<< Prev Question Next Question >>

Question 253/419

A recent application security assessment identified a number of low- and medium-level vulnerabilities. Which of the following stakeholders is responsible for deciding the appropriate risk treatment option?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (419q)
Question 1: Which of the following should be an information security man...
Question 2: Information security policies should PRIMARILY reflect align...
Question 3: The MOST important reason for having an information security...
Question 4: Penetration testing is MOST appropriate when a:...
Question 5: Which of the following backup methods requires the MOST time...
Question 6: Which of the following is MOST important to have in place wh...
Question 7: The PRIMARY reason to properly classify information assets i...
Question 8: Reevaluation of risk is MOST critical when there is:...
Question 9: A forensic examination of a PC is required, but the PC has b...
Question 10: Which of the following should be the FIRST consideration whe...
Question 11: Data entry functions for a web-based application have been o...
Question 12: Which of the following should include contact information fo...
Question 13: To prepare for a third-party forensics investigation followi...
Question 14: Which of the following should an information security manage...
Question 15: Which of the following is the BEST indication that an organi...
Question 16: Which of the following is the PRIMARY reason to assign a ris...
Question 17: When developing an information security strategy for an orga...
Question 18: When management changes the enterprise business strategy whi...
Question 19: The PRIMARY advantage of single sign-on (SSO) is that it wil...
Question 20: Which of the following is the MOST important factor of a suc...
Question 21: Which of the following is MOST important to complete during ...
Question 22: Which of the following processes is MOST important for the s...
Question 23: An incident response team has established that an applicatio...
Question 24: When is the BEST time to verify that a production system's s...
Question 25: Which of the following is the BEST way to improve an organiz...
Question 26: The GREATEST challenge when attempting data recovery of a sp...
Question 27: Determining the risk for a particular threat/vulnerability p...
Question 28: A financial company executive is concerned about recently in...
Question 29: Which of the following is the BEST indication of a mature in...
Question 30: Which of the following should be done FIRST after a ransomwa...
Question 31: The PRIMARY reason to create and externally store the disk h...
Question 32: An information security manager finds that a soon-to-be depl...
Question 33: An organization has just updated its backup capability to a ...
Question 34: Which of the following is MOST important to have in place to...
Question 35: Which of the following is the GREATEST inherent risk when pe...
Question 36: A new risk has been identified in a high availability system...
Question 37: An organization is selecting security metrics to measure sec...
Question 38: Which of the following BEST enables staff acceptance of info...
Question 39: Which of the following events would MOST likely require a re...
Question 40: Which of the following is the MOST important benefit of usin...
Question 41: Which of the following is the BEST starting point for a newl...
Question 42: When selecting metrics to monitor the effectiveness of an in...
Question 43: What should be the NEXT course of action when an information...
Question 44: Which of the following Is MOST useful to an information secu...
Question 45: What should an information security manager do FIRST when an...
Question 46: Which of the following is the GREATEST concern resulting fro...
Question 47: Which of the following is the BEST course of action if the b...
Question 48: An organization plans to offer clients a new service that is...
Question 49: For the information security manager, integrating the variou...
Question 50: An information security team is investigating an alleged bre...
Question 51: An organization has identified an increased threat of extern...
Question 52: Which of the following is the BEST indicator of a successful...
Question 53: Which of the following BEST enables the restoration of opera...
Question 54: An organization has identified IT failures in a call center ...
Question 55: Following a risk assessment, an organization has made the de...
Question 56: Which of the following is the PRIMARY reason to perform regu...
Question 57: Which of the following is an information security manager's ...
Question 58: Which of the following is MOST important to ensuring informa...
Question 59: Which of the following is the MOST important issue in a pene...
Question 60: Business objectives and organizational risk appetite are MOS...
Question 61: Which of the following is MOST important for an information ...
Question 62: Of the following, who is in the BEST position to evaluate bu...
Question 63: Which of the following will ensure confidentiality of conten...
Question 64: Which of the following provides the BEST assurance that secu...
Question 65: A business unit recently integrated the organization's new s...
Question 66: During a post-incident review, it was determined that a know...
Question 67: Which of the following is the BEST justification for making ...
Question 68: An online trading company discovers that a network attack ha...
