<< Prev Question Next Question >>

Question 27/593

The security baselines of an organization should be based on:

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (593q)
Question 1: The PRIMARY reason to properly classify information assets i...
Question 2: Which of the following BEST demonstrates the effectiveness o...
Question 3: Of the following, who is BEST positioned to perform a busine...
Question 4: An organization dealing with an increased number of successf...
Question 5: A hacking group has posted an organization's employee data o...
Question 6: Information security needs to invest in new tools to align w...
Question 7: An outsourced vendor handles an organization's business-crit...
Question 8: Which of the following is the GREATEST benefit of integratin...
Question 9: Which of the following information security activities is MO...
Question 10: Which of the following is the PRIMARY purpose of an incident...
Question 11: An information security manager wants to upgrade an organiza...
Question 12: Which of the following metrics would BEST measure the reliab...
Question 13: Activities leading up to the declaration of a disaster as ou...
Question 14: Which of the following should occur NEXT after a successful ...
Question 15: Of the following, who should own the risk associated with un...
Question 16: During an information security audit, it was determined that...
Question 17: What is the MOST important information to provide to senior ...
Question 18: Which of the following backups is BEST for forensic purposes...
Question 19: Which of the following BEST indicates that an organization h...
Question 20: Which of the following is the PRIMARY benefit of assigning c...
Question 21: Which of the following BEST mitigates risk associated with a...
Question 22: In an organization that has an established social media poli...
Question 23: After a recent malware incident, an organization's IT steeri...
Question 24: The security team is developing a business case to submit to...
Question 25: A chief information security officer (CISO) has identified m...
Question 26: Which of the following should be done FIRST after a ransomwa...
Question 27: The security baselines of an organization should be based on...
Question 28: In the context of DevSecOps, which of the following BEST ena...
Question 29: Which of the following is the BEST reason to implement a com...
Question 30: Which of the following is the BEST approach for encouraging ...
Question 31: What is the PRIMARY role of the information security program...
Question 32: Which of the following should be of GREATEST concern to an i...
Question 33: Which of the following is the MOST effective method to ensur...
Question 34: Which of the following BEST demonstrates the potential for s...
Question 35: Which of the following is MOST effective for real-time ident...
Question 36: A startup company deployed several new applications with vul...
Question 37: Which of the following roles is PRIMARILY accountable for re...
Question 38: An organization experienced a loss of revenue during a recen...
Question 39: When developing an information security strategy for an orga...
Question 40: Which of the following devices, when placed in a demilitariz...
Question 41: Without prior approval a training department enrolled the co...
Question 42: Which of the following is the BEST course of action when it ...
Question 43: An organization has decided to implement an Internet of Thin...
Question 44: A new information security manager learns that the organizat...
Question 45: Which of the following BEST enables an organization to trans...
Question 46: An information security team must obtain approval from the i...
Question 47: A multinational organization is introducing a security gover...
Question 48: Which of the following is the PRIMARY purpose of a business ...
Question 49: Meeting which of the following security objectives BEST ensu...
Question 50: Which of the following should be the NEXT step after a secur...
Question 51: Which of the following BEST enables the effectiveness of an ...
Question 52: Which of the following is the BEST approach for an informati...
Question 53: Which of the following is the PRIMARY objective of the incid...
Question 54: An organization has adopted a generative AI system. Which of...
Question 55: An organization successfully responded to an information sec...
Question 56: Which of the following is the MOST appropriate action during...
Question 57: At what point should risk ownership be assigned?...
Question 58: What is the information security steering committee's PRIMAR...
Question 59: An employee of an organization has reported losing a smartph...
Question 60: Which of the following is the MOST critical input to develop...
Question 61: Which of the following should be done FIRST in response to a...
Question 62: The cost of a security mechanism should be aligned to the:...
Question 63: Which of the following is MOST appropriate to report to mana...
Question 64: Which of the following processes determines whether an event...
Question 65: Which of the following would BEST help an organization ident...
Question 66: Which of the following provides the MOST comprehensive insig...
Question 67: Several months after the installation of a new firewall with...
Question 68: Which of the following is the BEST method for determining wh...
Question 69: An information security manager finds that the security func...
Question 70: Which of the following BEST conveys minimum information secu...
Question 71: Which of the following is the MOST effective long-term metho...
Question 72: Which of the following is the BEST reason to include an inci...
Question 73: Which of the following is an information security manager's ...
