<< Prev Question Next Question >>

Question 301/732

Which step of the Risk Management Framework (RMF) identifies the initial set of baseline security controls?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (732q)
Question 1: Which of the following documents specifies services from the...
Question 2: In which of the following scenarios is locking server cabine...
Question 3: Which of the following measures serves as the BEST means for...
Question 4: A security architect is implementing an authentication syste...
Question 5: Which of the following BEST describes why software assurance...
Question 6: An organization is implementing security review as part of s...
Question 7: An application team is running tests to ensure that user ent...
Question 8: Which of the following is an effective control in preventing...
Question 9: Which event magnitude is defined as deadly, destructive, and...
Question 10: A company's core Security Operations Center (SOC) would have...
Question 11: What is the MOST effective way to determine a mission critic...
Question 12: During testing, where are the requirements to inform parent ...
Question 13: Which of the following would an information security profess...
Question 14: The application of a security patch to a product previously ...
Question 15: When implementing a secure wireless network, which of the fo...
Question 16: At which stage of the System Development Life Cycle (SDLC)ar...
Question 17: Which of the following is BEST achieved through the use of e...
Question 18: Which of the following areas need a higher level of security...
Question 19: With what frequency should monitoring of a control occur whe...
Question 20: The MAIN task of promoting security for Personal Computers (...
Question 21: In a data classification scheme, the data is owned by the...
Question 22: Which of the following is an example of a Time of Check/Time...
Question 23: When all of the security components in a security strategy a...
Question 24: In Session Layer of the Open System Interconnect (OSI) model...
Question 25: Which of the following wireless security protocols presents ...
Question 26: A security practitioner has just been assigned to address an...
Question 27: Which of the following threats would be MOST likely mitigate...
Question 28: Which of the following would be the FJB^T step to take when ...
Question 29: Which area of embedded devices are most commonly attacked?...
Question 30: In Federated Identity Management (FIM), which of the followi...
Question 31: One of Canada's leading pharmaceutical firms recently hired ...
Question 32: Which of the following is the BEST reason for writing an inf...
Question 33: A manager identified two conflicting sensitive user function...
Question 34: In the Open System Interconnection (OSI) reference model, wh...
Question 35: An information security consultant is asked to make recommen...
Question 36: Which of the following technologies would provide the BEST a...
Question 37: Which of the following would be the BEST mitigation practice...
Question 38: Continuity of operations is BEST supported by which of the f...
Question 39: In which of the following phases in the change management pr...
Question 40: What protocol is often used between gateway hosts on the Int...
Question 41: The existence of physical barriers, card and personal identi...
Question 42: What is the benefit of using Network Admission Control (NAC)...
Question 43: Which of the following is an essential element of a cloud se...
Question 44: Which of the following should be completed FIRST when securi...
Question 45: Which of the following is a valid routable Transmission Cont...
Question 46: Which of the following is a second optional use of Network A...
Question 47: Which of the following is a benefit in implementing an enter...
Question 48: Which of the following sets of controls should allow an inve...
Question 49: Write Once, Read Many (WORM) data storage devices are design...
Question 50: A Denial of Service (DoS) attack on a syslog server exploits...
Question 51: Which of the following describes the BEST configuration mana...
Question 52: Dumpster diving is a technique used in which stage of penetr...
Question 53: A cloud hosting provider would like to provide a Service Org...
Question 54: Why is Plan of Action and Milestones (PA&amp;M) created when...
Question 55: Which of the following events prompts a review of the disast...
Question 56: Which of the following is the PRIMARY benefit of a formalize...
Question 57: An organization plans to acquire @ commercial off-the-shelf ...
Question 58: What is the MOST important element when considering the effe...
Question 59: Which of the following terms is used to describe original, u...
Question 60: Which of the following types of web-based attack is happenin...
Question 61: Before allowing a web application into the production enviro...
Question 62: Which of the following problems is not addressed by using Op...
Question 63: Which of the following BEST mitigates a replay attack agains...
Question 64: A financial organization that works according to agile princ...
Question 65: Which of the following phases involves researching a target'...
Question 66: Which of the following encryption technologies is based on t...
Question 67: Which of the following protects personally identifiable info...
Question 68: A web developer is completing a new web application security...
Question 69: What is the FIRST step that should be considered in a Data L...
Question 70: Which of the following MUST the administrator of a security ...
Question 71: Which of the following is an initial consideration when deve...
Question 72: Security issues with shared push-button combination lock dev...
Question 73: What should be the FIRST action for a security administrator...
Question 74: What High Availability (HA) option of database allow multipl...
Question 75: A security architect is developing an information system for...
Question 76: Which of the following features is MOST effective in mitigat...
Question 77: Which of the following is a source to consider when assessin...
Question 78: Along with detection, which of the following security strate...
Question 79: When implementing a data classification program, why is it i...
Question 80: Which series of activities should an organization perform to...
Question 81: An organization is found lacking the ability to properly est...
Question 82: A hospital has three data classification levels: shareable w...
Question 83: As a security manger which of the following is the MOST effe...
Question 84: Before implementing an internet-facing router, a network adm...
Question 85: Which Radio Frequency Interference (RFI) phenomenon associat...
Question 86: Which of the following is a MUST for creating a new custom-b...
Question 87: Which of the following attacks is dependent upon the comprom...
Question 88: Which of the following is the PRIMARY security interest of t...
Question 89: An organization needs to evaluate the effectiveness of secur...
Question 90: What is the MAIN reason to ensure the appropriate retention ...
