Valid CISM Dumps shared by EduDump.com for Helping Passing CISM Exam! EduDump.com now offer the newest CISM exam dumps, the EduDump.com CISM exam questions have been updated and answers have been corrected get the newest EduDump.com CISM dumps with Test Engine here:

Access CISM Dumps Premium Version
(1193 Q&As Dumps, 35%OFF Special Discount Code: freecram)

<< Prev Question Next Question >>

Question 59/619

When a user employs a client-side digital certificate to authenticate to a web server through Secure Socket Layer (SSI.), confidentiality is MOST vulnerable to which of the following?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (619q)
Question 1: Which of the following is the MOST important consideration w...
Question 2: In order to highlight to management the importance of integr...
Question 3: Which of the following are the MOST important individuals to...
Question 4: In the course of responding 10 an information security incid...
Question 5: The PRIMARY purpose of installing an intrusion detection sys...
Question 6: An IS manager has decided to implement a security system to ...
Question 7: An information security manager has been assigned to impleme...
Question 8: The MOST important reason that statistical anomaly-based int...
Question 9: The FIRST step in developing an information security managem...
Question 10: Security awareness training should be provided to new employ...
Question 11: The MOST basic requirement for an information security gover...
Question 12: A new regulation for safeguarding information processed by a...
Question 13: Which of the following would help to change an organization'...
Question 14: Which of the following would raise security awareness among ...
Question 15: Which of the following guarantees that data in a file have n...
Question 16: Which is the BEST way to measure and prioritize aggregate ri...
Question 17: There is reason to believe that a recently modified web appl...
Question 18: An information security manager reviewed the access control ...
Question 19: When creating a forensic image of a hard drive, which of the...
Question 20: A business unit intends to deploy a new technology in a mann...
Question 21: Which of the following is the MOST important reason why info...
Question 22: Primary direction on the impact of compliance with new regul...
Question 23: What is the BEST technique to determine which security contr...
Question 24: A message* that has been encrypted by the sender's private k...
Question 25: After completing a full IT risk assessment, who can BEST dec...
Question 26: Which of the following tools is MOST appropriate to assess w...
Question 27: Which of the following is the BEST method to reduce the numb...
Question 28: Which of the following areas is MOST susceptible to the intr...
Question 29: When residual risk is minimized:...
Question 30: Which of the following BEST describes an information securit...
Question 31: Acceptable risk is achieved when:...
Question 32: Which of the following requirements would have the lowest le...
Question 33: A critical component of a continuous improvement program for...
Question 34: Which of the following is MOST effective in preventing weakn...
Question 35: Information security policies should:...
Question 36: Previously accepted risk should be:...
Question 37: What is the GREATEST risk when there is an excessive number ...
Question 38: A root kit was used to capture detailed accounts receivable ...
Question 39: Which of the following is MOST important when deciding wheth...
Question 40: How would an information security manager balance the potent...
Question 41: The BEST way to ensure that security settings on each platfo...
Question 42: Which of the following tools is MOST appropriate for determi...
Question 43: Which of the following is the MOST relevant metric to includ...
Question 44: After obtaining commitment from senior management, which of ...
Question 45: The PRIMARY consideration when defining recovery time object...
Question 46: Which of the following change management activities would be...
Question 47: An online banking institution is concerned that the breach o...
Question 48: Several business units reported problems with their systems ...
Question 49: A business partner of a factory has remote read-only access ...
Question 50: The BEST time to perform a penetration test is after:...
Question 51: To BEST improve the alignment of the information security ob...
Question 52: Which of the following is the PRIMARY prerequisite to implem...
Question 53: An account with full administrative privileges over a produc...
Question 54: Which of the following roles would represent a conflict of i...
Question 55: When an organization is implementing an information security...
Question 56: Which of the following BEST indicates a successful risk mana...
Question 57: When configuring a biometric access control system that prot...
Question 58: Relationships among security technologies are BEST defined t...
Question 59: When a user employs a client-side digital certificate to aut...
Question 60: An e-commerce order fulfillment web server should generally ...
Question 61: Which of the following terms and conditions represent a sign...
Question 62: Risk acceptance is a component of which of the following?...
Question 63: Which of the following is the MOST appropriate frequency for...
Question 64: An organization has been experiencing a number of network-ba...
Question 65: The MOST important reason for formally documenting security ...
Question 66: There is a time lag between the time when a security vulnera...
Question 67: Which of the following would be the BEST option to improve a...
Question 68: The effectiveness of virus detection software is MOST depend...
Question 69: Which of the following are the essential ingredients of a bu...
