Filters
Question type

The policy administrator is responsible for the creation, revision, distribution, and storage of the policy.

A) True
B) False

Correct Answer

verifed

verified

A(n) strategic ​information security policy is also known as a general security policy, and sets the strategic direction, scope, and tone for all security efforts. _________________________

A) True
B) False

Correct Answer

verifed

verified

Within security perimeters the organization can establish security redundancies, each with differing levels of security, between which traffic must be screened. _________________________

A) True
B) False

Correct Answer

verifed

verified

Security training provides detailed information and hands-on instruction to employees to prepare them to perform their duties securely.

A) True
B) False

Correct Answer

verifed

verified

​The goals of information security governance include all but which of the following?


A) Regulatory compliance by using information security knowledge and infrastructure to support minimum standards of due care
B) ​Strategic alignment of information security with business strategy to support organizational objectives
C) ​Risk management by executing appropriate measures to manage and mitigate threats to information resources
D) ​Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved

E) A) and D)
F) B) and C)

Correct Answer

verifed

verified

Failure to develop an information security system based on the organization's mission, vision, and culture guarantees the failure of the information security program.

A) True
B) False

Correct Answer

verifed

verified

The SETA program is a control measure designed to reduce the instances of __________ security breaches by employees.


A) intentional
B) external
C) accidental
D) physical

E) A) and C)
F) A) and B)

Correct Answer

verifed

verified

_________ is the rapid determination of the scope of the breach in the confidentiality, integrity, and availability of information and information assets during or just following an incident.


A) Damage assessment
B) Containment development
C) Incident response
D) Disaster assessment

E) A) and C)
F) B) and D)

Correct Answer

verifed

verified

Good security programs begin and end with policy.

A) True
B) False

Correct Answer

verifed

verified

To remain viable, security policies must have a responsible manager, a schedule of reviews, a method for making recommendations for reviews, and a policy issuance and revision date. _________________________

A) True
B) False

Correct Answer

verifed

verified

Showing 101 - 110 of 110

Related Exams

Show Answer