AND ANSWERS SURE A+
✔✔The implementation of a security program requires: - ✔✔a person that takes
ownership of each activity
✔✔The manipulation of staff to perform unauthorized actions is known as: -
✔✔NNTPSocial engineering
✔✔Audit is a form of: - ✔✔business assurance
✔✔When an organization undertakes a program to outsource the IT function what must
it do as part of the outsourcing program? - ✔✔Ensure that security requirements are
addressed in any contracts
✔✔What is the best way to understand business priorities? - ✔✔Interviews with senior
management
✔✔In case the implementation of an IT project fails, what is the next step? -
✔✔Rollback the implementation if possible
, ✔✔A gap analysis can be used to: - ✔✔Determine the disparity between current and
desired state
✔✔Every policy should be backed up through the use of: - ✔✔Procedures, standards
and baselines
✔✔The testing and evaluation of the security of a system made in support of the
decision to implement the system is known as - ✔✔Certification
✔✔Ensuring that a system is not implemented until it has been formally approved by a
senior manager is part of: - ✔✔Accreditation
✔✔Teaching staff how to use a new security tool is known as: - ✔✔Training
✔✔To ensure the quality and adherence to standards for a modification to a system the
organization enforces: - ✔✔Change control
✔✔One of the most important considerations when two organizations are considering a
merger is? - ✔✔Confidentiality
✔✔What document is used to set out the expectations for vendors or suppliers? -
✔✔Service level agreements
✔✔Good information security metrics are clear, timely and? - ✔✔Relevant
✔✔A vulnerability test is intended to: - ✔✔Find weaknesses in the system
✔✔True/False: Penetration testing and vulnerability assessments can be either internal
or external. - ✔✔True
✔✔True/False: Gathering data to evaluate the security program cannot be done through
interviews since the answers are too subjective. - ✔✔False
✔✔Metrics to evaluate the effectiveness of system controls may be based on: - ✔✔Key
performance indicators (KPIs)
✔✔The three authentication factors are: - ✔✔knowledge, ownership, biometric
✔✔Sensitive information about a person is called: - ✔✔PII
✔✔Remote access poses the risk that - ✔✔Unauthorized users may use remote access
systems to gain access