<< Prev Question Next Question >>

Question 319/619

Who should be responsible for enforcing access rights to application data?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (619q)
Question 1: Which of the following is the MOST important consideration w...
Question 2: In order to highlight to management the importance of integr...
Question 3: Which of the following are the MOST important individuals to...
Question 4: In the course of responding 10 an information security incid...
Question 5: The PRIMARY purpose of installing an intrusion detection sys...
Question 6: An IS manager has decided to implement a security system to ...
Question 7: An information security manager has been assigned to impleme...
Question 8: The MOST important reason that statistical anomaly-based int...
Question 9: The FIRST step in developing an information security managem...
Question 10: Security awareness training should be provided to new employ...
Question 11: The MOST basic requirement for an information security gover...
Question 12: A new regulation for safeguarding information processed by a...
Question 13: Which of the following would help to change an organization'...
Question 14: Which of the following would raise security awareness among ...
Question 15: Which of the following guarantees that data in a file have n...
Question 16: Which is the BEST way to measure and prioritize aggregate ri...
Question 17: There is reason to believe that a recently modified web appl...
Question 18: An information security manager reviewed the access control ...
Question 19: When creating a forensic image of a hard drive, which of the...
Question 20: A business unit intends to deploy a new technology in a mann...
Question 21: Which of the following is the MOST important reason why info...
Question 22: Primary direction on the impact of compliance with new regul...
Question 23: What is the BEST technique to determine which security contr...
Question 24: A message* that has been encrypted by the sender's private k...
Question 25: After completing a full IT risk assessment, who can BEST dec...
Question 26: Which of the following tools is MOST appropriate to assess w...
Question 27: Which of the following is the BEST method to reduce the numb...
Question 28: Which of the following areas is MOST susceptible to the intr...
Question 29: When residual risk is minimized:...
Question 30: Which of the following BEST describes an information securit...
Question 31: Acceptable risk is achieved when:...
Question 32: Which of the following requirements would have the lowest le...
Question 33: A critical component of a continuous improvement program for...
Question 34: Which of the following is MOST effective in preventing weakn...
Question 35: Information security policies should:...
Question 36: Previously accepted risk should be:...
Question 37: What is the GREATEST risk when there is an excessive number ...
Question 38: A root kit was used to capture detailed accounts receivable ...
Question 39: Which of the following is MOST important when deciding wheth...
Question 40: How would an information security manager balance the potent...
Question 41: The BEST way to ensure that security settings on each platfo...
Question 42: Which of the following tools is MOST appropriate for determi...
Question 43: Which of the following is the MOST relevant metric to includ...
Question 44: After obtaining commitment from senior management, which of ...
Question 45: The PRIMARY consideration when defining recovery time object...
Question 46: Which of the following change management activities would be...
Question 47: An online banking institution is concerned that the breach o...
Question 48: Several business units reported problems with their systems ...
Question 49: A business partner of a factory has remote read-only access ...
Question 50: The BEST time to perform a penetration test is after:...
Question 51: To BEST improve the alignment of the information security ob...
Question 52: Which of the following is the PRIMARY prerequisite to implem...
Question 53: An account with full administrative privileges over a produc...
Question 54: Which of the following roles would represent a conflict of i...
Question 55: When an organization is implementing an information security...
Question 56: Which of the following BEST indicates a successful risk mana...
Question 57: When configuring a biometric access control system that prot...
Question 58: Relationships among security technologies are BEST defined t...
Question 59: When a user employs a client-side digital certificate to aut...
Question 60: An e-commerce order fulfillment web server should generally ...
Question 61: Which of the following terms and conditions represent a sign...
Question 62: Risk acceptance is a component of which of the following?...
Question 63: Which of the following is the MOST appropriate frequency for...
Question 64: An organization has been experiencing a number of network-ba...
Question 65: The MOST important reason for formally documenting security ...
Question 66: There is a time lag between the time when a security vulnera...
Question 67: Which of the following would be the BEST option to improve a...
Question 68: The effectiveness of virus detection software is MOST depend...
Question 69: Which of the following are the essential ingredients of a bu...
Question 70: An internal audit has identified major weaknesses over IT pr...
Question 71: A border router should be placed on which of the following?...
Question 72: Who is ultimately responsible for ensuring that information ...
Question 73: An internal review of a web-based application system finds t...
Question 74: When properly tested, which of the following would MOST effe...
Question 75: What is the MAIN drawback of e-mailing password-protected zi...
Question 76: Senior management commitment and support for information sec...