Question 70: An internal audit has identified major weaknesses over IT pr...
Question 71: A border router should be placed on which of the following?...
Question 72: Who is ultimately responsible for ensuring that information ...
Question 73: An internal review of a web-based application system finds t...
Question 74: When properly tested, which of the following would MOST effe...
Question 75: What is the MAIN drawback of e-mailing password-protected zi...
Question 76: Senior management commitment and support for information sec...
Question 77: When a newly installed system for synchronizing passwords ac...
Question 78: To help ensure that contract personnel do not obtain unautho...
Question 79: What is the BEST method to verify that all security patches ...
Question 80: The PRIMARY objective of a security steering group is to:...
Question 81: Data owners must provide a safe and secure environment to en...
Question 82: The MAIN reason why asset classification is important to a s...
Question 83: The PRIMARY objective of an Internet usage policy is to prev...
Question 84: A risk analysis should:
Question 85: The security responsibility of data custodians in an organiz...
Question 86: The PRIMARY benefit of performing an information asset class...
Question 87: A database was compromised by guessing the password for a sh...
Question 88: Attackers who exploit cross-site scripting vulnerabilities t...
Question 89: Isolation and containment measures lor a compromised compute...
Question 90: In a social engineering scenario, which of the following wil...
Question 91: Which of the following is the MOST important management sign...
Question 92: Which of the following is the MOST important consideration f...
Question 93: What is the BEST defense against a Structured Query Language...
Question 94: In business-critical applications, user access should be app...
Question 95: A customer credit card database has been breached by hackers...
Question 96: Successful social engineering attacks can BEST be prevented ...
Question 97: When personal information is transmitted across networks, th...
Question 98: An organization keeps backup tapes of its servers at a warm ...
Question 99: An organization has adopted a practice of regular staff rota...
Question 100: The configuration management plan should PRIMARILY be based ...
Question 101: What is the BEST way to ensure data protection upon terminat...
Question 102: The PRIMARY concern of an information security manager docum...
Question 103: Which of the following is the PRIMARY reason for implementin...
Question 104: The PRIMARY focus of the change control process is to ensure...
Question 105: Which of the following is the MOST important process that an...
Question 106: Which of the following is generally used to ensure that info...
Question 107: Which of the following is the MOST appropriate individual to...
Question 108: Obtaining senior management support for establishing a warm ...
Question 109: Evidence from a compromised server has to be acquired for a ...
Question 110: The IT function has declared that, when putting a new applic...
Question 111: An information security manager believes that a network file...
Question 112: Which of the following is the BEST way to ensure that a corp...
Question 113: When performing a qualitative risk analysis, which of the fo...
Question 114: Which of the following events generally has the highest info...
Question 115: Which of the following is MOST essential for a risk manageme...
Question 116: Which of the following BEST contributes to the development o...
Question 117: The BEST way to determine if an anomaly-based intrusion dete...
Question 118: Temporarily deactivating some monitoring processes, even if ...
Question 119: Who would be in the BEST position to determine the recovery ...
Question 120: Which of the following should be determined FIRST when estab...
Question 121: Which would be one of the BEST metrics an information securi...
Question 122: What would be the MOST significant security risks when using...
Question 123: Which of the following is the MOST important item to conside...
Question 124: Who should determine the appropriate classification of accou...
Question 125: To justify the need to invest in a forensic analysis tool, a...
Question 126: Which of the following practices is BEST to remove system ac...
Question 127: It is MOST important that information security architecture ...
Question 128: In the process of deploying a new e-mail system, an informat...
Question 129: Based on the information provided, which of the following si...
Question 130: As an organization grows, exceptions to information security...
Question 131: Data owners are PRIMARILY responsible for establishing risk ...
Question 132: When contracting with an outsourcer to provide security admi...
Question 133: Which of the following is the MOST appropriate method to pro...
Question 134: Which of the following would be the MOST significant securit...
Question 135: An organization has to comply with recently published indust...
Question 136: The MOST appropriate role for senior management in supportin...
Question 137: The PRIMARY purpose of performing an internal attack and pen...
Question 138: Which of the following is the MOST effective type of access ...
Question 139: Which of the following are likely to be updated MOST frequen...
Question 140: Which of the following is the BEST indicator that an effecti...
Question 141: Which of the following presents the GREATEST exposure to int...
Question 142: Which of the following is MOST effective for securing wirele...
Question 143: Which of the following ensures that newly identified securit...
Question 144: The BEST way to justify the implementation of a single sign-...
Question 145: Which of the following will MOST likely reduce the chances o...
Question 146: Which of the following would be MOST helpful to achieve alig...
