<< Prev Question Next Question >>

Question 257/329

The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization Which of the following should be done FIRST?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (329q)
Question 1: Which of the following eradication methods is MOST appropria...
Question 2: Which of the following Is MOST useful to an information secu...
Question 3: Which of the following is the BEST method to protect against...
Question 4: Which of the following has the GREATEST influence on the suc...
Question 5: Who is BEST suited to determine how the information in a dat...
Question 6: An organization has multiple data repositories across differ...
Question 7: Prior to implementing a bring your own device (BYOD) program...
Question 8: What is the role of the information security manager in fina...
Question 9: Which of the following should be the PRIMARY basis for an in...
Question 10: Which of the following presents the GREATEST challenge to a ...
Question 11: What is the BEST way to reduce the impact of a successful ra...
Question 12: During the selection of a Software as a Service (SaaS) vendo...
Question 13: An enterprise has decided to procure security services from ...
Question 14: When performing a business impact analysis (BIA), who should...
Question 15: When assigning a risk owner, the MOST important consideratio...
Question 16: Which of the following is the BEST course of action when con...
Question 17: An information security manager has identified that privileg...
Question 18: The PRIMARY goal of the eradication phase in an incident res...
Question 19: Which of the following BEST enables the assignment of risk a...
Question 20: When designing a disaster recovery plan (DRP), which of the ...
Question 21: Which of the following should be the PRIMARY focus of a stat...
Question 22: The MOST appropriate time to conduct a disaster recovery tes...
Question 23: Which of the following is the MOST effective way to help sta...
Question 24: An organization is close to going live with the implementati...
Question 25: Management decisions concerning information security investm...
Question 26: An organization wants to integrate information security into...
Question 27: Which of the following is the BEST method to ensure complian...
Question 28: Which of the following is the GREATEST challenge with assess...
Question 29: During which phase of an incident response plan is the root ...
Question 30: Which of the following should be done FIRST when implementin...
Question 31: When an organization experiences a disruptive event, the bus...
Question 32: Which of the following metrics BEST demonstrates the effecti...
Question 33: After the occurrence of a major information security inciden...
Question 34: Which of the following should be the MOST important consider...
Question 35: A balanced scorecard MOST effectively enables information se...
Question 36: Which of the following roles is PRIMARILY responsible for de...
Question 37: Which of the following is the PRIMARY objective of informati...
Question 38: Which of the following is the MOST effective defense against...
Question 39: Which of the following is the BEST defense-in-depth implemen...
Question 40: Which of the following is MOST important when developing an ...
Question 41: An organization is increasingly using Software as a Service ...
1 commentQuestion 42: Which of the following should an information security manage...
Question 43: When integrating security risk management into an organizati...
Question 44: An information security manager learns that business unit le...
Question 45: What type of control is being implemented when a security in...
Question 46: In order to gain organization-wide support for an informatio...
Question 47: A newly appointed information security manager has been aske...
Question 48: Which of the following is ESSENTIAL to ensuring effective in...
Question 49: Which of the following is MOST important to have in place as...
Question 50: An organization has remediated a security flaw in a system. ...
Question 51: Which of the following is the MOST effective way to detect s...
Question 52: Which of the following is MOST effective in monitoring an or...
Question 53: Which of the following is MOST critical when creating an inc...
Question 54: An intrusion has been detected and contained. Which of the f...
Question 55: When management changes the enterprise business strategy whi...
Question 56: Which of the following is the PRIMARY benefit of implementin...
Question 57: When implementing a security policy for an organization hand...
1 commentQuestion 58: Recommendations for enterprise investment in security techno...
Question 59: An information security manager has been notified about a co...
Question 60: Meeting which of the following security objectives BEST ensu...
Question 61: Of the following, who is BEST positioned to be accountable f...
Question 62: Which of the following components of an information security...
Question 63: Which of the following would BEST guide the development and ...
