After the occurrence of a major information security incident, which of the following will BEST help an information security manager determine corrective actions?
Predetermined containment methods to be used in a cybersecurity incident response should be based PRIMARILY on the:
The MOST important information for influencing management’s support of information security is:
Which of the following will BEST enable an effective information asset classification process?
Which of the following should be the PRIMARY basis for determining the value of assets?
Which of the following is the MOST important consideration when attempting to create a security-focused culture?
Which of the following BEST helps to enable the desired information security culture within an organization?
Who is accountable for ensuring proper controls are in place to address the confidentiality and availability of an information system?
Which of the following is the BEST way to improve an organization ' s ability to detect and respond to incidents?
An organization recently identified a significant risk related to data exfiltration, and the information security manager is asked to quickly address this issue. The security team suggests a number of different security controls. Which of the following is the BEST approach for selecting controls to manage the risk?
Which of the following is a viable containment strategy for a distributed denial of service (DDoS) attack?
Which of the following should an information security manager do FIRST upon confirming a privileged user ' s unauthorized modifications to a security application?
Which of the following would provide the MOST effective security outcome in an organizations contract management process?
An online bank identifies a successful network attack in progress. The bank should FIRST:
When assigning a risk owner, the MOST important consideration is to ensure the owner has:
The executive management of a domestic organization has announced plans to expand operations to multiple international locations. Which of the following should be the information security manager ' s FIRST step upon learning of these plans?
Which of the following is MOST important to include in an incident response plan to ensure incidents are responded to by the appropriate individuals?
Which of the following roles has the PRIMARY responsibility to ensure the operating effectiveness of IT controls?
What type of control is being implemented when a security information and event management (SIEM) system is installed?
Which of the following is the MOST effective way to detect security incidents?
Which of the following is the MOST essential element of an information security program?
Which of the following is the MOST important role of the information security manager when the organization is in the process of adopting emerging technologies?
Which of the following should review and approve the objectives within an organization’s information security framework?
Which of the following is MOST important to verify during a test of an organization’s incident response process?
Which of the following is the MOST important detail to capture in an organization ' s risk register?
Which of the following should an information security manager do FIRST after a new cybersecunty regulation has been introduced?
Which of the following is the BEST course of action when an online company discovers a network attack in progress?
An organization is in the process of defining policies for employee use of social media. It is MOST important for the information security manager to:
Which of the following processes BEST supports the evaluation of incident response effectiveness?
Which of the following would BEST demonstrate the status of an organization ' s information security program to the board of directors?
An organization experienced a loss of revenue during a recent disaster. Which of the following would BEST prepare the organization to recover?
Which of the following should be established FIRST when implementing an information security governance framework?
Which of the following BEST enables an organization to continuously assess the information security risk posture?
Which of the following should be the FIRST step in patch management procedures when receiving an emergency security patch?
As part of incident response activities, the BEST time to begin the recovery process is after:
An organization ' s security policy is to disable access to USB storage devices on laptops and desktops. Which of the following is the STRONGEST justification for granting an exception to the policy?
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
Which of the following would BEST help to ensure compliance with an organization ' s information security requirements by an IT service provider?
Which of the following is the BEST way to achieve compliance with new global regulations related to the protection of personal information?
An information security manager learns that a risk owner has approved exceptions to replace key controls with weaker compensating controls to improve process efficiency. Which of the following should be the GREATEST concern?
A business impact analysis (BIA) BEST enables an organization to establish:
Which of the following is MOST helpful in the development of a cost-effective information security strategy that is aligned with business requirements?
When evaluating cloud storage solutions, the FIRST consideration should be:
In violation of a policy prohibiting the use of cameras at the office, employees have been issued smartphones and tablet computers with enabled web cameras. Which of the following should be the information security manager ' s FIRST course of action?
An organization recently outsourced the development of a mission-critical business application. Which of the following would be the BEST way to test for the existence of backdoors?
Which type of recovery site is MOST reliable and can support stringent recovery requirements?
Which of the following is the MOST important security consideration when planning to use a cloud service provider in a different country?
Which of the following BEST helps to ensure risk appetite is considered during the risk treatment process?
Which of the following is the MOST important consideration during the design phase of a business impact analysis (BIA)?
Which of the following should be the PRIMARY consideration when developing an incident response plan?
