Certified Information Security Manager Questions and Answers
When implementing a security policy for an organization handling personally identifiable information (Pll); the MOST important objective should be:
When establishing metrics for an information security program, the BEST approach is to identify indicators that:
Data classification is PRIMARILY the responsibility of:
The PRIMARY goal of the eradication phase in an incident response process is to:
Which of the following would be MOST important to include in a proposal justifying investments for an organization ' s information security program?
Following a risk assessment, an organization has made the decision to adopt a bring your own device (BYOD) strategy. What should the information security manager do NEXT?
Capacity planning would prevent:
Which of the following is the MOST important consideration when updating procedures for managing security devices?
Which of the following should an information security manager do FIRST when a mandatory security standard hinders the achievement of an identified business objective?
An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?
Which of the following MOST effectively identifies the organization’s ability to comply with legal, regulatory, and contractual requirements?
To overcome the perception that security is a hindrance to business activities, it is important for an information security manager to:
Which of the following is MOST relevant for an information security manager to communicate to the board of directors?
Which of the following is the PRIMARY role of an information security manager in a software development project?
An incident response plan is being developed for servers hosting sensitive information. In the event of a breach, who should make the decision to shut down the system?
During an information security audit, it was determined that IT staff did not follow the established standard when configuring and managing IT systems. Which of the following is the BEST way to prevent future occurrences?
The PRIMARY benefit of integrating information security activities into change management processes is to:
In an organization with a rapidly changing environment, business management has accepted an information security risk. It is MOST important for the information security manager to ensure:
Which of the following provides the MOST useful information for identifying security control gaps on an application server?
Which of the following is the PRIMARY objective of the incident management recovery phase?
IT projects have gone over budget with too many security controls being added post-production. Which of the following would MOST help to ensure that relevant controls are applied to a project?
Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:
Which type of backup BEST enables an organization to recover data after a ransomware attack?
A business continuity plan (BCP) should contain:
Which of the following is MOST helpful for determining which information security policies should be implemented by an organization?
Which of the following is the BEST course of action if the business activity residual risk is lower than the acceptable risk level?
Which of the following processes should be done NEXT after completing a business impact analysis (BIA)?
Which of the following is MOST important to include in an information security status report management?
Which of the following BEST enables an organization to evaluate the security posture of a cloud service?
Which of the following BEST supports effective and timely incident response?
An organization is experiencing a sharp increase in incidents related to phishing messages. The root cause is an outdated email filtering system that is no longer supported by the vendor. Which of the following should be the information security manager ' s FIRST course of action?
Which of the following plans should be invoked by an organization in an effort to remain operational during a disaster?
An information security manager is reporting on open items from the risk register to senior management. Which of the following is MOST important to communicate with regard to these risks?
Information security needs to invest in new tools to align with a recently updated bring your own device (BYOD) policy that now includes wearable technologies. Which of the following would BEST demonstrate return on investment (ROI) in risk management when presenting to the strategy committee for review?
Without prior approval, a training department enrolled the company in a free cloud-based collaboration site and invited employees to use it. Which of the following is the BEST response of the information security manager?
A software vendor has announced a zero-day vulnerability that exposes an organization ' s critical business systems. The vendor has released an emergency patch. Which of the following should be the information security managers PRIMARY concern?
Which of the following BEST enables the assignment of risk and control ownership?
An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?
Which of the following is the BEST approach to incident response for an organization migrating to a cloud-based solution?
Of the following, who is MOST appropriate to own the risk associated with the failure of a privileged access control?
Who is accountable for ensuring proper controls are in place to address the confidentiality and availability of an information system?
Which of the following is the MOST important consideration when determining which type of failover site to employ?
Which of the following is MOST important to ensuring information stored by an organization is protected appropriately?
Which of the following would BEST support the business case for an increase in the information security budget?
When a critical system incident is reported, the FIRST step of the incident handler should be to:
Which of the following is MOST helpful for protecting an enterprise from advanced persistent threats (APTs)?
Which of the following is the BEST way to ensure data is not co-mingled or exposed when using a cloud service provider?
Which of the following is the BEST way to evaluate the effectiveness of physical and environmental security controls implemented for fire-related disasters?