Question 74: Which of the following is the MOST important component of in...
Question 75: Which of the following should an information security manage...
Question 76: An organization is transitioning to a Zero Trust architectur...
Question 77: Which of the following eradication methods is MOST appropria...
Question 78: Which of the following is the MOST effective alternative to ...
Question 79: Which of the following should be an information security man...
Question 80: What is the PRIMARY purpose of an unannounced disaster recov...
Question 81: Which of the following observations should be of GREATEST co...
Question 82: For an application hosted in a public cloud, which of the fo...
Question 83: Risk treatment options should PRIMARILY focus on:...
Question 84: The PRIMARY reason to establish a business continuity plan (...
Question 85: Which of the following is MOST important when developing an ...
Question 86: The PRIMARY objective of an organized phishing simulation is...
Question 87: An information security manager learns that a risk owner has...
Question 88: Which of the following is the PRIMARY reason to involve stak...
Question 89: An organization has identified IT failures in a call center ...
Question 90: What should be used to determine whether an information asse...
Question 91: Which of the following is the MOST important benefit of cond...
Question 92: Which of the following BEST demonstrates senior management s...
Question 93: Which of the following is the MOST appropriate risk response...
Question 94: Senior management has requested a budget cut for the informa...
Question 95: The PRIMARY purpose of an information security governance fr...
Question 96: Which of the following is the MOST important consideration w...
Question 97: Which of the following is the MOST appropriate response to a...
Question 98: An organization has implemented a new email filter to mitiga...
Question 99: The department head of application development has decided t...
Question 100: Which of the following is the MOST important characteristic ...
Question 101: A financial institution is expanding to international jurisd...
Question 102: The executive management of a domestic organization has anno...
Question 103: The MOST important reason to classify security incidents is ...
Question 104: A post-incident review revealed that key stakeholders took l...
Question 105: Who should be responsible for determining the level of data ...
Question 106: Which of the following is an objective of incident containme...
Question 107: Which of the following would be the PRIMARY reason to use a ...
Question 108: When reporting information security risk to senior managemen...
Question 109: An information security manager has completed a risk assessm...
Question 110: What should be the PRIMARY objective of an information secur...
Question 111: Which of the following is the MOST important consideration w...
Question 112: Which of the following should be given the HIGHEST priority ...
Question 113: A new information security manager finds that the organizati...
Question 114: Which of the following attributes is MOST important to consi...
Question 115: Which of the following should be the FIRST step in recoverin...
Question 116: When recommending compensating controls for a system, which ...
Question 117: Which of the following metrics BEST measures the effectivene...
Question 118: As part of an organization's business continuity plan (BCP),...
Question 119: Which of the following is MOST important to include in an in...
Question 120: Which of the following is MOST important to consider when de...
Question 121: Which of the following is the MOST common contributor to cyb...
Question 122: Which of the following is the MOST critical requirement to b...
Question 123: A disaster recovery plan (DRP) is MOST likely to be activate...
Question 124: Which of the following is MOST important to verify during a ...
Question 125: Which of the following BEST enables organizations to conduct...
Question 126: Which of the following is the MOST important consideration w...
Question 127: A robotic process automation (RPA) assisting in monthly bank...
Question 128: Which of the following is a PRIMARY responsibility of a data...
Question 129: An organization has been adhering to the requirements of str...
Question 130: Which of the following is MOST important to the effectivenes...
Question 131: Which of the following is the BEST method for minimizing the...
Question 132: Which of the following is the GREATEST benefit of conducting...
Question 133: Which of the following BEST enables an organization to enhan...
Question 134: When building or upgrading enterprise cryptographic infrastr...
Question 135: A business unit has requested an exception to the organizati...
Question 136: An incident response plan is being developed for servers hos...
Question 137: Which of the following BEST determines whether an incident r...
Question 138: During which phase of new system development should an organ...
Question 139: What is the BEST way for an information security manager to ...
Question 140: Which of the following is a PRIMARY reason for senior manage...
Question 141: Which of the following is MOST important when performing ass...
Question 142: Which of the following should be established FIRST when impl...
Question 143: What will BEST facilitate the success of new security initia...
Question 144: Which of the following is the BEST resource for determining ...
Question 145: Which of the following is the PRIMARY objective of developin...
Question 146: An organization has suffered from a large-scale security eve...
Question 147: Which of the following is the MOST relevant control to addre...
Question 148: What is the BEST way to address vulnerabilities associated w...