Question 91: Which of the following techniques is known to be effective i...
Question 92: An organization wants to enable uses to authenticate across ...
Question 93: Drag and Drop Question Drag the following Security Engineeri...
Question 94: Which of the following types of physical security testing do...
Question 95: Which of the following is the MOST important goal of informa...
Question 96: A software developer installs a game on their organization-p...
Question 97: Which of the following is recommended to establish repeatabl...
Question 98: A company wants to buy a Commercial ff-The-Shelf (CTS) appli...
Question 99: An advantage of link encryption in a communications network ...
Question 100: Who is responsible for classifying assists in an organizatio...
Question 101: An organization implements supply chain risk management (SCR...
Question 102: How does Encapsulating Security Payload (ESP) in transport m...
Question 103: Which of the following is the weakest form of protection for...
Question 104: Which is the RECOMMENDED configuration mode for sensors for ...
Question 105: What is the PRIMARY advantage of using automated application...
Question 106: Which of the following represents and ethics concern when us...
Question 107: Information security practitioners are in the midst of imple...
Question 108: Why would a system be structured to isolate different classe...
Question 109: A chemical plan wants to upgrade the Industrial Control Syst...
Question 110: What is considered the BEST when determining whether to prov...
Question 111: If virus infection is suspected, which of the following is t...
Question 112: Which is the PRIMARY mechanism for providing the workforce w...
Question 113: During a routine audit of network logs, the security adminis...
Question 114: Which of the following options is the best to provide remote...
Question 115: Which of the following is critical if an employee is dismiss...
Question 116: When selecting a disk encryption technology, which of the fo...
Question 117: Which access control method is based on users issuing access...
Question 118: Drag and Drop Question Match the types of e-authentication t...
Question 119: Which of the following addresses requirements of security as...
Question 120: What should be the FIRST action to protect the chain of evid...
Question 121: Which of the following should be done at a disaster site bef...
Question 122: Which of the following is the BEST method for authenticating...
Question 123: Which one of the following documentation should be included ...
Question 124: Which of the following threats exists with an implementation...
Question 125: A user has infected a computer with malware by connecting a ...
Question 126: A large manufacturing organization arranges to buy an indust...
Question 127: Which of the following was developed to support multiple pro...
Question 128: In the common criteria, which of the following is a formal d...
Question 129: A control to protect from the Denial-of-Service (DOS) attack...
Question 130: An organization is formulating a strategy to provide access ...
Question 131: An organization has implemented a new backup process which p...
Question 132: In an IDEAL encryption system, who has sole access to the de...
Question 133: Which of the following resources is the BEST reference for w...
Question 134: For network based evidence, which of the following contains ...
Question 135: Who is primarily responsible to review analyzed reports resu...
Question 136: Which of the following is the PRIMARY reason for selecting t...
Question 137: Which of the following is part of a Trusted Platform Module ...
Question 138: What set of documents would aid in planning, performance and...
Question 139: Which of the following entails identification of data and li...
Question 140: Which of the following advantages does Secure Sockets Layer ...
Question 141: Why is authentication by ownership stronger than authenticat...
Question 142: A company is attempting to enhance the security of its user ...
Question 143: Digital non-repudiation requires which of the following?...
Question 144: What should be the FIRST action for a security administrator...
Question 145: An organization is planning to establish a connection to a t...
Question 146: When transmitting data over Unshielded Twisted Pair (UTP)cab...
Question 147: When developing an organization's security policy, which of ...
Question 148: A criminal organization is planning an attack on a governmen...
Question 149: Which of the following is the BEST network defense against u...
Question 150: What is the MAIN purpose of a bastion host?...
Question 151: An organization is developing employee training content to i...
Question 152: In a disaster recovery (DR) test, which of the following wou...
Question 153: Individual access to a network is BEST determined based on...
Question 154: A financial company has decided to move its main business ap...
Question 155: What is the difference between media marking and media label...
Question 156: A large corporation is looking for a solution to automate ac...
Question 157: In which process MUST security be considered during the acqu...
Question 158: Extensible Authentication Protocol-Message Digest 5 (EAP-MD5...
Question 159: If a content management system (CMC) is implemented, which o...
Question 160: An organization discovers that its secure file transfer prot...
Question 161: An organization suspects it is receiving spoofed e-mails fro...
Question 162: An information security consultant has been tasked with sele...
Question 163: Drag and Drop Question Match the functional roles in an exte...
Question 164: Which of the (ISC) Code of Ethics canons is MOST reflected w...
Question 165: What is the BEST approach to addressing security issues in l...
Question 166: A user downloads a file from the Internet, then applies the ...
Question 167: the MOST significant impact of compliance failure in a comme...
Question 168: Which of the following is the reason that transposition ciph...
Question 169: A Chief Information Security Officer (CISO) of a firm which ...
Question 170: Which of the following BEST describes botnets?...
Question 171: Which security service is served by the process of encryptio...
Question 172: A large organization's human resources and security teams ar...
Question 173: employee training, risk management, and data handling proced...
Question 174: Which of the following poses the GREATEST privacy risk to pe...
Question 175: Which one of the following is an advantage of an effective r...
Question 176: A director within the organization has told an employee abou...
Question 177: When partnering with a third-party, it is the responsibility...
Question 178: Which type of log collection is focused on detecting and res...
Question 179: Which of the following is the MAIN benefit of off-site stora...
Question 180: Which of the following is strategy of grouping requirements ...
Question 181: Which of the following is the BEST definition of Cross-Site ...
Question 182: What is the Best approach for maintaining ethics when a secu...
