Scenario: An organization has made a decision to address Information Security formally and consistently by adopting established best practices and industry standards. The organization is a small retail merchant but it is expected to grow to a global customer base of many millions of customers in just a few years. This global retail company is expected to accept credit card payments. Which of the following is of MOST concern when defining a security program for this organization?
-
A
Adherence to local data breach notification laws
-
B
Compliance to Payment Card Industry (PCI) data security standards
-
C
Compliance with local government privacy laws
-
D
International encryption restrictions
Reveal answer details
Close answer details
Which of the following strategies provides the BEST response to a ransomware attack?
-
A
Real-time off-site replication
-
B
-
C
-
D
Daily differential backup
Reveal answer details
Close answer details
An organization's firewall technology needs replaced. A specific technology has been selected that is less costly than others and lacking in some important capabilities. The security officer has voiced concerns about sensitive data breaches but the decision is made to purchase. What does this selection indicate?
-
A
A high threat environment
-
B
A low vulnerability environment
-
C
A high risk tolerance environment
-
D
A low risk tolerance environment
Reveal answer details
Close answer details
When choosing a risk mitigation method what is the MOST important factor?
-
A
Approval from the board of directors
-
B
Metrics of mitigation method success
-
C
Cost of the mitigation is less than a risk
-
D
Mitigation method complies with PCI regulations
Reveal answer details
Close answer details
When managing the critical path of an IT security project, which of the following is MOST important?
-
A
Knowing all the stakeholders.
-
B
Knowing the milestones and timelines of deliverables.
-
C
Knowing the people on the data center team.
-
D
Knowing the threats to the organization.
Reveal answer details
Close answer details
Which one of the following BEST describes which member of the management team is accountable for the day-to-day operation of the information security program?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Scenario: As you begin to develop the program for your organization, you assess the corporate culture and determine that there is a pervasive opinion that the security program only slows things down and limits the performance of the "real workers." Which group of people should be consulted when developing your security program?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following is a fundamental component of an audit record?
-
A
-
B
Date and time of the event
-
C
-
D
Reveal answer details
Close answer details
When evaluating a Managed Security Services Provider (MSSP), which service(s) is/are most important:
-
A
-
B
-
C
Ability to provide security services tailored to the business' needs
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://digitalguardian.com/blog/how-hire-evaluate-managed-security-service-providers-mssps
Question 10
Single choice
-
A
Quantitative plus qualitative impact
-
B
Asset loss times likelihood of event
-
C
Advisory plus capability plus vulnerability
-
D
Threat times vulnerability divided by control
Reveal answer details
Close answer details
Correct answerB
Explanationrisk = likelihood x impact (or damage incurred by the event. If you put a dollar value on the impact, then you can value the risk and in a simple way compare one risk factor to another)
Question 11
Single choice
How often should the Statements of Standards for Attestation Engagements-16 (SSAE16)/International Standard on Assurance Engagements 3402 (ISAE3402) report of your vendors be reviewed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
The main purpose of the SOC is:
-
A
An organization which provides Tier 1 support for technology issues and provides escalation when needed
-
B
A distributed organization which provides intelligence to governments and private sectors on cyber-criminal activities
-
C
The coordination of personnel, processes and technology to identify information security events and provide timely response and remediation
-
D
A device which consolidates event logs and provides real-time analysis of security alerts generated by applications and network hardware
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.eccouncil.org/what-is-soc/
Question 13
Single choice
Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs. When formulating the remediation plan, what is a required input?
-
A
-
B
Latest virus definitions file
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Human resource planning for security professionals in your organization is a:
-
A
Training requirement that is on-going and always changing.
-
B
Simple and easy task because the threats are getting easier to find and correct.
-
C
Training requirement that is met through once every year user training.
-
D
Not needed because automation and anti-virus software has eliminated the threats.
Reveal answer details
Close answer details
Question 15
Single choice
Which of the following represents the best method of ensuring business unit alignment with security program requirements?
-
A
Create collaborative risk management approaches within the organization
-
B
Perform increased audits of security processes and procedures
-
C
Provide clear communication of security requirements throughout the organization
-
D
Demonstrate executive support with written mandates for security policy adherence
Reveal answer details
Close answer details
Question 16
Single choice
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company's building dressed like an electrician and waits in the lobby for an employee to pass through the main access gate, then the consultant follows the employee behind to get into the restricted area. Which type of attack did the consultant perform?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
SQL injection is a very popular and successful injection attack method. Identify the basic SQL injection text:
-
A
-
B
-
C
-
D
`O 1=1 - -Option D
Reveal answer details
Close answer details
Question 18
Single choice
Which of the following is the MOST important for a CISO to understand when identifying threats?
