1. A risk analysis for a new system is being performed. For which of the following is business knowledge MORE important than IT knowledge?
A) Vulnerability analysis B) Cost-benefit analysis C) Impact analysis D) Balanced scorecard
2. Which of the following is the MOST important security consideration when using infrastructure as a Service (IaaS)?
A) User access management B) Compliance with internal standards C) Segmentation among guests D) Backup and recovery strategy
3. Which of the following sites would be MOST appropriate in the case of a very short recovery time objective (RTO)?
A) Mobile B) Redundant C) Shared D) Warm
4. Which of the following would provide the STRONGEST indication that senior management commitment to information security is lacking within an organization?
A) Inconsistent enforcement of information security policies B) A reduction in information security investment C) A high of information security risk acceptance D) The information security manager reports to the chief risk officer
5. Which of the following is the GREATEST risk associated with the lack of an effective data privacy program?
A) Failure to prevent fraudulent transactions B) Inability to manage access to private or sensitive data C) Inability to obtain customer confidence D) Failure to comply with data-related regulations
Leave a comment