Question 149: Which of the following is the MOST useful input for a busine...
Question 150: An organization has learned that several employees recently ...
Question 151: Which of the following is MOST likely to be impacted when em...
Question 152: Which of the following should be the MOST important consider...
Question 153: When selecting metrics to monitor the effectiveness of an in...
Question 154: Which of the following activities is MOST appropriate to con...
Question 155: An information security manager discovers that the organizat...
Question 156: Which of the following is the MOST important component of th...
Question 157: Which of the following is the MOST important reason to devel...
Question 158: An organization has identified a weakness in the ability of ...
Question 159: Which of the following has the GREATEST impact on the abilit...
Question 160: Which of the following is the MOST effective way to identify...
Question 161: During incident recovery, which of the following is the BEST...
Question 162: Which of the following BEST helps to ensure a third-party ba...
Question 163: When performing a computer forensics investigation, a securi...
Question 164: Which of the following would pose the GREATEST risk to the p...
Question 165: A financial institution experiences a cybersecurity incident...
Question 166: An organization experienced a breach which was successfully ...
Question 167: An organization has implemented controls to mitigate risks r...
Question 168: Recommendations for investment in security technology should...
Question 169: Which of the following is the MOST important goal when analy...
Question 170: For an e-business that requires high availability, which of ...
Question 171: During the due diligence phase of an acquisition, the MOST i...
Question 172: After an incident has been eradicated, which of the followin...
Question 173: Which of the following is the MOST effective way to ensure t...
Question 174: Which of the following should be an information security man...
Question 175: Which of the following elements of a service contract would ...
Question 176: Which of the following BEST enables an information security ...
Question 177: Which of the following is the BEST way for an organization t...
Question 178: Which of the following is the GREATEST benefit of including ...
Question 179: Which of the following should be the MOST important consider...
Question 180: Which of the following information BEST supports risk manage...
Question 181: Which of the following is the BEST evidence of an effectivel...
Question 182: Which of the following groups MUST be involved in developing...
Question 183: Which of the following is the BEST way for the organization ...
Question 184: An organization is migrating critical workloads to a multi-c...
Question 185: When conducting a post-implementation review for a security ...
Question 186: Which of the following BEST helps to reduce system configura...
Question 187: An organization is in the process of selecting a third party...
Question 188: Which of the following BEST indicates ongoing senior managem...
Question 189: Which of the following should have the MOST influence on an ...
Question 190: What is the MOST important consideration when establishing m...
Question 191: Which of the following is MOST likely to require an organiza...
Question 192: Which of the following is the BEST defense-in-depth implemen...
Question 193: A small organization's information security manager is consi...
Question 194: Which of the following BEST facilitates recovery of data los...
Question 195: A business unit is not complying with a control implemented ...
Question 196: Which of the following BEST enables an organization to conti...
Question 197: During a post-incident review, which of the following would ...
Question 198: An organization learns that a third party has outsourced cri...
Question 199: Which of the following is the MOST important factor in an or...
Question 200: Which of the following information security aspects benefits...
Question 201: Which of the following is the MOST important objective of po...
Question 202: An organization's head of information security has been task...
Question 203: Which of the following processes can be used to remediate id...
Question 204: Access logs that are frequently required as evidence in lega...
Question 205: An enterprise has decided to procure security services from ...
Question 206: Which of the following is MOST important for an information ...
Question 207: An intrusion prevention system (IPS) has reported a signific...
Question 208: An information security manager has identified the loss of c...
Question 209: The PRIMARY purpose of a cloud access security broker (CASB)...
Question 210: The categorization of incidents is MOST important for evalua...
Question 211: Which of the following BEST minimizes disruptions to service...
Question 212: Which of the following BEST enables the implementation of an...
Question 213: An organization depends on a complex supply chain to support...
Question 214: Which of the following security practices is MOST essential ...
Question 215: Which of the following BEST contributes to a strong informat...
Question 216: A business impact analysis (BIA) should be periodically exec...
Question 217: Which of the following is best practice for the implementati...
Question 218: Senior management is concerned about data exposure through t...
Question 219: When developing an incident response plan, which of the foll...
Question 220: Which of the following BEST enables users to recover from ra...
Question 221: Which of the following is the MOST appropriate metric to dem...
Question 222: Which of the following provides the BEST opportunity to eval...
Question 223: Which of the following should an information security manage...
Question 224: Which of the following should be the PRIMARY basis for a sev...