-
A
How the security operations team will behave to reported incidents
-
B
How vulnerabilities can potentially be exploited in systems that impact the organization
-
C
How the firewall and other security devices are configured to prevent attacks
-
D
How the incident management team prepares to handle an attack
Reveal answer details
Close answer details
Question 19
Single choice
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN. What type of control is being implemented by supervisors and data owners?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
You have been hired as the CISO for a hospital. The hospital currently deploys a hybrid cloud model using a Software as a Service (SaaS) product for healthcare clearinghouse services. The Health Insurance Portability and Accountability Act (HIPAA) require an agreement between Cloud Service Providers (CSP) and the covered entity. Based on HIPAA, once the agreement between the covered entity and the CSP signed, the CSP is ____________?
-
A
Partially liable for compliance with the applicable requirements of the HIPAA Rules
-
B
Directly liable for compliance with the applicable requirements of the HIPAA Rules
-
C
Not liable for compliance with the applicable requirements of the HIPAA Rules
-
D
Indirectly liable for compliance with the applicable requirements of the HIPAA Rules
Reveal answer details
Close answer details
Question 21
Single choice
The BEST organization to provide a comprehensive, independent and certifiable perspective on established security controls in an environment is _______________.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
Which of the following is a benefit of a risk-based approach to audit planning?
-
A
Resources are allocated to the areas of the highest concern
-
B
Scheduling may be performed months in advance
-
C
Budgets are more likely to be met by the IT audit staff
-
D
Staff will be exposed to a variety of technologies
Reveal answer details
Close answer details
Question 23
Single choice
Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
At what level of governance are individual projects monitored and managed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
A newly-hired CISO needs to understand the organization's financial management standards for business units and operations. Which of the following would be the best source of this information?
-
A
The internal accounting department
-
B
The Chief Financial Officer (CFO)
-
C
The external financial audit service
-
D
The managers of the accounts payables and accounts receivables teams
Reveal answer details
Close answer details
Question 26
Single choice
Which level of data destruction applies logical techniques to sanitize data in all user-addressable storage locations?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://it.brown.edu/computing-policies/electronic-equipment-disposition-policy/data-removal-recommendations
Question 27
Single choice
Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
The process of identifying and classifying assets is typically included in the________________.
-
A
-
B
-
C
Asset configuration management process
-
D
Reveal answer details
Close answer details
Question 29
Single choice
A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?
-
A
Effective use of existing technologies
-
B
Create a comprehensive security awareness program and provide success metrics to business units
-
C
-
D
Leveraging existing implementations
Reveal answer details
Close answer details
Correct answerD
ExplanationBy conducting an analysis of the IT infrastructure, the CISO aims to leverage existing implementations, meaning they want to maximize the use and effectiveness of the organization's current security solutions. This approach recognizes the value of utilizing the systems and technologies that are already in place rather than completely replacing or discarding them. It allows for cost savings, optimization of resources, and minimizing disruption to the overall IT environment
Question 30
Single choice
What is the name of a formal statement that defines the strategy, approach, or expectations related to specific concerns within an organization?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
Which of the following refers to the quantity or quality of project deliverables expanding from the original project plan?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 32
Single choice
Which of the following is the MOST important goal of risk management?
-
A
Finding economic balance between the impact of the risk and the cost of the control
-
B
Identifying the victim of any potential exploits
-
C
-
D
Assessing the impact of potential threats
Reveal answer details
Close answer details
Question 33
Single choice
The ultimate goal of an IT security projects is:
-
A
Support business requirements
-
B
Implement information security policies
-
C
-
D
Reveal answer details
Close answer details
Question 34
Single choice
Which of the following best describes the sensors designed to project and detect a light beam across an area?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationReferences: https://en.wikipedia.org/wiki/Photoelectric_sensor
Question 35
Single choice
The process for management approval of the security certification process which states the risks and mitigation of such risks of a given IT system is called___________________.
-
A
-
B
-
C
Alignment with business practices and goals
-
D
Reveal answer details
Close answer details
Question 36
Single choice
Control Objectives for Information and Related Technology (COBIT) is which of the following?
-
A
An audit guideline for certifying secure systems and controls
-
B
An information Security audit standard
-
C
A framework for Information Technology management and governance
-
D
A set of international regulations for Information Technology governance
Reveal answer details
Close answer details
Question 37
Single choice
When a CISO considers delaying or not remediating system vulnerabilities which of the following are MOST important to take into account?
-
A
Threat Level, Risk of Compromise, and Consequences of Compromise
-
B
Risk Avoidance, Threat Level, and Consequences of Compromise
-
C
Reputational Impact, Financial impact, and Risk of Compromise
-
D
Risk transfer, reputational Impact, and Consequences of Compromise
Reveal answer details
Close answer details
Question 38
Single choice
The process for identifying, collecting, and producing digital information in support of legal proceedings is called _____________________________.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
In accordance with best practices and international standards, how often is security awareness training provided to employees of an organization?
