The MOST important factor in ensuring the success of an information security program is effective:
A. communication of information security requirements to all users in the organization.
B. formulation of policies and procedures for information security.
C. alignment with organizational goals and objectives.
D. monitoring compliance with information security policies and procedures.
Which of the following BEST enables the deployment of consistent security throughout international branches within a multinational organization?
A. Maturity of security processes
B. Remediation of audit findings
C. Decentralization of security governance
D. Establishment of security governance
An information security organization should PRIMARILY:
A. support the business objectives of the company by providing security-related support services.
B. be responsible for setting up and documenting the information security responsibilities of the information security team members.
C. ensure that the information security policies of the company are in line with global best practices and standards.
D. ensure that the information security expectations are conveyed to employees.
A message* that has been encrypted by the sender's private key and again by the receiver's public key achieves:
A. authentication and authorization.
B. confidentiality and integrity.
C. confidentiality and nonrepudiation.
D. authentication and nonrepudiation.
For an enterprise implementing a bring your own device (BYOD) program, which of the following would provide the BEST security of corporate data residing on unsecured mobile devices?
A. Acceptable use policy
B. Device certification process
C. Containerization solution
D. Data loss prevention (DLP)
The MAIN reason for an information security manager to monitor industry level changes in the business and IT is to:
A. evaluate the effect of the changes on the levels of residual risk.
B. identity changes in the risk environment.
C. update information security policies in accordance with the changes.
D. change business objectives based on potential impact.
What should be the FIRST step when implementing data loss prevention (DLP) technology?
A. Perform due diligence with vendor candidates.
B. Build a business case.
C. Classify the organization's data.
D. Perform a cost-benefit analysis.
The PRIMARY goal of a post-incident review should be to:
A. establish the cost of the incident to the business.
B. determine why the incident occurred.
C. identify policy changes to prevent a recurrence.
D. determine how to improve the incident handling process.
Which of the following is the PRIMARY reason to assign a risk owner in an organization?
A. To remediate residual risk
B. To define responsibilities
C. To ensure accountability
D. To identify emerging risk
Which of the following would be MOST effective in gaining senior management approval of security investments in network infrastructure?
A. Performing penetration tests against the network to demonstrate business vulnerability
B. Highlighting competitor performance regarding network best security practices
C. Demonstrating that targeted security controls tie to business objectives
D. Presenting comparable security implementation estimates from several vendors