Which of the following is the BEST indication that an organization has integrated information security governance with corporate governance?
Which of the following is the BEST way to obtain support for a new organization-wide information security program?
Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?
Which of the following is a PRIMARY responsibility of the information security goxernance function?
Which of the following would BEST help to ensure compliance with an organization ' s information security requirements by an IT service provider?
Which of the following is an example of risk mitigation?
Which of the following is MOST likely to reduce the effectiveness of a SIEM system?
Which of the following is the MOST important factor in an organization ' s selection of a key risk indicator (KRI)?
An information security team has started work to mitigate findings from a recent penetration test. Which of the following presents the GREATEST risk to the organization?
Which of the following would MOST effectively ensure that a new server is appropriately secured?
Which of the following is MOST useful to an information security manager when reporting the performance of the information security program to senior management?
When drafting the corporate privacy statement for a public website, which of the following MUST be included?
A recent audit found that an organization ' s new user accounts are not set up uniformly. Which of the following is MOST important for the information security manager to review?
An organization is about to purchase a rival organization. The PRIMARY reason for performing information security due diligence prior to making the purchase is to:
The PRIMARY objective of a post-incident review of an information security incident is to:
Which of the following is the BEST defense-in-depth implementation for protecting high value assets or for handling environments that have trust concerns?
Of the following, who is accountable for data loss in the event of an information security incident at a third-party provider?
For event logs to be acceptable for incident investigation, which of the following is the MOST important consideration to establish chain of evidence?
Which of the following will ensure confidentiality of content when accessing an email system over the Internet?
In addition to executive sponsorship and business alignment, which of the following is MOST critical for information security governance?
Which of the following should be the MOST important consideration when establishing information security policies for an organization?
When multiple Internet intrusions on a server are detected, the PRIMARY concern of the information security manager should be to ensure:
An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done
FIRST?
Which of the following should be the PRIMARY basis for the development of a business case to obtain support for an information security project?
Which of the following is MOST important for responding effectively to security breaches?
During the selection of a Software as a Service (SaaS) vendor for a business process, the vendor provides evidence of a globally accepted information security certification. Which of the following is the MOST important consideration?
Which of the following is the GREATEST benefit of performing a tabletop exercise of the business continuity plan (BCP)?
Which of the following is the MOST critical factor for information security program success?
In the context of developing an information security strategy, which of the following provides the MOST useful input to determine the or
During the initiation phase of the system development life cycle (SDLC) for a software project, information security activities should address:
A data discovery project uncovers an unclassified process document. Of the following, who is BEST suited to determine the classification?
Reevaluation of risk is MOST critical when there is:
Which of the following BEST indicates that information assets are classified accurately?
To ensure the information security of outsourced IT services, which of the following is the MOST critical due diligence activity?
Which of the following is the BEST indicator of an organization ' s information security status?
Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?
An employee of an organization has reported losing a smartphone that contains sensitive information The BEST step to address this situation is to:
An online bank identifies a successful network attack in progress. The bank should FIRST:
Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?
Which of the following BEST supports information security management in the event of organizational changes in security personnel?
A Seat a-hosting organization ' s data center houses servers, appli
BEST approach for developing a physical access control policy for the organization?
Which of the following is the MOST important objective of post-incident review activities?
When developing security processes for handling credit card data on the business unit ' s information system, the information security manager should FIRST:
A global organization has outsourced security processes to a service provider by means of a global agreement. What is the MOST efficient approach to meet country-specific regulatory requirements?
Which of the following Is MOST useful to an information security manager when conducting a post-incident review of an attack?
Which of the following would be MOST helpful when creating information security policies?
Which of the following would be MOST effective in reducing the impact of a distributed denial of service (DDoS) attack?
Which of the following is MOST important for an information security manager to consider when developing a business continuity plan (BCP) for ransomware attacks?
Which of the following is the GREATEST benefit of conducting an organization-wide security awareness program?
Which of the following metrics provides the BEST evidence of alignment of information security governance with corporate governance?
An organization ' s marketing department wants to use an online collaboration service, which is not in compliance with the information security policy, A risk assessment is performed, and risk acceptance is being pursued. Approval of risk acceptance should be provided by:
An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?