Question 147: Which of the following would be MOST critical to the success...
Question 148: A good privacy statement should include:...
Question 149: A third party was engaged to develop a business application....
Question 150: In an organization, information systems security is the resp...
Question 151: Who is responsible for ensuring that information is categori...
Question 152: Which of the following would be the FIRST step in establishi...
Question 153: Which of the following is the BEST metric for evaluating the...
Question 154: A critical device is delivered with a single user and passwo...
Question 155: The BEST way to ensure that information security policies ar...
Question 156: What is the MOST important element to include when developin...
Question 157: The main mail server of a financial institution has been com...
Question 158: What is the BEST way to ensure that an intruder who successf...
Question 159: The data access requirements for an application should be de...
Question 160: Which of the following is the MOST important requirement for...
Question 161: What is the PRIMARY role of the information security manager...
Question 162: From an information security perspective, information that n...
Question 163: When an organization hires a new information security manage...
Question 164: What will have the HIGHEST impact on standard information se...
Question 165: Which of the following is the MOST important prerequisite fo...
Question 166: The BEST reason for an organization to have two discrete fir...
Question 167: Which of the following is MOST important in determining whet...
Question 168: Recovery point objectives (RPOs) can be used to determine wh...
Question 169: Which of the following would be the MOST important factor to...
Question 170: Which of the following actions should lake place immediately...
Question 171: Which of the following would BEST ensure the success of info...
Question 172: Which of the following processes is critical for deciding pr...
Question 173: The MAIN reason for deploying a public key infrastructure (P...
Question 174: Identification and prioritization of business risk enables p...
Question 175: An organization has decided to implement additional security...
Question 176: A benefit of using a full disclosure (white box) approach as...
Question 177: Which of the following security mechanisms is MOST effective...
Question 178: Which of the following types of information would the inform...
Question 179: Which of the following actions should be taken when an infor...
Question 180: The information classification scheme should:...
Question 181: A successful information security management program should ...
Question 182: When a proposed system change violates an existing security ...
Question 183: When speaking to an organization's human resources departmen...
Question 184: Which of the following is an inherent weakness of signature-...
Question 185: Minimum standards for securing the technical infrastructure ...
Question 186: Which of the following is the MOST important area of focus w...
Question 187: On a company's e-commerce web site, a good legal statement r...
Question 188: What is the BEST method for mitigating against network denia...
Question 189: Security policies should be aligned MOST closely with:...
Question 190: A web-based business application is being migrated from test...
Question 191: Which of the following characteristics is MOST important whe...
Question 192: Which of the following is the MAIN reason for performing ris...
Question 193: Which of the following would BEST prepare an information sec...
Question 194: When security policies are strictly enforced, the initial im...
Question 195: In organizations where availability is a primary concern, th...
Question 196: Which of the following risks would BEST be assessed using qu...
Question 197: An intrusion detection system should be placed:...
Question 198: Which of the following MOST commonly falls within the scope ...
Question 199: When performing a business impact analysis (BIA), which of t...
Question 200: The advantage of Virtual Private Network (VPN) tunneling for...
Question 201: An information security manager reviewing firewall rules wil...
Question 202: Which of the following is the MOST important element of an i...
Question 203: A new port needs to be opened in a perimeter firewall. Which...
Question 204: A desktop computer that was involved in a computer security ...
Question 205: Emergency actions are taken at the early stage of a disaster...
Question 206: Ongoing tracking of remediation efforts to mitigate identifi...
Question 207: When considering the value of assets, which of the following...
Question 208: A risk assessment study carried out by an organization noted...
Question 209: What is the BEST method to confirm that all firewall rules a...
Question 210: Of the following, the BEST method for ensuring that temporar...
Question 211: The MOST important factor in planning for the long-term rete...
Question 212: Which of the following would BEST address the risk of data l...
Question 213: Which of the following would be the MOST important goal of a...
Question 214: The BEST method for detecting and monitoring a hacker's acti...
Question 215: Which of the following would represent a violation of the ch...
Question 216: Which of the following devices should be placed within a DMZ...
Question 217: Which of the following is the BEST indicator that security a...
Question 218: The purpose of a corrective control is to:...
Question 219: What does a network vulnerability assessment intend to ident...
Question 220: Effective IT governance is BEST ensured by:...
Question 221: An organization is entering into an agreement with a new bus...
Question 222: A serious vulnerability is reported in the firewall software...
Question 223: The PRIMARY objective of security awareness is to:...
Question 224: Which of the following metrics would be the MOST useful in m...
Question 225: What mechanisms are used to identify deficiencies that would...