Question 77: When a newly installed system for synchronizing passwords ac...
Question 78: To help ensure that contract personnel do not obtain unautho...
Question 79: What is the BEST method to verify that all security patches ...
Question 80: The PRIMARY objective of a security steering group is to:...
Question 81: Data owners must provide a safe and secure environment to en...
Question 82: The MAIN reason why asset classification is important to a s...
Question 83: The PRIMARY objective of an Internet usage policy is to prev...
Question 84: A risk analysis should:
Question 85: The security responsibility of data custodians in an organiz...
Question 86: The PRIMARY benefit of performing an information asset class...
Question 87: A database was compromised by guessing the password for a sh...
Question 88: Attackers who exploit cross-site scripting vulnerabilities t...
Question 89: Isolation and containment measures lor a compromised compute...
Question 90: In a social engineering scenario, which of the following wil...
Question 91: Which of the following is the MOST important management sign...
Question 92: Which of the following is the MOST important consideration f...
Question 93: What is the BEST defense against a Structured Query Language...
Question 94: In business-critical applications, user access should be app...
Question 95: A customer credit card database has been breached by hackers...
Question 96: Successful social engineering attacks can BEST be prevented ...
Question 97: When personal information is transmitted across networks, th...
Question 98: An organization keeps backup tapes of its servers at a warm ...
Question 99: An organization has adopted a practice of regular staff rota...
Question 100: The configuration management plan should PRIMARILY be based ...
Question 101: What is the BEST way to ensure data protection upon terminat...
Question 102: The PRIMARY concern of an information security manager docum...
Question 103: Which of the following is the PRIMARY reason for implementin...
Question 104: The PRIMARY focus of the change control process is to ensure...
Question 105: Which of the following is the MOST important process that an...
Question 106: Which of the following is generally used to ensure that info...
Question 107: Which of the following is the MOST appropriate individual to...
Question 108: Obtaining senior management support for establishing a warm ...
Question 109: Evidence from a compromised server has to be acquired for a ...
Question 110: The IT function has declared that, when putting a new applic...
Question 111: An information security manager believes that a network file...
Question 112: Which of the following is the BEST way to ensure that a corp...
Question 113: When performing a qualitative risk analysis, which of the fo...
Question 114: Which of the following events generally has the highest info...
Question 115: Which of the following is MOST essential for a risk manageme...
Question 116: Which of the following BEST contributes to the development o...
Question 117: The BEST way to determine if an anomaly-based intrusion dete...
Question 118: Temporarily deactivating some monitoring processes, even if ...
Question 119: Who would be in the BEST position to determine the recovery ...
Question 120: Which of the following should be determined FIRST when estab...
Question 121: Which would be one of the BEST metrics an information securi...
Question 122: What would be the MOST significant security risks when using...
Question 123: Which of the following is the MOST important item to conside...
Question 124: Who should determine the appropriate classification of accou...
Question 125: To justify the need to invest in a forensic analysis tool, a...
Question 126: Which of the following practices is BEST to remove system ac...
Question 127: It is MOST important that information security architecture ...
Question 128: In the process of deploying a new e-mail system, an informat...
Question 129: Based on the information provided, which of the following si...
Question 130: As an organization grows, exceptions to information security...
Question 131: Data owners are PRIMARILY responsible for establishing risk ...
Question 132: When contracting with an outsourcer to provide security admi...
Question 133: Which of the following is the MOST appropriate method to pro...
Question 134: Which of the following would be the MOST significant securit...
Question 135: An organization has to comply with recently published indust...
Question 136: The MOST appropriate role for senior management in supportin...
Question 137: The PRIMARY purpose of performing an internal attack and pen...
Question 138: Which of the following is the MOST effective type of access ...
Question 139: Which of the following are likely to be updated MOST frequen...
Question 140: Which of the following is the BEST indicator that an effecti...
Question 141: Which of the following presents the GREATEST exposure to int...
Question 142: Which of the following is MOST effective for securing wirele...
Question 143: Which of the following ensures that newly identified securit...
Question 144: The BEST way to justify the implementation of a single sign-...
Question 145: Which of the following will MOST likely reduce the chances o...
Question 146: Which of the following would be MOST helpful to achieve alig...
Question 147: Which of the following would be MOST critical to the success...
Question 148: A good privacy statement should include:...
Question 149: A third party was engaged to develop a business application....
Question 150: In an organization, information systems security is the resp...
Question 151: Who is responsible for ensuring that information is categori...
Question 152: Which of the following would be the FIRST step in establishi...
