<< Prev Question Next Question >>

Question 331/400

To integrate security into system development fie cycle (SDLC) processes, an organization MUST ensure that security.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (400q)
Question 1: An organization wants to implement an emerging technology to...
Question 2: Business units within an organization are resistant to propo...
Question 3: The MOST important reason to maintain key risk indicators (K...
Question 4: Which of the following is the NEXT course of action for an i...
1 commentQuestion 5: Following a recent acquisition, an information security mana...
Question 6: The MAIN consideration when designing an incident escalation...
Question 7: An organization has detected potential risk emerging from no...
Question 8: When creating an information security governance program, wh...
Question 9: Which of the following is the MOST effective way to facilita...
Question 10: Which of the following is the PRIMARY reason to include mess...
Question 11: Which of the following would provide senior management with ...
Question 12: Which of the following is the MOST useful metric for determi...
Question 13: Which of the following is the BEST way to monitor for advanc...
Question 14: Establishing which of the following is the BEST way of ensur...
Question 15: The PRIMARY advantage of a network intrusion detection syste...
1 commentQuestion 16: Which of the following should be the PRIMARY goal of an Info...
Question 17: Which of the following is a PRIMARY goal of an information s...
Question 18: The MOST important reason that security risk assessments sho...
Question 19: Which of the following is the- BEST method to determine whet...
Question 20: An organization plans to acquire and implement a new web-bas...
Question 21: The MOST effective way to determine the resources required b...
Question 22: A new organization has been hit with a ransomware attack tha...
Question 23: Which of the following is the PRIMARY purpose for defining k...
Question 24: When creating a bring your own device (BYOD) program, it is ...
Question 25: An organization is planning to create a website that will co...
Question 26: When an organization lacks internal expertise to conduct hig...
Question 27: Before final acceptance of residual risk, what is the BEST w...
Question 28: Which of the following would BEST mitigate identified vulner...
Question 29: In which of the following situations is it MOST important to...
Question 30: After assessing risk, the decision to treat the risk should ...
Question 31: Within the confidentiality, integrity, and availability (CIA...
Question 32: Which of the following would provide the BEST input to a bus...
Question 33: Which of the following statements indicates that a previousl...
Question 34: With limited resources in the information security departmen...
Question 35: An awareness program is implemented to mitigate the risk of ...
Question 36: A large organization is considering a policy that would allo...
Question 37: A new program has been implemented to standardize security c...
1 commentQuestion 38: Which is MOST important when contracting an external party t...
Question 39: Which of the following BEST indicates the value a purchased ...
Question 40: Which of the following is the PRIMARY goal of a risk managem...
Question 41: A message is being sent with a hash. The risk of an attacker...
Question 42: Which of the following is the MOST effective way for an Info...
Question 43: The risk of mishandling alerts identified by an intrusion de...
Question 44: Which of the following is the MOST important security consid...
Question 45: An organization's security was compromised by outside attack...
Question 46: The PRIMARY purpose of aligning information security with co...
Question 47: The MOST effective way to communicate the level of impact of...
Question 48: Senior management wants to provide mobile devices to its sal...
Question 49: An organization's information security strategy for the comi...
Question 50: Which of the following should be done FIRST when implementin...
Question 51: Which of the following is MOST important to present to stake...
Question 52: Which of the following is the MOST effective method of preve...
Question 53: After a recent malware Incident an organization's IT steerin...
1 commentQuestion 54: When an organization and its IT-hosting service provider are...
1 commentQuestion 55: Which of the following is the BEST way to address any gaps i...
Question 56: For computer forensics evidence to be admissible in a court ...
Question 57: Which of the following is a PRIMARY responsibility of a data...
Question 58: Which of the following provides the GREATEST assurance that ...
Question 59: When multiple Internet intrusions on a server are detected, ...
Question 60: Which of the following is MOST important to consider when ha...
Question 61: Which of the following should be the FIRST step of incident ...
Question 62: The integration of information security risk management proc...