Which of the following should be triggered FIRST when unknown malware has infected an organization ' s critical system?
The manager of a key project has bypassed the standard contractor onboarding process to acquire additional resources for delivering the project on time. Contracts were executed offline, and contractors were provided organizational access without going through the standard due diligence process. Which of the following should be the PRIMARY concern?
Following a breach where the risk has been isolated and forensic processes have been performed, which of the following should be done NEXT?
Which of the following BEST conveys minimum information security requirements to an organization in alignment with policies?
Which of the following BEST indicates senior management support for an information security program?
When defining a security baseline, it is MOST important that the baseline:
Which of the following is MOST important for a healthcare organization to address during the requirements gathering phase of AI development?
Within the confidentiality, integrity, and availability (CIA) triad, which of the following activities BEST supports the concept of
confidentiality?
An international organization with remote branches is implementing a corporate security policy for managing personally identifiable information (PII). Which of the following should be the information security manager ' s MAIN concern?
Which of the following is MOST relevant for an information security manager to communicate to the board of directors?
What is the PRIMARY benefit to an organization when information security program requirements are aligned with employment and staffing processes?
Which of the following is the MOST effective way to influence organizational culture to align with security guidelines?
An online trading company discovers that a network attack has penetrated the firewall. What should be the information security manager ' s FIRST response?
The MOST effective tools for responding to new and advanced attacks are those that detect attacks based on:
Which of the following would provide the BEST input to a business case for a technical solution to address potential system vulnerabilities?
Management decisions concerning information security investments will be MOST effective when they are based on:
When implementing a security policy for an organization handling personally identifiable information (Pll); the MOST important objective should be:
Which of the following is the BEST approach to reduce unnecessary duplication of compliance activities?
Which of the following is the BEST indicator of a successful intrusion into an organization ' s systems?
Which of the following has the GREATEST impact on efforts to improve an organization ' s security posture?
Which of the following should be the FIRST step when performing triage of a malware incident?
Which of the following is BEST used to determine the maturity of an information security program?
An organization has discovered that a server processing real-time visual data could be vulnerable to a lateral movement stage in a ransomware attack. Which of the following controls BEST mitigates this vulnerability?
Which of the following is the PRIMARY reason for conducting an incident response tabletop exercise?
Which of the following is MOST helpful in determining whether a phishing email is malicious?
Which of the following is the MOST effective control to prevent proliferation of shadow IT?
Which of the following is the BEST security control to minimize the risk of successful ransomware attacks?
An organization is considering the feasibility of implementing a big data solution to analyze customer data. In order to support this initiative, the information security manager should FIRST:
An information security team has discovered that users are sharing a login account to an application with sensitive information, in violation of the access policy. Business management indicates that the practice creates operational efficiencies. What is the information security manager ' s BEST course of action?
An organization is strategizing on how to improve security awareness. Which of the following is MOST important to consider when developing this strategy?
Which of the following is the BEST way to reduce the risk associated with a bring your own device (BYOD) program?
Which of the following is the MOST important consideration when updating procedures for managing security devices?
Which of the following should an information security manager do FIRST when developing an organization ' s disaster recovery plan (DRP)?
A startup company deployed several new applications with vulnerabilities into production because security reviews were not conducted. What will BEST help to ensure effective application risk management going forward?
An information security manager learns that business unit leaders are encouraging increased use of social media platforms to reach customers. Which of the following should be done FIRST to help mitigate the risk of confidential information being disclosed by employees on social media?
An organization has remediated a security flaw in a system. Which of the following should be done NEXT?
Which of the following MUST be established to maintain an effective information security governance framework?
What is the role of the information security manager in finalizing contract negotiations with service providers?
Which of the following is the PRIMARY objective of the incident management recovery phase?
When building support for an information security program, which of the following elements is MOST important?
Which of the following BEST indicates that an organization has effectively tested its business continuity and disaster recovery plans within the stated recovery time objectives (RTOs)?
Which of the following processes should be done NEXT after completing a business impact analysis (BIA)?
Which of the following is a function of the information security steering committee?
Which of the following is the MOST cost-effective method for assessing an organization’s incident response capabilities?
Senior management recently approved a mobile access policy that conflicts with industry best practices. Which of the following is the information security manager ' s BEST course of action when developing security standards for mobile access to the organization ' s network?