Question 183: Review of which of the following would be MOST preferred in ...
Question 184: Two computers, each with a single connection on the same phy...
Question 185: Due to system constraints, a group of system administrators ...
Question 186: Which of the following is a PRIMARY benefit of using a forma...
Question 187: What are the steps of a risk assessment?...
Question 188: Which is MOST important when negotiating an Internet service...
Question 189: When configuring Extensible Authentication Protocol (EAP) in...
Question 190: Why is lexical obfuscation in software development discourag...
Question 191: Organization A is adding a large collection of confidential ...
Question 192: Which of the following provides for the STRONGEST protection...
Question 193: Which of the following goals represents a modern shift in ri...
Question 194: How is the session key used to encrypt a Secure Multipurpose...
Question 195: What should an auditor do when conducting a periodic audit o...
Question 196: Which technique helps system designers consider potential se...
Question 197: A retail company is looking to start a development project t...
Question 198: What information will BEST assist security and financial ana...
Question 199: What is the MOST efficient way to verify the integrity of da...
Question 200: Why are mobile devices something difficult to investigate in...
Question 201: An organization is establishing a privacy program to ensure ...
Question 202: A Chief Information Officer (CIO) has delegated responsibili...
Question 203: In order to provide dual assurance in a digital signature sy...
Question 204: The security team plans on using automated account reconcili...
Question 205: Which of the following is the FIRST step in the incident res...
Question 206: Which of the following is the BEST way to protect against St...
Question 207: An organization has discovered that users are visiting unaut...
Question 208: Which of the following is primarily responsible for deciding...
Question 209: XYZ Textiles has just acquired a smaller competitor, AcmeTex...
Question 210: Which of the following is the MOST likely reason a Human Res...
Question 211: Mandatory Access Controls (MAC) are based on:...
Question 212: A security professional recommends that a company integrate ...
Question 213: Which of the following is a credible source to validate that...
Question 214: An information security professional is performing an intern...
Question 215: What is the FIRST step required in establishing a records re...
Question 216: A security professional was tasked with rebuilding a company...
Question 217: A security professional should consider the protection of wh...
Question 218: An organization plan on purchasing a custom software product...
Question 219: Digital certificates used transport Layer security (TLS) sup...
Question 220: Which of the following should be included in a good defense-...
Question 221: Which of the following would BEST describe the role directly...
Question 222: Which inherent password weakness does a One Time Password (O...
Question 223: Which of the following factors should be considered characte...
Question 224: Which of the following protocols transmits User IDs and pass...
Question 225: Which of the following mandates the amount and complexity of...
Question 226: Which of the following is a benefit of implementing data-in-...
Question 227: What secure coding practice is used, in conjunction with oth...
Question 228: Which of the following benefits does Role Based Access Contr...
Question 229: What is the BEST defense against an unauthorized sniffer on ...
Question 230: Which role is primarily responsible for reviewing an analyze...
Question 231: Which application type is considered high risk and provides ...
Question 232: What is the PRIMARY purpose of the identification phase of t...
Question 233: When reviewing the security logs, the password shown for an ...
Question 234: Which of the following is the MOST significant key managemen...
Question 235: Which of the following is the BEST security practice for dat...
Question 236: Which of the following is a common measure within a Local Ar...
Question 237: Which of the following is the primary security consideration...
Question 238: Which of the following is the MOST appropriate action when r...
Question 239: Which of the following are effective countermeasures against...
Question 240: The Chief Information Security Officer (CISO) has requested ...
Question 241: A network security engineer needs to ensure that a security ...
Question 242: What is the PRIMARY responsibility of a data owner?...
Question 243: Which of the following BEST describes a virtual circuit wher...
Question 244: Which of the following does the security design process ensu...
Question 245: An organization recently suffered from a web-application att...
Question 246: While reviewing the financial reporting risks of a third-par...
Question 247: A security professional determines that a number of outsourc...
Question 248: A software engineer uses automated tools to review applicati...
Question 249: The European Union (EU) General Data Protection Regulation (...
Question 250: How does a Host Based Intrusion Detection System (HIDS) iden...
Question 251: Which of the following Disaster recovery (DR) testing proces...
Question 252: An organization has requested storage area network (SAN) dis...
Question 253: When designing a new Voice over Internet Protocol (VoIP) net...
Question 254: Which of the following is the MOST common cause of system or...
Question 255: Which of the following is a possible advantage of manual vul...
Question 256: A MAJOR security flaw with Voice over Internet Protocol (VoI...
Question 257: Which of the following is the MOST effective way to ensure t...
Question 258: Which of the following is MOST appropriate for protecting co...
Question 259: An information security analyst observed a device on the org...
Question 260: Which of the following is the BEST approach to implement mul...
Question 261: Which of the following is the BEST way to protect an organiz...
Question 262: Network-based logging has which advantage over host-based lo...
Question 263: An employee's home address should be categorized according t...
Question 264: A fiber link connecting two campus networks is broken. Which...
Question 265: Which of the following is an advantage of Secure Shell?...
Question 266: Which of the following reports issued by third party provide...
Question 267: What is the MOST appropriate hierarchy of documents when imp...
Question 268: In an organization where Network Access Control (NAC) has be...
Question 269: What is the document that describes the measures that have b...
Question 270: Which of the following is an attacker MOST likely to target ...
Question 271: Which of the following is the MOST effective way to ensure h...
Question 272: Lack of which of the following options could cause a negativ...
Question 273: Which of the following is the LEAST secure authentication me...