Question 64: A forensic examination of a PC is required, but the PC has b...
Question 65: What is the PRIMARY objective of performing a vulnerability ...
Question 66: A business requires a legacy version of an application to op...
Question 67: Which of the following is the MOST important reason for obta...
Question 68: Which of the following is MOST important to consider when al...
Question 69: The PRIMARY reason for creating a business case when proposi...
Question 70: Which of the following presents the GREATEST risk associated...
Question 71: Before approving the implementation of a new security soluti...
Question 72: Which of the following is the MOST important consideration w...
Question 73: Which of the following is the PRIMARY benefit achieved when ...
Question 74: Which of the following is MOST important for an information ...
Question 75: A security incident has been reported within an organization...
Question 76: A small organization has a contract with a multinational clo...
Question 77: The business value of an information asset is derived from:...
Question 78: Which of the following should an information security manage...
Question 79: An employee of an organization has reported losing a smartph...
Question 80: Which of the following is the GREATEST concern resulting fro...
Question 81: Which of the following would provide the BEST input to a bus...
Question 82: Which of the following is the BEST starting point for a newl...
Question 83: What should be an information security manager's MOST import...
Question 84: An organization is aligning its incident response capability...
Question 85: To improve the efficiency of the development of a new softwa...
Question 86: Which of the following is the PRIMARY benefit of implementin...
Question 87: Which of the following MUST be established to maintain an ef...
Question 88: Recovery time objectives (RTOs) are an output of which of th...
Question 89: Measuring which of the following is the MOST accurate way to...
Question 90: Which of the following is MOST important to include in an in...
Question 91: Which of the following BEST supports information security ma...
Question 92: Which of the following BEST helps to ensure a risk response ...
Question 93: Which of the following is the BEST course of action when an ...
Question 94: An organization faces severe fines and penalties if not in c...
Question 95: An organization's quality process can BEST support security ...
Question 96: When developing a categorization method for security inciden...
Question 97: An organization's HR department requires that employee accou...
Question 98: Which of the following is MOST appropriate to communicate to...
Question 99: Which of the following is MOST important to consider when de...
Question 100: Which of the following is the MOST effective way to convey i...
Question 101: Which of the following is the BEST approach for governing no...
Question 102: Regular vulnerability scanning on an organization's internal...
Question 103: Of the following, whose input is of GREATEST importance in t...
Question 104: A critical server for a hospital has been encrypted by ranso...
Question 105: An organization's main product is a customer-facing applicat...
Question 106: Which of the following functions is MOST critical when initi...
Question 107: Which of the following is MOST important when defining how a...
Question 108: Which of the following is MOST important in order to obtain ...
Question 109: Which of the following is the PRIMARY advantage of an organi...
Question 110: Which of the following is MOST important to convey to employ...
Question 111: Which of the following is the MOST important consideration w...
Question 112: A cloud application used by an organization is found to have...
Question 113: An organization's information security team presented the ri...
Question 114: When developing a business case to justify an information se...
Question 115: When choosing the best controls to mitigate risk to acceptab...
Question 116: Which of the following is MOST important to include in an in...
1 commentQuestion 117: Company A, a cloud service provider, is in the process of ac...
1 commentQuestion 118: A new regulatory requirement affecting an organization's inf...
Question 119: Which of the following BEST enables an organization to trans...
Question 120: During which of the following development phases is it MOST ...
Question 121: Penetration testing is MOST appropriate when a:...
Question 122: An organization's security policy is to disable access to US...
Question 123: Which of the following should be the MOST important consider...
Question 124: Which of the following is the MOST important requirement for...
Question 125: The effectiveness of an information security governance fram...
Question 126: Of the following, who is accountable for data loss in the ev...
Question 127: Which of the following is the BEST justification for making ...
Question 128: A recovery point objective (RPO) is required in which of the...
Question 129: Which of the following is MOST important to complete during ...
Question 130: Which of the following is the MOST appropriate metric to dem...