Question 69: What is the MOST important consideration for an organization...
Question 70: A financial institution is planning to develop a new mobile ...
Question 71: Which of the following considerations is MOST important when...
Question 72: An incident management team is alerted to a suspected securi...
Question 73: To overcome the perception that security is a hindrance to b...
Question 74: Which of the following would be MOST useful to a newly hired...
Question 75: Implementing the principle of least privilege PRIMARILY requ...
Question 76: Which of the following is MOST important to maintain integra...
Question 77: Which of the following is MOST important to include in an in...
Question 78: Which of the following is the BEST way to determine the gap ...
Question 79: Which of the following would provide the MOST effective secu...
Question 80: When drafting the corporate privacy statement for a public w...
Question 81: Which of the following functions is MOST critical when initi...
Question 82: Which or the following is MOST important to consider when de...
Question 83: When properly implemented, secure transmission protocols pro...
Question 84: An organization requires that business-critical applications...
Question 85: Which of the following eradication methods is MOST appropria...
Question 86: Network isolation techniques are immediately implemented aft...
Question 87: Which of the following should be updated FIRST to account fo...
Question 88: Which of the following is MOST effective in preventing the i...
Question 89: When designing a disaster recovery plan (DRP), which of the ...
Question 90: Communicating which of the following would be MOST helpful t...
Question 91: Company A, a cloud service provider, is in the process of ac...
Question 92: Which of the following should be the GREATEST consideration ...
Question 93: A department has reported that a security control is no long...
Question 94: Due to changes in an organization's environment, security co...
Question 95: Which of the following is MOST important when designing an i...
Question 96: Which of the following is MOST appropriate for an organizati...
Question 97: Which of the following BEST helps to ensure the effective ex...
Question 98: An information security manager has been notified about a co...
Question 99: Prior to implementing a bring your own device (BYOD) program...
Question 100: For event logs to be acceptable for incident investigation, ...
Question 101: When multiple Internet intrusions on a server are detected, ...
Question 102: Which type of recovery site is MOST reliable and can support...
Question 103: An incident response plan is being developed for servers hos...
Question 104: An organization faces severe fines and penalties if not in c...
Question 105: Which of the following is MOST important to include in an in...
Question 106: Which of the following would BEST support the business case ...
Question 107: An organization engages a third-party vendor to monitor and ...
Question 108: A penetration test was conducted by an accredited third part...
Question 109: Which of the following is the BEST way to address data avail...
Question 110: An incident response team recently encountered an unfamiliar...
Question 111: A small organization has a contract with a multinational clo...
Question 112: Which of the following is the BEST method for determining wh...
Question 113: Which of the following is the MOST important consideration w...
Question 114: An organization has remediated a security flaw in a system. ...
Question 115: Which of the following is MOST important to include in an in...
Question 116: Which of the following is the BEST way to help ensure alignm...
Question 117: Meeting which of the following security objectives BEST ensu...
Question 118: Which of the following is the PRIMARY reason for granting a ...
Question 119: From a business perspective, the GREATEST benefit of an inci...
Question 120: Which of the following is the BEST indication of an effectiv...
Question 121: Which of the following would MOST effectively ensure that a ...
Question 122: When testing an incident response plan for recovery from a r...
Question 123: Which of the following is the MOST important criterion when ...
Question 124: Which of the following is the PRIMARY benefit achieved when ...
Question 125: An information security manager has been notified that two s...
Question 126: The PRIMARY purpose of implementing information security gov...
Question 127: An information security team is planning a security assessme...
Question 128: Senior management wants to thoroughly test a disaster recove...
Question 129: Which of the following tools would be MOST helpful to an inc...
Question 130: Spoofing should be prevented because it may be used to:...
Question 131: Following an unsuccessful denial of service (DoS) attack, id...
Question 132: Which of the following is the BEST way to ensure data is not...
Question 133: Before approving the implementation of a new security soluti...
Question 134: Which of the following BEST determines the data retention st...
Question 135: Which of the following messages would be MOST effective in o...
Question 136: Which of the following is the BEST way to obtain support for...
Question 137: An information security team must obtain approval from the i...
Question 138: An information security manager notes that security incident...