When investigating an information security incident, details of the incident should be shared:
Which of the following BEST encourages staff to report issues related to information security?
Which of the following is the BEST indicator of a successful intrusion into an organization ' s systems?
ACISO learns that a third-party service provider did not notify the organization of a data breach that affected the service provider ' s data center. Which of the following should the CISO do FIRST?
During which phase of new system development should an organization FIRST address emerging risk?
When management changes the enterprise business strategy which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?
Which of the following BEST supports the incident management process for attacks on an organization ' s supply chain?
An information security manager has identified that privileged employee access requests to production servers are approved; but user actions are not logged. Which of the following should be the GREATEST concern with this situation?
Which of the following is the BEST way to reduce the risk associated with a bring your own device (BYOD) program?
Which of the following should be an information security manager s MOST important consideration when determining the priority for implementing security controls?
Which of the following tasks should be performed once a disaster recovery plan (DRP) has been developed?
An organization has purchased an Internet sales company to extend the sales department. The information security manager ' s FIRST step to ensure the security policy framework encompasses the new business model is to:
An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?
The PRIMARY purpose of vulnerability identification is to:
Which of the following will provide the MOST guidance when deciding the level of protection for an information asset?
The results of a risk assessment for a potential network reconfiguration reveal a high likelihood of sensitive data being compromised. What is the information security manager ' s BEST course of
action?
Which of the following should have the MOST influence on the development of information security policies?
Which of the following is the MOST important criterion when deciding whether to accept residual risk?
Which of the following activities is MOST appropriate to conduct during the eradication phase of a cyber incident response?
Which of the following should be updated FIRST to account for new regulatory requirements that impact current information security controls?
Which of the following is MOST important when designing security controls for new cloud-based services?
From a business perspective, the GREATEST benefit of an incident response plan is that it:
Which of the following is the BEST method to ensure compliance with password standards?
Which of the following BEST determines the allocation of resources during a security incident response?
Following an information security risk assessment of a critical system, several significant issues have been identified. Which of the following is MOST important for the information security manager to confirm?
The executive management of a domestic organization has announced plans to expand operations to multiple international locations. Which of the following should be the information security manager ' s FIRST step upon learning of these plans?
Which of the following is the BEST control to protect customer personal information that is stored in the cloud?
An incident management team is alerted ta a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:
An organization ' s main product is a customer-facing application delivered using Software as a Service (SaaS). The lead security engineer has just identified a major security vulnerability at the primary cloud provider. Within the organization, who is PRIMARILY accountable for the associated task?
If civil litigation is a goal for an organizational response to a security incident, the PRIMARY step should be to:
What should an information security manager do FIRST when an organization is planning to use a third-party cloud computing service for a critical business process?
The MOST appropriate time to conduct a disaster recovery test would be after:
Behavioral analytics tools are used PRIMARILY to manage risks within an organization by:
Which of the following should be considered FIRST when recovering a compromised system that needs a complete rebuild?
A PRIMARY benefit of adopting an information security framework is that it provides:
Which of the following is the MOST effective way to convey information security responsibilities across an organization?
Following a successful attack, an information security manager should be confident the malware @ continued to spread at the completion of which incident response phase?
Which of the following is the BEST way to achieve compliance with new global regulations related to the protection of personal information?
Which of the following BEST supports effective communication during information security incidents?
Which of the following is the GREATEST benefit of information asset classification?
Which of the following is the BEST way to help ensure alignment of the information security program with organizational objectives?
An organization recently identified a significant risk related to data exfiltration, and the information security manager is asked to quickly address this issue. The security team suggests a number of different security controls. Which of the following is the BEST approach for selecting controls to manage the risk?
Information security controls should be designed PRIMARILY based on:
Which of the following is the BEST option to lower the cost to implement application security controls?
Reverse lookups can be used to prevent successful:
Which of the following is the PRIMARY reason to assign a risk owner in an organization?
In a cloud technology environment, which of the following would pose the GREATEST challenge to the investigation of security incidents?
Information security policies should PRIMARILY reflect alignment with:
Which of the following should be an information security manager ' s FIRST course of action when one of the organization ' s critical third-party providers experiences a data breach?