Question 225: A mean time to resolve (MTTR) metric reported to senior mana...
Question 226: A business impact analysis (BIA) BEST enables an organizatio...
Question 227: For an organization that subscribes to a cloud computing ser...
Question 228: Which of the following should be the information security ma...
Question 229: A Software as a Service (SaaS) application has been implemen...
Question 230: Which of the following should be the PRIMARY goal of informa...
Question 231: Which of the following is the information security manager's...
Question 232: Which of the following is the PRIMARY responsibility of a da...
Question 233: An information security manager learns that a third-party da...
Question 234: Which of the following BEST enables the restoration of opera...
Question 235: Which of the following would be MOST helpful if more detail ...
Question 236: When implementing a Zero Trust Architecture (ZTA), which of ...
Question 237: Application security controls should FIRST be addressed duri...
Question 238: Which of the following is the MOST important objective of a ...
Question 239: Which of the following is the PRIMARY purpose of performing ...
Question 240: A critical vulnerability has been discovered in a password v...
Question 241: When taking a risk-based approach to vulnerability managemen...
Question 242: Which of the following will BEST facilitate integrating the ...
Question 243: Which of the following is the BEST way to monitor the effect...
Question 244: An organization is evaluating mobile device management (MDM)...
Question 245: The PRIMARY reason to conduct application security and penet...
Question 246: Which of the following should be the PRIMARY focus for an in...
Question 247: An organization is planning to open a new office in another ...
Question 248: Which of the following provides the GREATEST assurance that ...
Question 249: Which of the following risk assessment findings for an onlin...
Question 250: A healthcare company is scanning patient health records with...
Question 251: Which of the following BEST encourages staff to report issue...
Question 252: An organization's information security manager should PRIMAR...
Question 253: Which of the following is MOST important to consider when de...
Question 254: Which of the following BEST ensures prompt and effective com...
Question 255: An organization is considering the feasibility of implementi...
Question 256: Which of the following is MOST helpful to an information sec...
Question 257: Which of the following BEST helps to establish an organizati...
Question 258: An organization is considering using a third party to host s...
Question 259: Which of the following is the MOST important consideration w...
Question 260: The integration of information security risk management proc...
Question 261: Which of the following is the GREATEST benefit of integratin...
Question 262: Which of the following would be MOST important to include in...
Question 263: Which of the following would BEST support the business case ...
Question 264: Which of the following is the BEST way to obtain organizatio...
Question 265: Which of the following is the BEST way to help ensure timely...
Question 266: When developing a categorization method for security inciden...
Question 267: Which of the following is an example of a deterrent control?...
Question 268: Which of the following should an information security manage...
Question 269: Which of the following is the BEST metric to measure the eff...
Question 270: Which of the following is the PRIMARY reason to continue inc...
Question 271: To help users apply appropriate controls related to data pri...
Question 272: A risk assessment of a custom application was performed duri...
Question 273: An organization is looking to incorporate DevSecOps practice...
Question 274: Which of the following roles is accountable for the protecti...
Question 275: Which of the following has the GREATEST impact on the effect...
Question 276: Which of the following metrics would BEST demonstrate the su...
Question 277: While responding to a security incident, the response team r...
Question 278: An access rights review revealed that some former employees'...
Question 279: Which of the following should be the PRIMARY area of focus w...
Question 280: Which of the following techniques should be applied FIRST to...
Question 281: An incident handler is preparing a forensic image of a hard ...
Question 282: Which of the following is MOST important for obtaining senio...
Question 283: Which of the following is MOST helpful for determining which...
Question 284: Which of the following is the BEST approach for an informati...
Question 285: Which of the following is the MOST effective data loss contr...
Question 286: Which of the following is the BEST approach for addressing n...
Question 287: Which of the following is the PRIMARY reason to establish in...
Question 288: Which of the following should be considered FIRST when respo...
Question 289: Which of the following MOST effectively allows for disaster ...
Question 290: Which of the following provides the MOST comprehensive under...
Question 291: Which of the following should be implemented FIRST when deve...
Question 292: Which of the following should be implemented to BEST reduce ...
Question 293: To improve an organization's information security culture, i...
Question 294: Which of the following should be considered FIRST when updat...
Question 295: Which of the following tools would be MOST helpful to an inc...
Question 296: Which of the following is MOST important for building a stro...
Question 297: Which of the following BEST illustrates residual risk within...
