Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?
Which of the following is MOST appropriate for an organization to consider when defining incident classification and categorization levels?
Which of the following is the MOST important objective of post-incident review activities?
Which of the following would be the GREATEST threat posed by a distributed denial of service (DDoS) attack on a public-facing web server?
Which of the following should be done NEXT following senior management ' s decision to comply with new personal data regulations that are much more stringent than those currently followed to avoid massive fines?
An information security manager learns that an existing supplier plans to begin using its recently developed generative AI technology for the same scope of service. A risk assessment was performed on the supplier three months ago with no outstanding findings. Which of the following is the BEST course of action to address the associated risk?
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager ' s MOST important course of action?
Which of the following is the PRIMARY role of an information security manager in a software development project?
The use of a business case to obtain funding for an information security investment is MOST effective when the business case:
Which of the following is the GREATEST privacy concern when personal data is collected and processed?
Which of the following BEST enables staff acceptance of information security policies?
In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?
Which of the following is MOST important to the effectiveness of an information security steering committee?
Which of the following should be the PRIMARY focus of a lessons learned exercise following a successful response to a cybersecurity incident?
An organization is planning to outsource network management to a service provider. Including which of the following in the contract would be the MOST effective way to mitigate information security risk?
The MAIN reason for having senior management review and approve an information security strategic plan is to ensure:
A technical vulnerability assessment on a personnel information management server should be performed when:
Which of the following is the MOST important detail to capture in an organization ' s risk register?
An organization is implementing an information security governance framework. To communicate the program ' s effectiveness to stakeholders, it is MOST important to establish:
Which of the following is MOST important to emphasize when presenting information to gain senior management support for control enhancements?