•Question 1
4 out of 4 points
A good security awareness program makes employees aware of the behaviors
expected of them. All security awareness programs have two enforcement
components, the carrot and the stick. Which of the following best captures the
relationship of the two components?
Selected
Answer:
The carrot aims to educate the employee about the importance of
security policies, and the stick reminds the employees of the
consequences of not following policy.
Answers:
The carrot reminds the employees of the consequences of not
following policy, and the stick
aims to educate the employee about the importance of security
policies.
The carrot reminds employees that it is up to them whether to follow
security policies, and the stick provides positive reinforcement for
following policies.
The carrot aims to educate the employee about the importance of
security policies, and the stick reminds the employees of the
consequences of not following policy.
The carrot reminds employees exactly what the security policies
are, and the stick provides the reward for remembering those
policies.
•Question 2
4 out of 4 points
There are many distinct benefits to control measurement. Which of the following
benefits is the result of determining which security controls to measure?
Selected Answer:
defines the scope of the compliance being measured
Answers:
defines the effectiveness of the controls being measured
defines the scope of the compliance being measured
defines the impact to the business if the goals are not achieved
defines how the policy will be enforced
•Question 3
4 out of 4 points
____________ is a widely accepted international best practices framework for
implementing information systems security.
Selected
Answer:
Control Objectives for Information and related Technology
(COBIT)
Answers:
Information Systems Audit and Control Association (ISACA)
Control Objectives for Information and related Technology
(COBIT)
Business as Usual (BAU)
Business process reengineering (BPR)
•Question 4
4 out of 4 points
There are many barriers to policy acceptance and enforcement. Which of the
following is not one the challenges to policy acceptance?
Selected Answer:
disciplinary action for employees who fail to accept policies
Answers:
organizational support at all levels
giving employees a stake
policy awareness and understanding
disciplinary action for employees who fail to accept policies
•Question 5
4 out of 4 points
Although it is impossible to eliminate all business risks, a good policy can
reduce the likelihood of risk occurring or reduce its impact. A business must find
a way to balance a number of competing drivers. Which of the following
is not one of these drivers?
Selected Answer:
regulation
Answers:
cost
customer satisfaction
compliance
regulation
•Question 6
4 out of 4 points
When writing a ____________________ one could state how often a supplier
will provide a service or how quickly a firm will respond. For managed services,
this document often covers system availability and acceptable performance
measures.
Selected Answer:
service level agreement
Answers:
contract
policy
service level agreement
standard
•Question 7
4 out of 4 points
________________ functions as a preventive control designed to prevent
mistakes from happening. ________________functions as a detective control
intended to improve the quality over time by affording opportunities to learn from
past mistakes.
Selected Answer:
Quality assurance; Quality control
Answers:
Quality control; Quality assurance
Governance; Nonrepudiation
Quality assurance; Quality control
Quality control; Business as usual
•Question 8
4 out of 4 points
A(n) ___________________is a confirmed event that compromises the
confidentiality, integrity, or availability of information.
Selected Answer:
breach
Answers:
breach
residual risk
operational deviation
threat
•Question 9
4 out of 4 points
A security awareness program gains credibility when the business sees a
reduction of risk, and there are multiple benefits that come with a security
awareness program that emphasizes the business risk. Which of the following
is not one of the benefits?
Selected Answer:
relevance
Answers:
value
culture
resiliency
relevance
•Question 10
4 out of 4 points
Once an organization clearly defines its IP, the security policies should specify
how to ___________ documents with marks or comments, and ____________
the data, which determines in what location the sensitive file should be placed.
Selected Answer:
label, classify
Answers:
label, classify
restrict, filter
label, filter
classify, restrict.
•Question 11
4 out of 4 points
_______________are owned by an organization if they are created on the
computer by company employees or if the assets were custom developed for
and purchased by the organization.
Selected Answer:
Digital Assets
Answers:
Intellectual properties
Digital Assets
Classified Data
Security controls
•Question 12
4 out of 4 points
Which of the following is not one of the four domains that collectively represent
a conceptual information systems security management life cycle?