Question 131: An incident response team has been assembled from a group of...
Question 132: Which of the following is the BEST way to ensure the organiz...
Question 133: Which of the following is BEST to include in a business case...
Question 134: The MOST important element in achieving executive commitment...
Question 135: Which of the following is the BEST way to ensure the busines...
1 commentQuestion 136: To ensure that a new application complies with information s...
Question 137: Which of the following BEST enables an organization to maint...
Question 138: Which of the following is MOST helpful for protecting an ent...
Question 139: The PRIMARY advantage of involving end users in continuity p...
Question 140: Which of the following should an information security manage...
Question 141: When establishing an information security governance framewo...
Question 142: Which of the following is the BEST course of action for an i...
1 commentQuestion 143: Relationships between critical systems are BEST understood b...
Question 144: To help ensure that an information security training program...
Question 145: An employee has just reported the loss of a personal mobile ...
Question 146: Which of the following is the BEST technical defense against...
Question 147: Which of the following is MOST important to include in month...
1 commentQuestion 148: Which of the following should be established FIRST when impl...
Question 149: Following an employee security awareness training program, w...
Question 150: Which of the following MUST be defined in order for an infor...
Question 151: Which of the following is the BEST indication of a mature in...
Question 152: An information security program is BEST positioned for succe...
Question 153: Of the following, who is in the BEST position to evaluate bu...
Question 154: An information security team has discovered that users are s...
Question 155: Which of the following would be of GREATEST assistance in de...
Question 156: Which of the following should be the PRIMARY objective of th...
Question 157: An organization is in the process of acquiring a new company...
Question 158: Which of the following security processes will BEST prevent ...
Question 159: An incident management team is alerted ta a suspected securi...
Question 160: Which of the following tools provides an incident response t...
Question 161: Which of the following should be an information security man...
Question 162: Which of the following BEST enables the integration of infor...
Question 163: Which of the following should be the PRIMARY basis for a sev...
Question 164: Which of the following would be MOST useful when determining...
Question 165: Which of the following factors has the GREATEST influence on...
Question 166: Which of the following would be MOST useful to help senior m...
Question 167: When deciding to move to a cloud-based model, the FIRST cons...
Question 168: Which of the following would be an information security mana...
Question 169: Which of the following is the MOST essential element of an i...
Question 170: Following a risk assessment, an organization has made the de...
Question 171: Which of the following plans should be invoked by an organiz...
Question 172: Data entry functions for a web-based application have been o...
2 commentQuestion 173: An information security manager has been tasked with develop...
Question 174: An international organization with remote branches is implem...
Question 175: Which of the following is the BEST course of action if the b...
Question 176: Which of the following should be the PRIMARY area of focus w...
Question 177: Which of the following is MOST important to include in an in...
Question 178: When drafting the corporate privacy statement for a public w...
Question 179: Which of the following would be MOST helpful when creating i...
Question 180: Which of the following is MOST important to consider when ch...
Question 181: Which of the following has The GREATEST positive impact on T...
Question 182: Which of the following metrics provides the BEST evidence of...
Question 183: Which of the following will provide the MOST guidance when d...
Question 184: Which of the following is the PRIMARY reason to monitor key ...
Question 185: An organization's information security manager is performing...
Question 186: When developing an asset classification program, which of th...
Question 187: Which of the following is MOST important to consider when de...
Question 188: A new application has entered the production environment wit...
Question 189: Which of the following is the PRIMARY role of the informatio...
Question 190: Which of the following is the MOST important issue in a pene...
Question 191: Which of the following is the BEST way to determine if an in...
Question 192: Which of the following has the MOST influence on the inheren...
Question 193: Which of the following is the GREATEST benefit of informatio...
Question 194: A newly appointed information security manager has been aske...
Question 195: Within the confidentiality, integrity, and availability (CIA...
Question 196: Which of the following is MOST important to ensure when deve...
