1. Which of the following is the weakest element in any security solution?
A. Software products
B. Internet connections
C. Security policies
D. Humans - Answer D
2. When seeking to hire new employees, what is the first step?
A. Create a job description.
B. Set position classification.
C. Screen candidates.
D. Request résumés. - Answer A
3. Which of the following is a primary purpose of an exit interview?
A. To return the exiting employee's personal belongings
B. To review the nondisclosure agreement
C. To evaluate the exiting employee's performance
D. To cancel the exiting employee's network access accounts - Answer B
4. When an employee is to be terminated, which of the following should be done?
A. Inform the employee a few hours before they are officially terminated.
B. Disable the employee's network access just as they are informed of the termination.
C. Send out a broadcast email informing everyone that a specific employee is to be
terminated.
D. Wait until you and the employee are the only people remaining in the building before
announcing the termination. - Answer B
5. If an organization contracts with outside entities to provide key business functions or
services, such as account or technical support, what is the process called that is used to
ensure that these entities support sufficient security?
A. Asset identification
B. Third-party governance
C. Exit interview
D. Qualitative analysis - Answer B
6. A portion of the __________________ is the logical and practical investigation of
business processes and organizational policies. This process policy review ensures that
the stated and implemented business tasks, systems, and methodologies are practical,
efficient, and cost-effective, but most of all (at least in relation to security governance)
that they support security through the reduction of vulnerabilities and the avoidance,
reduction, or mitigation of risk.