Question 139: An international organization with remote branches is implem...
Question 140: An incident management team leader sends out a notification ...
Question 141: Which of the following presents the GREATEST challenge to a ...
Question 142: Which of the following is the BEST indication that an organi...
Question 143: Which of the following is the BEST way to enhance training f...
Question 144: Which of the following is the BEST indicator of an organizat...
Question 145: The PRIMARY benefit of integrating information security acti...
Question 146: Which of the following is the BEST way to obtain organizatio...
Question 147: Measuring which of the following is the MOST accurate way to...
Question 148: Which of the following is the MOST effective way to influenc...
Question 149: Which of the following is the MOST important consideration d...
Question 150: Which of the following BEST enables an organization to trans...
Question 151: Which of the following is the PRIMARY objective of incident ...
Question 152: An organization's research department plans to apply machine...
Question 153: A risk assessment exercise has identified the threat of a de...
Question 154: During the due diligence phase of an acquisition, the MOST i...
Question 155: Which of the following is the BEST technical defense against...
Question 156: When an organization lacks internal expertise to conduct hig...
Question 157: Which of the following is MOST important to the effectivenes...
Question 158: A KEY consideration in the use of quantitative risk analysis...
Question 159: Which of the following is the MOST effective way to prevent ...
Question 160: An employee clicked on a link in a phishing email, triggerin...
Question 161: Which of the following is the GREATEST benefit of including ...
Question 162: A penetration test against an organization's external web ap...
Question 163: Which of the following is the MOST effective way to identify...
Question 164: An organization is implementing an information security gove...
Question 165: Which of the following BEST helps to enable the desired info...
Question 166: During which of the following development phases is it MOST ...
Question 167: Which of the following has the MOST influence on the inheren...
Question 168: Which of the following is MOST helpful for aligning security...
Question 169: An information security manager is MOST likely to obtain app...
Question 170: Which of the following is the MOST appropriate metric to dem...
Question 171: A recovery point objective (RPO) is required in which of the...
Question 172: To support effective risk decision making, which of the foll...
Question 173: Which of the following metrics is MOST appropriate for evalu...
Question 174: Which of the following is BEST to include in a business case...
Question 175: Which of the following is the GREATEST benefit of conducting...
Question 176: A project team member notifies the information security mana...
Question 177: The PRIMARY purpose of conducting a business impact analysis...
Question 178: Which of the following should be considered FIRST when recov...
Question 179: Which of the following is the BEST way to contain an SQL inj...
Question 180: The PRIMARY objective of performing a post-incident review i...
Question 181: Which of the following is MOST important to consider when de...
Question 182: An employee who is a remote user has copied financial data f...
Question 183: Which of the following is the BEST source of information to ...
Question 184: Once a suite of security controls has been successfully impl...
Question 185: An organization needs to comply with new security incident r...
Question 186: An organization has implemented controls to mitigate risks r...
Question 187: Which of the following BEST demonstrates the added value of ...
Question 188: Which of the following is the PRIMARY benefit of implementin...
Question 189: An organization plans to utilize Software as a Service (SaaS...
Question 190: Which of the following elements of a service contract would ...
Question 191: Which of the following is an information security manager's ...
Question 192: An online bank identifies a successful network attack in pro...
Question 193: An information security program is BEST positioned for succe...
Question 194: When performing a business impact analysis (BIA), who should...
Question 195: An organization has implemented a new customer relationship ...
Question 196: An organization would like to invest in a new emerging techn...
Question 197: An organization's main product is a customer-facing applicat...
Question 198: Which of the following is the BEST control to protect custom...
Question 199: Which of the following is the BEST course of action for an i...
Question 200: What is the PRIMARY objective of implementing standard secur...
Question 201: Which of the following MUST be established to maintain an ef...
Question 202: Which of the following presents the GREATEST challenge to th...
Question 203: Of the following, who should be assigned as the owner of a n...
Question 204: To inform a risk treatment decision, which of the following ...
Question 205: Which of the following presents the GREATEST challenge to a ...
Question 206: What is the role of the information security manager in fina...
Question 207: An investigation of a recent security incident determined th...
Question 208: Which of the following BEST provides an information security...