-
A
-
B
-
C
High risk environments 6 months, low-risk environments 12 months
-
D
Reveal answer details
Close answer details
Question 40
Single choice
Scenario: A CISO has several two-factor authentication systems under review and selects the one that is most sufficient and least costly. The implementation project planning is completed and the teams are ready to implement the solution. The CISO then discovers that the product it is not as scalable as originally thought and will not fit the organization's needs. The CISO is unsure of the information provided and orders a vendor proof of concept to validate the system's scalability. This demonstrates which of the following?
-
A
A methodology-based approach to ensure authentication mechanism functions
-
B
An approach providing minimum time impact to the implementation schedules
-
C
An approach that allows for minimum budget impact if the solution is unsuitable
-
D
A risk-based approach to determine if the solution is suitable for investment
Reveal answer details
Close answer details
Question 41
Single choice
The PRIMARY objective for information security program development should be:
-
A
Reducing the impact of the risk to the business.
-
B
Establishing incident response programs.
-
C
Establishing strategic alignment with business continuity requirements.
-
D
Identifying and implementing the best security solutions.
Reveal answer details
Close answer details
Question 42
Single choice
Which type of scan is used on the eye to measure the layer of blood vessels?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 43
Single choice
Which of the following is MOST likely to be discretionary?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 44
Single choice
If a CISO wants to understand the liabilities of the company, she will refer to the:
-
A
Profit and Loss statement
-
B
Statement of retained earnings
-
C
-
D
Reveal answer details
Close answer details
Question 45
Single choice
Knowing the potential financial loss an organization is willing to suffer if a system fails is a determination of which of the following?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
An information security department is required to remediate system vulnerabilities when they are discovered. Please select the three primary remediation methods that can be used on an affected system.
-
A
Install software patch, configuration adjustment, software removal
-
B
Install software patch, operate system, maintain system
-
C
Discover software, remove affected software, apply software patch
-
D
Software removal, install software patch, maintain system
Reveal answer details
Close answer details
Question 47
Single choice
Scenario: The new CISO was informed of all the Information Security projects that the section has in progress. Two projects are over a year behind schedule and way over budget. Which of the following will be most helpful for getting an Information Security project that is behind schedule back on schedule?
-
A
-
B
-
C
More frequent project milestone meetings
-
D
More training of staff members
Reveal answer details
Close answer details
Question 48
Single choice
Security related breaches are assessed and contained through which of the following?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 49
Single choice
As the Risk Manager of an organization, you are task with managing vendor risk assessments. During the assessment, you identified that the vendor is engaged with high profiled clients, and bad publicity can jeopardize your own brand. Which is the BEST type of risk that defines this event?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
Which of the following is MOST useful when developing a business case for security initiatives?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 51
Single choice
Which wireless encryption technology makes use of temporal keys?
-
A
Wi-Fi Protected Access version 2 (WPA2)
-
B
Wireless Equivalence Protocol (WEP)
-
C
Wireless Application Protocol (WAP)
-
D
Extensible Authentication Protocol (EAP)
Reveal answer details
Close answer details
Question 52
Single choice
Scenario: You are the newly hired Chief Information Security Officer for a company that has not previously had a senior level security practitioner. The company lacks a defined security policy and framework for their Information Security Program. Your new boss, the Chief Financial Officer, has asked you to draft an outline of a security policy and recommend an industry/sector neutral information security control framework for implementation. Which of the following industry / sector neutral information security control frameworks should you recommend for implementation?
-
A
Payment Card Industry Digital Security Standard (PCI DSS)
-
B
National Institute of Standards and Technology (NIST) Special Publication 800-53
-
C
International Organization for Standardization ?ISO 27001/2
-
D
British Standard 7799 (BS7799)
Reveal answer details
Close answer details
Question 53
Single choice
When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?
-
A
SaaS provider's website certifications and representations (certs and reps)
-
B
-
C
-
D
Statement from SaaS provider attesting their ability to secure your data
Reveal answer details
Close answer details
Correct answerB
ExplanationReferences: https://www.threatstack.com/blog/how-saas-companies-can-build-a-compliance-roadmap
Question 54
Single choice
Which of the following has the GREATEST impact on the implementation of an information security governance model?
-
A
Complexity of organizational structure
-
B
Distance between physical locations
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Single choice
Developing effective security controls is a balance between:
-
A
Technology and Vendor Management
-
B
Operations and Regulations
-
C
Risk Management and Operations
-
D
Corporate Culture and Job Expectations
Reveal answer details
Close answer details
Question 57
Single choice
IT control objectives are useful to IT auditors as they provide the basis for understanding the:
-
A
The audit control checklist
-
B
Technique for securing information
-
C
Desired results or purpose of implementing specific control procedures.
