Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?
Which of the following is the MOST important consideration when evaluating the performance of existing security controls?
Penetration testing is MOST appropriate when a:
An organization needs to comply with new security incident response requirements. Which of the following should the information security manager do FIRST?
Which of the following should be done FIRST when establishing a new data protection program that must comply with applicable data privacy regulations?
Measuring which of the following is the MOST accurate way to determine the alignment of an information security strategy with organizational goals?
The PRIMARY purpose for deploying information security metrics is to:
Which of the following should an information security manager do FIRST when creating an organization ' s disaster recovery plan (DRP)?
When an organization experiences a disruptive event, the business continuity plan (BCP) should be triggered PRIMARILY based on:
Which of the following is MOST important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals?
Which of the following BEST determines the allocation of resources during a security incident response?
A business unit recently integrated the organization ' s new strong password policy into its business application which requires users to reset passwords every 30 days. The help desk is now flooded with password reset requests. Which of the following is the information security manager ' s BEST course of action to address this situation?
Which of the following is BEST to include in a business case when the return on investment (ROI) for an information security initiative is difficult to calculate?
Which of the following MOST directly influences the efficiency of incident response immediately after an incident has been detected?
Which of the following is the GREATEST benefit of including incident classification criteria within an incident response plan?
Which of the following should be the NEXT step after a security incident has been reported?
For the information security manager, integrating the various assurance functions of an organization is important PRIMARILY to enable:
When evaluating cloud storage solutions, the FIRST consideration should be:
A healthcare company is working with a virtual reality (VR) vendor to provide a training solution for customers of the organization’s products. Which of the following is MOST important to include in the contract?
Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?