An online bank identifies a successful network attack in progress. The bank should FIRST:
-
A
isolate the affected network segment.
-
B
report the root cause to the board of directors.
-
C
assess whether personally identifiable information (Pll) is compromised.
-
D
shut down the entire network.
Reveal answer details
Close answer details
Correct answerA
ExplanationBecause the attack is successful and still in progress, the immediate priority is containment. Isolating the affected network segment restricts attacker movement and further damage while allowing unaffected operations to continue. Impact assessment and root-cause reporting follow containment, while shutting down the entire network would be unnecessarily disruptive.
The PRIMARY purpose for continuous monitoring of security controls is to ensure:
-
A
control gaps are minimized.
-
B
-
C
effectiveness of controls.
-
D
alignment with compliance requirements.
Reveal answer details
Close answer details
Correct answerC
ExplanationContinuous monitoring determines whether security controls continue to operate as designed and achieve their intended results as systems and threats change. This ongoing evidence reveals degradation or failure that requires correction. Minimizing gaps, supporting availability, and meeting compliance obligations may result, but the primary focus is control effectiveness.
Which of the following is the MOST important objective of testing a security incident response plan?
-
A
Ensure the thoroughness of the response plan.
-
B
Verify the response assumptions are valid.
-
C
Confirm that systems are recovered in the proper order.
-
D
Validate the business impact analysis (BIA).
Reveal answer details
Close answer details
Correct answerB
ExplanationAn incident response plan depends on assumptions about people, communications, resources, authority, and response conditions. Testing is most valuable when it verifies that these assumptions remain valid and exposes dependencies that fail under realistic conditions. Thoroughness can then be improved from the results, while recovery order and the business impact analysis belong primarily to continuity activities.
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
-
A
Evaluate the results of business continuity testing.
-
B
Review key performance indicators (KPIs).
-
C
Evaluate the business impact of incidents.
-
D
Engage business process owners.
Reveal answer details
Close answer details
Correct answerD
ExplanationBusiness process owners understand the objectives, priorities, dependencies, and risk concerns of the operations they manage. Engaging them reveals whether security activities support those business needs and whether protection priorities match the strategy. Performance indicators can measure chosen activities, but owners provide the direct business perspective needed to judge alignment.
Which of the following components of an information security risk assessment is MOST valuable to senior management?
-
A
-
B
-
C
Return on investment (ROI)
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationResidual risk represents the exposure that remains after existing controls and treatment measures are considered. Senior management needs this information to decide whether remaining risk is within tolerance or requires further action. A threat profile and mitigation actions are useful components, but neither alone communicates the organization's current remaining exposure.
Which of the following should be done FIRST after discovering a security incident within an AI system?
-
A
Notify internal stakeholders
-
B
Inform regulatory authorities
-
C
Update the board of directors
-
D
Report incident details to law enforcement
Reveal answer details
Close answer details
Correct answerA
ExplanationInternal stakeholders responsible for security, operations, ownership, and management need prompt notification so the organization can coordinate assessment and response. They can establish scope, activate procedures, preserve information, and determine further reporting obligations. Regulators, the board, or law enforcement may be contacted later when the incident's impact and applicable requirements support escalation.
Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?
-
A
Place the web server in quarantine.
-
B
Rebuild the server from the last verified backup.
-
C
Shut down the server in an organized manner.
-
D
Rebuild the server with relevant patches from the original media.
Reveal answer details
Close answer details
Correct answerD
ExplanationIsolation and forensic work have already preserved the affected environment and gathered investigative information. The next recovery step is to rebuild the server from trusted original media and apply relevant patches, producing a known baseline while addressing applicable weaknesses. A backup could contain compromised or vulnerable components, and quarantine or shutdown repeats containment actions already completed.
A PRIMARY purpose of creating security policies is to:
-
A
define allowable security boundaries.
-
B
communicate management's security expectations.
-
C
establish the way security tasks should be executed.
-
D
implement management's security governance strategy.
Reveal answer details
Close answer details
Correct answerB
ExplanationSecurity policies express management's direction and expectations for protecting information and guide decisions across the organization. Their primary function is communication at a governing level, not prescribing the detailed steps used to perform individual tasks. Procedures describe execution, while standards and supporting controls translate policy expectations into more specific boundaries and practices.
The MOST important element in achieving executive commitment to an information security governance program is:
-
A
a defined security framework.
-
B
a process improvement model
-
C
established security strategies.
-
D
identified business drivers.
Reveal answer details
Close answer details
Correct answerD
ExplanationIdentified business drivers connect information security governance to the outcomes executives are responsible for, such as supporting operations, managing risk, and meeting obligations. This connection demonstrates why executive commitment is necessary. Frameworks, improvement models, and security strategies are more persuasive after their business purpose is established.
Question 10
Single choice
An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?
-
A
-
B
-
C
The contract with the SIEM vendor
-
D
Available technical support
Reveal answer details
Close answer details
Correct answerA
ExplanationBefore implementing a SIEM, the organization must identify the controls to be monitored and the security objectives that monitoring should support. That scope determines which events are relevant and what monitoring outcomes are needed. Reporting features, vendor terms, and support matter operationally, but they cannot establish what the implementation is intended to monitor.
Question 11
Single choice
Which of the following is the GREATEST challenge when developing key risk indicators (KRIs)?
-
A
Limiting the number of KRIs
-
B
Comprehensively reporting on KRIs
-
C
-
D
Linking KRIs to specific risks
Reveal answer details
Close answer details
Correct answerD
ExplanationA key risk indicator is useful only when its movement can be interpreted as a change in a particular risk. Linking KRIs to specific risks is difficult because the relationship must be meaningful enough to support decisions and escalation. Limiting, aggregating, or reporting indicators becomes useful only after each indicator has a clear risk connection.
Question 12
Single choice
An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?
-
A
Initiate incident response.
-
B
-
C
-
D
Conduct a risk assessment.
Reveal answer details
Close answer details
Correct answerA
ExplanationA lost personal device containing corporate information creates a potential security incident requiring coordinated action. Initiating incident response first activates the established process for assessment, containment, communication, and documentation. Specific actions such as disabling access or resetting the device should follow that process according to the device's exposure and available controls.
Question 13
Single choice
A health care organization has been informed of a breach at a third-party vendor. Which of the following should the organization's information security manager do FIRST?
-
A
Notify relevant regulatory bodies
-
B
Review the relevant contract clauses
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA breach at a vendor does not by itself establish what organizational data, systems, or obligations are affected. The security manager should first assess the impact to determine scope, severity, and potential consequences for the healthcare organization. Those findings provide the basis for accurate management escalation, contractual action, and any required regulatory notification.
Question 14
Single choice
Organization A offers e-commerce services and uses secure transport protocol to protect Internet communication. To confirm communication with Organization A, which of the following would be the BEST for a client to verify?