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationCorrective actions involve addressing identified issues or problems within a system or process to prevent their recurrence. When corrective actions are implemented, they often require change requests to modify the existing system or process. These change requests capture the necessary modifications or updates needed to rectify the identified issues and improve the overall performance or functionality. Therefore, corrective actions typically lead to change requests as part of the process for implementing the necessary changes.
Question 58
Single choice
Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 59
Single choice
When dealing with a risk management process, asset classification is important because it will impact the overall:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 60
Single choice
Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
-
A
-
B
-
C
-
D
Network Security administration
Reveal answer details
Close answer details
Question 61
Single choice
Which of the following items of a computer system will an anti-virus program scan for viruses?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 62
Single choice
Which of the following can the company implement in order to avoid this type of security issue in the future?
-
A
Network based intrusion detection systems
-
B
An audit management process
-
C
A security training program for developers
-
D
A risk management process
Reveal answer details
Close answer details
Question 63
Single choice
A stakeholder is a person or group:
-
A
Vested in the success and/or failure of a project or initiative regardless of budget implications.
-
B
That will ultimately use the system.
-
C
That has budget authority.
-
D
Vested in the success and/or failure of a project or initiative and is tied to the project budget.
Reveal answer details
Close answer details
Question 64
Single choice
What is a key policy that should be part of the information security plan?
-
A
Account management policy
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://www.exabeam.com/information-security/information-security-policy/
Question 65
Single choice
Which of the following is the MOST important benefit of an effective security governance process?
-
A
Senior management participation in the incident response process
-
B
-
C
Reduction of security breaches
-
D
Reduction of liability and overall risk to the organization
Reveal answer details
Close answer details
Question 66
Single choice
When would it be more desirable to develop a set of decentralized security policies and procedures within an enterprise environment?
-
A
When there is a variety of technologies deployed in the infrastructure.
-
B
When it results in an overall lower cost of operating the security program.
-
C
When there is a need to develop a more unified incident response capability.
-
D
When the enterprise is made up of many business units with diverse business activities, risks profiles and regulatory requirements.
Reveal answer details
Close answer details
Question 67
Single choice
Which of the following intellectual Property components is focused on maintaining brand recognition?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 68
Single choice
The Board of Directors of a publicly-traded company is concerned about the security implications of a strategic project that will migrate 50% of the organization's information technology assets to the cloud. They have requested a briefing on the project plan and a progress report of the security stream of the project. As the CISO, you have been tasked with preparing the report for the Chief Executive Officer to present. Using the Earned Value Management (EVM), what does a Cost Variance (CV) of -1,200 mean?
-
A
The project is over budget
-
B
The project budget has reserves
-
C
The project cost is in alignment with the budget
-
D
The project is under budget
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://www.pmi.org/learning/library/earned-value-management-systems-analysis-8026#:~:text=The%20cost%20variance%20is%20defined,the%20project%20is%20on%20budget
Question 69
Single choice
A security manager has created a risk program. Which of the following is a critical part of ensuring the program is successful?
-
A
Ensuring developers include risk control comments in code
-
B
Creating risk assessment templates based on specific threats
-
C
Providing a risk program governance structure
-
D
Allowing for the acceptance of risk for regulatory compliance requirements
Reveal answer details
Close answer details
Question 70
Single choice
Scenario: Your organization employs single sign-on (user name and password only) as a convenience to your employees to access organizational systems and data. Permission to individual systems and databases is vetted and approved through supervisors and data owners to ensure that only approved personnel can use particular applications or retrieve information. All employees have access to their own human resource information, including the ability to change their bank routing and account information and other personal details through the Employee Self-Service application. All employees have access to the organizational VPN. Recently, members of your organization have been targeted through a number of sophisticated phishing attempts, resulting in compromised credentials. What action can you take to prevent external misuse of compromised credentials while still allowing employees to manage their bank information?
-
A
Turn off VPN access for users originating from outside the country
-
B
Remove VPN access for all employees except for senior management
-
C
Enable monitoring on the VPN for suspicious activity
-
D
Block access to the Employee-Self Service application via VPN
Reveal answer details
Close answer details
Question 71
Single choice
Scenario: Your company has many encrypted telecommunications links for their world-wide operations. Physically distributing symmetric keys to all locations has proven to be administratively burdensome, but symmetric keys are preferred to other alternatives. Symmetric encryption in general is preferable to asymmetric encryption when:
-
A
The number of unique communication links is large
-
B
The distance to the end node is farthest away
-
C
The volume of data being transmitted is small
-
D
The speed of the encryption / deciphering process is essential
Reveal answer details
Close answer details
|