Question 63: Which of the following should be the PRIMARY consideration w...
Question 64: An information security manager is evaluating the key risk i...
Question 65: Which of the following BEST indicates that information secur...
Question 66: Which of the following will BEST enable an effective informa...
Question 67: Which of the following is the MOST important outcome of a we...
Question 68: An information security manager has been asked to identify p...
Question 69: Which of the following is MOST relevant for an information s...
Question 70: Who within an organization is accountable for ensuring incid...
Question 71: A system administrator failed to report a security incident ...
Question 72: The MOST important factors in determining the scope and timi...
Question 73: Which of the following has the MOST influence on an organiza...
Question 74: An organization recently implemented a data loss prevention ...
Question 75: Which of the following is the BEST way to reduce the risk of...
Question 76: Which of the following is the MOST important reason for perf...
Question 77: When preparing a strategy for protection from SQL injection ...
Question 78: Which of the following is the MOST effective way for senior ...
Question 79: Which of the following should an information security manage...
Question 80: During a post-incident review, the sequence and correlation ...
Question 81: A risk management program will be MOST effective when:...
Question 82: Which of the following will BEST provide an organization wit...
Question 83: Which of the following BEST enables new third-party supplier...
Question 84: Which of the following presents the GREATEST concern to the ...
Question 85: It is MOST important tot an information security manager to ...
Question 86: In an organization that has undergone an expansion through a...
Question 87: Mitigating technology risks to acceptable levels should be b...
Question 88: Which of the following is MOST important to consider when de...
Question 89: Which of the following would BEST enable management to be aw...
Question 90: In a large organization requesting outsourced services, whic...
Question 91: Which of the following is the MOST important function of inf...
Question 92: After undertaking a security assessment of a production syst...
Question 93: What is the role of the information security manager in fina...
Question 94: What is the MOST important role of an organization's data cu...
Question 95: Which of the following is the MOST important consideration f...
Question 96: Which of the following should the information security manag...
Question 97: Human resources is evaluating potential Software as a Servic...
Question 98: The frequency of conducting business impact analysis (BIA) s...
Question 99: Which of the following metrics BEST evaluates the completene...
Question 100: Which of the following BEST determines an information asset'...
Question 101: Several significant risks have been identified after a centr...
Question 102: The selection of security controls is PRIMARILY linked to:...
Question 103: Which of the following is the BEST criterion to use when cla...
Question 104: Which of the following is MOST helpful in integrating inform...
Question 105: Which of the following will BEST help to ensure security is ...
Question 106: Noncompliance issues were identified through audit. Which of...
Question 107: An information security manager is concerned that executive ...
Question 108: Which of the following is the BEST evidence that proper secu...
Question 109: After a risk has been mitigated, which of the following is t...
Question 110: The BEST way to improve the effectiveness of responding to a...
Question 111: An information security manager is preparing an incident res...
Question 112: Which of the following BEST describes an intrusion detection...
Question 113: Which of the following is MOST important to include in contr...
Question 114: Which of the following is the MOST effective way to communic...
Question 115: What is the MOST effective way to ensure information securit...
Question 116: The PRIMARY purpose of vulnerability assessments is to:...
Question 117: Which of the following is the PRIMARY responsibility of an i...
Question 118: Who is MOST important to include when establishing the respo...
Question 119: Failure to include information security requirements within ...
Question 120: What should be the PRIMARY basis for prioritizing incident c...
Question 121: The PRIMARY reason an organization would require that users ...
Question 122: Which of the following is the BEST way to determine if an in...
Question 123: Which of the following is MOST important to the successful d...
Question 124: Which of the following would present the GREATEST need to re...
Question 125: A business unit has updated its long-term business plan to i...
Question 126: The FIRST step in a risk assessment for a business applicati...
Question 127: During the due diligence phase of an acquisition, the MOST i...
Question 128: Which of the following is MOST helpful to management in dete...
Question 129: Which of the following is the BIST course of action for the ...
