1-2 QUESTIONS AND
VERIFIED CORRECT
ANSWERS GRADED A+
LATEST 100% GUARANTEED
PASS
Security Benchmarks and Top 20 as discussed in class that are used to harden security
appliances, operating systems applications, or security environments can be obtained from
which organization - CORRECT ANSWER-None of the above
What two things oocur if one does not have sound Configuration Management process and
procedures in place and positively acted upon? - CORRECT ANSWER-The security posture of a
system or capability cannot be determined without sound Configuration Management process
and procedures in place and positively acted upon
IN RACI you cannot have more then one "A" assigned to a task, even for those high priority tasks
assigned by the Board of Directors - CORRECT ANSWER-True
Due Care = Do Correct (CISSP Hint, Shon Harris, 4th Ed) - CORRECT ANSWER-False
Operational planning is anything greater then 10 months or more - CORRECT ANSWER-False
Information security could be part of an organizations IT Security organization - CORRECT
ANSWER-True
, Information Security is the same as Privacy - CORRECT ANSWER-False
The major deference as presented in class as to what is considered data and what is considered
information is context - CORRECT ANSWER-True
Security Steering Committee can be instrumental in gaining consensus to aid security program
activities as well as serving as a forum for dispute resolution - CORRECT ANSWER-True
A privacy Impact Assessment/Analysis must be accomplished when there is an upgrade or
change to an existing capability - CORRECT ANSWER-True
Security configuration management is the management and control of configurations for an
information system with the goal of enabling security and managing risk. - CORRECT ANSWER-
True
Payment Card Industry is a law that applies to All organizations that store, process, or transmit
cardholder data do so in a secure environment - CORRECT ANSWER-False
The five Risk Management Process core components include the following except for - CORRECT
ANSWER-Treatment Monitoring
(Identification
Evaluation
Treatment Planning
Disposition)
Standards are important because - CORRECT ANSWER-They set security baselines across the
organization by defining the minimum security limits