Question 153: Which of the following is the BEST metric for evaluating the...
Question 154: A critical device is delivered with a single user and passwo...
Question 155: The BEST way to ensure that information security policies ar...
Question 156: What is the MOST important element to include when developin...
Question 157: The main mail server of a financial institution has been com...
Question 158: What is the BEST way to ensure that an intruder who successf...
Question 159: The data access requirements for an application should be de...
Question 160: Which of the following is the MOST important requirement for...
Question 161: What is the PRIMARY role of the information security manager...
Question 162: From an information security perspective, information that n...
Question 163: When an organization hires a new information security manage...
Question 164: What will have the HIGHEST impact on standard information se...
Question 165: Which of the following is the MOST important prerequisite fo...
Question 166: The BEST reason for an organization to have two discrete fir...
Question 167: Which of the following is MOST important in determining whet...
Question 168: Recovery point objectives (RPOs) can be used to determine wh...
Question 169: Which of the following would be the MOST important factor to...
Question 170: Which of the following actions should lake place immediately...
Question 171: Which of the following would BEST ensure the success of info...
Question 172: Which of the following processes is critical for deciding pr...
Question 173: The MAIN reason for deploying a public key infrastructure (P...
Question 174: Identification and prioritization of business risk enables p...
Question 175: An organization has decided to implement additional security...
Question 176: A benefit of using a full disclosure (white box) approach as...
Question 177: Which of the following security mechanisms is MOST effective...
Question 178: Which of the following types of information would the inform...
Question 179: Which of the following actions should be taken when an infor...
Question 180: The information classification scheme should:...
Question 181: A successful information security management program should ...
Question 182: When a proposed system change violates an existing security ...
Question 183: When speaking to an organization's human resources departmen...
Question 184: Which of the following is an inherent weakness of signature-...
Question 185: Minimum standards for securing the technical infrastructure ...
Question 186: Which of the following is the MOST important area of focus w...
Question 187: On a company's e-commerce web site, a good legal statement r...
Question 188: What is the BEST method for mitigating against network denia...
Question 189: Security policies should be aligned MOST closely with:...
Question 190: A web-based business application is being migrated from test...
Question 191: Which of the following characteristics is MOST important whe...
Question 192: Which of the following is the MAIN reason for performing ris...
Question 193: Which of the following would BEST prepare an information sec...
Question 194: When security policies are strictly enforced, the initial im...
Question 195: In organizations where availability is a primary concern, th...
Question 196: Which of the following risks would BEST be assessed using qu...
Question 197: An intrusion detection system should be placed:...
Question 198: Which of the following MOST commonly falls within the scope ...
Question 199: When performing a business impact analysis (BIA), which of t...
Question 200: The advantage of Virtual Private Network (VPN) tunneling for...
Question 201: An information security manager reviewing firewall rules wil...
Question 202: Which of the following is the MOST important element of an i...
Question 203: A new port needs to be opened in a perimeter firewall. Which...
Question 204: A desktop computer that was involved in a computer security ...
Question 205: Emergency actions are taken at the early stage of a disaster...
Question 206: Ongoing tracking of remediation efforts to mitigate identifi...
Question 207: When considering the value of assets, which of the following...
Question 208: A risk assessment study carried out by an organization noted...
Question 209: What is the BEST method to confirm that all firewall rules a...
Question 210: Of the following, the BEST method for ensuring that temporar...
Question 211: The MOST important factor in planning for the long-term rete...
Question 212: Which of the following would BEST address the risk of data l...
Question 213: Which of the following would be the MOST important goal of a...
Question 214: The BEST method for detecting and monitoring a hacker's acti...
Question 215: Which of the following would represent a violation of the ch...
Question 216: Which of the following devices should be placed within a DMZ...
Question 217: Which of the following is the BEST indicator that security a...
Question 218: The purpose of a corrective control is to:...
Question 219: What does a network vulnerability assessment intend to ident...
Question 220: Effective IT governance is BEST ensured by:...
Question 221: An organization is entering into an agreement with a new bus...
Question 222: A serious vulnerability is reported in the firewall software...
Question 223: The PRIMARY objective of security awareness is to:...
Question 224: Which of the following metrics would be the MOST useful in m...
Question 225: What mechanisms are used to identify deficiencies that would...
Question 226: In order to highlight to management the importance of networ...
Question 227: Which of the following mechanisms is the MOST secure way to ...
Question 228: An information security program should be sponsored by:...
Question 229: To determine the selection of controls required to meet busi...
Question 230: Who is responsible for raising awareness of the need for ade...
