問題1
When dealing with a risk management process, asset classification is important because it will impact the overall:
When dealing with a risk management process, asset classification is important because it will impact the overall:
正確答案: B
問題2
What is the first thing that needs to be completed in order to create a security program for your organization?
What is the first thing that needs to be completed in order to create a security program for your organization?
正確答案: C
問題3
Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?
Which of the following provides an independent assessment of a vendor's internal security controls and overall posture?
正確答案: B
問題4
The regular review of a firewall ruleset is considered a
The regular review of a firewall ruleset is considered a
正確答案: B
問題5
An information security department is required to remediate system vulnerabilities when they are discovered.
Please select the three primary remediation methods that can be used on an affected system.
An information security department is required to remediate system vulnerabilities when they are discovered.
Please select the three primary remediation methods that can be used on an affected system.
正確答案: C
問題6
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?
正確答案: C
問題7
The process for identifying, collecting, and producing digital information in support of legal proceedings is called
The process for identifying, collecting, and producing digital information in support of legal proceedings is called
正確答案: B
問題8
An audit was conducted and many critical applications were found to have no disaster recovery plans in place.
You conduct a Business Impact Analysis (BIA) to determine impact to the company for each application.
What should be the NEXT step?
An audit was conducted and many critical applications were found to have no disaster recovery plans in place.
You conduct a Business Impact Analysis (BIA) to determine impact to the company for each application.
What should be the NEXT step?
正確答案: C
問題9
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
What is the SECOND step to creating a risk management methodology according to the National Institute of Standards and Technology (NIST) SP 800-30 standard?
正確答案: B
問題10
The PRIMARY objective for information security program development should be:
The PRIMARY objective for information security program development should be:
正確答案: C