Question 130: A third-party contract signed by a business unit manager fai...
Question 131: An organization plans to leverage popular social network pla...
Question 132: Which of the following is MOST useful to include in a report...
Question 133: Which of the following BIST validates that security controls...
Question 134: Which of the following is MOST important when prioritizing a...
Question 135: Which of the following is the MOST effective method to help ...
Question 136: Which of the following should be the GREATEST concern when c...
Question 137: Which of the following would BEST protect against web-based ...
Question 138: Which of the following defines the MOST comprehensive set of...
Question 139: Which of the following is an information security manager's ...
Question 140: An internal control audit has revealed a control deficiency ...
Question 141: Which of the following is the FIRST task when determining an...
Question 142: Organization XYZ. a lucrative, Internet-only business, recen...
Question 143: Which of the following would be MOST effective in preventing...
Question 144: Senior management learns of several web application security...
Question 145: Which of the following provides the BEST indication that the...
Question 146: Information security governance is PRIMARILY driven by which...
Question 147: After implementing an information security governance framew...
Question 148: When preparing a business case for the implementation of a s...
Question 149: When developing an information security governance framework...
Question 150: Which of the following BEST promotes stakeholder accountabil...
Question 151: An organization us&amp; a particular encryption protocol for...
Question 152: The PRIMARY goal of a security infrastructure design is the:...
Question 153: Which of the following is the BEST way to provide management...
Question 154: The BEST way to establish a security baseline is by document...
Question 155: A new mobile application is unable to adhere to the organiza...
Question 156: Which of the following should be the FIRST step to ensure sy...
Question 157: Which of the following should be the FIRST step to ensure an...
Question 158: What should be the FIRST step when developing an asset manag...
Question 159: The PRIMARY goal of a post-incident review should be to...
Question 160: A new regulation has been announced that requires mandatory ...
Question 161: The BEST way to ensure information security efforts and init...
Question 162: Which of the following is the MOST important criterion for c...
Question 163: Information security policies should be designed PRIMARILY o...
Question 164: An executive's personal mobile device used for business purp...
Question 165: Which of the following is MOST important to have in place to...
Question 166: An incident response team has determined there is a need to ...
Question 167: Which of the following would be of GREATEST concern to an in...
Question 168: Which of the following is an indicator of improvement in the...
Question 169: Which of the following metrics would BEST monitor how well i...
Question 170: In the development of an information security strategy, reco...
Question 171: When determining an acceptable risk level, which of the foll...
Question 172: An information security manager is preparing a presentation ...
Question 173: Which of the following should be reviewed to obtain a struct...
Question 174: What is the PRIMARY benefit to executive management when aud...
Question 175: When establishing classifications of security incidents for ...
Question 176: Which of the following should an information security manage...
Question 177: Which of the following defines the minimum security requirem...
Question 178: Which of the following should be done FIRST when establishin...
Question 179: Which of the following is MOST effective in preventing the i...
Question 180: Which of the following is the MOST effective method to preve...
Question 181: An organization is adopting a standardized corporate chat me...
Question 182: An incident was detected where customer records were altered...
Question 183: When aligning an organization's information security program...
Question 184: Which of the following is the GREATEST benefit of integratin...
Question 185: A business previously accepted the risk associated with a ze...
Question 186: When supporting an organization's privacy officer, which of ...
Question 187: Which of the following sites would be MOST appropriate in th...
Question 188: For an organization with a large and complex IT infrastructu...
Question 189: An organization's security policy is to disable access to US...
Question 190: A business impact analysis (BIA) should be periodically exec...
Question 191: Which of the following metrics would be considered an accura...
Question 192: When establishing the trigger levels for an organization's k...
Question 193: Which of the following is MOST relevant for an information s...
Question 194: Which of the following would MOST effectively help to restri...
Question 195: After a server has been attacked, which of the following is ...
Question 196: An information security manager has been made aware that imp...
Question 197: An information security manager is planning to purchase a mo...
