<< Prev Question Next Question >>

Question 45/400

What should the information security manager do FIRST when end users express that new security controls are too restrictive?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (400q)
Question 1: During the restoration of several servers, a critical proces...
Question 2: Which of the following is PRIMARILY influenced by a business...
Question 3: Which of the following is BEST to include in a business case...
Question 4: Which of the following elements of risk is MOST difficult to...
Question 5: A message is being sent with a hash. The risk of an attacker...
Question 6: To meet operational business needs. IT staff bypassed the ch...
Question 7: Which of the following would be an information security mana...
Question 8: Which of the following sites would be MOST appropriate in th...
Question 9: Which of the following has the GREATEST impact on efforts to...
Question 10: Which of the following is the PRIMARY reason to conduct peri...
Question 11: Which of the following BEST supports the alignment of inform...
Question 12: Which of the following is the BEST strategy to implement an ...
Question 13: Several identified risks have been mitigated to an acceptabl...
Question 14: Which of the following is MOST helpful in determining the pr...
Question 15: Which of the following is BEST performed by the security dep...
Question 16: An organization s senior management wants to allow employees...
Question 17: An information security manager is concerned that executive ...
Question 18: Which of the following is MOST important when prioritizing a...
Question 19: Which of the following is the BEST reason to reassess risk f...
Question 20: To ensure IT equipment meets organizational security standar...
Question 21: Which of the following is the GREATEST security threat when ...
Question 22: An organization has established information security policie...
Question 23: There are concerns that security events are not reported to ...
Question 24: An information security manager is implementing controls to ...
Question 25: An organization recently implemented a data loss prevention ...
Question 26: Which of the following is the BEST way to address any gaps i...
Question 27: Which of the following is MOST helpful when justifying the f...
Question 28: Which of the following is the BEST way to ensure that organi...
Question 29: Which of the following is the BEST resource for evaluating t...
Question 30: When implementing a new risk assessment methodology, which o...
Question 31: Shortly after installation, an intrusion detection system (I...
Question 32: A new program has been implemented to standardize security c...
Question 33: When monitoring the security of a web-based application, whi...
Question 34: The use of digital signatures ensures that a message:...
Question 35: When facilitating the alignment of corporate governance and ...
Question 36: The PRIMARY responsibility to communicate with legal authori...
Question 37: Which of the following is MOST important to enable after com...
Question 38: The BEST way to avoid session hijacking is to use:...
Question 39: Labeling information according to its security classificatio...
Question 40: Which of the following is MOST important to consider when de...
Question 41: An organization's information security strategy for the comi...
Question 42: Which of the following would be MOST important to include in...
Question 43: Conducting a cost-benefit analysis for a security investment...
Question 44: A team developing an interface to a key financial system has...
Question 45: What should the information security manager do FIRST when e...
Question 46: The MOST effective way to continuously monitor an organizati...
Question 47: Which of the following is a PRIMARY responsibility of an inf...
Question 48: An organization is considering moving one its critical busin...
Question 49: In addition to cost what is the BEST criteria for selecting ...
Question 50: The MOST important reason to maintain metrics for incident r...
Question 51: When supporting a large corporation's board of directors in ...
Question 52: A significant gap in an organization's breach containment pr...
Question 53: Which of the following is the STRONGEST indication that seni...
Question 54: Which of the following is MOST likely to be included in an e...
Question 55: Which of the following is the BEST way to measure the effect...
Question 56: Which of the following is MOST important when developing a s...
Question 57: What is the BEST way for a customer to authenticate an e-com...
Question 58: To ensure appropriate control of information processed in IT...
Question 59: Which of the following is the MOST important reason to consi...
Question 60: Which of the following would present the GREATEST challenge ...
Question 61: An information security manager recently received funding fo...
Question 62: Which of the following outsourced services has the GREATEST ...
Question 63: An organization's IT department is undertaking a large virtu...
Question 64: Which of the following factors are the MAIN reasons why larg...