Question 274: Which of the following techniques evaluates the secure desig...
Question 275: Which of the following criteria ensures information is prote...
Question 276: A developer begins employment with an information technology...
Question 277: Which of the following should ALWAYS be included in audit re...
Question 278: Which of the following is MOST important when determining ap...
Question 279: Which of the following is the FIRST control step in provisio...
Question 280: In Identity Management (IdM), when is the verification stage...
Question 281: It is better to use Elliptic Curve Cryptography (ECC) instea...
Question 282: An Internet media company produces and broadcasts highly pop...
Question 283: Point-to-Point Protocol (PPP) was designed to specifically a...
Question 284: For the purpose of classification, which of the following is...
Question 285: Which of the following MOST accurately describes the Securit...
Question 286: Which process presents the greatest security concern while a...
Question 287: Which of the following is the MOST important activity an org...
Question 288: Which Identity and Access Management (IAM) process can be us...
Question 289: Which of the following is the MOST effective countermeasure ...
Question 290: After a breach incident, investigators narrowed the attack t...
Question 291: The Chief Information Security Officer (CISO) of a large fin...
Question 292: Which of the following is the BEST way to verify that patche...
Question 293: Which scenario would be an example of a risk associated with...
Question 294: Once the types of information have been identified, who shou...
Question 295: To comply with industry requirements, a security assessment ...
Question 296: The MAIN purpose of placing a tamper seal on a computer syst...
Question 297: Which of the following authorization standards is built to h...
Question 298: When would an organization review a Business Continuity Mana...
Question 299: Which of the following adds end-to-end security inside a Lay...
Question 300: What is the MAIN purpose of a security assessment plan?...
Question 301: Which step of the Risk Management Framework (RMF) identifies...
Question 302: Which stage in the identity management (IdM) lifecycle const...
Question 303: Which of the following activities are part of the Build and ...
Question 304: Which of the following components of the Content Distributio...
Question 305: Risk based internal audit (RBIA) of an organization must be ...
Question 306: Information pruning reflects which of the following security...
Question 307: Which of the following is a MAJOR consideration in implement...
Question 308: Which of the following would present the highert annualized ...
Question 309: Which of the following is the MOST comprehensive Business Co...
Question 310: Which of the following is considered the PRIMARY security is...
Question 311: Which of the following management process allows ONLY those ...
Question 312: A security professional can BEST mitigate the risk of using ...
Question 313: What is the PRIMARY objective for conducting an internal sec...
Question 314: The design of a security system to prevent potential conflic...
Question 315: A security professional in an enterprise organization is eva...
Question 316: When developing an information security policy, why is it BE...
Question 317: Vulnerability scanners may allow for administrator to assign...
Question 318: Malicious attack on a vital trucking company A security prac...
Question 319: A new internal auditor is tasked with auditing the supply ch...
Question 320: Which of the following BEST describes the practice of utiliz...
Question 321: When network management is outsourced to third parties, whic...
Question 322: Which of the following is the FINAL step when implementing a...
Question 323: Which of the following can a system administrator do to impr...
Question 324: When developing an external facing web-based system, which o...
Question 325: What is the MOST common component of a vulnerability managem...
Question 326: Which technique can be used to make an encryption scheme mor...
Question 327: Which of the following media sanitization techniques is MOST...
Question 328: Which of the fallowing is the FIRST step in a patch manageme...
Question 329: In systems security engineering, what does the security prin...
Question 330: Which of the following uses the destination IP address to fo...
Question 331: Which is the MOST effective countermeasure to prevent electr...
Question 332: What is the MOST effective response to a hacker who has alre...
Question 333: When dealing with shared, privilaged accounts, especially th...
Question 334: Which of the following VPN configurations should be used to ...
Question 335: A company hired an external vendor to perform a penetration ...
Question 336: Which of the following command line tools can be used in the...
Question 337: Within a large organization, what business unit is BEST posi...
Question 338: An attacker has intruded into the source code management sys...
Question 339: Why should Open Wab Application Secuirty Project (OWASP) App...
Question 340: Clothing retailer employees are provisioned with user accoun...
Question 341: Following project initiation, which of the following items r...
Question 342: The initial security categorization should be done early in ...
Question 343: Which of the following reports provides the BEST attestation...
Question 344: What is the BEST way to establish identity over the internet...
Question 345: A Distributed Denial of Service (DDoS) attack was carried ou...
Question 346: Which of the following provides the MOST comprehensive filte...
Question 347: Which of the following value comparisons MOST accurately ref...
Question 348: Why Is It important to have a comprehensive inventory of Inf...
Question 349: Which of the following regulations dictates how data breache...
Question 350: How can an enterprise BEST handle spam?...
Question 351: Which dynamic routing protocol is BEST suited for a disperse...
Question 352: When a flaw in Industrial control (ICS) software is discover...
Question 353: Which of the following methods protects Personally Identifia...
Question 354: What is the PRIMARY consideration when testing industrial co...
Question 355: What is the expected outcome of security awareness in suppor...
Question 356: A distributed Denial of Service (DDoS) attack was carried ou...
Question 357: Which of the following protection is provided when using a V...
Question 358: Which of the following types of information security assessm...
Question 359: Which one of the following can be used to detect an anomaly ...
Question 360: An organization implements a Remote Access Server (RAS). Onc...
Question 361: A company's sales team needs to securely access a database c...
Question 362: An external attacker has compromised an organization's netwo...
Question 363: What is the FIRST action a security professional needs to ta...
Question 364: What Service Organization Controls (SOC) report can be freel...