Question 209: An information security manager is working to incorporate me...
Question 210: Which of the following should an information security manage...
Question 211: Data classification is PRIMARILY the responsibility of:...
Question 212: After logging in to a web application, additional authentica...
Question 213: Recovery time objectives (RTOs) are an output of which of th...
Question 214: An organization experienced a loss of revenue during a recen...
Question 215: Which of the following is the MOST important detail to captu...
Question 216: If the investigation of an incident is not completed within ...
Question 217: The MAIN benefit of implementing a data loss prevention (DLP...
Question 218: When performing a business impact analysis (BIA), who should...
Question 219: Which of the following BEST facilitates the effectiveness of...
Question 220: Which of the following is MOST important to include in a pos...
Question 221: Which of the following should be done FIRST to prioritize re...
Question 222: During which of the following phases should an incident resp...
Question 223: When preventive controls to appropriately mitigate risk are ...
Question 224: Which of the following is MOST important to convey to employ...
Question 225: Which of the following BEST facilitates the effective execut...
Question 226: The business value of an information asset is derived from:...
Question 227: An organization has received complaints from users that some...
Question 228: Which of the following would be MOST helpful to identify wor...
Question 229: An organization is about to purchase a rival organization. T...
Question 230: A common drawback of email software packages that provide na...
Question 231: Threat and vulnerability assessments are important PRIMARILY...
Question 232: Which of the following BEST enables an organization to opera...
Question 233: Which of the following components of an information security...
Question 234: Recovery time objectives (RTOs) are BEST determined by:...
Question 235: Which of the following is the PRIMARY responsibility of an i...
Question 236: Of the following, who is BEST suited to own the risk discove...
Question 237: Which of the following should be done FIRST when establishin...
Question 238: Which of the following is the BEST way to ensure the busines...
Question 239: Which of the following should an information security manage...
Question 240: Which of the following should be the FIRST step in developin...
Question 241: A data loss prevention (DLP) tool has flagged personally ide...
Question 242: Which of the following is the BEST approach to reduce unnece...
Question 243: Which of the following BEST enables an organization to effec...
Question 244: Which of the following is MOST critical when creating an inc...
Question 245: Which of the following would be MOST helpful when creating i...
Question 246: A global organization is planning to expand its operations i...
Question 247: An organization is in the process of acquiring a new company...
Question 248: Which of the following is the PRIMARY reason to use a phased...
Question 249: An organization's information security manager is performing...
Question 250: Which of the following should have the MOST influence on an ...
Question 251: Which of the following is the BEST indication ofa successful...
Question 252: Which of the following is the BEST approach for managing use...
Question 253: A recent application security assessment identified a number...
Question 254: An organization has acquired a company in a foreign country ...
Question 255: Which of the following metrics would BEST demonstrate the su...
Question 256: Which of the following metrics BEST demonstrates the effecti...
Question 257: Reviewing which of the following would be MOST helpful when ...
Question 258: Unintentional behavior by an employee caused a major data lo...
Question 259: Which of the following is MOST important to include in month...
Question 260: Which of the following BEST illustrates residual risk within...
Question 261: A critical server for a hospital has been encrypted by ranso...
Question 262: Which of the following is MOST important for building 4 robu...
Question 263: Which of the following is a desired outcome of information s...
Question 264: Which of the following is MOST helpful in determining whethe...
Question 265: Who should be responsible for determining the level of data ...
Question 266: Which of the following would BEST demonstrate the status of ...
Question 267: Which of the following BEST indicates that information secur...
Question 268: During the implementation of a new system, which of the foll...
Question 269: What should a global information security manager do FIRST w...
Question 270: Which of the following presents the GREATEST risk associated...
Question 271: Which of the following is the MOST important reason to consi...
Question 272: Which of the following is the MOST important characteristic ...
Question 273: Which of the following is necessary to ensure consistent pro...
Question 274: In a cloud technology environment, which of the following wo...
Question 275: ACISO learns that a third-party service provider did not not...
Question 276: An organization's HR department requires that employee accou...
Question 277: An organization is close to going live with the implementati...
Question 278: Which of the following will BEST facilitate the integration ...
Question 279: An organization is planning to outsource network management ...