Question 197: Which of the following is MOST important to include in a rep...
Question 198: The PRIMARY reason to create and externally store the disk h...
Question 199: An information security manager has recently been notified o...
Question 200: Which of the following should be done FIRST when a SIEM flag...
Question 201: Which of the following is the BEST approach to incident resp...
Question 202: An organization is planning to outsource network management ...
Question 203: Which of the following is the BEST method for determining wh...
Question 204: Which of the following is the BEST way to ensure data is not...
Question 205: An organization plans to offer clients a new service that is...
Question 206: Which of the following BEST enables an organization to maint...
Question 207: Which of the following should be the FIRST step in patch man...
Question 208: Which of the following BEST enables an organization to opera...
Question 209: When developing an information security strategy for an orga...
Question 210: Which of the following is the BEST way to obtain support for...
Question 211: The ULTIMATE responsibility for ensuring the objectives of a...
Question 212: An email digital signature will:...
Question 213: Which is following should be an information security manager...
Question 214: Which of the following is the PRIMARY objective of a busines...
Question 215: Which of the following will BEST enable an effective informa...
Question 216: Which of the following is the PRIMARY purpose of an acceptab...
Question 217: Which of the following is the PRIMARY reason to perform regu...
Question 218: Which of the following is BEST used to determine the maturit...
Question 219: Which of the following is MOST helpful for aligning security...
Question 220: Embedding security responsibilities into job descriptions is...
Question 221: The PRIMARY objective of performing a post-incident review i...
Question 222: Which of the following is the PRIMARY reason to assign a ris...
Question 223: Of the following, who is MOST appropriate to own the risk as...
Question 224: An organization recently outsourced the development of a mis...
Question 225: Which of the following would be MOST effective in reducing t...
Question 226: During the due diligence phase of an acquisition, the MOST i...
Question 227: An organization has purchased an Internet sales company to e...
Question 228: A penetration test against an organization's external web ap...
Question 229: When determining an acceptable risk level which of the follo...
Question 230: An organization has implemented a new customer relationship ...
Question 231: Which of the following should be an information security man...
Question 232: Which of the following will have the GREATEST influence on t...
Question 233: If civil litigation is a goal for an organizational response...
Question 234: The BEST way to ensure that frequently encountered incidents...
Question 235: Which of the following BEST enables the capability of an org...
Question 236: A security incident has been reported within an organization...
Question 237: Management would like to understand the risk associated with...
Question 238: An organization implemented a number of technical and admini...
Question 239: Which of the following is the BEST way to determine the effe...
Question 240: Which of the following is an information security manager's ...
Question 241: Which of the following metrics is MOST appropriate for evalu...
Question 242: Which of the following is MOST important to ensuring informa...
Question 243: A KEY consideration in the use of quantitative risk analysis...
Question 244: Which of the following processes BEST supports the evaluatio...
Question 245: An organization wants to integrate information security into...
Question 246: In the context of developing an information security strateg...
Question 247: The PRIMARY consideration when responding to a ransomware at...
Question 248: An information security manager believes that information ha...
Question 249: Which of the following should be the FIRST step when perform...
Question 250: A PRIMARY purpose of creating security policies is to:...
Question 251: Which of the following is the MOST important reason to ensur...
Question 252: An information security manager has been asked to provide bo...
Question 253: Which of the following parties should be responsible for det...
Question 254: Which of the following should be the PRIMARY basis for deter...
Question 255: When testing an incident response plan for recovery from a r...
Question 256: While conducting a test of a business continuity plan (BCP),...
Question 257: The information security manager has been notified of a new ...
Question 258: To overcome the perception that security is a hindrance to b...
Question 259: To support effective risk decision making, which of the foll...
Question 260: Which of the following is the MOST effective way to determin...
Question 261: The PRIMARY advantage of single sign-on (SSO) is that it wil...
Question 262: Which of the following is the BEST way to help ensure an org...