-
A
The URL of the e-commerce server
-
B
The certificate of the e-commerce server
-
C
The IP address of the e-commerce server
-
D
The browser's indication of SSL use
Reveal answer details
Close answer details
Correct answerB
ExplanationA server certificate binds the e-commerce server's identity to the cryptographic credentials used for secure communication. Verifying that certificate, including the identity it represents and its validity, confirms that the client is communicating with Organization A rather than merely using an encrypted connection. A URL, IP address, or browser SSL indication alone does not authenticate the organization.
Question 15
Single choice
Which of the following would BEST enable an organization to aggregate information from different systems to allow for centralized categorization of incidents?
-
A
Intrusion detection system (IDS)
-
B
Application program interfaces (APIs)
-
C
Intrusion prevention system (IPS)
-
D
Security information and event management (SIEM)
Reveal answer details
Close answer details
Correct answerD
ExplanationSecurity information and event management centralizes event and log information received from multiple systems. By correlating and normalizing those records, a SIEM supports consistent categorization and handling of incidents across the organization. Detection or prevention tools alone do not provide the same enterprise-wide aggregation function.
Question 16
Single choice
Which of the following should be done FIRST when establishing an information security governance framework?
-
A
Evaluate information security tools and skills relevant for the environment.
-
B
Gain an understanding of the business and cultural attributes.
-
C
Contract a third party to conduct an independent review of the program.
-
D
Conduct a cost-benefit analysis of the framework.
Reveal answer details
Close answer details
Correct answerB
ExplanationA governance framework must fit the organization it will govern. Understanding the business and cultural attributes first reveals objectives, decision structures, risk attitudes, and practical expectations that the framework must support. Tools, skills, external reviews, and cost analysis are meaningful only after that organizational context is established.
Question 17
Single choice
Which of the following is an information security manager's BEST course of action to gain approval for investment in a technical control?
-
A
Calculate the exposure factor
-
B
Perform a cost-benefit analysis
-
C
Conduct a risk assessment
-
D
Conduct a business impact analysis (BIA)
Reveal answer details
Close answer details
Correct answerB
ExplanationA cost-benefit analysis compares the investment and operating costs of the technical control with the value of its expected risk reduction and business benefits. This gives management a financial and operational basis for approval. A risk assessment establishes need, but it does not alone demonstrate that the proposed investment is worthwhile.
Question 18
Single choice
Which of the following BEST enables an organization to appropriately prioritize information security-focused projects?
-
A
Return on investment (ROI)
-
B
Privacy compliance requirements
-
C
Organizational risk appetite
-
D
Historical security incidents
Reveal answer details
Close answer details
Correct answerC
ExplanationOrganizational risk appetite defines the amount and type of risk the enterprise is prepared to accept while pursuing its objectives. Comparing proposed security projects against that boundary enables consistent prioritization of initiatives that address unacceptable exposure. Individual incidents, privacy obligations, or ROI figures provide narrower inputs.
Question 19
Single choice
The categorization of incidents is MOST important for evaluating which of the following?
-
A
Appropriate communication channels
-
B
Allocation of needed resources
-
C
Risk severity and incident priority
-
D
Response and containment requirements
Reveal answer details
Close answer details
Correct answerC
ExplanationIncident categories provide a consistent basis for assessing what is affected and how serious the event is. That assessment establishes risk severity and incident priority, which then drive resource allocation, communication, containment, and response decisions. Those later actions depend on first determining the incident's relative significance and urgency.
Question 20
Single choice
The PRIMARY reason for senior management to monitor information security metrics is to ensure:
-
A
alignment of the information security budget to corporate funding.
-
B
alignment of information security with corporate governance.
-
C
alignment of security and IT objectives.
-
D
alignment with risk mitigation efforts.
Reveal answer details
Close answer details
Correct answerB
ExplanationSecurity metrics give senior management visibility into whether security objectives, accountability, and risk oversight operate within the organization's governance structure. Monitoring them therefore helps keep information security aligned with corporate governance. Budget alignment, IT coordination, and mitigation progress are narrower concerns that may be represented by particular measures.
Question 21
Single choice
Which of the following is the MOST important security consideration when developing an incident response strategy with a cloud provider?
-
A
-
B
Technological capabilities
-
C
Recovery time objective (RTO)
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationIncident response with a cloud provider requires coordinated action across organizational boundaries. Defined escalation processes establish when and how an incident is raised, who must be involved, and where decision authority resides, enabling timely joint response. Technical capability and audit information are useful inputs, but they do not ensure that the correct parties act when an incident occurs.
Question 22
Single choice
What type of control is being implemented when a security information and event management (SIEM) system is installed?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA security information and event management system collects and correlates event information to identify suspicious activity and generate alerts. That function discovers conditions that may indicate an incident, making the system a detective control. It does not primarily prevent the activity or correct the underlying condition after detection.
Question 23
Single choice
Which of the following is the GREATEST benefit of incorporating information security governance into the corporate governance framework?
-
A
Heightened awareness of information security strategies
-
B
Improved process resiliency in the event of attacks
-
C
Promotion of security-by-design principles to the business
-
D
Management accountability for information security
Reveal answer details
Close answer details
Correct answerD
ExplanationEmbedding security governance in corporate governance places information security within management's established authority, oversight, and decision-making structure. This creates management accountability for security objectives and risk decisions. Awareness, resilience, and security-by-design can improve as outcomes, but accountability is the broad governance benefit that enables them.
Question 24
Single choice
Which of the following presents the GREATEST challenge for protecting Internet of Things (IoT) devices?
-
A
-
B
IoT architecture diversity
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationIoT architecture diversity creates a broad and inconsistent protection problem because devices can differ in design, interfaces, capabilities, and operating environments. A uniform control approach may therefore be difficult to apply across the population. Vendor reputation, training, and policies can influence security management, but they do not remove the underlying architectural variation.
Question 25
Single choice
Which of the following metrics is MOST appropriate for evaluating the incident notification process?
-
A
Average total cost of downtime per reported incident
-
B
Elapsed time between response and resolution
-
C
Average number of incidents per reporting period
-
D
Elapsed time between detection, reporting, and response
Reveal answer details
Close answer details
Correct answerD
ExplanationIncident notification effectiveness depends on how quickly information moves from detection through reporting to the start of response. Measuring elapsed time across those points reveals delays in recognition, communication, or activation of responders. Downtime cost and incident counts measure other outcomes, while time to resolution extends beyond the notification process.
Question 26
Single choice
How would the information security program BEST support the adoption of emerging technologies?
-
A
Conducting a control assessment
-
B
Developing an emerging technology roadmap
-
C
Providing effective risk governance
-
D
Developing an acceptable use policy
Reveal answer details
Close answer details
Correct answerC
ExplanationEmerging technology introduces new opportunities and risks that must be evaluated against business objectives and risk appetite. Effective risk governance supplies decision authority, accountability, and consistent criteria for accepting, treating, or avoiding those risks. This enables adoption decisions while keeping technology use aligned with the organization's risk direction.
Question 27
Single choice
An information security manager is assisting in the development of the request for proposal (RFP) for a new outsourced service. This will require the third party to have access to critical business information. The security manager should focus PRIMARILY on defining:
-
A
service level agreements (SLAs)
-
B
security requirements for the process being outsourced.
-
C
risk-reporting methodologies.