Question 231: Which item would be the BEST to include in the information s...
Question 232: An organization's operations staff places payment files in a...
Question 233: Which of the following is MOST effective in preventing the i...
Question 234: Which of the following is the MOST appropriate individual to...
Question 235: In a well-controlled environment, which of the following act...
Question 236: The FIRST step to create an internal culture that focuses on...
Question 237: Which of the following is a key area of the ISO 27001 framew...
Question 238: Information security governance is PRIMARILY driven by:...
Question 239: Which of the following is the MAIN objective in contracting ...
Question 240: The advantage of sending messages using steganographic techn...
Question 241: An information security manager mapping a job description to...
Question 242: Which of the following is the MOST likely to change an organ...
Question 243: An outsource service provider must handle sensitive customer...
Question 244: The MAIN goal of an information security strategic plan is t...
Question 245: Which of the following is the FIRST phase in which security ...
Question 246: Which of the following would a security manager establish to...
Question 247: Which of the following measures is the MOST effective deterr...
Question 248: The MAIN advantage of implementing automated password synchr...
Question 249: Requiring all employees and contractors to meet personnel se...
Question 250: Which of the following is MOST closely associated with a bus...
Question 251: Which of the following is the MOST essential task for a chie...
Question 252: The MOST important reason for conducting periodic risk asses...
Question 253: Which of the following activities is MOST likely to increase...
Question 254: Which of the following is the MOST important risk associated...
Question 255: When an emergency security patch is received via electronic ...
Question 256: Which of the following factors is a PRIMARY driver for infor...
Question 257: Which of the following would be MOST useful in developing a ...
Question 258: Which of the following risks is represented in the risk appe...
Question 259: Which of the following is the MOST effective at preventing a...
Question 260: Which of the following application systems should have the s...
Question 261: The PRIMARY reason for using metrics to evaluate information...
Question 262: Which of the following BEST provides message integrity, send...
Question 263: Which of the following should be in place before a black box...
Question 264: To justify its ongoing security budget, which of the followi...
Question 265: One way to determine control effectiveness is by determining...
Question 266: Which of the following is the BEST method to provide a new u...
Question 267: At the conclusion of a disaster recovery test, which of the ...
Question 268: Information security policy enforcement is the responsibilit...
Question 269: An information security manager has been asked to develop a ...
Question 270: When electronically stored information is requested during a...
Question 271: Which of the following devices should be placed within a dem...
Question 272: Which of the following is the MOST important consideration w...
Question 273: Which of the following is MOST effective in preventing secur...
Question 274: What is the PRIMARY objective of a post-event review in inci...
Question 275: Which of the following should be included in an annual infor...
Question 276: The criticality and sensitivity of information assets is det...
Question 277: Which of the following documents would be the BES T referenc...
Question 278: Which of the following would be MOST effective in successful...
Question 279: Which of the following is the MOST important to keep in mind...
Question 280: For virtual private network (VPN) access to the corporate ne...
Question 281: A risk management approach to information protection is:...
Question 282: When designing an information security quarterly report to m...
Question 283: After a risk assessment study, a bank with global operations...
Question 284: Which of the following is the MOST important element to ensu...
Question 285: The chief information security officer (CISO) should ideally...
Question 286: Which of the following BEST ensures that security risks will...
Question 287: Which of the following is responsible for legal and regulato...
Question 288: Which of the following is the MOST immediate consequence of ...
Question 289: When implementing effective security governance within the r...
Question 290: When a security standard conflicts with a business objective...
Question 291: An organization is already certified to an international sec...
Question 292: The PRIMARY reason for initiating a policy exception process...
Question 293: Before conducting a formal risk assessment of an organizatio...
Question 294: What is the MOST important factor in the successful implemen...
Question 295: What is the MOST effective access control method to prevent ...
Question 296: The recovery point objective (RPO) requires which of the fol...
Question 297: Which of the following, using public key cryptography, ensur...
Question 298: Which of the following is the BEST way to verify that all cr...
Question 299: The MAIN reason for having the Information Security Steering...
Question 300: A company recently developed a breakthrough technology. Sinc...
Question 301: What is the MOST important reason for conducting security aw...
Question 302: The FIRST step in an incident response plan is to:...
Question 303: To ensure that payroll systems continue on in an event of a ...
Question 304: When an organization is setting up a relationship with a thi...
Question 305: Which of the following will BEST protect an organization fro...
Question 306: The BEST metric for evaluating the effectiveness of a firewa...
Question 307: Which of the following is the MOST effective solution for pr...