Question 65: A payroll application system accepts individual user sign-on...
Question 66: Which of the following will identify a deviation in the info...
Question 67: The head of a department affected by a recent security incid...
Question 68: When integrating information security requirements into soft...
Question 69: Which of the following circumstances would MOST likely requi...
Question 70: Information security governance is PRIMARILY driven by which...
Question 71: Which of the following will BEST ensure that risk is evaluat...
Question 72: Which of the following BEST demonstrates alignment between i...
Question 73: Which of the following should be the PRIMARY objective when ...
Question 74: Which of the following BEST enables an information security ...
Question 75: Which of the following is the PRIMARY reason to include mess...
Question 76: Which of the following is the MOST important reason to have ...
Question 77: Which of the following is the PRIMARY reason social media ha...
Question 78: Which of the following is the MOST beneficial outcome of tes...
Question 79: Which of the following metrics is MOST useful to demonstrate...
Question 80: Which of the following is the BKT approach for an informatio...
Question 81: Which of the following defines the triggers within a busines...
Question 82: The authorization to transfer the handling of an internal se...
Question 83: Which of the following is MOST likely to result from a prope...
Question 84: Which aspect of an incident response plan will MOST effectiv...
Question 85: Which of the following is an information security manager's ...
Question 86: Which of the following is the GREATEST risk of single sign-o...
Question 87: Which of the following is the MOST important consideration o...
Question 88: The MOST important outcome of information security governanc...
Question 89: Which of the following BEST demonstrates the performance of ...
Question 90: The selection of security controls is PRIMARILY linked to:...
Question 91: It is suspected that key emails have been viewed by unauthor...
Question 92: An organization has outsourced many application development ...
Question 93: When two different controls are available to mitigate a risk...
Question 94: A risk assessment report shows that phishing attacks are an ...
Question 95: Which of the following is the BEST way to determine if an in...
Question 96: An organization has decided to store production data in a cl...
Question 97: Which of the following is MOST critical for prioritizing act...
Question 98: Which of the following is the BEST way for an organization t...
Question 99: Which of the following is an information security manager's ...
Question 100: Which of the following is MOST important when selecting a th...
Question 101: Which of the following defines the minimum security requirem...
Question 102: A new regulation has been announced that requires mandatory ...
Question 103: Which is MOST important to enable a timely response to a sec...
Question 104: Which of the following threats is prevented by using token-b...
Question 105: Which of the following BEST promotes stakeholder accountabil...
Question 106: What should be the PRIMARY basis for defining the appropriat...
Question 107: In a resource-restricted security program, which of the foll...
Question 108: An organization was forced to pay a ransom to regain access ...
Question 109: Which of the following would be an information security mana...
Question 110: Which of the following is MOST important to consider when de...
Question 111: Which of the following is the PRIMARY reason for performing ...
Question 112: Which of the following is the MOST effective approach for in...
Question 113: What is the PRIMARY purpose of communicating business impact...
Question 114: Which of the following is MOST critical for the successful i...
Question 115: Which of the following is the MOST important outcome of moni...
Question 116: Organization XYZ. a lucrative, Internet-only business, recen...
Question 117: When defining responsibilities with a cloud computing vendor...
Question 118: Which of the following would MOST likely require a business ...
Question 119: Using which of the following metrics will BEST help to deter...
Question 120: A hash algorithm is used to:
Question 121: Which of the following provides a sound basis for effective ...
Question 122: Which of the following is the BEST option for addressing reg...
Question 123: An organization is developing a disaster recover/ plan for a...
Question 124: Which of the following is MOST important to include in contr...
Question 125: When preventative controls to appropriately mitigate risk ar...
Question 126: What should the information security manager recommend to su...
Question 127: What is the PRIMARY benefit to executive management when aud...
Question 128: Which of the following is MOST helpful to review to gain an ...
Question 129: Which of the following is the PRIMARY purpose of data classi...
Question 130: An organization's information security manager is performing...