Question 198: Which of the following is MOST likely to occur following a s...
Question 199: Which of the following is the MOST important reason for perf...
Question 200: An information security manager has implemented an ongoing s...
Question 201: Which of the following is MOST relevant for an information s...
Question 202: If the inherent risk of a business activity is higher than t...
Question 203: In addition to business alignment and security ownership, wh...
Question 204: An information security manager has been asked to integrate ...
Question 205: Which of the following is the BEST way to sustain employee i...
Question 206: Which of the following is the MOST important outcome of test...
Question 207: Which of the following BEST enables an effective escalation ...
Question 208: When drafting the corporate privacy statement for a public w...
Question 209: Which of the following activities would BEST incorporate sec...
Question 210: To gain a clear understanding of the impact that a new regul...
Question 211: During the establishment of a service level agreement (SLA) ...
Question 212: Which of the following is the BEST way for an information se...
Question 213: Which of the following is the MOST important security consid...
Question 214: It is suspected that key emails have been viewed by unauthor...
Question 215: The PRIMARY goal of conducting a business impact analysis (B...
Question 216: As part of an international expansion plan, an organization ...
Question 217: Following a significant change to the underlying code of an ...
Question 218: Which of the following is the MOST effective approach to ens...
Question 219: Which of the following activities should take place FIRST wh...
Question 220: Which of the following is MOST critical for prioritizing act...
Question 221: Which of the following is the KEY outcome of conducting a po...
Question 222: A data leakage prevention (DLP) solution has identified that...
Question 223: The MOST important reason that security risk assesements sho...
Question 224: A risk has been formally accepted and documented. Which of t...
Question 225: Which of the following should be the PRIMARY basis for a sev...
Question 226: Which of the following is the MOST important reason to have ...
Question 227: Which of the following techniques is MOST useful when an inc...
Question 228: Which of the following BEST describes a buffer overflow?...
Question 229: Which of the following would be MOST important to include in...
Question 230: Which of the following is the BEST indication that an inform...
Question 231: Which of the following is an information security manager's ...
Question 232: Which of the following is the BEST way to identify the poten...
Question 233: Reviewing which of the following would provide the GREATEST ...
Question 234: An online payment provider's computer security incident resp...
Question 235: Which of the following is MOST important to include in an in...
Question 236: Which of the following should an information security manage...
Question 237: Which of the following is the BEST method to protect against...
Question 238: Which of the following would be MOST helpful in gaming suppo...
Question 239: Which of the following is the MOST important step in risk ra...
Question 240: Which of the following is the BEST way to ensure that organi...
Question 241: Which of the following activities BEST enables executive man...
Question 242: Which of the following is MOST important for an information ...
Question 243: Senior management is concerned a security solution may not a...
Question 244: For an organization with operations in different parts of th...
Question 245: The value of information assets relative to the organization...
Question 246: An organization s HR department would like to outsource its ...
Question 247: Which of the following is the BEST approach for determining ...
Question 248: Which of the following is the BEST way to improve the timely...
Question 249: Senior management has allocated funding to each of the organ...
Question 250: Which of the following BEST reduces the likelihood of leakag...
Question 251: Which of the following BEST demonstrates effective informati...
Question 252: An information security manager finds that corporate informa...
Question 253: An organization planning to contract with a cloud service pr...
Question 254: Which of the following is the MOST reliable way to ensure ne...
Question 255: The MAIN reason for internal certification of web-based busi...
Question 256: An information security manager recently received funding fo...
Question 257: Which of the following is MOST likely to be included in an e...
Question 258: What should an information security manager do FIRST when a ...
Question 259: Which of the following measures BEST indicates an improvemen...
Question 260: Which of the following is the GREATEST benefit of informatio...
Question 261: Which of the following is the BEST indicator that an organiz...
Question 262: An organization has concerns regarding a potential advanced ...
Question 263: Which of the following is the BEST way to measure the effect...
Question 264: Ensuring that activities performed by outsourcing providers ...