Question 365: Drag and Drop Question Match the level of evaluation to the ...
Question 366: Which of the following phrases involves researching a target...
Question 367: When collecting a raw dump of physical memory, when should t...
Question 368: Which of the following secure design principles would be rec...
Question 369: Which of the following is the BEST action while reviewing re...
Question 370: What MUST each information owner do when a system contains d...
Question 371: The security architect is designing and implementing an inte...
Question 372: Which of the following MUST be part of a contract to support...
Question 373: In configuration management, what baseline configuration inf...
Question 374: An organization is planning to have an it audit of its as a ...
Question 375: A company's Access Control Policy restricts internal network...
Question 376: Which of the following is an advantage of on-premise Credent...
Question 377: From a security perspective, which of the following is a bes...
Question 378: Which of the following is the PRIMARY concern when using an ...
Question 379: Upon commencement of an audit within an organization, which ...
Question 380: According to the (ISC)? ethics canon "act honorably, honestl...
Question 381: The core component of Role Based Access Control (RBAC) must ...
Question 382: Which of the following is the MOST important part of an awar...
Question 383: What is the GREATEST challenge of an agent based patch manag...
Question 384: A company-wide penetration test result shows customers could...
Question 385: Which of the following is held accountable for the risk to o...
Question 386: In software development, which of the following entities nor...
Question 387: A security practitioner needs to implement a solution to ver...
Question 388: Which of the following is a peer entity authentication metho...
Question 389: Which of the following is the FIRST thing to consider when r...
Question 390: What Is a risk of using commercial off-the-shelf (COTS) prod...
Question 391: What would be the BEST action to take in a situation where c...
Question 392: Which of the following MUST be done before a digital forensi...
Question 393: What steps can be taken to prepare personally identifiable i...
Question 394: An internal audit for an organization recently identified ma...
Question 395: Wireless users are reporting intermittent Internet connectiv...
Question 396: Which of the following is an essential requirement of a faul...
Question 397: A project manager for a large software firm has acquired a g...
Question 398: Which type of access control includes a system that allows o...
Question 399: A cloud service provider requires its customer organizations...
Question 400: Which of the following is an advantage of' Secure Shell (SSH...
Question 401: When conduting a security assessment of access controls , Wh...
Question 402: When reviewing vendor certifications for handling and proces...
Question 403: Which of the following vulnerabilities can be BEST detected ...
Question 404: How is supply chain risk determined?...
Question 405: Who is the BEST person to review developed application code ...
Question 406: Which of the following is a peor entity authentication metho...
Question 407: Which of the following is FIRST defined in a company's data ...
Question 408: Utilizing a public wireless Local Area network (WLAN) to con...
Question 409: In a change-controlled environment, which of the following i...
Question 410: What is the BEST way to prevent an encrypted hard drive from...
Question 411: What is the most effective form of media sanitization to ens...
Question 412: Which of the following presents the PRIMARY concern to an or...
Question 413: Which of the following is an important requirement when desi...
Question 414: It is MOST important to perform which of the following to mi...
Question 415: In which of the following programs is it MOST important to i...
Question 416: If the wide area network (WAN) is supporting converged appli...
Question 417: A patch for a third-party software product has been released...
Question 418: While classifying credit card data related to Payment Card I...
Question 419: A user's credential for an application is stored in a relati...
Question 420: An information technology (IT) employee who travels frequent...
Question 421: For cellular networks, how does a rogue base station take ad...
Question 422: Why is it important for a security officer to report directl...
Question 423: Which of the following describes total evacuation time?...
Question 424: When assessing the audit capability of an application, which...
Question 425: During a recent assessment an organization has discovered th...
Question 426: A breach investigation found a website was exploited through...
Question 427: What type of investigation applies when malicious behavior i...
Question 428: An employee receives a promotion that entities them to acces...
Question 429: A large organization is conducting an internal audit of tech...
Question 430: During a disruptive event, which security continuity objecti...
Question 431: Two remote offices need to be connected securely over an unt...
Question 432: Which of the following tenets of information security is MOS...
Question 433: An international trading organization that holds an Internat...
Question 434: A malicious user gains access to unprotected directories on ...
Question 435: The Security Content Automation Protocol (SCAP) framework us...
Question 436: Which (ISC)2 Code of Ethics canon requires members to tell t...
Question 437: What is the BEST method to use for assessing the security im...
Question 438: What is the MAIN reason for testing a Disaster Recovery Plan...
Question 439: An organization publishes and periodically updates its emplo...
Question 440: Which of the following BEST represents a defense in depth co...
Question 441: What is the PRIMARY reason that a bit-level copy is more des...
Question 442: Which of the following is the FIRST requirement a data owner...
Question 443: Which type of test suite should be run for fast feedback dur...
Question 444: Which factors MUST be considered when classifying informatio...
Question 445: Which of the following are important criteria when designing...
Question 446: The ability to send malicious code, generally in the form of...
Question 447: When auditing the Software Development Life Cycle (SDLC) whi...
Question 448: Which of the following is a direct monetary cost of a securi...
Question 449: An organization is implementing a bring your own device (BYO...
Question 450: Which of the following is an example of a vulnerability of f...
Question 451: Which of the following is the PRIMARY issue when analyzing d...
Question 452: Which of the following principles is intended to produce inf...
Question 453: For the detection of internet of things (loT) devices, a pro...
Question 454: Additional padding may be added to toe Encapsulating Securit...
Question 455: What capability would typically be included in a commerciall...
Question 456: What are the roles within a scrum methodology?...
