Predetermined containment methods to be used in a cybersecurity incident response should be based PRIMARILY on the:
Which of the following functions is MOST critical when initiating the removal of system access for terminated employees?
An organization that conducts business globally is planning to utilize a third-party service provider to process payroll information. Which of the following issues poses the GREATEST risk to the organization?
A common drawback of email software packages that provide native encryption of messages is that the encryption:
After a server has been attacked, which of the following is the BEST course of action?
An organization plans to implement a new e-commerce operation in a highly regulated market. Which of the following is MOST important to consider when updating the risk management strategy?
Which of the following is the PRIMARY reason for an information security manager to periodically review existing controls?
Which type of test is MOST effective in communicating the roles of end users to support timely identification and response to information security incidents?
Which of the following is the MOST effective defense against malicious insiders compromising confidential information?
Within the confidentiality, integrity, and availability (CIA) triad, which of the following activities BEST supports the concept of
confidentiality?
Which of the following is the PRIMARY objective of incident triage?
Which of the following is the BEST reason to implement a comprehensive information security management system?
To ensure continuous alignment with the organizational strategy
To gain senior management support for the information security program
To support identification of key risk indicators (KRIs)
Which of the following is the MOST effective way to address an organizations security concerns during contract negotiations with a third party?
Which of the following is MOST likely to be the cause of systems and applications missing critical patches?
Which of the following BEST facilitates effective strategic alignment of security initiatives?
A business impact analysis (BIA) BEST enables an organization to establish:
An employee has just reported the loss of a personal mobile device containing corporate information. Which of the following should the information security manager do FIRST?
The PRIMARY benefit of integrating information security activities into change management processes is to:
As part of a risk assessment, a security control was discovered to be inadequate. When assigning a risk owner, which of the following attributes is MOST important to consider?
What is the BEST way to reduce the impact of a successful ransomware attack?