Question 265: Which of the following is the MOST important consideration m...
Question 266: Which of the following is an information security manager's ...
Question 267: Information classification is a fundamental step in determin...
Question 268: Which of the following is BEST performed by the security dep...
Question 269: When implementing security architecture, an information secu...
Question 270: An information security manager is developing a new informat...
Question 271: Which of the following is the MOST important reason for logg...
Question 272: The success of a computer forensic investigation depends on ...
Question 273: Which of the following is MOST critical for the successful i...
Question 274: An organization's recent risk assessment has identified many...
Question 275: An investigation of a recent security incident determined th...
Question 276: When outsourcing sensitive data to a cloud service provider,...
Question 277: Which of the following should be the MOST important consider...
Question 278: Which of the following is the MOST effective preventive cont...
Question 279: To gain a clear+ understanding of the impact that a new regu...
Question 280: An organization is considering whether to allow employees to...
Question 281: Which of the following is the PRIMARY purpose of establishin...
Question 282: Which of the following should be an information security man...
Question 283: Segregation of duties is a security control PRIMARILY used t...
Question 284: An organization has outsourced many application development ...
Question 285: The MOST likely reason to use qualitative security risk asse...
Question 286: Which of the following approaches is BEST for selecting cont...
Question 287: Which of the following is the PRIMARY objective of reporting...
Question 288: A risk profile supports effective security decisions PRIMARI...
Question 289: An organization is concerned with the risk of information le...
Question 290: What should an information security team do FIRST when notif...
Question 291: What is the BEST approach for the information security manag...
Question 292: Which of the following has the GREATEST impact on efforts to...
Question 293: When an operating system is being hardened, it is MOST impor...
Question 294: Which of the following is the BKT approach for an informatio...
Question 295: What is the MAIN reason for an organization to develop an in...
Question 296: An information security manager terms that the root password...
Question 297: The MOST important reason for an information security manage...
Question 298: During which phase of an incident response process should co...
Question 299: An organization with a maturing incident response program co...
Question 300: Which of the following is BEST determined by using technical...
Question 301: Which of the following would provide senior management with ...
Question 302: Which of the following is MOST effective in the strategic al...
Question 303: Which of the following is the PRIMARY purpose of conducting ...
Question 304: Which of the following should be of MOST influence to an inf...
Question 305: A regulatory organization sends an email to an information s...
Question 306: An information security manager is reviewing the business ca...
Question 307: Which of the following messages would be MOST effective in o...
Question 308: Which of the following is the MOST important consideration w...
Question 309: An IT department has given a vendor remote access to the int...
Question 310: Which of the following external entities would provide the B...
Question 311: What should an information security manager do NEXT when man...
Question 312: Which of the following processes is the FIRST step in establ...
Question 313: Which of the following is the information security manager's...
Question 314: An organization has determined that one of its web servers h...
Question 315: Which of the following is the MOST important consideration w...
Question 316: An organization s senior management wants to allow employees...
Question 317: The BEST way to avoid session hijacking is to use:...
Question 318: Which of the following is the MOST important reason for perf...
Question 319: An organization recently rolled out a new procurement progra...
Question 320: An information security manager has identified and implement...
Question 321: Which of the following is the BEST mechanism to prevent data...
Question 322: The PRIMARY purpose of a security information and event mana...
Question 323: Which of the following is the BEST way to prevent segregatio...
Question 324: Which of the following is the BEST way to determine if an or...
Question 325: Which of the following is MOST critical for an effective inf...
Question 326: Which of the following is MOST important to building an effe...
Question 327: Which of the following is the BEST evidence that information...
Question 328: Which of the following is the BEST resource for evaluating t...
Question 329: Which of the following needs to be established between an IT...
Question 330: Which of the following is the BEST approach when using sensi...
Question 331: To integrate security into system development fie cycle (SDL...
Question 332: Which of the following will BEST facilitate the development ...
Question 333: What is the BEST way to determine the level of risk associat...