Question 308: Data owners are normally responsible for which of the follow...
Question 309: Which of the following is the BEST approach to mitigate onli...
Question 310: A risk mitigation report would include recommendations for:...
Question 311: Which of the following is the MOST important to ensure a suc...
Question 312: An information security strategy document that includes spec...
Question 313: An information security manager at a global organization tha...
Question 314: An organization has verified that its customer information w...
Question 315: When designing the technical solution for a disaster recover...
Question 316: Which of the following would be a MAJOR consideration for an...
Question 317: Which of the following is the BEST method for ensuring that ...
Question 318: From an information security manager perspective, what is th...
Question 319: Who should be responsible for enforcing access rights to app...
Question 320: Which of the following is the BEST method or technique to en...
Question 321: Which of the following is an example of a corrective control...
Question 322: Which of the following are the MOST important criteria when ...
Question 323: During which phase of development is it MOST appropriate to ...
Question 324: What is the MOS T cost-effective means of improving security...
Question 325: Which of the following is MOST effective in protecting again...
Question 326: A risk assessment should be conducted:...
Question 327: A project manager is developing a developer portal and reque...
Question 328: The BEST protocol to ensure confidentiality of transmissions...
Question 329: When performing a risk assessment, the MOST important consid...
Question 330: Which of the following will BEST prevent external security a...
Question 331: Which of (lie following would be the MOST relevant factor wh...
Question 332: Which of the following would present the GREATEST risk to in...
Question 333: Good information security procedures should:...
Question 334: Which of the following technologies is utilized to ensure th...
Question 335: An organization's information security manager has been aske...
Question 336: Which of the following provides the BKST confirmation that t...
Question 337: An organization plans to contract with an outside service pr...
Question 338: The PRIMARY objective of a risk management program is to:...
Question 339: Nonrepudiation can BEST be assured by using:...
Question 340: A mission-critical system has been identified as having an a...
Question 341: Security monitoring mechanisms should PRIMARILY:...
Question 342: The value of information assets is BEST determined by:...
Question 343: Which of the following disaster recovery testing techniques ...
Question 344: Successful implementation of information security governance...
Question 345: An intranet server should generally be placed on the:...
Question 346: Because of its importance to the business, an organization w...
Question 347: The management staff of an organization that does not have a...
Question 348: Which of the following would be MOST relevant to include in ...
Question 349: The MOST useful way to describe the objectives in the inform...
Question 350: Which of the following should be the FIRST step in developin...
Question 351: Prior to having a third party perform an attack and penetrat...
Question 352: What is an appropriate frequency for updating operating syst...
Question 353: A possible breach of an organization's IT system is reported...
Question 354: Who should drive the risk analysis for an organization?...
Question 355: Which of the following is the MOST effective way to treat a ...
Question 356: When developing incident response procedures involving serve...
Question 357: Which of the following is the MOST usable deliverable of an ...
Question 358: An organization's board of directors has learned of recent l...
Question 359: Which of the following is the BEST method to securely transf...
Question 360: Which of the following is MOST important to understand when ...
Question 361: The MOST complete business case for security solutions is on...
Question 362: Which of the following roles is PRIMARILY responsible for de...
Question 363: An organization plans to outsource its customer relationship...
Question 364: The FIRST priority when responding to a major security incid...
Question 365: The PRIMARY goal of a corporate risk management program is t...
Question 366: When a departmental system continues to be out of compliance...
Question 367: What is the BEST way to alleviate security team understaffin...
Question 368: The decision on whether new risks should fall under periodic...
Question 369: In the course of examining a computer system for forensic ev...
Question 370: When developing an information security program, what is the...
Question 371: Which of the following is the MOST important factor when des...
Question 372: Who can BEST approve plans to implement an information secur...
Question 373: An incident response policy must contain:...
Question 374: Senior management commitment and support for information sec...
Question 375: Which of the following security activities should be impleme...
Question 376: The organization has decided to outsource the majority of th...
Question 377: While implementing information security governance an organi...
Question 378: Which of the following represents the MAJOR focus of privacy...
Question 379: The decision as to whether a risk has been reduced to an acc...
Question 380: When collecting evidence for forensic analysis, it is import...
Question 381: When an organization is using an automated tool to manage an...
Question 382: An information security manager must understand the relation...
Question 383: Which of the following recovery strategies has the GREATEST ...
Question 384: Which of the following situations would be the MOST concern ...
Question 385: Which of the following is the MOST appropriate position to s...
Question 386: Good information security standards should:...