Question 298: Which of the following is the PRIMARY role of digital forens...
Question 299: Which of the following is the PRIMARY reason to use a phased...
Question 300: Which of the following BEST enables the successful implement...
Question 301: Which of the following is the GREATEST benefit of business c...
Question 302: Which of the following is a PRIMARY goal of conducting a pos...
Question 303: Within an incident response plan, which of the following MUS...
Question 304: When integrating security risk management into an organizati...
Question 305: The PRIMARY purpose of conducting a business impact analysis...
Question 306: Which of the following is MOST helpful in determining whethe...
Question 307: A business unit has updated its long-term business plan to i...
Question 308: Which of the following is the MOST appropriate action during...
Question 309: From a business perspective, the GREATEST benefit of an inci...
Question 310: Which of the following is a prerequisite for formulating a b...
Question 311: Which of the following is the MOST important consideration w...
Question 312: Who is PRIMARILY responsible for selecting risk responses fo...
Question 313: Which of the following provides the BEST evidence that a sec...
Question 314: An organization is increasingly using Software as a Service ...
Question 315: Defining risk appetite PRIMARILY helps an organization to:...
Question 316: Which of the following is MOST important to have in place to...
Question 317: Which of the following is the MOST important reason to ensur...
Question 318: Which of the following is MOST important to include when pre...
Question 319: Which of the following is the MOST common cause of cybersecu...
Question 320: Which of the following is MOST important to include in a sec...
Question 321: Which of the following is the MOST useful input for an infor...
Question 322: Which of the following is the MOST important consideration r...
Question 323: Which of the following is the BEST way to reduce the risk as...
Question 324: Which of the following should be done FIRST to prioritize re...
Question 325: Which of the following is MOST important to the ongoing effe...
Question 326: Following an unsuccessful denial of service (DoS) attack, id...
Question 327: When establishing an information security governance framewo...
Question 328: Which of the following should be an IS auditor's PRIMARY foc...
Question 329: A post-incident review reveals that incidents are not report...
Question 330: Which of the following is MOST important to convey to employ...
Question 331: Which of the following is the GREATEST concern when an organ...
Question 332: An organization identified a security breach resulting from ...
Question 333: Which of the following is the MOST important consideration f...
Question 334: Which of the following is the MOST important reason for an i...
Question 335: An organization has recently purchased cybersecurity insuran...
Question 336: Which of the following is the BEST way to enhance an organiz...
Question 337: Which of the following BEST indicates the organizational ben...
Question 338: When an organization fosters a culture where security awaren...
Question 339: Which of the following is the GREATEST benefit resulting fro...
Question 340: Which of the following principles BEST addresses the protect...
Question 341: Which of the following is the MOST effective way to ensure t...
Question 342: Which of the following is the PRIMARY reason to perform regu...
Question 343: Following a breach where the risk has been isolated and fore...
Question 344: Which of the following would BEST enable senior management t...
Question 345: Which of the following actions is MOST important to perform ...
Question 346: Which of the following would be MOST useful to a newly hired...
Question 347: The manager of a key project has bypassed the standard contr...
Question 348: Which of the following is an information security manager's ...
Question 349: Which of the following metrics provides the BEST evidence of...
Question 350: An organization plans to implement a new e-commerce operatio...
Question 351: A new risk has been identified in a high availability system...
Question 352: Which of the following actions should be taken during a post...
Question 353: Which of the following topics within an incident response tr...
Question 354: Which of the following should a newly appointed information ...
Question 355: Which of the following is the MOST important component of a ...
Question 356: Which of the following should be done FIRST when a system is...
Question 357: Which of the following BEST helps to ensure risk appetite is...
Question 358: Which of the following is the BEST way to determine the read...
Question 359: The BEST way to achieve a strong information security cultur...
Question 360: Which of the following is the GREATEST potential risk associ...
Question 361: An organization wants to integrate information security into...
Question 362: In the event that password rules cannot be implemented for a...
Question 363: Which of the following is the MOST essential element of an i...
Question 364: Which of the following is the BEST reason to implement an in...
Question 365: Which of the following is the PRIMARY benefit of training se...
Question 366: Which of the following is the BEST source of data for measur...
Question 367: For an enterprise implementing a bring your own device (BYOD...
Question 368: Which of the following is the PRIMARY reason for granting a ...
Question 369: Which of the following is the BEST indication of a mature in...
Question 370: Which of the following is the GREATEST benefit of a successf...