Question 457: If a security requirement for a given system states that una...
Question 458: During a Disaster Recovery (DR) simulation, it is discovered...
Question 459: What is the PRIMARY benefit of relying on Security Content A...
Question 460: A thorough review of an organization's audit logs finds that...
Question 461: An organization discovers a significant amount of confidenti...
Question 462: Organizational leadership wants to move away from compliance...
Question 463: Which of the following is a characteristic of convert securi...
Question 464: An information security administrator wishes to block peer-t...
Question 465: An application is used for funds transfer between an organiz...
Question 466: Which of the following is the MOST challenging issue in appr...
Question 467: Which of the following methods provides the MOST protection ...
Question 468: Which one of the following requires the system to manage acc...
Question 469: A security analyst for a large financial institution is revi...
Question 470: Mapping out all functionality and features to their associat...
Question 471: Which of the following is MOST important to follow when deve...
Question 472: Which of the following languages supports a modular program ...
Question 473: Which of the following is the BEST method to validate secure...
Question 474: Which is the MOST important consideration for a policy safeg...
Question 475: Assuming an individual has taken all of the steps to keep th...
Question 476: From a cryptographic perspective, the service of non-repudia...
Question 477: Which of the following is the MOST important consideration w...
Question 478: An organization's security policy delegates to the data owne...
Question 479: Which of the following is a PIRIMARY security weakness in th...
Question 480: Which of the following is the MOST likely cause of a comprom...
Question 481: Which of the following system components enforces access con...
Question 482: Which of the following can cause a web application to malfun...
Question 483: Which of the following is the MOST effective measure to prev...
Question 484: In Disaster Recovery (DR) and business continuity training, ...
Question 485: Under which circumstances can law enforcement seize physical...
Question 486: Which of the following significantly influences the level of...
Question 487: Personally Identifiable Information (PIT) is becoming an ext...
Question 488: Which of the following is critical if an empolyee is dismiss...
Question 489: An organization recently conducted a review of the security ...
Question 490: What is an advantage of using a third-party Identity Provide...
Question 491: Which of the following is a recommended method to control re...
Question 492: During an internal audit of an organizational Information Se...
Question 493: What is the MOST effective method to enhance security of a s...
Question 494: To ensure proper governance of information throughout the li...
Question 495: Concerning appropriate data retention policies, which of the...
Question 496: Which of the following is a strong security protection provi...
Question 497: Which of the following mobile code security models relies on...
Question 498: An Information Technology [IT) manager has learned that vend...
Question 499: A cybersecurity engineer has been tasked to research and imp...
Question 500: Which of the following entities is ultimately accountable fo...
Question 501: What is the BE ST method to ensure the integrity of physical...
Question 502: Which is the BEST control to meet the Statement on Standards...
Question 503: Who should perform the design review to uncover security des...
Question 504: Who in the organization is accountable for classification of...
Question 505: Which of the following is the MOST common use of the Online ...
Question 506: Assessing a third party's risk by counting bugs in the code ...
Question 507: A digitally-signed e-mail was delivered over a wireless netw...
Question 508: Knowing the language in which an encrypted message was origi...
Question 509: Which of the following is of GREATEST assistance to auditors...
Question 510: What process facilitates the balance of operational and econ...
Question 511: An organization is considering partnering with a third-party...
Question 512: Which of the following BEST represents the concept of least ...
Question 513: A group of organizations follows the same access standards a...
Question 514: Which of the following actions will reduce risk to a laptop ...
Question 515: Which of the following purging methods will allow the full d...
Question 516: Which of the following would be the BEST guideline to follow...
Question 517: Which of the following measures is the MOST critical in orde...
Question 518: Which of the following is a common feature of an Identity as...
Question 519: Why might a network administrator choose distributed virtual...
Question 520: When conducting software development, what is the BEST secur...
Question 521: When accepting new software purchases, which of the followin...
Question 522: Which of the following ensures old log data is not overwritt...
Question 523: Which of the following is the BEST identity-as-a-service (ID...
Question 524: During a Disaster Recovery (DR) assessment, additional cover...
Question 525: What requirement MUST be met during internal security audits...
Question 526: What are the roles within a scrum methodoligy?...
Question 527: Which of the following initiates the system recovery phase o...
Question 528: An organization discovers that its Secure File Transfer Prot...
Question 529: Which of the following could be considered the MOST signific...
Question 530: Which of the following is the greatest weakness with attacke...
Question 531: An attacker has recreated a process on a local machine. This...
Question 532: Which of the following is MOST important when deploying digi...
Question 533: Which of the following is MOST effective in quickly detectin...
Question 534: Which of the following is a best practice in a data handling...
Question 535: Which change management role is responsible for the overall ...
Question 536: Which of the following is the PRIMARY benefit of applying a ...
Question 537: A vulnerability test on an Information System (IS) is conduc...
Question 538: Single sign-on (SSO) for federated identity management (FIM)...
Question 539: Which of the following is required to verify the authenticit...
Question 540: Which of the following types of report would an organization...
Question 541: An information security professional is reviewing user acces...
Question 542: Which is the MOST critical aspect of computer-generated evid...
Question 543: What is the MOST common security risk of a mobile device?...
Question 544: Which of the following attributes could be used to describe ...
Question 545: What is the MOST effective way to protect privacy?...
Question 546: An organization wants to ensure that employees that move to ...
Question 547: A client has reviewed a vulnerability assessment report and ...
Question 548: Which algorithm supports Advanced Encryption Standard (AES)?...
Question 549: Which of the following is a security feature of Global Syste...
