AND SYSTEM SECURITY TEST 2026 FULL
SOLUTION STUDY RESOURCE
◉ Lin is writing a risk management report. Of the major categories
of reporting requirements, which one becomes the actual risk
response plan?
Answer: Documenting and tracking implementation of accepted
recommendations
◉ Oscar works for a health insurance company. He is creating a
Health Insurance Portability and Accountability Act (HIPAA)
compliance plan. In the section on monitoring, what should Oscar
specify to be continuously monitored for changes?
Answer: Regulations and risks
◉ POAM stands for:
A. processes of accountable management.
B. plan of accurate mitigation.
C. procedures of accident management.
D. plan of action and milestones.
, Answer: Plan of Action and Milestones
◉ Qualitative risk assessments determine the level of risk based on
the __________ and _________ of risk.
Answer: probability, impact
◉ Regarding risk assessments, _____________ define(s) what a system
does.
Answer: the mission of the system
◉ Rodrigo is a network security specialist. He wants to perform real-
time analysis of security data gathered from networked systems.
Which of the following is the best solution for Rodrigo to
implement?
Answer: Security information and event management (SIEM)
◉ The Family Educational Rights and Privacy Act (FERPA) applies to
all of the following, except:
Answer: a medical center that hired recent nursing graduates.
◉ The following are major components of risk assessments, except:
Answer: Identifying insurance options