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationBecause the outsourced process will expose critical business information to a third party, its security requirements must be defined during the request-for-proposal. This allows candidate providers to be evaluated against the protections the process needs and enables those obligations to be included in the agreement. Metrics and reporting methods can follow from those requirements.
Question 28
Single choice
Of the following, who is BEST positioned to approve specific information security risk treatment options?
-
A
-
B
Information security manager
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe risk owner is accountable for the business exposure and has the authority to select among treatment options such as reducing, transferring, avoiding, or accepting the risk. Approval belongs with that owner because treatment affects business objectives and residual risk. Security and risk specialists analyze and recommend options but do not replace ownership.
Question 29
Single choice
Which of the following tools provides an incident response team with the GREATEST insight into insider threat activity across multiple systems?
-
A
A security information and event management (SIEM) system
-
B
An intrusion prevention system (IPS)
-
C
A virtual private network (VPN) with multi-factor authentication (MFA)
-
D
An identity and access management (IAM) system
Reveal answer details
Close answer details
Correct answerA
ExplanationA security information and event management system centralizes events and logs from multiple systems and correlates them across time and sources. This gives the incident response team a unified view of user activity, relationships, and abnormal patterns that may indicate an insider threat. Single-purpose network or access tools provide narrower visibility and less cross-system context.
Question 30
Single choice
Which of the following will MOST effectively minimize the chance of inadvertent disclosure of confidential information?
-
A
Applying data classification rules
-
B
Following the principle of least privilege
-
C
Restricting the use of removable media
-
D
Enforcing penalties for security policy violations
Reveal answer details
Close answer details
Correct answerA
ExplanationData classification rules identify which information is confidential and prescribe handling requirements appropriate to that sensitivity. Applying those rules helps personnel and systems consistently store, transmit, label, and dispose of information in ways that prevent inadvertent disclosure. A removable-media restriction addresses only one disclosure channel.
Question 31
Single choice
Which of the following is the BEST reason to consolidate security operations teams across a global organization?
-
A
Compliance with regulatory requirements
-
B
Enhanced visibility of threats
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationConsolidating security operations gives a global organization a unified view of events and patterns across locations. That enhanced visibility helps analysts recognize coordinated or distributed threats that separate teams might see only as isolated activity. Cost savings may occur, but the strongest security reason is the improved ability to understand enterprise-wide threats and coordinate action against them.
Question 32
Single choice
Which of the following is the BEST way for an information security manager to justify ongoing annual maintenance fees associated with an intrusion prevention system (IPS)?
-
A
Establish and present appropriate metrics that track performance.
-
B
Perform industry research annually and document the overall ranking of the IPS.
-
C
Perform a penetration test to demonstrate the ability to protect.
-
D
Provide yearly competitive pricing to illustrate the value of the IPS.
Reveal answer details
Close answer details
Correct answerA
ExplanationAppropriate performance metrics connect the intrusion prevention system's operation to measurable security value over time. Presenting trends in effectiveness and relevant outcomes gives management a repeatable basis for deciding whether annual maintenance remains justified. Market ranking, competitive pricing, or a single penetration test does not demonstrate the system's continuing contribution as directly.
Question 33
Single choice
An information security manager has become aware that system administrators are not changing server administrator accounts from the default usernames. A policy has been created and approved by business managers to require these changes. Which of the following should be the information security manager's FIRST course of action?
-
A
Include the requirement in information security awareness materials
-
B
Perform a policy compliance assessment
-
C
Ensure the policy has been communicated to the system administrators
Reveal answer details
Close answer details
Correct answerC
ExplanationApproval establishes the policy requirement, but administrators must receive and understand it before compliance can reasonably be expected. The first action is therefore to ensure the policy has been communicated to the system administrators responsible for changing the default usernames. A compliance assessment is meaningful after the requirement has been conveyed and implementation can occur.
Question 34
Single choice
Which of the following should be triggered FIRST when unknown malware has infected an organization's critical system?
-
A
-
B
Disaster recovery plan (DRP)
-
C
Business continuity plan (BCP)
-
D
Vulnerability management plan
Reveal answer details
Close answer details
Correct answerA
ExplanationAn unknown malware infection is an active security incident, so the incident response plan must be invoked first to coordinate identification, containment, eradication, and communication. Continuity or disaster recovery may become necessary if business services cannot continue or must be restored, but those decisions follow the initial incident assessment and response.
Question 35
Single choice
A strict new regulation is being finalized to address global concerns regarding cybersecurity. Which of the following should the information security manager do FIRST?
-
A
Monitor industry response to the regulation.
-
B
Seek legal counsel on the new regulation.
-
C
Validate the applicability of the regulation.
-
D
Escalate compliance risk to senior management
Reveal answer details
Close answer details
Correct answerC
ExplanationBefore planning compliance work, the information security manager must validate whether the new regulation applies to the organization, its locations, activities, or information. Applicability establishes whether a compliance obligation exists and defines its scope. Escalation, legal interpretation, and monitoring industry reaction follow from that initial determination.
Question 36
Single choice
Which of the following is MOST likely to require an organization to update its business continuity plan (BCP)?
-
A
Successful BCP testing results
-
B
Increases in information security risk trends
-
C
Multiple changes in organizational leadership
-
D
Major changes in the business operating environment
Reveal answer details
Close answer details
Correct answerD
ExplanationMajor changes in the business operating environment can alter critical processes, dependencies, facilities, resources, and recovery priorities. Because a continuity plan is built around these conditions, its strategies and assumptions must be updated when they change materially. Successful tests may confirm the existing plan, while risk trends or leadership changes do not necessarily alter continuity requirements.
Question 37
Single choice
When developing an information security strategy for an organization, which of the following is MOST helpful for understanding where to focus efforts?
-
A
-
B
-
C
-
D
Business impact analysis (BIA)
Reveal answer details
Close answer details
Correct answerA
ExplanationA gap analysis compares the organization's current security capabilities with its desired state. The resulting differences identify where controls, governance, resources, or processes need improvement, giving strategy development a clear basis for prioritizing effort. A vulnerability assessment is narrower, while project plans are created after priorities have been established.
Question 38
Single choice
Of the following, who would provide the MOST relevant input when aligning the information security strategy with organizational goals?
-
A
Enterprise risk committee
-
B
Information security steering committee
-
C
Data privacy officer (DPO)
-
D
Chief information security officer (CISO)
Reveal answer details
Close answer details
Correct answerB
ExplanationAn information security steering committee brings together business and security perspectives for governance decisions. Because it represents organizational priorities across functions, it can provide the most relevant input for aligning security strategy with business goals. An individual officer offers expertise, but not the same breadth of enterprise representation.
Question 39
Single choice
Over the last year, an information security manager has performed risk assessments on multiple third-party vendors. Which of the following criteria would be MOST helpful in determining the associated level of risk applied to each vendor?