Which of the following BEST facilitates effective incident response testing?
Which of the following would be the BEST way for an information security manager to improve the effectiveness of an organization’s information security program?
After a server has been attacked, which of the following is the BEST course of action?
Of the following, who is MOST appropriate to own the risk associated with the failure of a privileged access control?
Which of the following BEST enables an incident response team to determine appropriate actions during an initial investigation?
Which of the following provides the MOST comprehensive insight into ongoing threats facing an organization?
Which of the following is the BEST indication of information security strategy alignment with the “ &
Which of the following should an information security manager do FIRST when creating an organization ' s disaster recovery plan (DRP)?
An employee of an organization has reported losing a smartphone that contains sensitive information The BEST step to address this situation is to:
An organization permits the storage and use of its critical and sensitive information on employee-owned smartphones. Which of the following is the BEST security control?
Which of the following is the MOST critical consideration when shifting IT operations to an Infrastructure as a Service (laaS) model hosted in a foreign country?
Meeting which of the following security objectives BEST ensures that information is protected against unauthorized disclosure?
Which of the following is the MOST important consideration for an incident response team seeking to limit the impact of incidents?
Which of the following is the MOST important consideration when establishing an organization ' s information security governance committee?
Which of the following is the BEST approach for governing noncompliance with security requirements?
When developing a business case to justify an information security investment, which of the following would BEST enable an informed decision by senior management?
An organization has introduced a new bring your own device (BYOD) program. The security manager has determined that a small number of employees are utilizing free cloud storage services to store company data through their mobile devices. Which of the following is the MOST effective course of action?
Which of the following is MOST important for an information security manager to consider when determining whether data should be stored?
Which of the following is the BEST way to evaluate the effectiveness of physical and environmental security controls implemented for fire-related disasters?
Which of the following should an information security manager do FIRST when noncompliance with security standards is identified?
Which of the following is the MOST appropriate action during the containment phase of a cyber incident response?
Which of the following is the PRIMARY reason to use a phased incident recovery approach?
Which of the following is the MOST important reason for logging firewall activity?
What should be the FIRST step when implementing data loss prevention (DLP) technology?
Regular vulnerability scanning on an organization ' s internal network has identified that many user workstations have unpatched versions of software. What is the BEST way for the information security manager to help senior management understand the related risk?
A multinational organization is introducing a security governance framework. The information security manager ' s concern is that regional security practices differ. Which of the following should be evaluated FIRST?
Which of the following is an information security manager ' s MOST important course of action when responding to a major security incident that could disrupt the business?
Which of the following security initiatives should be the FIRST step in helping an organization maintain compliance with privacy regulations?
An information security manager wants to document requirements detailing the minimum security controls required for user workstations. Which of the following resources would be MOST appropriate for this purposed?
An organization has multiple data repositories across different departments. The information security manager has been tasked with creating an enterprise strategy for protecting data. Which of the following information security initiatives should be the HIGHEST priority for the organization?
Behavioral analytics tools are used PRIMARILY to manage risks within an organization by:
Which of the following would BEST enable senior management to integrate security into all organizational processes following an increase in cyberattacks on business applications?
In the absence of technical controls, what would be the BEST way to reduce unauthorized text messaging on company-supplied mobile devices?
To improve an organization’s information security culture, it is MOST important for senior management to:
An organization plans to offer clients a new service that is subject to regulations. What should the organization do FIRST when developing a security strategy in support of this new service?
Which is the BEST method to evaluate the effectiveness of an alternate processing site when continuous uptime is required?
In addition to executive sponsorship and business alignment, which of the following is MOST critical for information security governance?
The ULTIMATE responsibility for ensuring the objectives of an information security framework are being met belongs to:
An organization ' s information security manager reads on social media that a recently purchased vendor product has been compromised and customer data has been posted online. What should the information security manager do FIRST?
When developing security processes for handling credit card data on the business unit ' s information system, the information security manager should FIRST:
Which of the following should an information security manager do FIRST when there is a conflict between the organization ' s information security policy and a local regulation?
Which of the following is the PRIMARY objective of a cyber resilience strategy?
Which of the following is the PRIMARY benefit achieved when an information security governance framework is aligned with corporate governance?
Which of the following would BEST enable a new information security manager to assess the current state of information security governance within the organization?
