Topic 1: Exam Pool A
A recent audit found that an organization's new user accounts are not set up uniformly.
Which of the following is MOST important for the information security manager to review?
A.
Guidelines
B.
Automated controls
C.
Standards
D.
Security policies
Standards
Which of the following would be MOST useful to help senior management understand the
status of information security compliance?
A.
Key performance indicators (KPIs)
B.
Business impact analysis (BIA) results
C.
Industry benchmarks
D.
Risk assessment results
Risk assessment results
Which of the following is BEST to include in a business case when the return on investment
(ROI) for an information security initiative is difficult to calculate?
A.
Projected increase in maturity level
B.
Estimated increase in efficiency
C.
Projected costs over time
D.
Estimated reduction in risk
Estimated reduction in risk
When management changes the enterprise business strategy, which of the following
processes should be used to evaluate the existing information security controls as well as
to select new information security controls?
A.
Configuration management
B.
Risk management
C.
Change management
D.
Access control management
Risk management
The PRIMARY benefit of a centralized time server is that it
A.
allows decentralized logs to be kept in synchronization
B.
reduces individual time-of-day requests by client applications
C.
Is required by password synchronization programs
D.
decreases the likelihood of an unrecoverable systems failure
allows decentralized logs to be kept in synchronization
Page 6 out of 61 Pages |
Previous |