A common drawback of email software packages that provide native encryption of messages is that the encryption:
An organization wants to migrate a proprietary application to be hosted by a third-party cloud hosting provider using a Platform as a Service (PaaS) model. Prior to selecting the cloud provider, what is MOST important for the organization to ensure?
Management has announced the acquisition of a new company. The information security manager of the parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies. To BEST address this concern, the information security manager should:
Which of the following is the BEST reason to implement a comprehensive information security management system?
To ensure continuous alignment with the organizational strategy
To gain senior management support for the information security program
To support identification of key risk indicators (KRIs)
Which of the following is MOST important to determine following the discovery and eradication of a malware attack?
A business impact analysis (BIA) should be periodically executed PRIMARILY to:
An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information about the effectiveness of compensating controls?
Who is BEST suited to determine how the information in a database should be classified?
An organization ' s HR department requires that employee account privileges be removed from all corporate IT systems within three days of termination to comply with a government regulation However, the systems all have different user directories, and it currently takes up to four weeks to remove the privileges Which of the following would BEST enable regulatory compliance?
What is the MOST important consideration for an organization operating in a highly regulated market when new regulatory requirements with high impact to the business need to be implemented?
Of the following, who is accountable for ensuring the incident response plan is tested?
Which of the following is the GREATEST concern resulting from the lack of severity criteria in incident classification?
Which of the following is the PRIMARY objective of information asset classification?
An organization finds it necessary to quickly shift to a work-fromhome model with an increased need for remote access security.
Which of the following should be given immediate focus?
Which of the following should an organization do FIRST upon learning that a subsidiary is located in a country where civil unrest has just begun?
Which of the following would pose the GREATEST risk to the preparedness of an incident response team?
When mitigation is the chosen risk treatment, which of the following roles is responsible for effective implementation of the chosen treatment?
Which type of plan is PRIMARILY intended to reduce the potential impact of security events that may occur?
Which of the following is a desired outcome of information security governance?
When taking a risk-based approach to vulnerability management, which of the following is MOST important to consider when prioritizing a vulnerability?
Which of the following BEST facilitates an information security manager ' s efforts to obtain senior management commitment for an information security program?
Which of the following is the MOST cost-effective method for assessing an organization’s incident response capabilities?
Risk treatment options should PRIMARILY focus on:
A global organization is considering its geopolitical security risks. Which of the following is the information security manager ' s BEST approach?
Which of the following is the BEST way to align security and business strategies?
Which of the following is the GREATEST inherent risk when performing a disaster recovery plan (DRP) test?
Which of the following should an information security manager do FIRST after discovering that a business unit has implemented a newly purchased application and bypassed the change management process?
To effectively manage an organization ' s information security risk, it is MOST important to:
Which of the following is MOST important when responding to a major securi ty incident?
An organization ' s disaster recovery plan (DRP) is documented and kept at a disaster recovery site. Which of the following is the BEST way to ensure the plan can be carried out in an emergency?
An organization recently activated its business continuity plan (BCP). Employees were notified during the event, but some did not fully follow the communications plan. What is the BEST way to prevent a recurrence?
Which of the following is the BEST reason to implement an information security architecture?
A backdoor has been identified that enabled a cyberattack on an organization’s systems. Integrating which of the following into the software development life cycle would BEST enable the organization to mitigate similar attacks in the future?
Which of the following analyses will BEST identify the external influences to an organization ' s information security?
Which of the following will have the MOST negative impact on the effectiveness of incident response processes?
Which of the following metrics would provide an accurate measure of an information security program ' s performance?
How would the information security program BEST support the adoption of emerging technologies?
Which of the following BEST determines an information asset ' s classification?
Which of the following would BEST mitigate accidental data loss events?
A business impact analysis (BIA) BEST enables an organization to establish:
The effectiveness of an incident response team will be GREATEST when:
Which of the following is the PRIMARY responsibility of the information security function when an organization adopts emerging technologies?
Following an unsuccessful denial of service (DoS) attack, identified weaknesses should be:
Meeting which of the following security objectives BEST ensures that information is protected against unauthorized disclosure?