-
A
Compliance requirements associated with the regulation
-
B
Criticality of the service to the organization
-
C
Corresponding breaches associated with each vendor
-
D
Compensating controls in place to protect information security
Reveal answer details
Close answer details
Correct answerB
ExplanationThe criticality of a vendor's service indicates the business impact if that service is disrupted, compromised, or unavailable. It therefore provides a consistent basis for assigning vendor risk levels and directing greater oversight toward relationships with greater organizational consequences. A breach history or individual compensating control describes only part of the overall exposure.
Question 40
Single choice
Which of the following attributes is MOST important to consider when planning to adopt a recognized standard or framework for information security?
-
A
Ease of organization-wide implementation
-
B
Applicability to the organization's needs
-
C
Ability to measure and compare
-
D
Cost-benefit of implementation
Reveal answer details
Close answer details
Correct answerB
ExplanationA recognized framework creates value only when its scope and requirements fit the organization's objectives, risks, operations, and obligations. Applicability to organizational needs is therefore the first consideration when choosing one. Ease, measurement capability, and cost-benefit matter after confirming that the framework addresses the environment it is expected to govern.
Question 41
Single choice
An organization uses a security standard that has undergone a major revision by the certifying authority. The old version of the standard will no longer be used for organizations wishing to maintain their certifications. Which of the following should be the FIRST course of action?
-
A
Evaluate the cost of maintaining the certification.
-
B
Review the new standard for applicability to the business.
-
C
Modify policies to ensure new requirements are covered.
-
D
Communicate the new standard to senior leadership.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe revision must first be reviewed for applicability to the business so the organization can identify relevant changes, gaps, obligations, and effects on certification. That analysis supplies the basis for estimating cost, modifying policies, and communicating required action to leadership. Acting before understanding applicability could produce incomplete or unnecessary changes.
Question 42
Single choice
After updating password standards, an information security manager is alerted by various application administrators that the applications they support are incapable of enforcing these standards. The information security manager's FIRST course of action should be to:
-
A
determine the potential impact.
-
B
reevaluate the standards.
-
C
implement compensating controls.
-
D
evaluate the cost of replacing the applications.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe applications cannot enforce the new password standards, but the significance of that gap has not yet been established. Determining the potential impact first clarifies affected assets, exposure, and business consequences. That information is needed before deciding whether to revise the standard, implement compensating controls, or replace applications.
Question 43
Single choice
An organization that uses external cloud services extensively is concerned with risk monitoring and timely response. The BEST way to address this concern is to ensure:
-
A
the availability of continuous technical support.
-
B
appropriate service level agreements (SLAs) are in place.
-
C
a right-to-audit clause is included in contracts.
-
D
internal security standards are in place.
Reveal answer details
Close answer details
Correct answerB
ExplanationAppropriate service level agreements define the cloud provider's expected monitoring and response performance in measurable terms. They create a shared basis for evaluating whether events are detected and handled within required timeframes. Technical support availability alone does not establish response obligations, and a right to audit assesses compliance rather than setting ongoing service expectations.
Question 44
Single choice
Senior management is concerned about data exposure through the use of public Al services. Which of the following is the information security manager's BEST course of action?
-
A
Train all employees on the appropriate use of public Al services and confidential data.
-
B
Disable access to public Al from company devices.
-
C
Perform a risk assessment of public Al with appropriate recommendations for senior management.
-
D
Perform a business impact analysis (BIA) of public Al.
Reveal answer details
Close answer details
Correct answerC
ExplanationConcern about data exposure must first be translated into an evaluated business risk. A risk assessment identifies relevant use, exposure, likelihood, and impact, enabling appropriate recommendations for senior management. Training or blocking access selects a treatment before the risk is evaluated, while a business impact analysis focuses on disruption rather than exposure risk.
Question 45
Single choice
When creating an incident response plan, which of the following is MOST important to include during the preparation phase of the plan's life cycle?
-
A
-
B
-
C
-
D
Forensic analysis procedures
Reveal answer details
Close answer details
Correct answerA
ExplanationPreparation must establish how information will move among responders, management, affected parties, and other stakeholders before an incident occurs. A communication plan defines contacts, responsibilities, and communication paths so coordination can begin promptly. Detailed response and forensic procedures are used during later incident-handling activities.
Question 46
Single choice
Which of the following would be MOST useful to help senior management understand the status of information security compliance?
-
A
-
B
Key performance indicators (KPIs)
-
C
Business impact analysis (BIA) results
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationKey performance indicators translate compliance activity into measurable results that can be compared with targets and tracked over time. This gives senior management a concise view of current performance, trends, and areas requiring attention. Risk assessments and impact analyses address exposure or consequence, while benchmarks provide comparison rather than direct status against the organization's compliance goals.
Question 47
Single choice
When conducting a post-implementation review for a security investment, it is MOST important to determine whether the investment:
-
A
Meets internal requirements
-
B
Complies with industry standards
-
C
Achieves projected financial benefits
-
D
Delivers anticipated risk reduction
Reveal answer details
Close answer details
Correct answerD
ExplanationA security investment is justified by the risk treatment it was intended to produce. The post-implementation review should therefore determine whether the anticipated risk reduction was actually delivered. Financial benefits, internal requirements, and industry standards may matter, but they do not establish whether the security objective of the investment was achieved.
Question 48
Single choice
Which of the following has the GREATEST impact on the ability to successfully execute a disaster recovery plan (DRP)?
-
A
Conducting a walk-through of the plan
-
B
Updating the plan periodically
-
C
Communicating the plan to all stakeholders
-
D
Reviewing escalation procedures
Reveal answer details
Close answer details
Correct answerA
ExplanationConducting a walk-through makes participants trace the disaster recovery plan's actions, roles, dependencies, and decision points before a real disruption. This can expose unclear instructions or impractical assumptions that would prevent successful execution. Merely updating, communicating, or reviewing one procedure does not validate how the complete plan will operate.
Question 49
Single choice
A post-incident review revealed that key stakeholders took longer than acceptable to decide whether an application should be shut down following a security breach. Which of the following is management's BEST course of action to rectify this issue?
-
A
Improve incident response criteria.
-
B
Improve incident response testing.
-
C
Define incident classification.
-
D
Establish containment procedures.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe review identified delayed decision-making about shutdown, so management should improve the incident response criteria that guide that decision. Clear thresholds based on incident conditions and impact allow stakeholders to determine promptly when shutdown is warranted. Testing can reveal delays, but it does not resolve ambiguous decision rules; containment procedures address execution after the decision is made.
Question 50
Single choice
Which of the following is MOST helpful for retaining the support of executive management for an information security program?
-
A
Forming an information security steering committee to provide oversight of the program
-
B
Providing regular performance reports on the effectiveness of the program
-
C
Including satisfaction with information security in employee engagement surveys
-
D
Developing business cases to justify continued expenses for security awareness
Reveal answer details
Close answer details
Correct answerB
ExplanationRegular performance reports show executive management whether the information security program is meeting objectives, reducing risk, and using resources effectively. Trends and measurable results support continued oversight and investment. A steering committee provides governance, but evidence of program effectiveness is what most directly helps retain executive support over time.
Question 51
Single choice
Security administration efforts will be greatly reduced following the deployment of which of the following techniques?