Question 334: Which of the following would provide the BEST justification ...
Question 335: In an organization with effective IT risk management, the PR...
Question 336: A new mobile application is unable to adhere to the organiza...
Question 337: Which of the following is PRIMARILY influenced by a business...
Question 338: Which of the following is the MOST effective way to ensure s...
Question 339: Using which of the following metrics will BEST help to deter...
Question 340: Which of the following is the MOST important requirement for...
Question 341: The Information security manager and senior management of a ...
Question 342: When developing a classification method for incidents, the c...
Question 343: The use of digital signatures ensures that a message:...
Question 344: Which of the following should be the PRIMARY consideration w...
Question 345: Which of the following is the BEST advantage of a centralize...
Question 346: After logging in to a web application, additional authentica...
Question 347: Which of the following would BEST enable effective decision-...
Question 348: When is the BEST time to identify the potential regulatory r...
Question 349: A validated patch to address a new vulnerability that may af...
Question 350: What is the PRIMARY role of the information security program...
Question 351: Which of the following is MOST important to consider when de...
Question 352: What should an Information security manager do FIRST to ensu...
Question 353: A review of a number of recent XT system rollouts identified...
Question 354: Which of the following is an information security manager's ...
Question 355: What is the PRIMARY purpose of communicating business impact...
Question 356: The GREATEST benefit of choosing a private cloud over a publ...
Question 357: Which of the following would BEST enhance firewall security?...
Question 358: Which of the following is the FIRST step when defining and p...
Question 359: The MOST important reason to have a well-documented and test...
Question 360: When recommending a preventive control against cross-site sc...
Question 361: An organization has implemented a new customer relationship ...
Question 362: Which of the following would BEST demonstrate the status of ...
Question 363: Which of the following processes would BEST aid an informati...
Question 364: Reviewing security objectives and ensuring the integration o...
Question 365: A risk assessment report shows that phishing attacks are an ...
Question 366: Which of the following is the PRIMARY reason to avoid alerti...
Question 367: Which of the following provides the BEST evidence that the i...
Question 368: Which of the following is the BEST reason to initiate a reas...
Question 369: The authorization to transfer the handling of an internal se...
Question 370: Which of the following is the MOST important element of an e...
Question 371: Which of the following is MOST critical when creating an inc...
Question 372: Which of the following is the BEST method to obtain senior m...
Question 373: Cold sites for disaster recovery events are MOST helpful in ...
Question 374: To integrate security into system development life cycle (SD...
Question 375: Which of the following should be an information security man...
Question 376: In a resource-restricted security program, which of the foll...
Question 377: An organization has an approved bring your own device (BYOD)...
Question 378: Which of the following is the PRIMARY objective of implement...
Question 379: In information security governance, the PRIMARY role of the ...
Question 380: Which of the following is the MOST effective method for cate...
Question 381: Which of the ager to regularly report to senior management?...
Question 382: An internal security audit has reported several control weak...
Question 383: An organization is the victim of a targeted attack, and is u...
Question 384: Which of the following would BEST support a business case to...
Question 385: The PRIMARY focus of a training curriculum for members of an...
Question 386: Which of the following is MOST helpful in protecting against...
Question 387: To prevent computers on the corporate network from being use...
Question 388: Which of the following security characteristics is MOST impo...
Question 389: Which of the following is the MOST effective way to mitigate...
Question 390: Which of the following will BEST facilitate the understandin...
Question 391: Which of the following is the MOST important consideration w...
Question 392: An information security manager is implementing controls to ...
Question 393: Which of the following is the MOST critical security risk to...
Question 394: Which of the following is MOST likely to drive an update to ...
Question 395: Which is MOST important when aligning security priorities wi...
Question 396: Which of the following would provide the MOST helpful inform...
Question 397: Which of the following is MOST important for effective commu...
Question 398: The PRIMARY reason for classifying assets is to:...
Question 399: To implement a security framework, an information security m...
Question 400: Which of the following is the MOST important influence to th...