An information security manager of an e-commerce business is reviewing the results of a business continuity plan review. Which of the following findings should be the MOST immediate concern?
From a business perspective, the GREATEST benefit of an incident response plan is that it:
Which of the following is the BEST way to address data availability concerns when outsourcing information security administration?
What is the PRIMARY purpose of an unannounced disaster recovery exercise?
Which of the following is MOST important for an information security manager to verify before conducting full-functional continuity testing?
Which of the following is the MOST important reason to document information security incidents that are reported across the organization?
Data entry functions for a web-based application have been outsourced to a third-party service provider who will work from a remote site Which of the following issues would be of GREATEST concern to an information security manager?
The results of a risk assessment for a potential network reconfiguration reveal a high likelihood of sensitive data being compromised. What is the information security manager ' s BEST course of
action?
Which of the following metrics would BEST demonstrate the success of a newly implemented information security framework?
A business unit recently integrated the organization ' s new strong password policy into its business application which requires users to reset passwords every 30 days. The help desk is now flooded with password reset requests. Which of the following is the information security manager ' s BEST course of action to address this situation?
An incident handler is preparing a forensic image of a hard drive. Which of the following MUST be done to provide evidence that the image is an exact copy of the original?
Which of the following would be MOST useful to help senior management understand the status of information security compliance?
Which of the following BEST indicates the effectiveness of the vendor risk management process?
Which of the following is the MOST important function of an information security steering committee?
The MOST appropriate time to conduct a disaster recovery test would be after:
An intrusion has been detected and contained. Which of the following steps represents the BEST practice for ensuring the integrity of the recovered system?
An organization is MOST likely to accept the risk of noncompliance with a new regulatory requirement when:
Internal audit has reported a number of information security issues that are not in compliance with regulatory requirements. What should the information security manager do FIRST?
When conducting a post-implementation review for a security investment, it is MOST important to determine whether the investment:
Which of the following should be done FIRST when a SIEM flags a potential event?
An organization is planning to open a new office in another country. Sensitive data will be routinely sent between the two offices. What should be the information security manager’s FIRST course of action?
What is the PRIMARY objective of performing a vulnerability assessment following a business system update?
Which of the following is the BEST option to lower the cost to implement application security controls?
Which of the following provides the MOST useful information for identifying security control gaps on an application server?
Which type of policy BEST helps to ensure that all employees, contractors, and third-party users receive formal communication regarding an organization’s security program?
Of the following, who is BEST positioned to approve specific information security risk treatment options?
The PRIMARY purpose for continuous monitoring of security controls is to ensure:
Which of the following is the GREATEST benefit of conducting an organization-wide security awareness program?
An organization is going through a digital transformation process, which places the IT organization in an unfamiliar risk landscape. The information security manager has been tasked with leading the IT risk management process. Which of the following should be given the HIGHEST priority?
A financial institution is planning to develop a new mobile application. Which of the following is the BEST time to begin assessments of the application ' s security compliance?
Which of the following is the PRIMARY purpose of an acceptable use policy?
The MAIN benefit of implementing a data loss prevention (DLP) solution is to:
Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?
Which of the following is MOST important for the effective implementation of an information security governance program?
For an enterprise implementing a bring your own device program, which of the following would provide the BEST security for corporate data residing on unsecured mobile devices?
An organization is outsourcing a business function to an external vendor. Which of the following BEST enables management to ensure the vendor continuously complies with security requirements stated in the master contract?
An organization is increasingly using Software as a Service (SaaS) to replace in-house hosting and support of IT applications. Which of the following would be the MOST effective way to help ensure procurement decisions consider information security concerns?
Which of the following BEST facilitates effective strategic alignment of security initiatives?
Which of the following BEST indicates the effectiveness of a recent information security awareness campaign delivered across the organization?
Which of the following would MOST effectively ensure that a new server is appropriately secured?
Which of the following change management procedures is MOST likely to cause concern to the information security manager?
Which of the following would BEST guide the development and maintenance of an information security program?
When integrating security risk management into an organization it is MOST important to ensure:
An information security manager is assisting in the development of the request for proposal (RFP) for a new outsourced service. This will require the third party to have access to critical business information. The security manager should focus PRIMARILY on defining:
Which of the following is a PRIMARY benefit of managed security solutions?
Which of the following is the MOST important issue in a penetration test?