Question 280: Which of the following is MOST important in increasing the e...
Question 281: Following an unsuccessful denial of service (DoS) attack, id...
Question 282: In a call center, the BEST reason to conduct a social engine...
Question 283: A newly appointed information security manager has been aske...
Question 284: Which of the following would BEST guide the development and ...
Question 285: During the initiation phase of the system development life c...
Question 286: Which of the following BEST enables the integration of infor...
Question 287: Which of the following is MOST important for the effective i...
Question 288: Which of the following is the PRIMARY objective of informati...
Question 289: Which of the following devices, when placed in a demilitariz...
Question 290: To help users apply appropriate controls related to data pri...
Question 291: Detailed business continuity plans (BCPs) should be PRIMARIL...
Question 292: Which of the following is the PRIMARY benefit of an informat...
Question 293: Which of the following has the GREATEST impact on the effect...
Question 294: Which of the following is a viable containment strategy for ...
Question 295: The MOST appropriate time to conduct a disaster recovery tes...
Question 296: Which of the following is MOST important to ensure when deve...
Question 297: Which of the following BEST enables an organization to deter...
Question 298: Which of the following is a PRIMARY benefit of managed secur...
Question 299: An organization is in the process of defining policies for e...
Question 300: Of the following, who would provide the MOST relevant input ...
Question 301: Which of the following would BEST ensure that security is in...
Question 302: Which of the following BEST supports information security ma...
Question 303: An organization has purchased an Internet sales company to e...
Question 304: Several months after the installation of a new firewall with...
Question 305: An organization is MOST likely to accept the risk of noncomp...
Question 306: Which of the following is the PRIMARY reason to review the f...
Question 307: Which of the following is the GREATEST benefit of performing...
Question 308: Which of the following provides the MOST useful information ...
Question 309: What is the PRIMARY objective of performing a vulnerability ...
Question 310: In a business proposal, a potential vendor promotes being ce...
Question 311: A risk owner has accepted a large amount of risk due to the ...
Question 312: A balanced scorecard MOST effectively enables information se...
Question 313: Which of the following should be the MOST important consider...
Question 314: Which of the following metrics provides the BEST evidence of...
Question 315: Which of the following is the BEST way to reduce the risk as...
Question 316: An organization has decided to implement an Internet of Thin...
Question 317: Which of the following has The GREATEST positive impact on T...
Question 318: Which of the following is the MOST critical input to develop...
Question 319: Which of the following is MOST important for the information...
Question 320: When developing security processes for handling credit card ...
Question 321: Which of the following should an information security manage...
Question 322: Which of the following is MOST difficult to measure followin...
Question 323: The ULTIMATE responsibility for ensuring the objectives of a...
Question 324: Which of the following will BEST facilitate timely and effec...
Question 325: What should be an information security manager's MOST import...
Question 326: An organization has updated its business goals in the middle...
Question 327: The BEST way to report to the board on the effectiveness of ...
Question 328: An intrusion has been detected and contained. Which of the f...
Question 329: When investigating an information security incident, details...
Question 330: Which of the following is the BEST tool to use for identifyi...
Question 331: Which of the following BEST enables an information security ...
Question 332: Which of the following would BEST enable a new information s...
Question 333: An information security manager has recently been notified o...
Question 334: Which of the following is the BEST defense against a brute f...
Question 335: Which of the following is the BEST way to compete for fundin...
Question 336: Which of the following BEST facilitates recovery of data los...
Question 337: A global organization is developing an incident response tea...
Question 338: Which of the following would be MOST useful to help senior m...
Question 339: While responding to a high-profile security incident, an inf...
Question 340: Which of the following should be the MOST important consider...
Question 341: An organization is considering the feasibility of implementi...
Question 342: Which of the following BEST indicates that information asset...
Question 343: Which of the following is the MOST effective way to ensure t...
Question 344: Which of the following is the GREATEST benefit of using AI t...
Question 345: Which of the following desired outcomes BEST supports a deci...
Question 346: Which of the following is the MOST effective way to increase...
Question 347: Which of the following is MOST helpful in the development of...
Question 348: Which of the following should be implemented to BEST reduce ...
Question 349: Which of the following is MOST important for the successful ...