Question 371: Which of the following is MOST important to enable the escal...
Question 372: A contract bid is digitally signed and electronically mailed...
Question 373: Which of the following should be the PRIMARY basis for deter...
Question 374: Which of the following roles is BEST able to influence the s...
Question 375: Which of the following is a viable containment strategy for ...
Question 376: An information security manager has identified that a third-...
Question 377: Which of the following actions will BEST resolve the root ca...
Question 378: In a Zero Trust architecture, which of the following is the ...
Question 379: Which of the following is an example of a change to the exte...
Question 380: Which of the following would BEST address the risk of a syst...
Question 381: When introducing a new information asset, what is the MOST i...
Question 382: Which of the following should be the FIRST consideration whe...
Question 383: Which of the following is the BEST way to integrate informat...
Question 384: An organization requires that business critical applications...
Question 385: The MOST effective way to present information security risk ...
Question 386: Which of the following is MOST important to ensure ongoing s...
Question 387: Which of the following would cause the GREATEST concern to a...
Question 388: Which of the following communicates the MOST meaningful info...
Question 389: Which of the following is the MOST important consideration w...
Question 390: Behavioral analytics tools are used PRIMARILY to manage risk...
Question 391: Which of the following is the GREATEST concern with implemen...
Question 392: Which of the following BEST supports effective and timely in...
Question 393: A third-party vendor is developing a mobile app for an organ...
Question 394: Which of the following should an information security manage...
Question 395: Which of the following should be done FIRST when containing ...
Question 396: Which type of plan is PRIMARILY intended to reduce the poten...
Question 397: Which of the following is the BEST way for an information se...
Question 398: Which of the following is the BEST way to build a risk-aware...
Question 399: Which of the following is MOST important for responding effe...
Question 400: Which of the following is the MOST important consideration w...
Question 401: An information security manager is updating the organization...
Question 402: Which of the following is the BEST resource to obtain a comp...
Question 403: Which of the following is the MOST important course of actio...
Question 404: Which of the following should be an information security man...
Question 405: Which of the following controls MOST effectively reduces the...
Question 406: Which of the following BEST helps to ensure an organization'...
Question 407: Which of the following BEST enables the design of an effecti...
Question 408: Which of the following is MOST important for an information ...
Question 409: An organization has updated its business goals in the middle...
Question 410: Which of the following activities is BEST performed by someo...
Question 411: Which of the following MOST effectively addresses the risk a...
Question 412: Which of the following is conducted during the last phase in...
Question 413: When performing a data classification project, an informatio...
Question 414: Which of the following is the MOST important security consid...
Question 415: Senior management wants to thoroughly test a disaster recove...
Question 416: Which of the following is the BEST approach when conducting ...
Question 417: When performing vulnerability scans, the information securit...
Question 418: Which of the following is the BEST control to mitigate the t...
Question 419: Which of the following groups is BEST positioned to consult ...
Question 420: An organization has recently acquired a new entity. Which of...
Question 421: What should an information security manager do FIRST when an...
Question 422: An information security manager identified that a user's lap...
Question 423: What is the BEST way to verify the effectiveness of a newly ...
Question 424: Which of the following is the MOST important reason to perfo...
Question 425: Which of the following is the MOST effective way of ensuring...
Question 426: Which of the following is the MOST important consideration w...
Question 427: Which of the following BEST enables an organization to prote...
Question 428: Which of the following should be performed FIRST when implem...
Question 429: An event occurred that resulted in the activation of the bus...
Question 430: A successful breach of an organization's web application pla...
Question 431: Which of the following is the BEST approach for reporting in...
Question 432: Which of the following BEST enables an organization to ident...
Question 433: Which of the following incident response phases involves act...
Question 434: Which of the following would BEST fulfill a board of directo...
Question 435: Which of the following is the MOST likely reason for a vulne...
Question 436: Which of the following is MOST important to consider when de...
Question 437: Which of the following is the BEST way to ensure the organiz...
Question 438: Which of the following will BEST support the business case t...
Question 439: Which of the following BEST enables an organization to ensur...
Question 440: Which of the following is the BEST way to identify vulnerabi...
Question 441: Which of the following provides the MOST effective response ...
Question 442: Which of the following security initiatives should be the FI...
Question 443: Which of the following would be the BEST indicator that a re...
Question 444: Which of the following would BEST mature an organization's i...
Question 445: Which of the following is the MOST effective incident contai...