Management would like to understand the risk associated with engaging an Infrastructure-as-a-Service (laaS) provider compared to hosting internally. Which of the following would provide the BEST method of comparing risk scenarios?
Which of the following is MOST important to ensuring that incident management plans are executed effectively?
Which of the following would be the GREATEST threat posed by a distributed denial of service (DDoS) attack on a public-facing web server?
Which of the following is the PRIMARY benefit of implementing a vulnerability assessment process?
Which of the following is the MOST important reason for an information security manager to archive and retain the organization ' s electronic communication and email data?
Which of the following is the PRIMARY outcome of a business impact analysis (BIA)?
An organization involved in e-commerce activities operating from its home country opened a new office in another country with stringent security laws. In this scenario, the overall security strategy should be based on:
Which of the following is the MOST important consideration when developing key performance indicators (KPIs) for the information security program?
Which of the following should be of GREATEST concern regarding an organization ' s security controls?
Which of the following is the MOST important role of the information security manager when the organization is in the process of adopting emerging technologies?
Which of the following should be of GREATEST concern to an information security manager when evaluating a cloud service provider?
Which of the following is the GREATEST privacy concern when personal data is collected and processed?
In order to understand an organization ' s security posture, it is MOST important for an organization ' s senior leadership to:
Which of the following should an information security manager do FIRST after a new cybersecunty regulation has been introduced?
Which of the following will BEST facilitate timely and effective incident response?
Which of the following is the MOST important characteristic of an effective information security metric?
Which of the following should occur FIRST in the process of managing security risk associated with the transfer of data from unsupported legacy systems to supported systems?
The MOST important reason for an organization to establish a social media policy is to:
Which of the following should an information security manager do FIRST when a vulnerability has been disclosed?
Which of the following is MOST helpful for aligning security operations with the IT governance framework?
When an organization experiences a disruptive event, the business continuity plan (BCP) should be triggered PRIMARILY based on:
Which of the following BEST enables an information security manager to demonstrate the effectiveness of the information security and risk program to senior management?
A daily monitoring report reveals that an IT employee made a change to a firewall rule outside of the change control process. The information security manager ' s FIRST step in addressing the issue should be to:
An incident response policy should include:
An incident response team recently encountered an unfamiliar type of cyber event. Though the team was able to resolve the issue, it took a significant amount of time to identify. What is the BEST way to help ensure similar incidents are identified more quickly in the future?
Which of the following is the MOST essential element of an information security program?
Which type of test is MOST effective in communicating the roles of end users to support timely identification and response to information security incidents?
The GREATEST benefit of an effective information security awareness program is the organization’s ability to:
Which of the following is MOST important for a healthcare organization to address during the requirements gathering phase of AI development?
The business value of an information asset is derived from:
In information security governance, which of the following has PRIMARY responsibility for ensuring compliance with regulations?
What is the PRIMARY objective of performing a vulnerability assessment following a business system update?
In a call center, the BEST reason to conduct a social engineering is to:
Which of the following is the MOST important outcome of a post-incident review?
An organization has identified IT failures in a call center application. Of the following, who should own this risk?
The PRIMARY advantage of single sign-on (SSO) is that it will:
Which of the following is MOST important for an organization to have in place to determine the effectiveness of information security governance?
The information security manager has been notified of a new vulnerability that affects key data processing systems within the organization Which of the following should be done FIRST?
A small organization needs to use a solution that is out of support in order to meet business objectives. Which of the following is the information security manager’s BEST course of action to manage the associated risk?
Which of the following is the MOST effective control to prevent proliferation of shadow IT?
Which of the following devices, when placed in a demilitarized zone (DMZ), would be considered the MOST significant exposure?
Which of the following is the BEST indication of information security strategy alignment with the “ &
Which of the following is the BEST way to improve an organization ' s ability to detect and respond to incidents?
The MOST important reason to classify security incidents is to:
Which of the following is the BEST way to improve an organization’s ability to detect and respond to incidents?
Which of the following is the MOST important objective of a disaster recovery test?
Company A, a cloud service provider, is in the process of acquiring Company B to gain new benefits by incorporating their technologies within its cloud services.