Question 226: In order to highlight to management the importance of networ...
Question 227: Which of the following mechanisms is the MOST secure way to ...
Question 228: An information security program should be sponsored by:...
Question 229: To determine the selection of controls required to meet busi...
Question 230: Who is responsible for raising awareness of the need for ade...
Question 231: Which item would be the BEST to include in the information s...
Question 232: An organization's operations staff places payment files in a...
Question 233: Which of the following is MOST effective in preventing the i...
Question 234: Which of the following is the MOST appropriate individual to...
Question 235: In a well-controlled environment, which of the following act...
Question 236: The FIRST step to create an internal culture that focuses on...
Question 237: Which of the following is a key area of the ISO 27001 framew...
Question 238: Information security governance is PRIMARILY driven by:...
Question 239: Which of the following is the MAIN objective in contracting ...
Question 240: The advantage of sending messages using steganographic techn...
Question 241: An information security manager mapping a job description to...
Question 242: Which of the following is the MOST likely to change an organ...
Question 243: An outsource service provider must handle sensitive customer...
Question 244: The MAIN goal of an information security strategic plan is t...
Question 245: Which of the following is the FIRST phase in which security ...
Question 246: Which of the following would a security manager establish to...
Question 247: Which of the following measures is the MOST effective deterr...
Question 248: The MAIN advantage of implementing automated password synchr...
Question 249: Requiring all employees and contractors to meet personnel se...
Question 250: Which of the following is MOST closely associated with a bus...
Question 251: Which of the following is the MOST essential task for a chie...
Question 252: The MOST important reason for conducting periodic risk asses...
Question 253: Which of the following activities is MOST likely to increase...
Question 254: Which of the following is the MOST important risk associated...
Question 255: When an emergency security patch is received via electronic ...
Question 256: Which of the following factors is a PRIMARY driver for infor...
Question 257: Which of the following would be MOST useful in developing a ...
Question 258: Which of the following risks is represented in the risk appe...
Question 259: Which of the following is the MOST effective at preventing a...
Question 260: Which of the following application systems should have the s...
Question 261: The PRIMARY reason for using metrics to evaluate information...
Question 262: Which of the following BEST provides message integrity, send...
Question 263: Which of the following should be in place before a black box...
Question 264: To justify its ongoing security budget, which of the followi...
Question 265: One way to determine control effectiveness is by determining...
Question 266: Which of the following is the BEST method to provide a new u...
Question 267: At the conclusion of a disaster recovery test, which of the ...
Question 268: Information security policy enforcement is the responsibilit...
Question 269: An information security manager has been asked to develop a ...
Question 270: When electronically stored information is requested during a...
Question 271: Which of the following devices should be placed within a dem...
Question 272: Which of the following is the MOST important consideration w...
Question 273: Which of the following is MOST effective in preventing secur...
Question 274: What is the PRIMARY objective of a post-event review in inci...
Question 275: Which of the following should be included in an annual infor...
Question 276: The criticality and sensitivity of information assets is det...
Question 277: Which of the following documents would be the BES T referenc...
Question 278: Which of the following would be MOST effective in successful...
Question 279: Which of the following is the MOST important to keep in mind...
Question 280: For virtual private network (VPN) access to the corporate ne...
Question 281: A risk management approach to information protection is:...
Question 282: When designing an information security quarterly report to m...
Question 283: After a risk assessment study, a bank with global operations...
Question 284: Which of the following is the MOST important element to ensu...
Question 285: The chief information security officer (CISO) should ideally...
Question 286: Which of the following BEST ensures that security risks will...
Question 287: Which of the following is responsible for legal and regulato...
Question 288: Which of the following is the MOST immediate consequence of ...
Question 289: When implementing effective security governance within the r...
Question 290: When a security standard conflicts with a business objective...
Question 291: An organization is already certified to an international sec...
Question 292: The PRIMARY reason for initiating a policy exception process...
Question 293: Before conducting a formal risk assessment of an organizatio...
Question 294: What is the MOST important factor in the successful implemen...
Question 295: What is the MOST effective access control method to prevent ...
Question 296: The recovery point objective (RPO) requires which of the fol...
Question 297: Which of the following, using public key cryptography, ensur...
Question 298: Which of the following is the BEST way to verify that all cr...
Question 299: The MAIN reason for having the Information Security Steering...
Question 300: A company recently developed a breakthrough technology. Sinc...
Question 301: What is the MOST important reason for conducting security aw...
Question 302: The FIRST step in an incident response plan is to:...
Question 303: To ensure that payroll systems continue on in an event of a ...