-
A
Discretionary access control
-
B
Role-based access control
-
C
-
D
Distributed access control
Reveal answer details
Close answer details
Correct answerB
ExplanationRole-based access control assigns permissions to defined job roles and then associates users with the appropriate roles. Administrators can manage common access at the role level instead of repeatedly maintaining separate permissions for each user and resource. This reduces effort during onboarding, job changes, and departures while keeping access tied to job responsibilities.
Question 52
Single choice
Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
-
A
Determine the final root cause of the incident.
-
B
Remove all instances of the incident from the network.
-
C
Mitigate exploited vulnerabilities to prevent future incidents.
-
D
Isolate affected systems to prevent the spread of damage.
Reveal answer details
Close answer details
Correct answerD
ExplanationContainment is intended to limit an active incident's reach and immediate damage. Isolating affected systems interrupts their connection to unaffected resources and helps prevent further spread while investigation continues. Removing every instance belongs to eradication, and final root-cause analysis or long-term vulnerability mitigation follows the urgent containment action.
Question 53
Single choice
Which of the following is MOST important to ensure when considering exceptions to an information security policy?
-
A
Exceptions are approved by executive management.
-
B
Exceptions undergo regular review.
-
C
Exceptions reect the organizational risk appetite.
-
D
Exceptions are based on data classification.
Reveal answer details
Close answer details
Correct answerC
ExplanationA policy exception deliberately permits operation outside a required security rule, creating or retaining risk. It is acceptable only when that exposure reflects the organizational risk appetite. Approval and periodic review support governance of the exception, but neither makes an exception appropriate if its residual risk exceeds what the organization is willing to accept.
Question 54
Single choice
A software vendor has announced a zero-day vulnerability that exposes an organization's critical business systems. The vendor has released an emergency patch. Which of the following should be the information security managers PRIMARY concern?
-
A
Ability to test the patch prior to deployment
-
B
Documentation of patching procedures
-
C
Adequacy of the incident response plan
-
D
Availability of resources to implement controls
Reveal answer details
Close answer details
Correct answerA
ExplanationThe emergency patch addresses an active exposure, but deploying it without testing could disrupt the critical systems it is intended to protect. The primary concern is therefore the ability to test the patch before deployment, balancing urgent remediation with the need to avoid introducing operational failure.
Question 55
Single choice
For an enterprise implementing a bring your own device (BYOD) program, which of the following would provide the BEST security of corporate data residing on unsecured mobile devices?
-
A
Device certification process
-
B
-
C
Containerization solution
-
D
Data loss prevention (DLP)
Reveal answer details
Close answer details
Correct answerC
ExplanationContainerization separates corporate applications and data from the employee's personal environment on the same device. This boundary allows corporate information to be managed and protected without relying on the security of the entire unsecured device. Policies and certification provide governance, while containerization directly isolates the data at issue.
Question 56
Single choice
An organization has identified IT failures in a call center application. Of the following, who should own this risk?
-
A
Information security manager
-
B
-
C
Chief executive officer (CEO)
-
D
Head of the IT department
Reveal answer details
Close answer details
Correct answerB
ExplanationThe head of the call center owns the business process that depends on the application and is therefore accountable for the risk that IT failures pose to call center objectives. This owner can evaluate operational impact and decide on treatment priorities. IT and security leaders provide technical management and advice, but the affected business owner retains the risk.
Question 57
Single choice
Which of the following BEST indicates effective information security governance?
-
A
Availability of information security policies
-
B
Regular steering committee meetings
-
C
Organization-wide attendance at annual security training
-
D
Regular testing of the security incident response plan
Reveal answer details
Close answer details
Correct answerB
ExplanationRegular steering committee meetings demonstrate active governance because responsible leaders repeatedly review security direction, risks, priorities, and performance and make decisions across the organization. The existence of policies or completion of operational activities shows particular controls are present, but not that ongoing governance oversight is functioning.
Question 58
Single choice
Which of the following is the BEST approach when creating a security policy for a global organization subject to varying laws and regulations?
-
A
Incorporate policy statements derived from third-party standards and benchmarks.
-
B
Adhere to a unique corporate privacy and security standard
-
C
Establish baseline standards for all locations and add supplemental standards as required
-
D
Require that all locations comply with a generally accepted set of industry
Reveal answer details
Close answer details
Correct answerC
ExplanationA global policy should establish baseline standards that apply consistently to all locations, then add supplemental standards where local laws or regulations impose different or stronger requirements. This preserves an organization-wide minimum while accommodating regional obligations. A single corporate or industry standard alone cannot address every jurisdictional variation.
Question 59
Single choice
The PRIMARY objective of performing a post-incident review is to:
-
A
re-evaluate the impact of incidents
-
B
-
C
identify control improvements.
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA post-incident review converts experience from an incident into stronger future protection. By examining what happened, how controls performed, and where response or prevention failed, the organization can identify specific control improvements. Root-cause identification supports this analysis, but the primary objective is to apply the findings to improve controls.
Question 60
Single choice
Which of the following will BEST facilitate the integration of information security governance into enterprise governance?
-
A
Developing an information security policy based on risk assessments
-
B
Establishing an information security steering committee
-
C
Documenting the information security governance framework
-
D
Implementing an information security awareness program
Reveal answer details
Close answer details
Correct answerB
ExplanationAn information security steering committee creates a formal connection between security leadership and enterprise decision-makers. Through shared oversight, priorities, resources, risk decisions, and strategic direction can be integrated with broader governance. A documented framework or policy describes structure, while the committee actively embeds security governance into enterprise decisions.
Question 61
Single choice
The PRIMARY advantage of involving end users in continuity planning is that they:
-
A
have a better understanding of specific business needs.
-
B
are more objective than information security management.
-
C
can see the overall impact to the business.
-
D
can balance the technical and business risks.
Reveal answer details
Close answer details
Correct answerA
ExplanationEnd users understand the detailed activities, dependencies, timing needs, and practical constraints of the business processes they perform. Their participation helps continuity plans reflect specific business needs and workable recovery arrangements. An enterprise-wide view and balancing technical risk are broader management responsibilities, not the users' primary advantage.
Question 62
Single choice
A significant risk was identified within a core business function. Budget constraints do not allow for effective remediation. Who should be accountable for selecting the appropriate risk treatment?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA significant risk affecting a core business function requires a treatment decision that balances business impact, available resources, and accepted exposure. Senior management has the authority and accountability to make that decision when effective remediation cannot be funded. Custodians and security personnel can advise or implement controls, but they do not accept major business risk.
Question 63
Single choice
In information security governance, which of the following has PRIMARY responsibility for ensuring compliance with regulations?
-
A
-
B
Enterprise risk management
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationSenior management has primary governance accountability for ensuring the organization complies with applicable regulations. Management establishes direction, assigns responsibility, provides resources, and oversees corrective action. Legal counsel interprets obligations, enterprise risk management evaluates exposure, and control owners operate controls, but these roles support rather than replace executive accountability.
Question 64
Single choice
Of the following, who is in the BEST position to evaluate business impacts?