Which of the following MOST effectively identifies the organization’s ability to comply with legal, regulatory, and contractual requirements?
Following an information security risk assessment of a critical system, several significant issues have been identified. Which of the following is MOST important for the information security manager to confirm?
Which of the following should be done FIRST when establishing a new data protection program that must comply with applicable data privacy regulations?
An organization successfully responded to an information security incident. However, the information security manager learned that some of the steps specified in the incident management procedures were not taken by the response team. What should be the information security manager ' s FIRST step?
An organization is considering using a third party to host sensitive archived data. Which of the following is MOST important to verify before entering into the relationship?
Which of the following provides the BEST evidence that a recently established infofmation security program is effective?
Which of the following is the BEST technical defense against unauthorized access to a corporate network through social engineering?
ACISO learns that a third-party service provider did not notify the organization of a data breach that affected the service provider ' s data center. Which of the following should the CISO do FIRST?
Which of the following is the BEST tool to monitor the effectiveness of information security governance?
An anomaly-based intrusion detection system (IDS) operates by gathering data on:
Which of the following is the BEST way to determine the effectiveness of an incident response plan?
Which of the following BEST enables an organization to provide ongoing assurance that legal and regulatory compliance requirements can be met?
Which of the following would be MOST helpful to identify worst-case disruption scenarios?
Which of the following is MOST important for an information security manager to consider when developing a business continuity plan (BCP) for ransomware attacks?
Which of the following roles is BEST suited to validate user access requirements during an annual user access review?
Which of the following is the BEST way for an organization to ensure that incident response teams are properly prepared?
Which of the following MUST be defined in order for an information security manager to evaluate the appropriateness of controls currently in place?
Which of the following is MOST important to the effectiveness of an information security steering committee?
Which of the following will ensure confidentiality of content when accessing an email system over the Internet?
Which of the following would BEST help to ensure appropriate security controls are built into software?
Which of the following is the MOST important consideration when developing key performance indicators (KPIs) for the information security program?
An information security manager notes that security incidents are not being appropriately escalated by the help desk after tickets are logged. Which of the following is the BEST automated control to resolve this issue?
Which of the following will have the MOST negative impact on the effectiveness of incident response processes?
Which of the following is the PRIMARY benefit of implementing a vulnerability assessment process?
Which of the following is the BEST reason to implement a comprehensive information security management system?
To ensure continuous alignment with the organizational strategy
To gain senior management support for the information security program
To support identification of key risk indicators (KRIs)
Which risk is introduced when using only sanitized data for the testing of applications?
Which of the following is the PRIMARY benefit of a vulnerability scanning tool to an organization?
Which of the following will BEST facilitate integrating the information security program into corporate governance?
What should be the PRIMARY objective of an information classification scheme?
Which of the following is the BEST reason for senior management to support a business case for developing a monitoring system for a critical application?
What should be the GREATEST concern for an information security manager of a large multinational organization when outsourcing data processing to a cloud service provider?
A data loss prevention (DLP) tool has flagged personally identifiable information (Pll) during transmission. Which of the following should the information security manager do FIRST?
A financial company executive is concerned about recently increasing cyberattacks and needs to take action to reduce risk. The organization would BEST respond by:
When choosing the best controls to mitigate risk to acceptable levels, the information security manager ' s decision should be MAINLY driven by:
Which of the following is an information security manager ' s BEST course of action when a penetration test reveals a security exposure due to a firewall that is not configured correctly?
Which of the following desired outcomes BEST supports a decision to invest in a new security initiative?
Which of the following is MOST important to have in place for an organization ' s information security program to be effective?
Which of the following has the MOST influence on the information security investment process?
Which of the following is the PRIMARY reason to conduct a post-incident review?
Conducting log analysis falls into which phase of the incident management life cycle?
Which of the following roles is MOST appropriate to determine access rights for specific users of an application?
Which of the following should include contact information for representatives of equipment and software vendors?
A new risk has been identified in a high availability system. The BEST course of action is to:
Which of the following BEST determines an information asset ' s classification?
Which of the following presents the GREATEST challenge to the recovery of critical systems and data following a ransomware incident?
The PRIMARY benefit of integrating information security activities into change management processes is to:
Which of the following is the PRIMARY purpose of implementing information security standards?
