問題1
A type of assessment method that is characterized by the process of conducting discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or lead to the location of evidence, the results of which are used to support the determination of security control effectiveness over time.
Response:
A type of assessment method that is characterized by the process of conducting discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or lead to the location of evidence, the results of which are used to support the determination of security control effectiveness over time.
Response:
正確答案: D
問題2
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site?
Response:
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site?
Response:
正確答案: B
問題3
An instance of an information type.
Response:
An instance of an information type.
Response:
正確答案: B
問題4
A level of collaboration may be required between security and privacy control assessors with respect to controls that implemented to achieve both security and privacy objectives. Assessor findings must be:
Response:
A level of collaboration may be required between security and privacy control assessors with respect to controls that implemented to achieve both security and privacy objectives. Assessor findings must be:
Response:
正確答案: C
問題5
An analysis of an information system's requirements, functions, and interdependencies used to characterize system contingency requirements and priorities in the event of a significant disruption.
Response:
An analysis of an information system's requirements, functions, and interdependencies used to characterize system contingency requirements and priorities in the event of a significant disruption.
Response:
正確答案: B
問題6
The security controls for an information system that focus on the management of risk and the management of information system security are known as:
Response:
The security controls for an information system that focus on the management of risk and the management of information system security are known as:
Response:
正確答案: A
問題7
The security controls for an information system that primarily are implemented by people (as opposed to systems) are known as Response:
The security controls for an information system that primarily are implemented by people (as opposed to systems) are known as Response:
正確答案: D
問題8
Which if the following is an example of the test assessment method? Response:
Which if the following is an example of the test assessment method? Response:
正確答案: A
問題9
System Authorization is the risk management process. System Authorization Plan (SAP) is a comprehensive and uniform approach to the System Authorization Process. What are the different phases of System Authorization Plan? Each correct answer represents a part of the solution. Choose all that apply.
Response:
System Authorization is the risk management process. System Authorization Plan (SAP) is a comprehensive and uniform approach to the System Authorization Process. What are the different phases of System Authorization Plan? Each correct answer represents a part of the solution. Choose all that apply.
Response:
正確答案: B,C,D,E
問題10
An agreement that allows two organizations to back up each other.
Response:
An agreement that allows two organizations to back up each other.
Response:
正確答案: B
問題11
The Information system owner should strive to test every control at least every ___ years & most critical controls continuously.
Response:
The Information system owner should strive to test every control at least every ___ years & most critical controls continuously.
Response:
正確答案: C