Q: 1
An organization is looking for a framework to measure the efficiency and effectiveness of their
Information Security Management System. Which of the following international standards can BEST
assist this organization?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
The single most important consideration to make when developing your security program, policies,
and processes is:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
When managing the security architecture for your company you must consider:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Effective information security management programs require the active involvement of_________
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Scenario: Your program is developed around minimizing risk to information by focusing on people,
technology, and operations.
An effective way to evaluate the effectiveness of an information security awareness program for end
users, especially senior executives, is to conduct periodic:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
An organization licenses and uses personal information for business operations, and a server
containing that information has been compromised. What kind of law would require notifying the
owner or licensee of this incident?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
An organization's Information Security Policy is of MOST importance because
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
SCENARIO: Critical servers show signs of erratic behavior within your organization’s intranet. Initial
information indicates the systems are under attack from an outside entity. As the Chief Information
Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the
details of this incident and take action according to the information available to the team.
During initial investigation, the team suspects criminal activity but cannot initially prove or disprove
illegal actions. What is the MOST critical aspect of the team’s activities?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
In accordance with best practices and international standards, how often is security awareness
training provided to employees of an organization?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2