An organization’s human resources department is planning to migrate a legacy application to a new application in the cloud. What is the BEST way for the information security manager to support this effort?
When updating the information security policy to accommodate a new regulation, the information security manager should FIRST:
Which of the following is the BEST approach for addressing noncompliance with security standards?
An organization is transitioning to a Zero Trust architecture. Which of the following is the information security manager ' s BEST approach for communicating the implications of this transition to the board of directors?
A small organization has a contract with a multinational cloud computing vendor. Which of the following would present the GREATEST concern to an information security manager if omitted from the contract?
Which of the following BEST indicates that information assets are classified accurately?
An information security team has confirmed that threat actors are taking advantage of a newly announced critical vulnerability within an application. Which of the following should be done
FIRST?
Identifying which of the following BEST enables a cyberattack to be contained?
An organization is in the process of selecting a third party to process customer information. Which of the following provides the BEST evidence that the third party’s controls will operate as required?
Senior management has expressed concern that the organization ' s intrusion prevention system (IPS) may repeatedly disrupt business operations Which of the following BEST indicates that the information security manager has tuned the system to address this concern?
Management has announced the acquisition of a new company. The information security manager of the parent company is concerned that conflicting access rights may cause critical information to be exposed during the integration of the two companies. To BEST address this concern, the information security manager should:
Who is BEST suited to determine how the information in a database should be classified?
The categorization of incidents is MOST important for evaluating which of the following?
Which of the following would BEST address the risk of a system failing to detect a breach?
Which of the following should an information security manager do FIRST upon learning that a competitor has experienced a ransomware attack?
After logging in to a web application, additional authentication is checked at various application points. Which of the following is the PRIMARY reason for such an approach?
The PRIMARY consideration when responding to a ransomware attack should be to ensure:
Which of the following is the MOST important objective when planning an incident response program?
A business requires a legacy version of an application to operate but the application cannot be patched. To limit the risk exposure to the business, a firewall is implemented in front of the legacy application. Which risk treatment option has been applied?
When an organization lacks internal expertise to conduct highly technical forensics investigations, what is the BEST way to ensure effective and timely investigations following an information security incident?
An organization ' s disaster recovery plan (DRP) is documented and kept at a disaster recovery site. Which of the following is the BEST way to ensure the plan can be carried out in an emergency?
Which of the following is MOST important to include in an information security status report to senior management?
Which of the following should be done FIRST to prioritize response to incidents?
Which of the following incident response phases involves actions to help safeguard critical systems while maintaining business operations?
An experienced information security manager joins a new organization and begins by conducting an audit of all key IT processes. Which of the following findings about the vulnerability management program should be of GREATEST concern?
Of the following, who is responsible for ensuring security controls are aligned with business objectives and regulatory requirements?
After detecting an advanced persistent threat, which of the following should be the information security manager’s FIRST step?
An organization has been penalized by regulatory authorities for failing to notify them of a major security breach that may have compromised customer data. Which of the following is MOST likely in need of review and updating to prevent similar penalties in the future?
Which of the following should have the MOST influence on an organization ' s response to a new industry regulation?
The BEST way to identify the risk associated with a social engineering attack is to:
An organization ' s marketing department wants to use an online collaboration service, which is not in compliance with the information security policy, A risk assessment is performed, and risk acceptance is being pursued. Approval of risk acceptance should be provided by:
An organization is creating a risk mitigation plan that considers redundant power supplies to reduce the business risk associated with critical system outages. Which type of control is being considered?
Which of the following BEST indicates the organizational benefit of an information security solution?
Which of the following is the MOST effective way to convey information security responsibilities across an organization?
In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?
Which of the following should be the FIRST consideration when developing a strategy for protecting an organization ' s data?
To inform a risk treatment decision, which of the following should the information security manager compare with the organization ' s risk appetite?
The MOST significant security issue resulting from the growth in the number of mobile devices and an increase in their flexibility is the:
Which of the following is the MOST appropriate risk response when the risk impact has been determined to be immaterial and the likelihood is very low?
Which of the following would be an information security managers PRIMARY challenge when deploying a bring your own device (BYOD) mobile program in an enterprise?
Senior management is concerned about data exposure through the use of public Al services. Which of the following is the information security manager ' s BEST course of action?
Which type of system is MOST effective for prioritizing cyber incidents based on impact and tracking them until they are closed?