Question 446: Which of the following is an information security manager's ...
Question 447: Which of the following stakeholders is in the BEST position ...
Question 448: Which of the following BEST demonstrates a security-consciou...
Question 449: Which of the following is the BEST control to protect custom...
Question 450: The PRIMARY reason for establishing a data classification sc...
Question 451: Which of the following is an information security manager's ...
Question 452: Which of the following would provide the BEST justification ...
Question 453: An organization wants to migrate a proprietary application t...
Question 454: What is the BEST way to identify noncompliance with password...
Question 455: Which of the following is the MOST important factor in deter...
Question 456: Which of the following should be updated FIRST to account fo...
Question 457: An information security manager is notified that a third-par...
Question 458: An organization is planning to engage a third-party service ...
Question 459: Post-incident analysis of a recent security incident reveale...
Question 460: Which of the following is the MOST effective way to convey i...
Question 461: The PRIMARY objective of timely declaration of a disaster is...
Question 462: A business continuity plan (BCP) should contain:...
Question 463: Which of the following BEST illustrates residual risk within...
Question 464: Which of the following is the BEST way to enhance training f...
Question 465: Of the following, who would provide the MOST relevant input ...
Question 466: What should be an information security manager's FIRST cours...
Question 467: An information security manager has identified that privileg...
Question 468: Once a suite of security controls has been successfully impl...
Question 469: Which of the following would BEST enable an organization to ...
Question 470: Which of the following BEST defines security requirements fo...
Question 471: Which of the following is MOST important when identifying ad...
Question 472: Blockchain forensics supports the investigation of blockchai...
Question 473: Which of the following is the PRIMARY benefit of a centraliz...
Question 474: What should be the NEXT course of action when an information...
Question 475: Which of the following would be the GREATEST concern if an i...
Question 476: Which of the following BEST facilitates accountability and o...
Question 477: What should be the information security manager's FIRST step...
Question 478: Which of the following is the BEST method to manage risk in ...
Question 479: Which of the following metrics would provide an accurate mea...
Question 480: An information security manager is drafting a data protectio...
Question 481: Which of the following provides the BEST guidance when creat...
Question 482: Which of the following is the MOST valuable input for determ...
Question 483: Which of the following is the MOST important consideration f...
Question 484: Which of the following should be of GREATEST concern regardi...
Question 485: Which of the following would BEST help to determine incident...
Question 486: Which of the following is the MOST effective way to verify a...
Question 487: The BEST indication of the effectiveness of an organization'...
Question 488: Which of the following is the MOST effective way to identify...
Question 489: An organization has acquired a new system with strict mainte...
Question 490: Which of the following is MOST relevant to establishing secu...
Question 491: An incident response policy should include:...
Question 492: Which of the following is the PRIMARY objective of defining ...
Question 493: Which of the following BEST indicates that an organization's...
Question 494: Which of the following is the BEST reason to separate short-...
Question 495: Which of the following is the PRIMARY reason to review the f...
Question 496: Which of the following should have the MOST influence on dev...
Question 497: Which of the following is the MOST important characteristic ...
Question 498: Which of the following is the MOST effective way to influenc...
Question 499: An information security manager is developing a breach notif...
Question 500: An information security manager learns that an existing supp...
Question 501: What is the BEST way to inform senior management of the valu...
Question 502: Which of the following is MOST important to ensure incident ...
Question 503: Which of the following is the MOST important reason to condu...
Question 504: Which of the following is the MOST important aspect for an i...
Question 505: Which of the following should be the FIRST step after identi...
Question 506: Which of the following establishes the minimum technical bas...
Question 507: Which of the following is the MOST common contributor to cyb...
Question 508: Which of the following is the BEST indicator of an emerging ...
Question 509: Which of the following should be done FIRST once a cybersecu...
Question 510: An organization engages a third-party vendor to monitor and ...
Question 511: Which of the following is the BEST way to evaluate the effec...
Question 512: An organization's quality management program can BEST suppor...
Question 513: Within the confidentiality, integrity, and availability (CIA...
Question 514: If the investigation of an incident is not completed within ...
Question 515: Which of the following BEST enables an organization to evalu...
Question 516: Which of the following BEST indicates misalignment of securi...
Question 517: Which of the following BEST enables an information security ...
Question 518: A security review of an HR application reveals a file server...
Question 519: Which of the following BEST prepares an organization for sev...
Question 520: Which risk is introduced when using only sanitized data for ...
