ...
Question 158: What is the BEST method to verify that all security patches ...
Question 159: An information security manager wishing to establish securit...
Question 160: What is the BEST defense against a Structured Query Language...
Question 161: Which of the following documents would be the BEST reference...
Question 162: The "separation of duties" principle is violated if which of...
Question 163: Which of the following, using public key cryptography, ensur...
Question 164: When training an incident response team, the advantage of us...
Question 165: When contracting with an outsourcer to provide security admi...
Question 166: Managing the life cycle of a digital certificate is a role o...
Question 167: Information security policies should:...
Question 168: The advantage of Virtual Private Network (VPN) tunneling for...
Question 169: Which of the following situations would be the MOST concern ...
Question 170: Internal audit has reported a number of information security...
Question 171: The advantage of sending messages using steganographic techn...
Question 172: A serious vulnerability is reported in the firewall software...
Question 173: A computer incident response team (CIRT) manual should PRIMA...
Question 174: A web-based business application is being migrated from test...
Question 175: Which of the following is the MOST effective solution for pr...
Question 176: Which of the following is MOST critical for the successful i...
Question 177: Good information security standards should:...
Question 178: Which of the following would be MOST effective in ensuring t...
Question 179: Which of the following is the MOST important consideration w...
Question 180: Which of the following recovery strategies has the GREATEST ...
Question 181: Which of the following would BEST assist an information secu...
Question 182: Which of the following controls would BEST prevent accidenta...
Question 183: When an organization is using an automated tool to manage an...
Question 184: Which of the following is the MOST important consideration f...
Question 185: Which of the following is the MOST important to ensure a suc...
Question 186: Who is ultimately responsible for ensuring that information ...
Question 187: A post-incident review should be conducted by an incident ma...
Question 188: A large organization is considering a policy that would allo...
Question 189: Which of the following is the MOST likely to change an organ...
Question 190: Which of the following is the BEST indicator that an effecti...
Question 191: A critical device is delivered with a single user and passwo...
Question 192: The PRIMARY reason for assigning classes of sensitivity and ...
Question 193: Nonrepudiation can BEST be assured by using:...
Question 194: Which of the following practices completely prevents a man-i...
Question 195: Which of the following should be in place before a black box...
Question 196: Which of the following BEST enables the deployment of consis...
Question 197: All risk management activities are PRIMARILY designed to red...
Question 198: The configuration management plan should PRIMARILY be based ...
Question 199: Secure customer use of an e-commerce application can BEST be...
Question 200: Which of the following should be performed FIRST in the afte...
Question 201: Which of the following is the MOST effective, positive metho...
Question 202: An organization has implemented an enhanced password policy ...
Question 203: A major trading partner with access to the internal network ...
Question 204: When a new key business application goes into production, th...
Question 205: Which of the following would represent a violation of the ch...
Question 206: What is the GREATEST risk when there is an excessive number ...
Question 207: Evidence from a compromised server has to be acquired for a ...
Question 208: An organization's operations staff places payment files in a...
Question 209: When configuring a biometric access control system that prot...
Question 210: Which of the following would be the BEST indicator that an o...
Question 211: Which of the following represents a PRIMARY area of interest...
Question 212: Which of the following is the BEST metric for evaluating the...
Question 213: Which of the following are the MOST important criteria when ...
Question 214: An information security organization should PRIMARILY:...
Question 215: What is the MOST important item to be included in an informa...
Question 216: Who can BEST approve plans to implement an information secur...
Question 217: The MOST effective use of a risk register is to:...
Question 218: An extranet server should be placed:...
Question 219: When a large organization discovers that it is the subject o...
Question 220: Security awareness training should be provided to new employ...
Question 221: Which would be the BEST recommendation to protect against ph...
Question 222: Which of the following is the BEST way to ensure that a corp...
Question 223: An organization plans to allow employees to use their own de...
Question 224: When considering the value of assets, which of the following...
Question 225: An operating system (OS) noncritical patch to enhance system...