Which of the following should be the PRIMARY focus of Company A ' s information security manager?
Which of the following is the GREATEST challenge when developing key risk indicators (KRIs)?
When deciding to move to a cloud-based model, the FIRST consideration should be:
An incident response team has established that an application has been breached. Which of the following should be done NEXT?
Prior to implementing a bring your own device (BYOD) program, it is MOST important to:
Which of the following is MOST important when conducting a forensic investigation?
Which of the following is the MOST important reason to consider organizational culture when developing an information security program?
What should be the PRIMARY objective of an information security policy?
A financial company executive is concerned about recently increasing cyberattacks and needs to take action to reduce risk. The organization would BEST respond by:
Which of the following is the MOST important reason for an organization to communicate to affected parties that a security incident has occurred?
Which of the following is the BEST strategy when determining an organization’s approach to risk treatment?
Which is MOST important to identify when developing an effective information security strategy?
Detailed business continuity plans (BCPs) should be PRIMARILY based on:
Which of the following is the PRIMARY benefit of an information security awareness training program?
When establishing classifications of security incidents for the development of an incident response plan, which of the following provides the MOST valuable input?
To support effective risk decision making, which of the following is MOST important to have in place?
Which of the following provides the BEST evidence that a newly implemented security awareness program has been effective?
Which of the following is the MOST important detail to capture in an organization ' s risk register?
An organization is planning to outsource the execution of its disaster recovery activities. Which of the following would be MOST important to include in the outsourcing agreement?
Which of the following presents the GREATEST challenge when assessing the impact of emerging risk?
An information security manager has learned of an increasing trend in attacks that use phishing emails impersonating an organization ' s CEO in an attempt to commit wire transfer fraud. Which of the following is the BEST way to reduce the risk associated with this type of attack?
An investigation of a recent security incident determined that the root cause was negligent handing of incident alerts by system admit manager to address this issue?
An information security manager has been notified about a compromised endpoint device Which of the following is the BEST course of action to prevent further damage?
Which of the following provides the BEST indication of the return on information security investment?
Which of the following provides the MOST effective response against ransomware attacks?
Which of the following should be the PRIMARY basis for determining the value of assets?
Who is accountable for approving an information security governance framework?
Which of the following would BEST enable the timely execution of an incident response plan?
A security incident has been reported within an organization. When should an information security manager contact the information owner?
Which of the following would be of GREATEST assistance in determining whether to accept residual risk of a critical security system?
Which of the following is a prerequisite for formulating a business continuity plan (BCP)?
Which of the following is the BEST method for determining whether new risks exist in legacy systems?
An organization has identified an active cyberattack on its internal network. Which of the following considerations is MOST important to the success of the incident response?
Which of the following is the MOST effective way to help staff members understand their responsibilities for information security?
When performing a business impact analysis (BIA), who should be responsible for determining the initial recovery time objective (RTO)?
Which of the following is the MOST effective way to ensure the security of services and solutions delivered by third-party vendors?
An organization has implemented a new customer relationship management (CRM) system. Who should be responsible for enforcing authorized and controlled access to the CRM data?
Which of the following is established during the preparation phase of an incident response plan?
Which of the following would BEST ensure that security is integrated during application development?
An information security team has discovered that users are sharing a login account to an application with sensitive information, in violation of the access policy. Business management indicates that the practice creates operational efficiencies. What is the information security manager ' s BEST course of action?
Which of the following is the MOST critical input to developing policies, standards, and procedures to secure information assets?
In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?
Which of the following is the MOST important reason to have documented security procedures?
Which of the following BEST illustrates residual risk within an organization?
An organization is planning to outsource network management to a service provider. Including which of the following in the contract would be the MOST effective way to mitigate information security risk?
During which of the following phases should an incident response team document actions required to remove the threat that caused the incident?
Which of the following is the FIRST step to establishing an effective information security program?
Which of the following should the information security manager do FIRST after a ransomware attack is confirmed?
Which of the following is the MOST effective way to demonstrate alignment of information security strategy with business objectives?
Recovery time objectives (RTOs) are an output of which of the following?
Which of the following is the GREATEST benefit of classifying information security incidents?