Question 263: An information security manager is MOST likely to obtain app...
1 commentQuestion 264: Which of the following should be considered FIRST when recov...
Question 265: Spoofing should be prevented because it may be used to:...
Question 266: Which of the following BEST enables an information security ...
Question 267: Which of the following events is MOST likely to require an o...
Question 268: An organization that conducts business globally is planning ...
Question 269: The categorization of incidents is MOST important for evalua...
Question 270: Which of the following BEST demonstrates the added value of ...
Question 271: A balanced scorecard MOST effectively enables information se...
Question 272: Which of the following should include contact information fo...
Question 273: Which of the following defines the triggers within a busines...
Question 274: Which of the following is the BEST way to help ensure alignm...
Question 275: During which of the following phases should an incident resp...
Question 276: Which of the following is MOST important when developing an ...
Question 277: Which of the following should be an information security man...
Question 278: The MAIN reason for having senior management review and appr...
Question 279: Which of the following would provide the MOST effective secu...
Question 280: A business impact analysis (BIA) should be periodically exec...
Question 281: Which of the following provides the BEST evidence that a rec...
Question 282: An information security manager is working to incorporate me...
Question 283: Which of the following is the BEST justification for making ...
Question 284: In an organization with a rapidly changing environment, busi...
Question 285: Which of the following BEST provides an information security...
Question 286: The fundamental purpose of establishing security metrics is ...
Question 287: The MOST important reason for having an information security...
Question 288: A risk owner has accepted a large amount of risk due to the ...
Question 289: Which of the following has the GREATEST influence on an orga...
Question 290: Security administration efforts will be greatly reduced foll...
Question 291: Which of the following is MOST important for the improvement...
Question 292: A multinational organization is required to follow governmen...
Question 293: Which of the following is MOST useful to an information secu...
Question 294: An incident management team is alerted to a suspected securi...
Question 295: Which of the following trends would be of GREATEST concern w...
Question 296: Which of the following is the BEST indication ofa successful...
Question 297: Which of the following BEST enables an information security ...
Question 298: Which of the following is the PRIMARY purpose of a business ...
Question 299: An information security manager learns through a threat inte...
Question 300: Which of the following BEST describes a buffer overflow?...
Question 301: After a ransomware incident an organization's systems were r...
Question 302: An information security manager is assisting in the developm...
Question 303: Which of the following is the BEST tool to monitor the effec...
Question 304: Which of the following is the BEST option to lower the cost ...
Question 305: Which of the following BEST enables an organization to effec...
Question 306: Which of the following is MOST important for the effective i...
Question 307: Which of the following should an information security manage...
Question 308: An information security manager developing an incident respo...
Question 309: The ULTIMATE responsibility for ensuring the objectives of a...
Question 310: Which of the following is the PRIMARY responsibility of the ...
Question 311: Which of the following would BEST help to ensure compliance ...
Question 312: Which of the following is the MOST important consideration w...
Question 313: Which of the following should an information security manage...
Question 314: An organization has identified a large volume of old data th...
Question 315: An information security manager determines there are a signi...
Question 316: Which of the following would be the GREATEST threat posed by...
Question 317: An information security manager has become aware that a thir...
Question 318: An organization is about to purchase a rival organization. T...
Question 319: Which of the following risk scenarios is MOST likely to emer...
Question 320: Which of the following should have the MOST influence on an ...
Question 321: A security incident has been reported within an organization...
Question 322: A recent application security assessment identified a number...
Question 323: Which of the following is a PRIMARY responsibility of the in...
Question 324: An organization is experiencing a sharp increase in incident...
Question 325: Which of the following BEST indicates that information secur...
Question 326: Which of the following would BEST demonstrate the status of ...
Question 327: Which of the following will BEST facilitate the integration ...
Question 328: Which of the following roles is BEST suited to validate user...
Question 329: Which of the following is an example of risk mitigation?...