- Policy and Process Life Cycle Management
- Support Legal Compliance and Advocacy
- Common Business Documents to Support Security
- Security Requirements for Contracts
- General Privacy Principles for Sensitive Information
- Support the Development of Policies Containing Standard Security Practices
- Exam Preparation Tasks
- Review All Key Topics
- Define Key Terms
- Review Questions
Review Questions
Your organization has recently been the victim of fraud perpetrated by a single employee. After a thorough analysis has been completed of the event, security experts recommend that security controls be established to require multiple employees to complete a task. Which control should you implement, based on the expert recommendations?
mandatory vacation
separation of duties
least privilege
continuous monitoring
Your company has recently decided to switch Internet service providers. The new provider has provided a document that lists all the guaranteed performance levels of the new connection. Which document contains this information?
SLA
ISA
MOU
IA
Your organization has signed a new contract to provide database services to another company. The partner company has requested that the appropriate privacy protections be in place within your organization. Which document should be used to ensure data privacy?
ISA
IA
NDA
PII
Your organization has recently undergone major restructuring. During this time, a new chief security officer (CSO) was hired. He has asked you to make recommendations for the implementation of organizational security policies. Which of the following should you not recommend?
All personnel are required to use their vacation time.
All personnel should be cross-trained and should rotate to multiple positions throughout the year.
All high-level transactions should require a minimum of two personnel to complete.
The principle of least privilege should be implemented only for all high-level positions.
What is the primary concern of PII?
availability
confidentiality
integrity
authentication
Which of the following is an example of an incident?
an invalid user account’s login attempt
account lockout for a single user account
several invalid password attempts for multiple users
a user attempting to access a folder to which he does not have access
What is the first step of a risk assessment?
Balance threat impact with countermeasure cost.
Calculate threat probability and business impact.
Identify vulnerabilities and threats.
Identify assets and asset value.
During a recent security audit, your organization provided the auditor with an SOA. What was the purpose of this document?
to identify the controls chosen by an organization and explain how and why the controls are appropriate
to document the performance levels that are guaranteed
to document risks
to prevent the disclosure of confidential information
Which document requires that a vendor reply with a formal bid proposal?
RFI
RFP
RFQ
agreement
Your company has decided to deploy network access control (NAC) on the enterprise to ensure that all devices comply with corporate security policies. Which of the following should be done first?
Develop the process for NAC.
Develop the procedures for NAC.
Develop the policy for NAC.
Implement NAC.