Which of the following is MOST effective in preventing the introduction of vulnerabilities that may disrupt the availability of a critical business application?
A cloud application used by an organization is found to have a serious vulnerability. After assessing the risk, which of the following would be the information security manager ' s BEST course of action?
Which of the following BEST helps to ensure the effective execution of an organization ' s disaster recovery plan (DRP)?
An organization has determined that fixing a security vulnerability in a critical application is too costly to be feasible, but the impact is material to the business. Which of the following is the MOST appropriate risk treatment?
Which of the following should be the GREATEST concern for an information security manager when an annual audit reveals the organization ' s business continuity plan (BCP) has not been reviewed or updated in more than a year?
Which of the following is MOST effective in monitoring an organization ' s existing risk?
Which of the following is a prerequisite for formulating a business continuity plan (BCP)?
Which of the following is the MOST critical factor for information security program success?
Which of the following should be the PRIMARY basis for an information security strategy?
Which of the following is the BEST indication of an effective information security program?
Which of the following is the BEST way for an information security manager to learn of zero-day vulnerabilities?
Which of the following BEST minimizes information security risk in deploying applications to the production environment?
Which of the following is MOST important for an information security manager to consider when identifying information security resource requirements?
An organization has received complaints from users that some of their files have been encrypted. These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?
Which of the following is MOST important to ensure the alignment of an information security program with the organizational strategy?
An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?
A proposal designed to gain buy-in from senior management for a new security project will be MOST effective if it includes:
During which of the following phases should an incident response team document actions required to remove the threat that caused the incident?
Which of the following control types should be considered FIRST for aligning employee behavior with an organization ' s information security objectives?
To confirm that a third-party provider complies with an organization ' s information security requirements, it is MOST important to ensure:
Which of the following principles BEST addresses the protection of data from unauthorized modification?
Which of the following is the MOST effective defense against malicious insiders compromising confidential information?
Which of the following provides the MOST comprehensive understanding of an organization ' s information security posture?
Which of the following is an information security manager ' s BEST course of action when a threat intelligence report indicates a large number of ransomware attacks targeting the industry?
A daily monitoring report reveals that an IT employee made a change to a firewall rule outside of the change control process. The information security manager ' s FIRST step in addressing the issue should be to:
Which of the following is MOST important to the effectiveness of an information security program?
Which of the following is the MOST important consideration when evaluating the performance of existing security controls?
Which of the following BEST protects against emerging advanced persistent threat (APT) actors?
A small organization needs to use a solution that is out of support in order to meet business objectives. Which of the following is the information security manager’s BEST course of action to manage the associated risk?
Which of the following is the PRIMARY benefit of training service desk staff to recognize incidents?
Which of the following is MOST important to have in place when conducting a security control assessment of a system?
Of the following, who is BEST positioned to be accountable for risk acceptance decisions based on risk appetite?
An organization plans to leverage popular social network platforms to promote its products and services. Which of the following is the BEST course of action for the information security manager to support this initiative?
Which of the following is the MOST important reason for obtaining input from risk owners when implementing controls?
Which of the following BEST enables an organization to transform its culture to support information security?
Which of the following is MOST important for guiding the development and management of a comprehensive information security program?
Of the following, who is BEST suited to own the risk discovered in an application?
Which of the following is MOST critical when creating an incident response plan?
To help ensure that an information security training program is MOST effective, its contents should be:
What is the BEST way to reduce the impact of a successful ransomware attack?
An organization has implemented controls to mitigate risks resulting from identified vulnerabilities in an application. Which of the following is the BEST way to verify all weaknesses have been addressed?
Which of the following is MOST important to include in monthly information security reports to the board?
An incident management team is alerted ta a suspected security event. Before classifying the suspected event as a security incident, it is MOST important for the security manager to:
In the context of developing an information security strategy, which of the following provides the MOST useful input to determine the or
Which of the following metrics BEST demonstrates the effectiveness of an organization ' s security awareness program?
Which of the following is MOST important to the ongoing success of an information security program?
Which of the following is the MOST effective way to help staff members understand their responsibilities for information security?
Which of the following is the PRIMARY reason for an information security manager to periodically review existing controls?
Which of the following would BEST enable the timely execution of an incident response plan?
Which of the following is MOST useful to an information security manager when reporting the performance of the information security program to senior management?