Question 131: An organization has experienced a ransomware attack. Which o...
Question 132: What should an information security manager do NEXT when man...
Question 133: What should be an information security manager's BEST course...
Question 134: Which of the following should be done FIRST when handling mu...
Question 135: The PRIMARY goal of a post-incident review should be to...
Question 136: An incident was detected where customer records were altered...
Question 137: Which of the following should be the FIRST step when creatin...
Question 138: For proper escalation of events, it is MOST important for th...
Question 139: Which of the following is the MOST important characteristic ...
Question 140: Which of the following is the BEST method for management to ...
Question 141: A global organization is developing an incident response tea...
Question 142: Recovery time objectives (RTOs) are an output of which of th...
Question 143: Which of the following is MOST important for an information ...
Question 144: The MAIN reason for internal certification of web-based busi...
Question 145: Which of the following is MOST important for an information ...
Question 146: For an organization that encourages sales activities using m...
Question 147: An information security manager has identified multiple area...
Question 148: Mitigating technology risks to acceptable levels should be b...
Question 149: Which of the following would BEST enable management to be aw...
Question 150: Which of the following is MOST useful to include in a report...
Question 151: Which of the following is the MOST effective method to preve...
Question 152: Which of the following is the MOST important reason for logg...
Question 153: When creating a bring your own device (BYOD) program, it is ...
Question 154: An information security manager has identified and implement...
Question 155: Risk management is MOST cost-effective;...
Question 156: When a critical incident cannot be contained in a timely man...
Question 157: When training an incident response team, the advantage of us...
Question 158: Following a successful and well-publicized hacking incident,...
Question 159: A third-party service provider is developing a mobile app fo...
Question 160: Which of the following should an information security manage...
Question 161: Which of the following should be communicated FIRST to senio...
Question 162: An information security manager suspects that the organizati...
Question 163: Which of the following is MOST likely to reduce the effectiv...
Question 164: Which of the following provides the GREATEST assurance that ...
Question 165: Which of the following is the GREATEST benefit of integratin...
Question 166: Which of the following should be of GREATEST concern to a ne...
Question 167: Which of the following is the MOST effective way for senior ...
Question 168: Which of the following is the MOST important delivery outcom...
Question 169: Which of the following would BEST enable an effective respon...
Question 170: Which of the following should be the PRIMARY goal of an Info...
Question 171: When creating security baselines, it is MOST important to:...
Question 172: For computer forensics evidence to be admissible in a court ...
Question 173: Which of the following is the BEST way to provide management...
Question 174: Which of the following is the PRIMARY benefit to an organiza...
Question 175: Which of the following BEST contributes to the successful ma...
Question 176: What should an information security manager do FIRST when ma...
Question 177: Which of the following is the MOST important reason for an o...
Question 178: An information security manager learns that a departmental s...
Question 179: The PRIMARY reason for classifying assets is to:...
Question 180: A system administrator failed to report a security incident ...
Question 181: Which of the following metrics would provide management with...
Question 182: During the due diligence phase of an acquisition, the MOST i...
Question 183: Which of the following is the MOST effective way for an orga...
Question 184: An information security manager is developing evidence prese...
Question 185: Which of the following is the FIRST step when defining and p...
Question 186: When is the BEST time to identify the potential regulatory r...
Question 187: Which of the following is an information security manager's ...
Question 188: Which of the following is MOST important for an information ...
Question 189: Which of the following is MOST important for an information ...
Question 190: When developing a new application, which of the following is...
Question 191: Which of the following is the BEST way to prevent segregatio...
Question 192: When developing an escalation process for an incident respon...
Question 193: Which of the following would provide the HIGHEST level of co...
Question 194: In addition to business alignment and security ownership, wh...
Question 195: Which of the following is the MOST effective way to mitigate...
Question 196: An emergency change was made to an IT system as a result of ...
Question 197: Which of the following is the BEST method to defend against ...