Question 226: An outsource service provider must handle sensitive customer...
Question 227: Which of the following is the BEST metric for evaluating the...
Question 228: When electronically stored information is requested during a...
Question 229: Which of the following would be the FIRST step in establishi...
Question 230: Documented standards/procedures for the use of cryptography ...
Question 231: Which of the following is MOST important in determining whet...
Question 232: Which of the following would BEST mitigate identified vulner...
Question 233: The MOST effective way to ensure network users are aware of ...
Question 234: Which of the following will BEST ensure that management take...
Question 235: Which of the following would be a MAJOR consideration for an...
Question 236: A desktop computer that was involved in a computer security ...
Question 237: An incident response policy must contain:...
Question 238: Which is the BEST way to measure and prioritize aggregate ri...
Question 239: In the course of examining a computer system for forensic ev...
Question 240: Which of the following would be the MOST effective counterme...
Question 241: In an organization, the responsibilities for IT security are...
Question 242: In order to protect a network against unauthorized external ...
Question 243: Which of the following is the MOST important management sign...
Question 244: Which of the following is the MOST important reason why info...
Question 245: An organization with multiple data centers has designated on...
Question 246: Which of the following is MOST effective for securing wirele...
Question 247: Which of the following is MOST effective in preventing secur...
Question 248: The business continuity policy should contain which of the f...
Question 249: Which of the following is a key area of the ISO 27001 framew...
Question 250: Which of the following is the MOST effective solution for pr...
Question 251: What is the BEST way to ensure that an intruder who successf...
Question 252: The BEST way to mitigate the risk associated with a social e...
Question 253: When a newly installed system for synchronizing passwords ac...
Question 254: Who is responsible for raising awareness of the need for ade...
Question 255: An organization that outsourced its payroll processing perfo...
Question 256: Which of the following is the PRIMARY advantage of desk chec...
Question 257: When a proposed system change violates an existing security ...
Question 258: Which of the following will BEST prevent an employee from us...
Question 259: Which resource is the MOST effective in preventing physical ...
Question 260: Which of the following is the MOST important reason for an i...
Question 261: Which of the following is MOST important when deciding wheth...
Question 262: What task should be performed once a security incident has b...
Question 263: In a social engineering scenario, which of the following wil...
Question 264: Isolation and containment measures for a compromised compute...
Question 265: Which of the following devices should be placed within a DMZ...
Question 266: A database was compromised by guessing the password for a sh...
Question 267: The BEST way to determine if an anomaly-based intrusion dete...
Question 268: When performing a business impact analysis (BIA), which of t...
Question 269: Recovery point objectives (RPOs) can be used to determine wh...
Question 270: At what stage of the applications development process would ...
Question 271: The PRIMARY objective of an Internet usage policy is to prev...
Question 272: Which of the following is the BEST method for ensuring that ...
Question 273: Which of the following application systems should have the s...
Question 274: Why is "slack space" of value to an information security man...
Question 275: To determine how a security breach occurred on the corporate...
Question 276: The BEST way to ensure that an external service provider com...
Question 277: To help ensure that contract personnel do not obtain unautho...
Question 278: During a post-incident review, the sequence and correlation ...
Question 279: An information security program should focus on:...
Question 280: Which of the following is the MAIN reason for performing ris...
Question 281: The effectiveness of virus detection software is MOST depend...
Question 282: A business partner of a factory has remote read-only access ...
Question 283: In business-critical applications, user access should be app...
Question 284: A risk assessment study carried out by an organization noted...
Question 285: An information security manager reviewed the access control ...
Question 286: Which of the following is the MOST important element to ensu...
Question 287: Which of the following devices should be placed within a dem...
Question 288: Of the following, whose input is of GREATEST importance in t...
Question 289: What is the FIRST action an information security manager sho...
Question 290: Which of the following will MOST likely reduce the chances o...
Question 291: Which of the following is the MOST appropriate individual to...