Question 550: Drag and Drop Question Match the name of access control mode...
Question 551: Which of the following BEST describles a protection profile ...
Question 552: Identity and Access Management (IAM) tools support the use o...
Question 553: In order to provide dual assurance in a digital signature sy...
Question 554: An organization contracts with a consultant to perform a Sys...
Question 555: Which of the following is the key requirement for test resul...
Question 556: What is the purpose of code signing?...
Question 557: Which of the following addresses requirements of security as...
Question 558: Which of the following is the MOST effective method of mitig...
Question 559: Which of the following activities is MOST likely to be perfo...
Question 560: In general, servers that are facing the Internet should be p...
Question 561: A Chief Information Security Officer (CISO) is considering v...
Question 562: Which of the following job functions MUST be separated to ma...
Question 563: The Chief Information Security Officer (CISO) of an organiza...
Question 564: Which of the following are core categories of malicious atta...
Question 565: Which of the following is the BEST technique to facilitate s...
Question 566: Which of the following phases in the software acquisition pr...
Question 567: Which part of an operating system (OS) is responsible for pr...
Question 568: Which of the following is the PRIMARY benefit of implementin...
Question 569: Which of the following is an accurate statement when an asse...
Question 570: As part of the security assessment plan, the security profes...
Question 571: Which of the following is true of Service Organization Contr...
Question 572: A project requires the use of an authentication mechanism wh...
Question 573: To monitor the security of buried data lines inside the peri...
Question 574: When MUST an organization's information security strategic p...
Question 575: Which of the following is PRIMARILY adopted for ensuring the...
Question 576: Which of the following is the MAIN difference between a netw...
Question 577: Which of the following is the MOST important consideration i...
Question 578: A goal of the information security policy is to...
Question 579: The adoption of an enterprise-wide business continuilty prog...
Question 580: Which of the following is a unique feature of Attribute Base...
Question 581: An organization adopts a new firewall hardening standard. Ho...
Question 582: Which of the following is the BEST evidence of an organizati...
Question 583: Which of the following provides the MOST secure method for N...
Question 584: Which of the following is applicable to a publicly held comp...
Question 585: What does the Maximum Tolerable Downtime (MTD) determine?...
Question 586: Which of the following is required to determine classificati...
Question 587: Email credentials were stolen when a user clicked on a link ...
Question 588: Which of the following is a common characteristic of privacy...
Question 589: A cloud service accepts Security Assertion Markup Language (...
Question 590: When can Authorizing Officials (AO) authorize a system to op...
Question 591: How is Remote Authentication Dial-In User Service (RADIUS) a...
Question 592: Using Remote Authentication Dial User Service (RADIUS) retur...
Question 593: During the Security Assessment and Authorization process, wh...
Question 594: Which of the following should exist in order to perform a se...
Question 595: Which of the following steps should be performed FIRST when ...
Question 596: Which of the following mechanisms are PRIMARILY used to safe...
Question 597: An enterprise is developing a baseline cybersecurity standar...
Question 598: Which of the following types of data would be MOST difficult...
Question 599: An organization implements Network Access Control (NAC) ay I...
Question 600: What approach in embedded systems communication allows both ...
Question 601: Information Security continuous Monitoring (ISCM) is a criti...
Question 602: During the procurement of a new information system, it was d...
Question 603: The security team has been tasked with performing an interfa...
Question 604: An organization is awarded a software engineering institute ...
Question 605: Which of the following are key activities when conducting a ...
Question 606: Prohibiting which of the following techniques is MOST helpfu...
Question 607: Passive Infrared Sensors (PIR) used in a non-climate control...
Question 608: Physical Access Control Systems (PACS) allow authorized secu...
Question 609: Which of the following is the last-mile reliability of plain...
Question 610: Which of the following is the MOST important rule for digita...
Question 611: Which access control method allows an entity to make certain...
Question 612: Which of the following is the PRIMARY consideration when det...
Question 613: An organization allows ping traffic into and out of their ne...
Question 614: A Virtual Machine (VM) environment has five guest Operating ...
Question 615: A security engineer is designing a Customer Relationship Man...
Question 616: Which of the following describes the order in which a digita...
Question 617: Exploitation of knowledge regarding the response time for a ...
Question 618: Which of the following is the PRIMARY reason Android devices...
Question 619: Which of the following security tools monitors devices and r...
Question 620: Which of the following encryption types is used in Hash Mess...
Question 621: Which of the following is BEST used for large groups of geog...
Question 622: Which of the following is of GREATEST value to an organizati...
Question 623: An organization's internal audit team performed a security a...
Question 624: Which of the following is most helpful in applying the princ...
Question 625: An organization is considering outsourcing applications and ...
Question 626: Wi-Fi Protected Access 2 (WPA2) is a security protocol desig...
Question 627: What is the MOST important factor in establishing an effecti...
Question 628: Which of the following is performed to determine a measure o...
Question 629: An organization has developed a way for customers to share i...
Question 630: A security engineer is assigned to work with the patch and v...
Question 631: During a penetration test, an assessor has difficulty findin...
Question 632: What is the FIRST step in risk management?...
Question 633: How many phases are contained in Internet Key Exchange (IKE)...
Question 634: Which of the following statements is true regarding value bo...
Question 635: Which of the following types of business continuity tests in...
Question 636: A subscription service which provides power, climate control...
Question 637: How can a security engineer maintain network separation from...
Question 638: In order for application developers to detect potential vuln...
Question 639: Which of the following is the MOST appropriate control for a...