Question 350: Which of the following plans should be invoked by an organiz...
Question 351: Which of the following would BEST help to ensure compliance ...
Question 352: An organization has determined that fixing a security vulner...
Question 353: Which of the following should be established FIRST when impl...
Question 354: Which of the following is the BEST way to ensure the organiz...
Question 355: Which of the following BEST facilitates the development of a...
Question 356: An organization's automated security monitoring tool generat...
Question 357: After a ransomware incident an organization's systems were r...
Question 358: Which of the following is MOST helpful for determining which...
Question 359: Which of the following should be the PRIMARY area of focus w...
Question 360: Which of the following should be the PRIMARY objective of th...
Question 361: Which of the following control types should be considered FI...
Question 362: A security incident has been reported within an organization...
Question 363: An organization is going through a digital transformation pr...
Question 364: The PRIMARY goal to a post-incident review should be to:...
Question 365: Which of the following is the BEST indicator of an emerging ...
Question 366: Which of the following is the PRIMARY reason to regularly up...
Question 367: Which of the following is the BEST evidence of alignment bet...
Question 368: Which of the following is MOST important for the improvement...
Question 369: Which of the following should an information security manage...
Question 370: Which type of plan is PRIMARILY intended to reduce the poten...
Question 371: Which of the following is the BEST indication of effective i...
Question 372: Of the following, whose input is of GREATEST importance in t...
Question 373: An information security manager has confirmed the organizati...
Question 374: Which of the following is the MOST important outcome of effe...
Question 375: Which of the following roles is BEST able to influence the s...
Question 376: Which of the following is the BEST defense-in-depth implemen...
Question 377: Which of the following is the sole responsibility of the cli...
Question 378: Which of the following is the PRIMARY objective of testing s...
Question 379: An information security manager has become aware that a thir...
Question 380: Which of the following is the MOST important constraint to b...
Question 381: When analyzing the emerging risk and threat landscape, an in...
Question 382: An organization has decided to outsource IT operations. Whic...
Question 383: Which of the following is the BEST method for determining wh...
Question 384: Which of the following is the MOST important factor in an or...
Question 385: Which of the following is MOST important to have in place as...
Question 386: Which of the following is MOST important to include in an in...
Question 387: An organization is leveraging tablets to replace desktop com...
Question 388: An information security team has discovered that users are s...
Question 389: A security review identifies that confidential information o...
Question 390: The executive management of a domestic organization has anno...
Question 391: Which of the following is the MOST important reason for logg...
Question 392: Which of the following is MOST important for an information ...
Question 393: A security incident has been reported within an organization...
Question 394: Which of the following is the MOST important objective when ...
Question 395: Information security controls should be designed PRIMARILY b...
Question 396: The effectiveness of an information security governance fram...
Question 397: Which of the following is the BEST way for an organization t...
Question 398: Relationships between critical systems are BEST understood b...
Question 399: A multinational organization is introducing a security gover...
Question 400: Who is accountable for ensuring proper controls are in place...
Question 401: Which of the following is the MOST important security consid...
Question 402: Which of the following provides the BEST input to determine ...
Question 403: The BEST way to identify the risk associated with a social e...
Question 404: Which of the following is the BEST way to build a risk-aware...
Question 405: A PRIMARY benefit of adopting an information security framew...
Question 406: Which of the following analyses will BEST identify the exter...
Question 407: What is the PRIMARY benefit to an organization when informat...
Question 408: Who is BEST suited to determine how the information in a dat...
Question 409: Which risk is introduced when using only sanitized data for ...
Question 410: Who has the PRIMARY authority to decide if additional risk t...
Question 411: Which of the following is a PRIMARY function of an incident ...
Question 412: Which of the following is CRITICAL to ensure the appropriate...
Question 413: To ensure that a new application complies with information s...
Question 414: A business impact analysis (BIA) BEST enables an organizatio...
Question 415: Reverse lookups can be used to prevent successful:...
Question 416: Which of the following is PRIMARILY determined by asset clas...
Question 417: A user reports a stolen personal mobile device that stores s...
Question 418: What is the PRIMARY benefit to an organization that maintain...
Question 419: The PRIMARY advantage of performing black-box control tests ...