Question 304: When an organization is setting up a relationship with a thi...
Question 305: Which of the following will BEST protect an organization fro...
Question 306: The BEST metric for evaluating the effectiveness of a firewa...
Question 307: Which of the following is the MOST effective solution for pr...
Question 308: Data owners are normally responsible for which of the follow...
Question 309: Which of the following is the BEST approach to mitigate onli...
Question 310: A risk mitigation report would include recommendations for:...
Question 311: Which of the following is the MOST important to ensure a suc...
Question 312: An information security strategy document that includes spec...
Question 313: An information security manager at a global organization tha...
Question 314: An organization has verified that its customer information w...
Question 315: When designing the technical solution for a disaster recover...
Question 316: Which of the following would be a MAJOR consideration for an...
Question 317: Which of the following is the BEST method for ensuring that ...
Question 318: From an information security manager perspective, what is th...
Question 319: Who should be responsible for enforcing access rights to app...
Question 320: Which of the following is the BEST method or technique to en...
Question 321: Which of the following is an example of a corrective control...
Question 322: Which of the following are the MOST important criteria when ...
Question 323: During which phase of development is it MOST appropriate to ...
Question 324: What is the MOS T cost-effective means of improving security...
Question 325: Which of the following is MOST effective in protecting again...
Question 326: A risk assessment should be conducted:...
Question 327: A project manager is developing a developer portal and reque...
Question 328: The BEST protocol to ensure confidentiality of transmissions...
Question 329: When performing a risk assessment, the MOST important consid...
Question 330: Which of the following will BEST prevent external security a...
Question 331: Which of (lie following would be the MOST relevant factor wh...
Question 332: Which of the following would present the GREATEST risk to in...
Question 333: Good information security procedures should:...
Question 334: Which of the following technologies is utilized to ensure th...
Question 335: An organization's information security manager has been aske...
Question 336: Which of the following provides the BKST confirmation that t...
Question 337: An organization plans to contract with an outside service pr...
Question 338: The PRIMARY objective of a risk management program is to:...
Question 339: Nonrepudiation can BEST be assured by using:...
Question 340: A mission-critical system has been identified as having an a...
Question 341: Security monitoring mechanisms should PRIMARILY:...
Question 342: The value of information assets is BEST determined by:...
Question 343: Which of the following disaster recovery testing techniques ...
Question 344: Successful implementation of information security governance...
Question 345: An intranet server should generally be placed on the:...
Question 346: Because of its importance to the business, an organization w...
Question 347: The management staff of an organization that does not have a...
Question 348: Which of the following would be MOST relevant to include in ...
Question 349: The MOST useful way to describe the objectives in the inform...
Question 350: Which of the following should be the FIRST step in developin...
Question 351: Prior to having a third party perform an attack and penetrat...
Question 352: What is an appropriate frequency for updating operating syst...
Question 353: A possible breach of an organization's IT system is reported...
Question 354: Who should drive the risk analysis for an organization?...
Question 355: Which of the following is the MOST effective way to treat a ...
Question 356: When developing incident response procedures involving serve...
Question 357: Which of the following is the MOST usable deliverable of an ...
Question 358: An organization's board of directors has learned of recent l...
Question 359: Which of the following is the BEST method to securely transf...
Question 360: Which of the following is MOST important to understand when ...
Question 361: The MOST complete business case for security solutions is on...
Question 362: Which of the following roles is PRIMARILY responsible for de...
Question 363: An organization plans to outsource its customer relationship...
Question 364: The FIRST priority when responding to a major security incid...
Question 365: The PRIMARY goal of a corporate risk management program is t...
Question 366: When a departmental system continues to be out of compliance...
Question 367: What is the BEST way to alleviate security team understaffin...
Question 368: The decision on whether new risks should fall under periodic...
Question 369: In the course of examining a computer system for forensic ev...
Question 370: When developing an information security program, what is the...
Question 371: Which of the following is the MOST important factor when des...
Question 372: Who can BEST approve plans to implement an information secur...
Question 373: An incident response policy must contain:...
Question 374: Senior management commitment and support for information sec...
Question 375: Which of the following security activities should be impleme...
Question 376: The organization has decided to outsource the majority of th...
Question 377: While implementing information security governance an organi...
Question 378: Which of the following represents the MAJOR focus of privacy...
Question 379: The decision as to whether a risk has been reduced to an acc...
Question 380: When collecting evidence for forensic analysis, it is import...
Question 381: When an organization is using an automated tool to manage an...
Question 382: An information security manager must understand the relation...
Question 383: Which of the following recovery strategies has the GREATEST ...