Question 292: In addition to backup data, which of the following is the MO...
Question 293: An information security manager uses security metrics to mea...
Question 294: Which of the following tasks should be performed once a disa...
Question 295: Emergency actions are taken at the early stage of a disaster...
Question 296: An e-commerce order fulfillment web server should generally ...
Question 297: Risk assessment is MOST effective when performed:...
Question 298: An internal review of a web-based application system finds t...
Question 299: The MAIN goal of an information security strategic plan is t...
Question 300: Which of the following features is normally missing when usi...
Question 301: Which of the following will protect the confidentiality of d...
Question 302: Which of the following is the MOST important consideration w...
Question 303: Which of the following is a risk of cross-training?...
Question 304: Which of the following is the BEST method to ensure the over...
Question 305: Which of the following has the highest priority when definin...
Question 306: A border router should be placed on which of the following?...
Question 307: Which of the following is the MOST important action to take ...
Question 308: When collecting evidence for forensic analysis, it is import...
Question 309: A test plan to validate the security controls of a new syste...
Question 310: An organization has been experiencing a number of network-ba...
Question 311: What is the MOST effective access control method to prevent ...
Question 312: When developing security standards, which of the following w...
Question 313: Which of the following are the MOST important individuals to...
Question 314: Which of the following defines the triggers within a busines...
Question 315: When developing a tabletop test plan for incident response t...
Question 316: For virtual private network (VPN) access to the corporate ne...
Question 317: Which of the following is MOST difficult to achieve in a pub...
Question 318: A risk management approach to information protection is:...
Question 319: The MOST important reason to use a centralized mechanism to ...
Question 320: Which of the following is MOST important to the successful p...
Question 321: A possible breach of an organization's IT system is reported...
Question 322: Simple Network Management Protocol v2 (SNMP v2) is used freq...
Question 323: Which of the following devices should be placed within a DMZ...
Question 324: Which of the following is MOST effective in protecting again...
Question 325: Which of the following tools is MOST appropriate to assess w...
Question 326: In business critical applications, where shared access to el...
Question 327: Which of the following would present the GREATEST risk to in...
Question 328: The implementation of a capacity plan would prevent:...
Question 329: Security monitoring mechanisms should PRIMARILY:...
Question 330: The PRIORITY action to be taken when a server is infected wi...
Question 331: Which of the following is the MOST appropriate method for de...
Question 332: Which of the following would be MOST appropriate for collect...
Question 333: Prior to having a third party perform an attack and penetrat...
Question 334: Which of the following is the MOST important consideration w...
Question 335: The return on investment of information security can BEST be...
Question 336: An information security manager has been asked to develop a ...
Question 337: An information security manager learns that a departmental s...
Question 338: An organization keeps backup tapes of its servers at a warm ...
Question 339: The BEST way to ensure that information security policies ar...
Question 340: Access control to a sensitive intranet application by mobile...
Question 341: Which of the following is the BEST way to verify that all cr...
Question 342: Which of the following is the MOST important element to ensu...
Question 343: Which of the following is the MOST appropriate frequency for...
Question 344: Which of the following is an example of a corrective control...
Question 345: Which of the following provides the linkage to ensure that p...
Question 346: Which of the following steps should be performed FIRST in th...
Question 347: Which of the following would be the BEST metric for the IT r...
Question 348: Which of the following BEST ensures that modifications made ...
Question 349: Which of the following BEST provides message integrity, send...
Question 350: Which of the following is the MOST critical activity to ensu...
Question 351: The MAIN reason for deploying a public key infrastructure (P...
Question 352: Which of the following actions should be taken when an infor...
Question 353: In an organization, information systems security is the resp...
Question 354: What is the PRIMARY objective of a post-event review in inci...
Question 355: The BEST method for detecting and monitoring a hacker's acti...
Question 356: The BEST metric for evaluating the effectiveness of a firewa...
Question 357: What is the GREATEST advantage of documented guidelines and ...