Question 387: What is the MOST appropriate change management procedure for...
Question 388: A multinational organization operating in fifteen countries ...
Question 389: What is the FIRST action an information security manager sho...
Question 390: The service level agreement (SLA) for an outsourced IT funct...
Question 391: During the security review of organizational servers it was ...
Question 392: Which of the following actions should be taken when an onlin...
Question 393: Which of the following is the MOST effective, positive metho...
Question 394: The MOST important objective of a post incident review is to...
Question 395: The valuation of IT assets should be performed by:...
Question 396: The impact of losing frame relay network connectivity for 18...
Question 397: Which of the following controls is MOST effective in providi...
Question 398: Which of the following BEST ensures that modifications made ...
Question 399: Which of the following is the MOST important element to ensu...
Question 400: The MOST effective approach to address issues that arise bet...
Question 401: The "separation of duties" principle is violated if which of...
Question 402: Change management procedures to ensure that disaster recover...
Question 403: The implementation of continuous monitoring controls is the ...
Question 404: Which of the following represents a PRIMARY area of interest...
Question 405: Information security managers should use risk assessment tec...
Question 406: An organization's information security strategy should be ba...
Question 407: A test plan to validate the security controls of a new syste...
Question 408: The BEST approach in managing a security incident involving ...
Question 409: What is the GREATEST advantage of documented guidelines and ...
Question 410: Why is "slack space" of value to an information security man...
Question 411: An information security manager uses security metrics to mea...
Question 412: Which of the following would be the BEST metric for the IT r...
Question 413: If an organization considers taking legal action on a securi...
Question 414: Which of the following groups would be in the BEST position ...
Question 415: What task should be performed once a security incident has b...
Question 416: Which of the following measures would be MOST effective agai...
Question 417: Which of the following practices completely prevents a man-i...
Question 418: Which of the following is the BEST justification to convince...
Question 419: Nonrepudiation can BEST be ensured by using:...
Question 420: An information security manager at a global organization has...
Question 421: A post-incident review should be conducted by an incident ma...
Question 422: What is the BEST way to ensure that contract programmers com...
Question 423: Investment in security technology and processes should be ba...
Question 424: On which of the following should a firewall be placed?...
Question 425: Which of the following controls would BEST prevent accidenta...
Question 426: Information security should be:...
Question 427: Reviewing which of the following would BEST ensure that secu...
Question 428: The FIRST step in establishing a security governance program...
Question 429: What is the MOST cost-effective method of identifying new ve...
Question 430: After assessing and mitigating the risks of a web applicatio...
Question 431: At what stage of the applications development process should...
Question 432: Which of the following presents the GREATEST threat to the s...
Question 433: An intrusion detection system (IDS) should:...
Question 434: A new e-mail virus that uses an attachment disguised as a pi...
Question 435: Which of the following steps in conducting a risk assessment...
Question 436: A company has a network of branch offices with local file/pr...
Question 437: The MOST effective way to incorporate risk management practi...
Question 438: The MOST appropriate individual to determine the level of in...
Question 439: Which of the following is the BEST mechanism to determine th...
Question 440: An organization without any formal information security prog...
Question 441: Which of the following risks would BEST be assessed using qu...
Question 442: Which of the following is a benefit of information security ...
Question 443: Which of the following would generally have the GREATEST neg...
Question 444: An information security program should focus on:...
Question 445: The MOST important component of a privacy policy is:...
Question 446: Which of the following is the BEST metric for evaluating the...
Question 447: Who is ultimately responsible for the organization's informa...
Question 448: Which of the following has the highest priority when definin...
Question 449: When defining a service level agreement (SLA) regarding the ...
Question 450: Which of the following is the MOST effective solution for pr...
Question 451: Which of the following should be performed FIRST in the afte...
Question 452: When identifying legal and regulatory issues affecting infor...
Question 453: When a significant security breach occurs, what should be re...
Question 454: Which of the following is the MOST critical activity to ensu...
Question 455: Who can BEST advocate the development of and ensure the succ...
Question 456: Which of the following is the BEST approach for an organizat...
Question 457: Which of the following would BEST protect an organization's ...
Question 458: The cost of implementing a security control should not excee...
Question 459: Acceptable levels of information security risk should be det...
Question 460: Which of the following would be of GREATEST importance to th...
Question 461: To achieve effective strategic alignment of security initiat...
Question 462: At what stage of the applications development process would ...
Question 463: Which of the following is the BEST approach for improving in...
Question 464: The MOST effective way to ensure network users are aware of ...