Question 384: Which of the following situations would be the MOST concern ...
Question 385: Which of the following is the MOST appropriate position to s...
Question 386: Good information security standards should:...
Question 387: What is the MOST appropriate change management procedure for...
Question 388: A multinational organization operating in fifteen countries ...
Question 389: What is the FIRST action an information security manager sho...
Question 390: The service level agreement (SLA) for an outsourced IT funct...
Question 391: During the security review of organizational servers it was ...
Question 392: Which of the following actions should be taken when an onlin...
Question 393: Which of the following is the MOST effective, positive metho...
Question 394: The MOST important objective of a post incident review is to...
Question 395: The valuation of IT assets should be performed by:...
Question 396: The impact of losing frame relay network connectivity for 18...
Question 397: Which of the following controls is MOST effective in providi...
Question 398: Which of the following BEST ensures that modifications made ...
Question 399: Which of the following is the MOST important element to ensu...
Question 400: The MOST effective approach to address issues that arise bet...
Question 401: The "separation of duties" principle is violated if which of...
Question 402: Change management procedures to ensure that disaster recover...
Question 403: The implementation of continuous monitoring controls is the ...
Question 404: Which of the following represents a PRIMARY area of interest...
Question 405: Information security managers should use risk assessment tec...
Question 406: An organization's information security strategy should be ba...
Question 407: A test plan to validate the security controls of a new syste...
Question 408: The BEST approach in managing a security incident involving ...
Question 409: What is the GREATEST advantage of documented guidelines and ...
Question 410: Why is "slack space" of value to an information security man...
Question 411: An information security manager uses security metrics to mea...
Question 412: Which of the following would be the BEST metric for the IT r...
Question 413: If an organization considers taking legal action on a securi...
Question 414: Which of the following groups would be in the BEST position ...
Question 415: What task should be performed once a security incident has b...
Question 416: Which of the following measures would be MOST effective agai...
Question 417: Which of the following practices completely prevents a man-i...
Question 418: Which of the following is the BEST justification to convince...
Question 419: Nonrepudiation can BEST be ensured by using:...
Question 420: An information security manager at a global organization has...
Question 421: A post-incident review should be conducted by an incident ma...
Question 422: What is the BEST way to ensure that contract programmers com...
Question 423: Investment in security technology and processes should be ba...
Question 424: On which of the following should a firewall be placed?...
Question 425: Which of the following controls would BEST prevent accidenta...
Question 426: Information security should be:...
Question 427: Reviewing which of the following would BEST ensure that secu...
Question 428: The FIRST step in establishing a security governance program...
Question 429: What is the MOST cost-effective method of identifying new ve...
Question 430: After assessing and mitigating the risks of a web applicatio...
Question 431: At what stage of the applications development process should...
Question 432: Which of the following presents the GREATEST threat to the s...
Question 433: An intrusion detection system (IDS) should:...
Question 434: A new e-mail virus that uses an attachment disguised as a pi...
Question 435: Which of the following steps in conducting a risk assessment...
Question 436: A company has a network of branch offices with local file/pr...
Question 437: The MOST effective way to incorporate risk management practi...
Question 438: The MOST appropriate individual to determine the level of in...
Question 439: Which of the following is the BEST mechanism to determine th...
Question 440: An organization without any formal information security prog...
Question 441: Which of the following risks would BEST be assessed using qu...
Question 442: Which of the following is a benefit of information security ...
Question 443: Which of the following would generally have the GREATEST neg...
Question 444: An information security program should focus on:...
Question 445: The MOST important component of a privacy policy is:...
Question 446: Which of the following is the BEST metric for evaluating the...
Question 447: Who is ultimately responsible for the organization's informa...
Question 448: Which of the following has the highest priority when definin...
Question 449: When defining a service level agreement (SLA) regarding the ...
Question 450: Which of the following is the MOST effective solution for pr...
Question 451: Which of the following should be performed FIRST in the afte...
Question 452: When identifying legal and regulatory issues affecting infor...
Question 453: When a significant security breach occurs, what should be re...
Question 454: Which of the following is the MOST critical activity to ensu...
Question 455: Who can BEST advocate the development of and ensure the succ...
Question 456: Which of the following is the BEST approach for an organizat...
Question 457: Which of the following would BEST protect an organization's ...
Question 458: The cost of implementing a security control should not excee...
Question 459: Acceptable levels of information security risk should be det...
Question 460: Which of the following would be of GREATEST importance to th...
Question 461: To achieve effective strategic alignment of security initiat...
Question 462: At what stage of the applications development process would ...