-
A
-
B
Information security manager
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe process manager understands how the business process operates, which resources and dependencies it requires, and what interruption would mean for its outputs and stakeholders. That operational knowledge places this role in the best position to evaluate business impact. Security and IT managers can supply technical input, but they do not own the full business-process perspective.
Question 65
Single choice
Which of the following is the BEST reason to implement an information security architecture?
-
A
Assess the cost-effectiveness of the integration.
-
B
Fast-track the deployment of information security components.
-
C
Serve as a post-deployment information security road map.
-
D
Facilitate consistent implementation of security requirements.
Reveal answer details
Close answer details
Correct answerD
ExplanationInformation security architecture provides a structured blueprint that translates security requirements into consistent designs and control patterns across systems. This reduces fragmented implementation and supports integration as the environment evolves. Deployment speed and cost may improve, but consistent implementation of requirements is the principal reason for the architecture.
Question 66
Single choice
Which of the following is the BEST way to ensure that organizational security policies comply with data security regulatory requirements?
-
A
Obtain annual sign-off from executive management.
-
B
Align the policies to the most stringent global regulations.
-
C
Send the policies to stakeholders for review.
-
D
Outsource compliance activities.
Reveal answer details
Close answer details
Correct answerB
ExplanationAligning policies to the most stringent global regulations establishes a consistent baseline capable of satisfying the strongest applicable data security obligations across locations. This reduces the risk that a weaker organizational rule leaves a regulated operation noncompliant. Executive approval and stakeholder review support governance, but neither independently establishes substantive regulatory alignment.
Question 67
Single choice
Following an information security risk assessment of a critical system, several significant issues have been identified. Which of the following is MOST important for the information security manager to confirm?
-
A
The risks are reported to the business unit's senior management
-
B
The risks are escalated to the IT department for remediation
-
C
The risks are communicated to the central risk function
-
D
The risks are entered in the organization's risk register
Reveal answer details
Close answer details
Correct answerD
ExplanationSignificant risks identified through an assessment must be formally recorded so they can be assigned, evaluated, treated, accepted, and tracked through closure. Entering them in the organization's risk register creates that authoritative record and supports consistent oversight beyond a one-time report to a particular function.
Question 68
Single choice
An organization's research department plans to apply machine learning algorithms on a large data set containing customer names and purchase history. The risk of personal data leakage is considered high impact. Which of the following is the BEST risk treatment option in this situation?
-
A
Accept the risk, as the benefits exceed the potential consequences.
-
B
Mitigate the risk by applying anonymization on the data set.
-
C
Transfer the risk by purchasing insurance.
-
D
Mitigate the risk by encrypting the customer names in the data set.
Reveal answer details
Close answer details
Correct answerB
ExplanationAnonymization reduces leakage risk by removing or transforming identifying information so the research data cannot be tied to particular customers. It addresses both customer names and the link between identity and purchase history while retaining data for analysis. Encrypting only names would leave the data's identifying relationships insufficiently addressed.
Question 69
Single choice
Which of the following is the MOST appropriate risk response when the risk impact has been determined to be immaterial and the likelihood is very low?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA risk with both immaterial impact and very low likelihood has minimal significance to the organization. Accepting it avoids spending resources on treatment that would be disproportionate to the expected exposure. Mitigation, avoidance, and transfer are more suitable when reducing the likelihood or impact justifies their cost and operational consequences.
Question 70
Single choice
Management has announced the acquisition of a new company. The information security manager of the parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies. To BEST address this concern, the information security manager should:
-
A
review access rights as the acquisition integration occurs.
-
B
perform a risk assessment of the access rights.
-
C
escalate concerns for conflicting access rights to management.
-
D
implement consistent access control standards.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe exposure concern arises as identities, roles, systems, and entitlements from the two companies are combined. Reviewing access rights throughout the acquisition integration allows conflicts and excessive privileges to be identified at the points when they are introduced and corrected before they persist. This continuing review addresses the changing access environment created by the integration.
Question 71
Single choice
Which of the following BEST reduces the likelihood of leakage of private information via email?
-
A
-
B
Periodic phishing exercises
-
C
Email signature verification
-
D
Restricted personal use of company email
Reveal answer details
Close answer details
Correct answerA
ExplanationEmail leakage commonly depends on users making poor decisions about recipients, content, attachments, or handling of private information. Awareness training addresses these behaviors by teaching personnel how to recognize sensitive data and use email safely. Phishing exercises target a narrower threat, while signature verification addresses message authenticity rather than disclosure by a sender.
Question 72
Single choice
Following a significant change to the underlying code of an application, it is MOST important for the information security manager to:
-
A
inform senior management.
-
B
update the risk assessment.
-
C
validate the user acceptance testing (UAT).
-
D
modify key risk indicators (KRIs).
Reveal answer details
Close answer details
Correct answerB
ExplanationA significant application code change can alter vulnerabilities, control effectiveness, data exposure, and business impact. Updating the risk assessment determines whether the previous risk conclusions and treatments remain valid before relying on the changed application. User acceptance testing addresses business functionality and does not replace reassessment of security risk.
Question 73
Single choice
An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?
-
A
Benchmark the processes with best practice to identify gaps.
-
B
Calculate the return on investment (ROI).
-
C
Provide security awareness training to HR.
-
D
Assess the business objectives of the processes.
Reveal answer details
Close answer details
Correct answerD
ExplanationSecurity must support what the HR processes are intended to accomplish. Assessing their business objectives first establishes the required outcomes, information flows, and priorities against which security requirements can be designed. Benchmarking, investment analysis, and awareness activities become meaningful only after the organization understands the processes they are meant to support.
Question 74
Single choice
Which of the following BEST indicates ongoing senior management commitment to the organization's information security strategy?
-
A
An efficient incident response program
-
B
Established key performance indicators (KPIs)
-
C
A comprehensive security awareness training program
-
D
Adequate funding for the information security program
Reveal answer details
Close answer details
Correct answerD
ExplanationAdequate funding demonstrates that senior management is continually committing organizational resources to the information security program. That commitment enables planned controls, staffing, and strategic initiatives to be sustained. Incident response, metrics, and awareness programs are useful program components, but their existence alone does not demonstrate ongoing executive support as directly.
Question 75
Single choice
An organization has decided to outsource its disaster recovery function. Which of the following is the MOST important consideration when drafting the service level agreement (SLA)?
-
A
-
B
-
C
Recovery time objectives (RTOs)
-
D
Recovery point objectives (RPOs)
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen disaster recovery is outsourced, the service level agreement must define how quickly the provider is required to restore the service. Recovery time objectives establish this maximum restoration interval and connect provider performance to the organization's continuity needs. Recovery point objectives concern tolerable data loss, but the outsourced recovery function's central service commitment is timely restoration.
Question 76
Single choice
A new regulatory requirement affecting an organization's information security program is released. Which of the following should be the information security manager's FIRST course of action?
-
A
-
B
-
C
Notify the legal department.
-
D
Determine the disruption to the business.