Question 465: Which of the following is the MOST important reason for an i...
Question 466: The PRIMARY driver to obtain external resources to execute t...
Question 467: Which of the following attacks is BEST mitigated by utilizin...
Question 468: Which of the following is generally considered a fundamental...
Question 469: Which of the following is characteristic of decentralized in...
Question 470: Which of the following devices should be placed within a DMZ...
Question 471: To reduce the possibility of service interruptions, an entit...
Question 472: An organization has learned of a security breach at another ...
Question 473: The MOST important function of a risk management program is ...
Question 474: A business impact analysis (BIA) is the BEST tool for calcul...
Question 475: Which of the following is MOST important in developing a sec...
Question 476: An organization has a process in place that involves the use...
Question 477: Simple Network Management Protocol v2 (SNMP v2) is used freq...
Question 478: An outcome of effective security governance is:...
Question 479: A successful risk management program should lead to:...
Question 480: Which of the following authentication methods prevents authe...
Question 481: Which of the following will BEST prevent an employee from us...
Question 482: An effective way of protecting applications against Structur...
Question 483: Which of the following is the MOST serious exposure of autom...
Question 484: Risk management programs are designed to reduce risk to:...
Question 485: Which of the following BEST describes the scope of risk anal...
Question 486: Security audit reviews should PRIMARILY:...
Question 487: Which of the following would BEST assist an information secu...
Question 488: To determine how a security breach occurred on the corporate...
Question 489: In a business impact analysis, the value of an information s...
Question 490: The PRIMARY reason for assigning classes of sensitivity and ...
Question 491: The MOST effective use of a risk register is to:...
Question 492: Senior management commitment and support for information sec...
Question 493: To justify the establishment of an incident management team,...
Question 494: Who in an organization has the responsibility for classifyin...
Question 495: The recovery time objective (RTO) is reached at which of the...
Question 496: Which of the following is the MOST appropriate method of ens...
Question 497: An organization that outsourced its payroll processing perfo...
Question 498: Detailed business continuity plans should be based PRIMARILY...
Question 499: When a new key business application goes into production, th...
Question 500: What is the MAIN risk when there is no user management repre...
Question 501: Which of the following is the BEST reason to perform a busin...
Question 502: Risk assessment is MOST effective when performed:...
Question 503: A digital signature using a public key infrastructure (PKI) ...
Question 504: Which of the following situations must be corrected FIRST to...
Question 505: It is important to develop an information security baseline ...
Question 506: An information security manager is advised by contacts in la...
Question 507: In which of the following system development life cycle (SDL...
Question 508: An organization's information security processes are current...
Question 509: The PRIORITY action to be taken when a server is infected wi...
Question 510: Which would be the BEST recommendation to protect against ph...
Question 511: An information security organization should PRIMARILY:...
Question 512: After a risk assessment, it is determined that the cost to m...
Question 513: What would a security manager PRIMARILY utilize when proposi...
Question 514: Who is responsible for ensuring that information is classifi...
Question 515: Data owners will determine what access and authorizations us...
Question 516: Which resource is the MOST effective in preventing physical ...
Question 517: Which of the following steps should be performed FIRST in th...
Question 518: Which of the following is the MOST important guideline when ...
Question 519: Which of the following techniques MOST clearly indicates whe...
Question 520: In business critical applications, where shared access to el...
Question 521: Which of the following devices could potentially stop a Stru...
Question 522: When performing a quantitative risk analysis, which of the f...
Question 523: When implementing security controls, an information security...
Question 524: The PRIMARY goal in developing an information security strat...
Question 525: A common concern with poorly written web applications is tha...
Question 526: When a large organization discovers that it is the subject o...
Question 527: The BEST way to ensure that an external service provider com...
Question 528: For risk management purposes, the value of an asset should b...
Question 529: A global financial institution has decided not to take any f...
Question 530: Which of the following will BEST ensure that management take...
Question 531: Which two components PRIMARILY must be assessed in an effect...
Question 532: What is the MOST important success factor in launching a cor...
Question 533: A security manager meeting the requirements for the internat...
Question 534: The PRIMARY purpose of using risk analysis within a security...
Question 535: Which of the following results from the risk assessment proc...
Question 536: The return on investment of information security can BEST be...
Question 537: Documented standards/procedures for the use of cryptography ...
Question 538: Priority should be given to which of the following to ensure...
Question 539: An information security manager wishing to establish securit...
Question 540: Which of the following is MOST important to the success of a...
Question 541: The MOST important factor in ensuring the success of an info...