Question 198: Which of the following is the MOST important security consid...
Question 199: Reviewing which of the following would provide the GREATEST ...
Question 200: Which of the following is an example of a vulnerability?...
Question 201: The MOST important reason to maintain key risk indicators (K...
Question 202: Implementing a strong password policy is part of an organiza...
Question 203: Which of the following is MOST critical to the successful im...
Question 204: Which of the following would provide the BEST input to a bus...
Question 205: The PRIMARY objective of a risk response strategy should be:...
Question 206: Which of the following is the MOST important reason to docum...
Question 207: Risk scenarios simplify the risk assessment process by:...
Question 208: Risk identification, analysis, and mitigation activities can...
Question 209: Which of the following is the BEST way for an information se...
Question 210: When developing a protection strategy for outsourcing applic...
Question 211: An organization establishes an internal document collaborati...
Question 212: The PRIMARY reason an organization would require that users ...
Question 213: Which of the following poses the GREATEST risk to the operat...
Question 214: An organization with a strict need-to-know information acces...
Question 215: Which of the following BEST supports information security ma...
Question 216: An information security manager wants to justify the Investm...
Question 217: An organization us&amp; a particular encryption protocol for...
Question 218: Which of the following is MOST important to have in place to...
Question 219: Which of the following is the GREATEST benefit of integratin...
Question 220: When trying to integrate information security across an orga...
Question 221: Calculation of the recovery time objective (RTO) is necessar...
Question 222: An information security program should be established PRIMAR...
Question 223: Which of the following would provide senior management with ...
Question 224: The PRIMARY role of an information security steering group i...
Question 225: Which type of test is MOST effective in communicating the ro...
Question 226: What should an information security manager do FIRST after a...
Question 227: Which of the following metrics would be considered an accura...
Question 228: Which of the following is the BEST way to demonstrate to sen...
Question 229: Which of the following is the BEST mechanism to prevent data...
Question 230: Which of the following statements indicates that a previousl...
Question 231: Conflicting objectives are MOST likely to compromise the eff...
Question 232: What is the BEST way to manage access to data and applicatio...
Question 233: What is the role of the information security manager in fina...
Question 234: A business impact analysis (BIA) should be periodically exec...
Question 235: Which of the following BEST enables an effective escalation ...
Question 236: Which of the following is MOST relevant for an information s...
Question 237: When preparing a business case for the implementation of a s...
Question 238: Which of the following should provide the PRIMARY basis for ...
Question 239: Which of the following tools BEST demonstrates the effective...
Question 240: Which of the following would be MOST helpful to an informati...
Question 241: What is the MOST effective way to ensure information securit...
Question 242: When selecting risk response options to manage risk, an info...
Question 243: Which of the following is MOST important for an information ...
Question 244: Which of the following should be an information security man...
Question 245: A newly hired information security manager for a small organ...
Question 246: A multinational organization has developed a bring your own ...
Question 247: The PRIMARY reason for using information security metrics is...
Question 248: An internal security audit has reported several control weak...
Question 249: An organization has concerns regarding a potential advanced ...
Question 250: A security incident has resulted in a failure of the enterpr...
Question 251: Which activity is MOST important when identifying the approp...
Question 252: An information security manager wants to implement a securit...
Question 253: Which of the following would provide the MOST useful input w...
Question 254: When developing an information security governance framework...
Question 255: Which of the following is MOST important when selecting an i...
Question 256: Relying on which of the following methods when detecting new...
Question 257: In the development of an information security strategy, reco...
Question 258: The PRIMARY purpose of a periodic threat and risk assessment...
Question 259: Which of the following would provide the BEST justification ...
Question 260: The MOST likely cause of a security information event monito...
Question 261: Which of the following is the BEST indication that an inform...
Question 262: What is the MOST important role of an organization's data cu...
Question 263: An organization has identified an increased threat of extern...
Question 264: Noncompliance issues were identified through audit. Which of...
Question 265: The FIRST step in a risk assessment for a business applicati...