Question 463: Which of the following is the BEST approach for improving in...
Question 464: The MOST effective way to ensure network users are aware of ...
Question 465: Which of the following is the MOST important reason for an i...
Question 466: The PRIMARY driver to obtain external resources to execute t...
Question 467: Which of the following attacks is BEST mitigated by utilizin...
Question 468: Which of the following is generally considered a fundamental...
Question 469: Which of the following is characteristic of decentralized in...
Question 470: Which of the following devices should be placed within a DMZ...
Question 471: To reduce the possibility of service interruptions, an entit...
Question 472: An organization has learned of a security breach at another ...
Question 473: The MOST important function of a risk management program is ...
Question 474: A business impact analysis (BIA) is the BEST tool for calcul...
Question 475: Which of the following is MOST important in developing a sec...
Question 476: An organization has a process in place that involves the use...
Question 477: Simple Network Management Protocol v2 (SNMP v2) is used freq...
Question 478: An outcome of effective security governance is:...
Question 479: A successful risk management program should lead to:...
Question 480: Which of the following authentication methods prevents authe...
Question 481: Which of the following will BEST prevent an employee from us...
Question 482: An effective way of protecting applications against Structur...
Question 483: Which of the following is the MOST serious exposure of autom...
Question 484: Risk management programs are designed to reduce risk to:...
Question 485: Which of the following BEST describes the scope of risk anal...
Question 486: Security audit reviews should PRIMARILY:...
Question 487: Which of the following would BEST assist an information secu...
Question 488: To determine how a security breach occurred on the corporate...
Question 489: In a business impact analysis, the value of an information s...
Question 490: The PRIMARY reason for assigning classes of sensitivity and ...
Question 491: The MOST effective use of a risk register is to:...
Question 492: Senior management commitment and support for information sec...
Question 493: To justify the establishment of an incident management team,...
Question 494: Who in an organization has the responsibility for classifyin...
Question 495: The recovery time objective (RTO) is reached at which of the...
Question 496: Which of the following is the MOST appropriate method of ens...
Question 497: An organization that outsourced its payroll processing perfo...
Question 498: Detailed business continuity plans should be based PRIMARILY...
Question 499: When a new key business application goes into production, th...
Question 500: What is the MAIN risk when there is no user management repre...
Question 501: Which of the following is the BEST reason to perform a busin...
Question 502: Risk assessment is MOST effective when performed:...
Question 503: A digital signature using a public key infrastructure (PKI) ...
Question 504: Which of the following situations must be corrected FIRST to...
Question 505: It is important to develop an information security baseline ...
Question 506: An information security manager is advised by contacts in la...
Question 507: In which of the following system development life cycle (SDL...
Question 508: An organization's information security processes are current...
Question 509: The PRIORITY action to be taken when a server is infected wi...
Question 510: Which would be the BEST recommendation to protect against ph...
Question 511: An information security organization should PRIMARILY:...
Question 512: After a risk assessment, it is determined that the cost to m...
Question 513: What would a security manager PRIMARILY utilize when proposi...
Question 514: Who is responsible for ensuring that information is classifi...
Question 515: Data owners will determine what access and authorizations us...
Question 516: Which resource is the MOST effective in preventing physical ...
Question 517: Which of the following steps should be performed FIRST in th...
Question 518: Which of the following is the MOST important guideline when ...
Question 519: Which of the following techniques MOST clearly indicates whe...
Question 520: In business critical applications, where shared access to el...
Question 521: Which of the following devices could potentially stop a Stru...
Question 522: When performing a quantitative risk analysis, which of the f...
Question 523: When implementing security controls, an information security...
Question 524: The PRIMARY goal in developing an information security strat...
Question 525: A common concern with poorly written web applications is tha...
Question 526: When a large organization discovers that it is the subject o...
Question 527: The BEST way to ensure that an external service provider com...
Question 528: For risk management purposes, the value of an asset should b...
Question 529: A global financial institution has decided not to take any f...
Question 530: Which of the following will BEST ensure that management take...
Question 531: Which two components PRIMARILY must be assessed in an effect...
Question 532: What is the MOST important success factor in launching a cor...
Question 533: A security manager meeting the requirements for the internat...
Question 534: The PRIMARY purpose of using risk analysis within a security...
Question 535: Which of the following results from the risk assessment proc...
Question 536: The return on investment of information security can BEST be...
Question 537: Documented standards/procedures for the use of cryptography ...
Question 538: Priority should be given to which of the following to ensure...
Question 539: An information security manager wishing to establish securit...
Question 540: Which of the following is MOST important to the success of a...