An information security team is investigating an alleged breach of an organization ' s network. Which of the following would be the BEST single source of evidence to review?
What should be the GREATEST concern for an information security manager of a large multinational organization when outsourcing data processing to a cloud service provider?
Which of the following BEST ensures timely and reliable access to services?
An information security manager has been asked to provide contract guidance from a security perspective for outsourcing the organization’s payroll processing. Which of the following is MOST important to address?
Which of the following BEST enables staff acceptance of information security policies?
Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?
An organization is close to going live with the implementation of a cloud-based application. Independent penetration test results have been received that show a high-rated vulnerability. Which of the following would be the BEST way to proceed?
Which type of system is MOST effective for prioritizing cyber incidents based on impact and tracking them until they are closed?
Which of the following is the PRIMARY benefit achieved when an information security governance framework is aligned with corporate governance?
Which of the following is the MOST important consideration when evaluating the performance of existing security controls?
Which of the following is the MOST effective way to help assure the integrity of an organization’s accounting system?
Which of the following should be the PRIMARY focus of a lessons learned exercise following a successful response to a cybersecurity incident?
Which of the following would be the MOST effective way to present quarterly reports to the board on the status of the information security program?
Which of the following is an information security manager ' s BEST course of action when a penetration test reveals a security exposure due to a firewall that is not configured correctly?
An information security manager has identified that security risks are not being treated in a timely manner. Which of the following
Which of the following is MOST important for an information security manager to verify before conducting full-functional continuity testing?
Which of the following BEST facilitates effective incident response testing?
The PRIMARY purpose for conducting cybersecurity risk assessments is to:
Which of the following is the MOST likely reason for a vulnerability scanner to return incomplete results?
Which of the following is the PRIMARY reason to regularly update business continuity and disaster recovery documents?
As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?
What is the PRIMARY benefit to an organization that maintains an information security governance framework?
Which of the following BEST contributes to establishing an information security culture within an organization?
Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?
When collecting admissible evidence, which of the following is the MOST important requirement?
Which of the following is the GREATEST value provided by a security information and event management (SIEM) system?
Management decisions concerning information security investments will be MOST effective when they are based on:
Which of the following presents the GREATEST risk associated with the use of an automated security information and event management (SIEM) system?
Within the confidentiality, integrity, and availability (CIA) triad, which of the following activities BEST supports the concept of
confidentiality?
Determining the risk for a particular threat/vulnerability pair before controls are applied can be expressed as:
Which risk is introduced when using only sanitized data for the testing of applications?
From an information security perspective, legal issues associated with a transborder flow of technology-related items are MOST often
Which of the following business units should own the data that populates an identity management system?
An information security manager finds a legacy application has no defined data owner. Of the following, who would be MOST helpful in identifying the appropriate data owner?
Which of the following has the GREATEST impact on efforts to improve an organization ' s security posture?
Which of the following provides an information security manager with the MOST accurate indication of the organization ' s ability to respond to a cyber attack?
When selecting metrics to monitor the effectiveness of an information security program, it is MOST important for an information security manager to:
Which of the following is the BEST approach when creating a security policy for a global organization subject to varying laws and regulations?
Which of the following is ESSENTIAL to ensuring effective incident response?
Which of the following is the BEST indicator of an emerging incident?
A PRIMARY purpose of creating security policies is to:
Which of the following is the MOST important consideration during the design phase of a business impact analysis (BIA)?
A KEY benefit of effective information security governance is:
Which of the following is the MOST important consideration when defining control objectives?
Which of the following would BEST enable a new information security manager to obtain senior management support for an information security governance program?
Which of the following BEST describes a buffer overflow?
Which of the following is the PRIMARY objective of testing security controls within a critical infrastructure?
Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Which of the following is the PRIMARY impact of organizational culture on the effectiveness of an information security program?
Which of the following is MOST likely to be the cause of systems and applications missing critical patches?
Which of the following BEST helps to ensure the effective execution of an organization ' s disaster recovery plan (DRP)?
What is the BEST way to address vulnerabilities associated with a recent increase in the number of zero-day attacks?
Which of the following would BEST guide the development and maintenance of an information security program?
Which of the following is the MOST important function of an information security steering committee?