Question 266: Which of the following is the BEST course of action for an i...
Question 267: Which of the following is the MOST important reason for perf...
Question 268: Which of the following should an information security manage...
Question 269: Which of the following is the PRIMARY reason to avoid alerti...
Question 270: An information security manager learns users of an applicati...
Question 271: An organization is in the process of adopting a hybrid data ...
Question 272: A cloud service provider is unable to provide an independent...
Question 273: Which of the following should be the PRIMARY consideration w...
Question 274: Which of the following is the MOST significant benefit of ef...
Question 275: The BEST way to establish a security baseline is by document...
Question 276: The PRIMARY benefit of integrating information security acti...
Question 277: Which of the following is MOST likely to increase end user s...
Question 278: Which of the following is MOST important for an information ...
Question 279: Which of the following methods BEST ensures that a comprehen...
Question 280: Which of the following control type is the FIRST considerati...
Question 281: The PRIMARY objective of periodically testing an incident re...
Question 282: Which of the following is the BEST method to obtain senior m...
Question 283: The integration of information security risk management proc...
Question 284: Which of the following provides the BEST preparation for han...
Question 285: Which of the following is the MOST challenging aspect of sec...
Question 286: An executive's personal mobile device used for business purp...
Question 287: An attacker was able to gain access to an organizations peri...
Question 288: Which of the following is MOST important for effective commu...
Question 289: Which of the following is the PRIMARY objective of reporting...
Question 290: Which of the following would BEST fulfill a board of directo...
Question 291: Which of the following service offerings in a typical Infras...
Question 292: An information security manager is evaluating the key risk i...
Question 293: What should be the information security manager s MOST impor...
Question 294: Which of the following security characteristics is MOST impo...
Question 295: Which of the following would BEST help to ensure an organiza...
Question 296: Which of the following provides the BEST indication that the...
Question 297: Which of the following is the GREATEST benefit of a centrali...
Question 298: The MOST important reason for an information security manage...
Question 299: The MOST important objective of monitoring key risk indicato...
Question 300: An information security manager reads a media report of a ne...
Question 301: Information security awareness programs are MOST effective w...
Question 302: Which of the following is the BEST way to ensure information...
Question 303: An organization wants to ensure its confidential data is iso...
Question 304: Which of the following is the BEST evidence that proper secu...
Question 305: The risk of mishandling alerts identified by an intrusion de...
Question 306: Which of the following provides the MOST comprehensive under...
Question 307: Which of the following is the MOST important factor to consi...
Question 308: An information security manager is asked to provide a short ...
Question 309: An information security manager has been tasked with develop...
Question 310: When reporting on the effectiveness of the information secur...
Question 311: Which of the following will BEST ensure that possible securi...
Question 312: Senior management has endorsed a comprehensive information s...
Question 313: What should be the PRIMARY basis for prioritizing incident c...
Question 314: Which of the following is MOST important in the development ...
Question 315: A risk analysis for a new system is being performed. For whi...
Question 316: When establishing classifications of security incidents for ...
Question 317: Which of the following is MOST important to consider when de...
Question 318: The PRIMARY purpose of implementing information security gov...
Question 319: Which of the following is the NEXT course of action for an i...
Question 320: A data-hosting organization's data center houses servers, ap...
Question 321: An organization recently rolled out a new procurement progra...
Question 322: Which of the following is the BEST way to reduce the risk of...
Question 323: When an organization lacks internal expertise to conduct hig...
Question 324: Which of the following is the BEST way to increase the visib...
Question 325: The PRIMARY advantage of a network intrusion detection syste...
Question 326: Which of the following is the BEST way to prevent employees ...
Question 327: The PRIMARY disadvantage of using a cold-site recovery facil...
Question 328: After logging in to a web application, additional authentica...
Question 329: Which of the following should an information security manage...
Question 330: An information security manager is concerned about the risk ...
Question 331: An information security manager has discovered an external b...