Reveal answer details
Close answer details
Correct answerA
ExplanationA gap analysis compares the existing information security program with the new regulatory requirements. It identifies which obligations are already satisfied, which controls or processes are deficient, and where remediation is needed. This assessment must precede implementation planning because the organization first needs a defined difference between its current and required states.
Question 77
Single choice
Senior management is concerned that the incident response team took unapproved actions during incident response that put business objectives at risk. Which of the following is the BEST way for the information security manager to respond to this situation?
-
A
Update roles and responsibilities of the incident response team.
-
B
Train the incident response team on escalation procedures.
-
C
Implement a monitoring solution for incident response activities.
-
D
Validate that the information security strategy maps to corporate objectives.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe immediate deficiency is that responders took actions without the required approval. Training the incident response team on escalation procedures teaches when authority must be elevated, whom to contact, and when action must pause for a decision. Monitoring would detect behavior after it occurs, while changing roles is unnecessary unless the defined authority itself is unclear or unsuitable.
Question 78
Single choice
An organization has implemented a new email filter to mitigate risk associated with its email system. Who is BEST suited to be the control owner?
-
A
-
B
-
C
Head of corporate communications
-
D
Head of information security
Reveal answer details
Close answer details
Correct answerA
ExplanationThe control owner needs authority and accountability for the control's operation, maintenance, resources, and performance. Because the email filter is an operational technology control within the email environment, the head of the IT department is best positioned to manage it and ensure it functions as intended. Information security can define requirements and oversee risk without operating the control.
Question 79
Single choice
Which of the following is the BEST way to strengthen the alignment of an information security program with business strategy?
-
A
Establishing an information security steering committee
-
B
Increasing the frequency of control assessments
-
C
Providing organizational training on information security policies
-
D
Increasing budget for risk assessments
Reveal answer details
Close answer details
Correct answerA
ExplanationAn information security steering committee brings business and security leadership into a common governance forum. It can connect security priorities, investments, and risk decisions to organizational strategy and resolve competing business needs. More assessments, training, or budget may improve individual activities but do not create this governance alignment.
Question 80
Single choice
Which of the following is the PRIMARY responsibility of the information security function when an organization adopts emerging technologies?
-
A
Developing security training for the new technologies
-
B
Designing new security controls
-
C
Creating an acceptable use policy for the technologies
-
D
Assessing the potential security risk
Reveal answer details
Close answer details
Correct answerD
ExplanationBefore training, policies, or controls are designed for emerging technologies, the organization must understand the potential security risk created by their use. Risk assessment identifies relevant exposure and business impact, providing a basis for proportionate treatment. Designing controls first could address the wrong conditions or impose unnecessary restrictions.
Question 81
Single choice
Which of the following is MOST important to consider when prioritizing threats during the risk assessment process?
-
A
Regulatory requirements on the organization
-
B
The severity of exploited vulnerabilities
-
C
The threat landscape within the industry
-
D
The potential impact on operations
Reveal answer details
Close answer details
Correct answerD
ExplanationThreats should be prioritized according to the harm they could cause to business operations. Potential operational impact connects a threat to interrupted services, impaired objectives, and other business consequences. Vulnerability severity and the industry threat landscape are useful inputs, but neither establishes organizational priority without considering impact.
Question 82
Single choice
When deciding to move to a cloud-based model, the FIRST consideration should be:
-
A
storage in a shared environment.
-
B
availability of the data.
-
C
-
D
physical location of the data.
Reveal answer details
Close answer details
Correct answerC
ExplanationData classification identifies the sensitivity and business importance of the information being considered for cloud use. That classification establishes the protection requirements against which availability, shared storage, and location must be evaluated. Without knowing the data's classification first, the organization cannot determine which cloud safeguards and handling conditions are appropriate.
Question 83
Single choice
Which of the following is the BEST method to reduce the risk of an information security breach due to spear phishing?
-
A
Implementing a vulnerability management program
-
B
Deploying an intrusion protection system (IPS)
-
C
Establishing a company-wide information security awareness plan
-
D
Reviewing log files daily to identify any suspicious activity
Reveal answer details
Close answer details
Correct answerC
ExplanationSpear phishing targets human judgment with tailored messages intended to induce unsafe actions. A company-wide information security awareness plan prepares personnel to recognize suspicious approaches, verify unusual requests, and follow reporting procedures, reducing the chance that the attack succeeds. Vulnerability controls and an IPS address technical exposure, while daily log review detects activity after an attempted compromise.
Question 84
Single choice
Which of the following is the BEST method for reducing the risk of data loss due to phishing attacks?
-
A
Changing passwords frequently
-
B
Implementing data loss prevention
-
C
Using spam filtering solutions
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationPhishing succeeds by persuading users to disclose information, open harmful content, or approve deceptive requests. Educating users helps them recognize suspicious messages, verify requests, avoid unsafe actions, and report attempts. Spam filters reduce some messages, but user judgment remains necessary for phishing that reaches them through any channel.
Question 85
Single choice
Which of the following is the GREATEST value provided by a security information and event management (SIEM) system?
-
A
Maintaining a repository base of security policies
-
B
Measuring impact of exploits on business processes
-
C
Facilitating the monitoring of risk occurrences
-
D
Redirecting event logs to an alternate location for business continuity plan
Reveal answer details
Close answer details
Correct answerC
ExplanationA security information and event management system collects and correlates event information so potentially significant activity can be identified and monitored across systems. This facilitates visibility into risk occurrences and supports timely investigation. It does not primarily value business impact, maintain policy repositories, or provide continuity through log redirection.
Question 86
Single choice
Which of the following is the MOST effective way to address an organizations security concerns during contract negotiations with a third party?
-
A
Ensure security is involved in the procurement process.
-
B
Review the third-party contract with the organization's legal department.
-
C
Conduct an information security audit on the third-party vendor.
-
D
Communicate security policy with the third-party vendor.
Reveal answer details
Close answer details
Correct answerA
ExplanationSecurity involvement in procurement places security requirements, risk criteria, and contractual protections into the negotiation while terms can still be changed. This prevents the organization from committing to a service before its concerns are addressed. Legal review, audits, and policy communication can support the engagement but do not replace early security participation.
Question 87
Single choice
Which of the following is BEST determined by using technical metrics?
-
A
Whether controls are operating effectively
-
B
How well security risk is being managed
-
C
Whether security resources are adequately allocated
-
D
How well the security strategy is aligned with organizational objectives
Reveal answer details
Close answer details
Correct answerA
ExplanationTechnical metrics measure operational characteristics such as control availability, detection results, processing performance, and failure rates. These observations show whether specific controls are operating effectively. Overall risk management, resource allocation, and strategic alignment require business context and governance measures beyond technical data, so they cannot be determined from technical metrics alone.
Question 88
Single choice
Which of the following is the FIRST step in developing a business continuity plan (BCP)?
-
A
Determine the business recovery strategy
-
B
Determine available resources.
-
C
Identify the applications with the shortest recovery time objectives (RTOs).
-
D
Identify critical business processes.