Question 358: A benefit of using a full disclosure (white box) approach as...
Question 359: Attacks using multiple methods to spread should be classifie...
Question 360: Which of the following is MOST important for measuring the e...
Question 361: Which of the following events generally has the highest info...
Question 362: Which of the following is the MOST appropriate method to pro...
Question 363: An organization has decided to implement additional security...
Question 364: What is the MAIN drawback of e-mailing password-protected zi...
Question 365: Which of the following areas is MOST susceptible to the intr...
Question 366: Which of the following devices could potentially stop a Stru...
Question 367: To mitigate a situation where one of the programmers of an a...
Question 368: Which of the following would be the BEST defense against sni...
Question 369: Which of the following is the MOST important item to include...
Question 370: When developing a security architecture, which of the follow...
Question 371: An information security manager believes that a network file...
Question 372: Which of the following terms and conditions represent a sign...
Question 373: The main mail server of a financial institution has been com...
Question 374: An intranet server should generally be placed on the:...
Question 375: Which of the following actions should lake place immediately...
Question 376: In designing a backup strategy that will be consistent with ...
Question 377: It is important to develop an information security baseline ...
Question 378: Which of the following techniques MOST clearly indicates whe...
Question 379: When an emergency security patch is received via electronic ...
Question 380: Which of the following environments represents the GREATEST ...
Question 381: When properly tested, which of the following would MOST effe...
Question 382: A security awareness program should:...
Question 383: Which of the following is the initial step in creating a fir...
Question 384: What is the BEST way to ensure users comply with organizatio...
Question 385: Which of the following roles is PRIMARILY responsible for de...
Question 386: The MOST important objective of a post incident review is to...
Question 387: Which of the following disaster recovery testing techniques ...
Question 388: Which of the following is MOST important to the success of a...
Question 389: The MOST important reason that statistical anomaly-based int...
Question 390: Of the following, which is the MOST important aspect of fore...
Question 391: An information security manager is advised by contacts in la...
Question 392: Which of the following is the MOST effective way to treat a ...
Question 393: The PRIMARY focus of the change control process is to ensure...
Question 394: A digital signature using a public key infrastructure (PKI) ...
Question 395: Which of the following activities performed by a database ad...
Question 396: The PRIMARY objective of security awareness is to:...
Question 397: Good information security procedures should:...
Question 398: Which of the following change management activities would be...
Question 399: Which of the following would be the MOST appropriate physica...
Question 400: Priority should be given to which of the following to ensure...
Question 401: A data leakage prevention (DLP) solution has identified that...
Question 402: An unauthorized user gained access to a merchant's database ...
Question 403: The BEST protocol to ensure confidentiality of transmissions...
Question 404: An organization faces severe fines and penalties if not in c...
Question 405: What is the BEST policy for securing data on mobile universa...
Question 406: Which of the following is MOST closely associated with a bus...
Question 407: What is the MOST important element to include when developin...
Question 408: Which of the following technologies is utilized to ensure th...
Question 409: The PRIMARY purpose of involving third-party teams for carry...
Question 410: The MOST effective way to ensure that outsourced service pro...
Question 411: On which of the following should a firewall be placed?...
Question 412: Change management procedures to ensure that disaster recover...
Question 413: As part of an international expansion plan, an organization ...
Question 414: Which of the following is the BEST approach for an organizat...
Question 415: When segregation of duties concerns exists between IT suppor...
Question 416: The MOST important reason for formally documenting security ...
Question 417: The BEST way to facilitate the reporting and escalation of p...
Question 418: To BEST improve the alignment of the information security ob...
Question 419: When a departmental system continues to be out of compliance...
Question 420: In the course of responding 10 an information security incid...
Question 421: Previously accepted risk should be:...
Question 422: An incident response team has determined there is a need to ...
Question 423: Which of the following BEST ensures that security risks will...
Question 424: The PRIMARY consideration when defining recovery time object...
Question 425: Which of the following would be MOST effective in the strate...