Question 332: During a review to approve a penetration test plan, which of...
Question 333: Which is the MOST important driver for effectively communica...
Question 334: Which of the following is an information security manager's ...
Question 335: Which of the following should an information security manage...
Question 336: Which of the following enables compliance with a nonrepudiat...
Question 337: Business units within an organization are resistant to propo...
Question 338: A recent audit has identified that security controls require...
Question 339: An organization has purchased a security Information and eve...
Question 340: Which of the following is MOST important for an information ...
Question 341: Which of the following is the GREATEST benefit of informatio...
Question 342: An information security manager terms that the root password...
Question 343: Which of the following will provide the MOST accurate test r...
Question 344: An information security manager has been made aware that som...
Question 345: Which of the following is the MOST effective method for cate...
Question 346: An organization plans to leverage popular social network pla...
Question 347: A newly hired information security manager discovers that th...
Question 348: A contract bid is digitally signed and electronically mailed...
Question 349: Which of the following is the BEST way for an information se...
Question 350: Which of the following BEST describes a buffer overflow?...
Question 351: Which of the following models provides a client organization...
Question 352: Which of the following should be an information security man...
Question 353: Which of the following is the KST way to align security and ...
Question 354: Which of the following is the STRONGEST indicator of effecti...
Question 355: An internal audit has found that critical patches were not i...
Question 356: Management decisions concerning information security investm...
Question 357: An organization s senior management is encouraging employees...
Question 358: When developing security standards, which of the following w...
Question 359: Which of the following BEST protects against phishing attack...
Question 360: Which of the following BEST demonstrates the effectiveness o...
Question 361: The PRIMARY reason for implementing scenario-based training ...
Question 362: An organization with a maturing incident response program co...
Question 363: An information security manager is preparing an incident res...
Question 364: Which of the following external entities would provide the B...
Question 365: Exceptions to a security policy should be approved based PRI...
Question 366: After a security incident has been contained, which of the f...
Question 367: A risk was identified during a risk assessment. The business...
Question 368: Which of the following is the MOST relevant source of inform...
Question 369: Which of the following is the MOST important element of an e...
Question 370: Which of the following would provide the BEST evidence to se...
Question 371: Which of the following is the BEST approach for encouraging ...
Question 372: Which of the following provides the BEST justification for a...
Question 373: Which of the following will BEST facilitate the development ...
Question 374: Which of the following provides the GREATEST assurance that ...
Question 375: The PRIMARY benefit of integrating information security risk...
Question 376: What is the BEST course of action when an Information securi...
Question 377: Which of the following is the MOST effective way to help ens...
Question 378: In which of the following situations is it MOST important to...
Question 379: Which of the following is a PRIMARY objective of incident cl...
Question 380: Which of the following is an information security manager's ...
Question 381: Senior management has decided to accept a significant risk w...
Question 382: The PRIMARY goal of conducting a business impact analysis (B...
Question 383: Which of the following needs to be established between an IT...
Question 384: What information is MOST helpful in demonstrating to senior ...
Question 385: For an organization with operations in different parts of th...
Question 386: Which of the following is the PRIMARY advantage of having an...
Question 387: An information security manager has been asked to identify p...
Question 388: Which of the following is MOST important when carrying out a...
Question 389: An inexperienced information security manager is relying on ...
Question 390: Of the following, who should have PRIMARY responsibility for...
Question 391: Which of the following would provide the MOST comprehensive ...
Question 392: An information security manager has been asked to integrate ...
Question 393: The BEST way to obtain funding from senior management for a ...
Question 394: During the establishment of a service level agreement (SLA) ...
Question 395: Which of the following would be MOST important to include in...
Question 396: Which of the following is the MOST appropriate board-level a...
Question 397: Which of the following is MOST important when allowing emplo...
Question 398: When implementing security architecture, an information secu...
Question 399: Which of the following is a MAIN security challenge when con...
Question 400: An information security manager wants to document requiremen...