Which of the following BEST indicates ongoing senior management commitment to the organization’s information security strategy?
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
Which of the following components of an information security risk assessment is MOST valuable to senior management?
An information security manager has been tasked with developing materials to update the board, regulatory agencies, and the media about a security incident. Which of the following should the information security manager do FIRST?
Which of the following is the PRIMARY benefit of training service desk staff to recognize incidents?
The MOST appropriate time to conduct a disaster recovery test would be after:
Which of the following is the BEST way to assess the risk associated with using a Software as a Service (SaaS) vendor?
Which of the following is MOST important to have in place to help ensure an organization ' s cybersecurity program meets the needs of the business?
Which of the following is MOST important when conducting a forensic investigation?
A department has reported that a security control is no longer effective. Which of the following is the information security manager ' s BEST course of action?
Which of the following is MOST important for the information security manager to include when presenting changes in the security risk profile to senior management?
Of the following, who is BEST suited to own the risk discovered in an application?
Which of the following activities is MOST appropriate to conduct during the eradication phase of a cyber incident response?
Which of the following BEST supports investments in an information security program?
During which of the following phases should an incident response team document actions required to remove the threat that caused the incident?
Which of the following service offerings in a typical Infrastructure as a Service (laaS) model will BEST enable a cloud service provider to assist customers when recovering from a security incident?
The PRIMARY advantage of single sign-on (SSO) is that it will:
In order to understand an organization ' s security posture, it is MOST important for an organization ' s senior leadership to:
Which of the following should an information security manager do FIRST upon confirming a privileged user ' s unauthorized modifications to a security application?
The PRIMARY advantage of performing black-box control tests as opposed to white-box control tests is that they: