CIMA Risk Management P3 Question # 23 Topic 3 Discussion

CIMA Risk Management P3 Question # 23 Topic 3 Discussion

P3 Exam Topic 3 Question 23 Discussion:
Question #: 23
Topic #: 3

HJK is a publishing company that employs several hundred staff A member of the company's IT Security Department contacted 30 members of HJK's staff selected at random, and told each one that his or her computer appeared to be infected with a virus The staff members were asked to provide their login details and corporate passwords so that IT Security could remove the virus remotely A total of six members of staff provided this information.

Which TWO of the following statements are correct?


A.

HJK's entire staff should be informed of the investigation and of the disappointing fact that six members of staff handed over their logins and passwords


B.

The investigation should be repeated in the future on a different sample of staff, using other reasons for asking for logins and passwords


C.

HJK's response should be limited to briefing the six staff members on their error and ensuring that they change their passwords.


D.

It was acceptable for the staff to surrender their details because the request had actually been made by members of HJK's IT Security Department.


E.

It was unethical for HJK's IT Security Department to contact staff in this manner, lying about the suspected presence of a virus in order to provoke a response.


Get Premium P3 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.