Question 640: A Certified Information Systems Security Professional (CISSP...
Question 641: Where does Multiprotocol Label Switching (MPLS) fit in the p...
Question 642: An organization has received an initial draft of a security ...
Question 643: Which of the following is a best implementation practice rel...
Question 644: A company wants to implement two-factor authentication (2FA)...
Question 645: What type of sprinkler system employs smoke or heat detectio...
Question 646: During examination of internet history records, the followin...
Question 647: Which of the following is a security weakness in the evaluat...
Question 648: Which of the following is the FIRST step in data classificat...
Question 649: An organization is required to comply with a new privacy reg...
Question 650: A Simple Power Analysis (SPA) attack against a device direct...
Question 651: In regard to multimedia files, which Digital Rights Manageme...
Question 652: When participating in a forensic investigation, who should b...
Question 653: An organization needs to implement media encryption for a la...
Question 654: What is a common reason for implementing fine-grained segmen...
Question 655: An organization is the victim of a major data breach just on...
Question 656: Which of the following metrics are considered when evaluatin...
Question 657: Which of the following is a weakness of Wired Equivalent Pri...
Question 658: Which would result in the GREATEST import following a breach...
Question 659: Backup information that is critical to the organization is i...
Question 660: What is the BEST approach for controlling access to highly s...
Question 661: A recent information security risk assessment identified wea...
Question 662: An input validation and exception handling vulnerability has...
Question 663: For a federated identity solution, a third-party Identity Pr...
Question 664: Which of the following is the MOST likely attack on a hijack...
Question 665: Which of the following is a process in the access provisioni...
Question 666: Functional security testing is MOST critical during which ph...
Question 667: Which of the following processes is BEST used to determine t...
Question 668: An engineer notices some late collisions on a half-duplex li...
Question 669: Which of the following attacks describes the intent behind t...
Question 670: When is a Business Continuity Plan (BCP) considered to be va...
Question 671: Which mechanism provides the BEST protection against buffer ...
Question 672: An effective information security strategy is PRIMARILY base...
Question 673: Physical assets defined in an organization's Business Impact...
Question 674: The development team has been tasked with collecting data fr...
Question 675: Which component of the Security Content Automation Protocol ...
Question 676: Where can the Open Web Application Security Project (OWASP) ...
Question 677: What documentation is produced FIRST when performing an effe...
Question 678: Which of the following is an indicator that a company's new ...
Question 679: In which identity management process is the subject's identi...
Question 680: Which of the following types of datacenter architectures wil...
Question 681: Which of the following mechanisms will BEST prevent a Cross-...
Question 682: Which of the following is the PRIMARY purpose of routinely t...
Question 683: A security team member was selected as a member of a Change ...
Question 684: Which of the following is the MOST important first step in p...
Question 685: An application developer is developing a web application tha...
Question 686: Which of the following is the PRIMARY type of cryptography r...
Question 687: When investigating a possible cybercrime, which of the follo...
Question 688: How is protection for hypervisor host and software administr...
Question 689: Which of the following media is LEAST problematic with data ...
Question 690: Why is the principle of least privilege important?...
Question 691: The Chief Information Security Officer (CISO) is to establis...
Question 692: When developing an organization's information security budge...
Question 693: From a security perspective, which of the following are the ...
Question 694: A security engineer is tasked with implementing a new identi...
Question 695: A system developer has a requirement for an application to c...
Question 696: A network administrator is configuring a database server and...
Question 697: When a system changes significantly, who is PRIMARILY respon...
Question 698: When developing solutions for mobile devices, in which phase...
Question 699: A hospital enforces the Code of Fair Information Practices. ...
Question 700: Which concept might require users to use a second access tok...
Question 701: Which of the following statements BEST distinguishes a state...
Question 702: Which of the following has the responsibility of information...
Question 703: A company needs to provide employee access to travel service...
Question 704: At the destination host, which of the following OSI model la...
Question 705: As users switch roles within an organization, their accounts...
Question 706: Which of the following is included in change management?...
Question 707: A minimal implementation of endpoint security includes which...
Question 708: How is it possible to extract private keys securely stored o...
Question 709: The four basic principles of Kerberos are?...
Question 710: Which of the following models uses unique groups contained i...
Question 711: What does the result of Cost-Benefit Analysis (C8A) on new s...
Question 712: An organization decides to evaluate the security of a system...
Question 713: What is the MAIN objective of risk analysis in Disaster Reco...
Question 714: An Internet software application requires authentication bef...
Question 715: A new Chief Information Officer (CIO) created a group to wri...
Question 716: Which of the following is the MOST secure protocol for zremo...
Question 717: Which of the following is a term used to describe maintainin...
Question 718: Which of the following in the BEST way to reduce the impect ...
Question 719: When using Generic Routing Encapsulation (GRE) tunneling ove...
Question 720: Which function does 802.1X provide?...
Question 721: Which of the following open source software issues pose the ...
Question 722: Digital certificates used in Transport Layer Security (TLS) ...
Question 723: Who should formulate conclusions from a particular digital f...
Question 724: Which of the following controls would be the BEST recommenda...
Question 725: In a large company, a system administrator needs to assign u...
Question 726: Which of the following attacks can be leveraged only against...
Question 727: Although code using a specific program language may not be s...
Question 728: How should the retention period for an organization's social...
Question 729: Which of the following protocols will allow the encrypted tr...
Question 730: Which of the following is a responsibility of a data steward...
Question 731: Which of the following system security measures is required ...
Question 732: Which of the following is an important design feature for th...