Question 541: The MOST important factor in ensuring the success of an info...
Question 542: Which of the following environments represents the GREATEST ...
Question 543: Investments in information security technologies should be b...
Question 544: In designing a backup strategy that will be consistent with ...
Question 545: The MOST effective way to ensure that outsourced service pro...
Question 546: Of the following, which is the MOST important aspect of fore...
Question 547: Which of the following is MOST important to the successful p...
Question 548: Retention of business records should PRIMARILY be based on:...
Question 549: Which of the following would help management determine the r...
Question 550: Which of the following BEST ensures that information transmi...
Question 551: Risk assessment should be built into which of the following ...
Question 552: An organization has implemented an enterprise resource plann...
Question 553: The BEST strategy for risk management is to:...
Question 554: Which of the following should be determined while defining r...
Question 555: The systems administrator did not immediately notify the sec...
Question 556: When performing an information risk analysis, an information...
Question 557: A company's mail server allows anonymous file transfer proto...
Question 558: Which of the following is an advantage of a centralized info...
Question 559: Which of the following is MOST likely to be discretionary?...
Question 560: Which of the following is MOST important for measuring the e...
Question 561: Phishing is BEST mitigated by which of the following?...
Question 562: What is the BEST policy for securing data on mobile universa...
Question 563: The MOST important characteristic of good security policies ...
Question 564: What is the MOST important item to be included in an informa...
Question 565: In assessing risk, it is MOST essential to:...
Question 566: When an information security manager is developing a strateg...
Question 567: Which of the following features is normally missing when usi...
Question 568: How would an organization know if its new information securi...
Question 569: Information security projects should be prioritized on the b...
Question 570: Which of the following will BEST protect against malicious a...
Question 571: Which of the following is the BEST tool to maintain the curr...
Question 572: Which of the following situations would MOST inhibit the eff...
Question 573: A risk management program should reduce risk to:...
Question 574: A security awareness program should:...
Question 575: The PRIMARY reason for involving information security at eac...
Question 576: Which of the following would be MOST appropriate for collect...
Question 577: It is important to classify and determine relative sensitivi...
Question 578: An unauthorized user gained access to a merchant's database ...
Question 579: When application-level security controlled by business proce...
Question 580: Security technologies should be selected PRIMARILY on the ba...
Question 581: Before engaging outsourced providers, an information securit...
Question 582: Which of the following is MOST appropriate for inclusion in ...
Question 583: In assessing the degree to which an organization may be affe...
Question 584: Which of the following is the BEST method to ensure the over...
Question 585: Security awareness training is MOST likely to lead to which ...
Question 586: Which of the following is characteristic of centralized info...
Question 587: An organization with multiple data centers has designated on...
Question 588: Which of the following is MOST important for a successful in...
Question 589: A computer incident response team (CIRT) manual should PRIMA...
Question 590: An operating system (OS) noncritical patch to enhance system...
Question 591: To ensure that all information security procedures are funct...
Question 592: The MOST important success factor to design an effective IT ...
Question 593: A major trading partner with access to the internal network ...
Question 594: Managing the life cycle of a digital certificate is a role o...
Question 595: Which of the following would be the MOST appropriate physica...
Question 596: A security manager is preparing a report to obtain the commi...
Question 597: The MOST appropriate owner of customer data stored in a cent...
Question 598: Which of the following are seldom changed in response to tec...
Question 599: A risk assessment and business impact analysis (BIA) have be...
Question 600: In performing a risk assessment on the impact of losing a se...
Question 601: Which of the following is the MOST important information to ...
Question 602: In order to protect a network against unauthorized external ...
Question 603: Which of the following is the MOST important item to include...
Question 604: Access control to a sensitive intranet application by mobile...
Question 605: The PRIMARY purpose of involving third-party teams for carry...
Question 606: To mitigate a situation where one of the programmers of an a...
Question 607: Which program element should be implemented FIRST in asset c...
Question 608: A risk management program would be expected to:...
Question 609: A web server in a financial institution that has been compro...
Question 610: Which of the following provides the linkage to ensure that p...
Question 611: Which of the following is the MOST important action to take ...
Question 612: Secure customer use of an e-commerce application can BEST be...
Question 613: Which of the following is the MOST likely outcome of a well-...
Question 614: Logging is an example of which type of defense against syste...
Question 615: All risk management activities are PRIMARILY designed to red...
Question 616: Which of the following is the MOST important information to ...
Question 617: Which of the following is the MOST appropriate use of gap an...
Question 618: What is the BEST way to ensure users comply with organizatio...
Question 619: A security risk assessment exercise should be repeated at re...