Question 521: Following an information security risk assessment of a criti...
Question 522: The MOST important input for determining the severity of an ...
Question 523: A security policy exception that was approved by senior mana...
Question 524: Which of the following is the MOST important consideration w...
Question 525: Biometrics are BEST used for:
Question 526: Which of the following presents the GREATEST challenge when ...
Question 527: The PRIMARY purpose for continuous monitoring of security co...
Question 528: Which of the following should be the MOST important consider...
Question 529: What is the PRIMARY benefit to an organization that maintain...
Question 530: Which of the following is MOST important for an information ...
Question 531: Which of the following is MOST useful to an information secu...
Question 532: When an organization experiences a disruptive event, the bus...
Question 533: What should be an organization's MAIN concern when evaluatin...
Question 534: As part of a risk assessment, a security control was discove...
Question 535: Which of the following BEST demonstrates the alignment of in...
Question 536: Which of the following is the MOST significant contributor t...
Question 537: Which of the following is a fundamental principle for contro...
Question 538: Which of the following is the BEST way to help ensure third-...
Question 539: Which of the following is the MOST important consideration w...
Question 540: Which of the following is MOST important to consider when pr...
Question 541: Which of the following should have the GREATEST influence on...
Question 542: Which of the following is the BEST way to facilitate alignme...
Question 543: Which of the following types of users are MOST likely to hav...
Question 544: Which of the following should be the MOST important consider...
Question 545: When supporting a large corporation's board of directors in ...
Question 546: Which of the following is the MOST effective way to determin...
Question 547: A job is scheduled to transfer data from a transactional sys...
Question 548: Which of the following should be the GREATEST concern to an ...
Question 549: Which of the following is the PRIMARY reason to continuously...
Question 550: Which of the following is the BEST way for an information se...
Question 551: Which of the following is the GREATEST benefit of using AI t...
Question 552: Which phase of the incident management process includes remo...
Question 553: Which of the following BEST reduces the risk to an organizat...
Question 554: Which of the following is the GREATEST threat posed by quant...
Question 555: Who should give final approval for granting access rights to...
Question 556: Which of the following should be of GREATEST concern to an i...
Question 557: Which of the following would MOST effectively ensure that a ...
Question 558: Which of the following should be an information security man...
Question 559: Which of the following should be of GREATEST concern when cr...
Question 560: A PRIMARY benefit of adopting an information security framew...
Question 561: The PRIMARY purpose of developing and implementing an incide...
Question 562: The PRIMARY purpose of the recovery phase in incident respon...
Question 563: Which of the following risks is an example of risk transfer?...
Question 564: Which of the following factors has the GREATEST influence on...
Question 565: A global organization is developing an incident response tea...
Question 566: An information security manager is considering options for p...
Question 567: Which of the following is the MAIN feature of a web applicat...
Question 568: Which of the following is the MOST important consideration w...
Question 569: Which of the following should be an information security man...
Question 570: Which of the following is MOST important to have in place wh...
Question 571: Who is BEST positioned to take ownership of critical IT secu...
Question 572: When attempting to migrate to a new cloud vendor, an organiz...
Question 573: Detailed business continuity plans (BCPs) should be PRIMARIL...
Question 574: An organization's security team uses a repetitive threat hun...
Question 575: Which of the following is the MOST important factor of a suc...
Question 576: A backdoor has been identified that enabled a cyberattack on...
Question 577: Which of the following metrics provides the MOST insight on ...
Question 578: Which of the following is the MOST effective way to align an...
Question 579: An acceptable use policy would PRIMARILY address the integra...
Question 580: When assigning a risk owner, the MOST important consideratio...
Question 581: Which of the following is the MOST effective way for a softw...
Question 582: A chief information officer (CIO) recently approved remote a...
Question 583: Which of the following is MOST useful for providing senior m...
Question 584: Which of the following is MOST important to include in an en...
Question 585: Which of the following is MOST important to consider when de...
Question 586: Which of the following is the BEST method to determine the e...
Question 587: An incident management team has confirmed a cyberattack and ...
Question 588: Which of the following provides nonrepudiation of electronic...
Question 589: Which of the following tasks would provide a newly appointed...
Question 590: An information security manager has become aware that system...
Question 591: When adopting an information security framework, it is MOST ...
Question 592: Which of the following is the PRIMARY reason to perform a bu...
Question 593: Which of the following BEST facilitates the adoption of new ...