Selected Answer:
Evaluate, Assess, and Perform
Answers:
Align, Plan, and Organize
Build, Acquire, and Implement
Deliver, Service, and Support
Evaluate, Assess, and Perform
•Question 13
4 out of 4 points
The key to security policy is being able to measure compliance against a set of
controls. Security controls define _____ ______you protect the information. The
security policies should define ___________you set the goal.
Selected Answer:
how, why
Answers:
how, why
why, how
whether, if
where, when
•Question 14
4 out of 4 points
Generally, regardless of threat or vulnerability, there will ____________ be a
chance a threat can exploit a vulnerability.
Selected Answer:
always
Answers:
never
occasionally
always
seldom
•Question 15
4 out of 4 points
As employees find new ways to improve a system or process, it is important to
have a way to capture their ideas. ________________________ can be
understood as finding a better way or as a lesson learned.
Selected Answer:
Continuous improvement
Answers:
Business process reengineering
Continuous improvement
Policy implementation
Change management
•Question 16
4 out of 4 points
Which of the following situations best illustrates the process of authentication?
Selected
Answer:
A website sets users’ passwords to expire every 90 days
Answers:
A website sets users’ passwords to expire every 90 days
Using an electronic signature on official documentation
When an application sets a limit on how on the amount of
payment a user can approve
When a service is made unavailable to a user due to a server
crash
•Question 17
4 out of 4 points
When an organization lacks policies, its operations become less predictable.
Which of the following is a challenge you can expect without policies?
Selected Answer:
customer dissatisfaction
Answers:
lower costs
increased regulatory compliance
customer dissatisfaction
low retention rates for employees
•Question 18
4 out of 4 points
A ____________would be a misconfiguration of a system that allows the hacker
to gain unauthorized access, whereas a______________ is a combination of
the likelihood that such a misconfiguration could happen, a hacker’s exploitation
of it, and the impact if the event occurred.
Selected Answer:
vulnerability, risk
Answers:
vulnerability, risk
risk, vulnerability
threat, risk
risk, threat
•Question 19
4 out of 4 points
___________________________are formal written policies describing
employee behavior when using company computer and network systems.
Selected Answer:
Acceptable use policies
Answers:
Mitigating controls
Nondisclosure agreements
Confidentiality agreements
Acceptable use policies
•Question 20
4 out of 4 points
In the Build, Acquire, and Implement domain, the ability to manage change is
very important. Thus, there are often ___________________set to avoid
disrupting current services while new services are added.
Selected Answer:
upgrades
Answers:
authentications
entitlements
upgrades
guidelines
•Question 21
4 out of 4 points
A security awareness program can be implemented in many ways. Which of the
following is the list of generally accepted principles for implementing a program?
Selected Answer:
repetition, onboarding, support, relevance, metrics
Answers:
value, culture, support, relevance, metrics
repetition, onboarding, support, relevance, metrics
label, classify, restrict, educate, support
repetition, classify, support, relevance, filter
•Question 22
4 out of 4 points
The most senior leader responsible for managing an organization’s risks is the
chief privacy
officer (CPO). Which of the following is not one of the responsibilities of the
CPO?
Selected
Answer:
The CPOs must be a lawyer.
Answers:
The CPO is responsible for keeping up with privacy laws.
The CPO also needs to understand how the laws impact
business.
The CPOs must be a lawyer.
The CPO must work closely with a technology team to create
strong security policies.
•Question 23
4 out of 4 points
The COBIT Align, Plan, and Organize domain includes basic details of an
organization’s requirements and goals; this domain answers which of the
following questions?
Selected Answer:
What do you want to do?
Answers:
What are the areas of vulnerability?
Where is there room to build?
What are the processes for quality assurance?
What do you want to do?
•Question 24
4 out of 4 points
Which of the following security control design types does not prevent incidents
or breaches immediately and relies on a human to decide what action to take?
Selected Answer:
detective control
Answers:
detective control
automated control
corrective control
preventative control
•Question 25
4 out of 4 points
In the ______________ principle adopted by many organizations, you gain
access only to the systems and data you need to perform your job.
Selected Answer:
need to know
Answers:
confidentiality
integrity
don’t ask, don’t tell
need to know
Powered by TCPDF (www.tcpdf.org)