Question 542: Which of the following environments represents the GREATEST ...
Question 543: Investments in information security technologies should be b...
Question 544: In designing a backup strategy that will be consistent with ...
Question 545: The MOST effective way to ensure that outsourced service pro...
Question 546: Of the following, which is the MOST important aspect of fore...
Question 547: Which of the following is MOST important to the successful p...
Question 548: Retention of business records should PRIMARILY be based on:...
Question 549: Which of the following would help management determine the r...
Question 550: Which of the following BEST ensures that information transmi...
Question 551: Risk assessment should be built into which of the following ...
Question 552: An organization has implemented an enterprise resource plann...
Question 553: The BEST strategy for risk management is to:...
Question 554: Which of the following should be determined while defining r...
Question 555: The systems administrator did not immediately notify the sec...
Question 556: When performing an information risk analysis, an information...
Question 557: A company's mail server allows anonymous file transfer proto...
Question 558: Which of the following is an advantage of a centralized info...
Question 559: Which of the following is MOST likely to be discretionary?...
Question 560: Which of the following is MOST important for measuring the e...
Question 561: Phishing is BEST mitigated by which of the following?...
Question 562: What is the BEST policy for securing data on mobile universa...
Question 563: The MOST important characteristic of good security policies ...
Question 564: What is the MOST important item to be included in an informa...
Question 565: In assessing risk, it is MOST essential to:...
Question 566: When an information security manager is developing a strateg...
Question 567: Which of the following features is normally missing when usi...
Question 568: How would an organization know if its new information securi...
Question 569: Information security projects should be prioritized on the b...
Question 570: Which of the following will BEST protect against malicious a...
Question 571: Which of the following is the BEST tool to maintain the curr...
Question 572: Which of the following situations would MOST inhibit the eff...
Question 573: A risk management program should reduce risk to:...
Question 574: A security awareness program should:...
Question 575: The PRIMARY reason for involving information security at eac...
Question 576: Which of the following would be MOST appropriate for collect...
Question 577: It is important to classify and determine relative sensitivi...
Question 578: An unauthorized user gained access to a merchant's database ...
Question 579: When application-level security controlled by business proce...
Question 580: Security technologies should be selected PRIMARILY on the ba...
Question 581: Before engaging outsourced providers, an information securit...
Question 582: Which of the following is MOST appropriate for inclusion in ...
Question 583: In assessing the degree to which an organization may be affe...
Question 584: Which of the following is the BEST method to ensure the over...
Question 585: Security awareness training is MOST likely to lead to which ...
Question 586: Which of the following is characteristic of centralized info...
Question 587: An organization with multiple data centers has designated on...
Question 588: Which of the following is MOST important for a successful in...
Question 589: A computer incident response team (CIRT) manual should PRIMA...
Question 590: An operating system (OS) noncritical patch to enhance system...
Question 591: To ensure that all information security procedures are funct...
Question 592: The MOST important success factor to design an effective IT ...
Question 593: A major trading partner with access to the internal network ...
Question 594: Managing the life cycle of a digital certificate is a role o...
Question 595: Which of the following would be the MOST appropriate physica...
Question 596: A security manager is preparing a report to obtain the commi...
Question 597: The MOST appropriate owner of customer data stored in a cent...
Question 598: Which of the following are seldom changed in response to tec...
Question 599: A risk assessment and business impact analysis (BIA) have be...
Question 600: In performing a risk assessment on the impact of losing a se...
Question 601: Which of the following is the MOST important information to ...
Question 602: In order to protect a network against unauthorized external ...
Question 603: Which of the following is the MOST important item to include...
Question 604: Access control to a sensitive intranet application by mobile...
Question 605: The PRIMARY purpose of involving third-party teams for carry...
Question 606: To mitigate a situation where one of the programmers of an a...
Question 607: Which program element should be implemented FIRST in asset c...
Question 608: A risk management program would be expected to:...
Question 609: A web server in a financial institution that has been compro...
Question 610: Which of the following provides the linkage to ensure that p...
Question 611: Which of the following is the MOST important action to take ...
Question 612: Secure customer use of an e-commerce application can BEST be...
Question 613: Which of the following is the MOST likely outcome of a well-...
Question 614: Logging is an example of which type of defense against syste...
Question 615: All risk management activities are PRIMARILY designed to red...
Question 616: Which of the following is the MOST important information to ...
Question 617: Which of the following is the MOST appropriate use of gap an...
Question 618: What is the BEST way to ensure users comply with organizatio...
Question 619: A security risk assessment exercise should be repeated at re...