Reveal answer details
Close answer details
Correct answerD
ExplanationContinuity planning must begin by identifying the business processes whose interruption would materially affect the organization. Their criticality then drives impact analysis, recovery objectives, application dependencies, resource requirements, and suitable recovery strategies. Selecting resources or a recovery approach first would lack the business priorities needed to justify those decisions.
Question 89
Single choice
Which of the following BEST enables the deployment of consistent security throughout international branches within a multinational organization?
-
A
Remediation of audit findings
-
B
Decentralization of security governance
-
C
Establishment of security governance
-
D
Maturity of security processes
Reveal answer details
Close answer details
Correct answerC
ExplanationEstablishment of security governance creates common authority, accountability, policies, and oversight for all branches. That enterprise-level direction allows security requirements to be applied consistently despite differences in local operations. Decentralizing governance would make variation more likely, while process maturity alone does not establish organization-wide direction.
Question 90
Single choice
Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:
-
A
Tracked and reported on until their final resolution
-
B
Noted and re-examined later if similar weaknesses are found
-
C
Documented in security awareness programs
-
D
Quickly resolved and eliminated regardless of cost
Reveal answer details
Close answer details
Correct answerA
ExplanationEven though the denial of service attack failed, the discovered weaknesses remain potential exposure and require accountable treatment. Tracking and reporting each weakness through final resolution assigns ownership, preserves visibility, and confirms that corrective action is completed. Deferring issues can leave them exploitable, while eliminating everything regardless of cost ignores risk-based prioritization.
Question 91
Single choice
Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?
-
A
Projected Increase in maturity level
-
B
Estimated reduction in risk
-
C
Projected costs over time
-
D
Estimated increase in efficiency
Reveal answer details
Close answer details
Correct answerB
ExplanationWhen direct financial return is difficult to calculate, estimated reduction in risk expresses the initiative's principal business value. It shows how the investment may lower the likelihood or impact of adverse events and supports comparison with the organization's risk tolerance. Cost, maturity, and efficiency measures do not capture the security outcome as directly.
Question 92
Single choice
Which of the following should be the PRIMARY basis for an information security strategy?
-
A
The organization's vision and mission
-
B
Results of a comprehensive gap analysis
-
C
Information security policies
-
D
Audit and regulatory requirements
Reveal answer details
Close answer details
Correct answerA
ExplanationThe organization's vision and mission define its purpose, direction, and intended outcomes. Information security strategy should derive from that foundation so protection priorities enable the enterprise rather than operate independently of it. Gap analyses, policies, and compliance obligations shape implementation after the strategic direction is established.
Question 93
Single choice
An organization has implemented a new security control in response to a recently discovered vulnerability. Several employees have voiced concerns that the control disrupts their ability to work. Which of the following is the information security manager's BEST course of action?
-
A
Evaluate compensating control options.
-
B
Educate users about the vulnerability.
-
C
Accept the vulnerability.
-
D
Report the control risk to senior management.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe new control reduces vulnerability risk but interferes with business operations, so the organization needs a treatment that addresses both conditions. Evaluating compensating control options can identify another safeguard that provides comparable risk reduction with less disruption. Simply educating users does not resolve the operational impact of the control.
Question 94
Single choice
An organization is conducting a post-incident review to determine the root cause of an information security incident. Which of the following situations would be MOST harmful to this investigation?
-
A
Unencrypted logs of the affected systems were saved on magnetic tapes.
-
B
Antivirus signature update processes failed on the affected systems.
-
C
Systems logs were cleared by the administrator to free up space on the affected systems.
-
D
The incident response plan has not been updated during the past year.
Reveal answer details
Close answer details
Correct answerC
ExplanationSystem logs preserve event sequences, timestamps, actions, and other details needed to reconstruct an incident and determine its root cause. Clearing those logs destroys direct investigative information and may prevent reviewers from establishing what occurred. Failed antivirus updates may have contributed to the event, but they do not damage the investigation as severely as removing the records needed to analyze it.
Question 95
Single choice
An external security audit has reported multiple instances of control noncompliance. Which of the following is MOST important for the information security manager to communicate to senior management?
-
A
Control owner responses based on a root cause analysis
-
B
The impact of noncompliance on the organization's risk profile
-
C
A noncompliance report to initiate remediation activities
-
D
A business case for transferring the risk
Reveal answer details
Close answer details
Correct answerB
ExplanationSenior management needs the business significance of control noncompliance in order to make informed risk decisions. Explaining its impact on the organization's risk profile connects the audit findings to exposure, priorities, and possible treatment. Technical remediation records alone do not show leadership how the failures change organizational risk.
Question 96
Single choice
Which of the following is the MOST important reason for an organization to develop an information security governance program?
-
A
Establishment of accountability
-
B
Compliance with audit requirements
-
C
Creation of tactical solutions
-
D
Monitoring of security incidents
Reveal answer details
Close answer details
Correct answerA
ExplanationAn information security governance program establishes who owns security decisions, accepts risk, allocates resources, and oversees performance. This establishment of accountability is foundational because governance cannot operate when authority and responsibility are unclear. Audit compliance, tactical solutions, and incident monitoring are activities or outcomes that depend on that governance structure.
Question 97
Single choice
Which of the following is the GREATEST privacy concern when personal data is collected and processed?
-
A
More storage required to store collected data
-
B
Increased time and resources needed
-
C
Data collected without consent
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationConsent provides a legitimate basis for an individual to understand and agree to the collection and processing of personal data where consent is required. Collecting data without it directly undermines individual choice and creates a fundamental privacy violation. Storage demands and resource usage are operational concerns, while an outdated policy does not necessarily establish unauthorized collection.
Question 98
Single choice
An incident response team has been assembled from a group of experienced individuals, Which type of exercise would be MOST beneficial for the team at the first drill?
-
A
-
B
Black box penetration test
-
C
Disaster recovery exercise
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationFor a newly assembled team, a tabletop exercise provides a structured first opportunity to discuss an incident scenario, confirm roles, and work through decisions and communications. It exposes gaps in coordination and shared understanding without requiring a disruptive technical exercise. The members' individual experience does not yet demonstrate that they can operate effectively as one response team.
Question 99
Single choice
An organization is in the process of creating an agreement with a cloud provider. Who should determine the third party's destruction schedule for the organization's information?
-
A
The organization's information security manager
-
B
The cloud provider's information security manager
-
C
The organization's data owner
-
D
The cloud provider's data custodian
Reveal answer details
Close answer details
Correct answerC
ExplanationThe organization's data owner is accountable for determining how information must be handled throughout its lifecycle, including retention and destruction. That authority remains with the organization when storage or processing is outsourced to a cloud provider. Provider personnel may execute the schedule, but they should not decide the business and compliance requirements for the data.
Question 100
Single choice
During which stage of the software development life cycle (SDLC) should application security controls FIRST be addressed?
-
A
Software code development
-
B
-
C
-
D
Application system design
Reveal answer details
Close answer details
Correct answerC
ExplanationApplication security controls should first be addressed during requirements gathering, when business needs and protection obligations are defined. Early security requirements guide design, development, testing, and acceptance, reducing the need for costly later changes. Design and coding implement those requirements, while configuration management controls system changes after key security decisions have already been made.
|