Which of the following activities results in change requests?, Corrective actions, Defect repair, Preventive actions, Inspection, What is the MAIN reason for conflicts between Information Technology and Information Security programs?, The effective implementation of security controls can be viewed as an inhibitor, Technology Governance is focused on process risks whereas SecurityGovernance is focused on business risk., Technology governance defines technology policies and standards while security governance does not., Security governance defines technology best practices and Information Technology governance does not., Which of the following is the MOST important for a CISO to understand when identifying threats?, How the security operations team will behave to reported incidents, How vulnerabilities can potentially be exploited in systems that impact the organization, How the firewall and other security devices are configured to prevent attacks, How the incident management team prepares to handle an attack, Who is responsible for securing networks during a security incident?, Security Operations Center (SOC), Chief Information Security Officer (CISO), Disaster Recovery (DR) manager, Incident response Team (IRT), What is the BEST way to achieve on-going compliance monitoring in an organization?, Outsource compliance to a 3 rd party vendor and let them manage the program., Have Compliance Direct Information Security to fix issues after the auditor report., Only check compliance right before the auditors are scheduled to arrive onsite., Have Compliance and Information Security partner to correct issues as they arise., The success of the Chief Information Security Officer is MOST dependent upon:, following the recommendations of consultants and contractors, raising awareness of security issues with end users, favorable audit findings, development of relationships with organization executives, During the course of a risk analysis your IT auditor identified threats and potential impacts. Next, your IT auditor should:, Identify and assess the risk assessment process used by management., Identify and evaluate existing controls., Identify information assets and the underlying systems., Disclose the threats and impacts to management., Which of the following is a fundamental component of an audit record?, Originating IP-Address, Date and time of the event, Failure of the event, Authentication type, What is the main purpose of the Incident Response Team?, Communicate details of information security incidents, Create effective policies detailing program activities, Ensure efficient recovery and reinstate repaired systems, Provide effective employee awareness programs, Risk appetite directly affects what part of a vulnerability management program?, Scope, Schedule, Staff, Scan tools, Creating a secondary authentication process for network access would be an example of?, An administrator with too much time on their hands, Supporting the concept of layered security, Network segmentation, Putting undue time commitment on the system administrator, According to ISO 27001, of the steps for establishing an Information Security Governance program listed below, which comes first?, Decide how to manage risk, Define Information Security Policy, Identify threats, risks, impacts and vulnerabilities, Define the budget of the Information Security Management System, Which of the following functions MUST your Information Security Governance program include for formal organizational reporting?, Human Resources and Budget, Audit and Legal, Budget and Compliance, Legal and Human Resources, The implementation of anti-malware and anti-phishing controls on centralized Email, Technical control, Management control, Procedural control, Organization control, Which of the following is a term related to risk management that represents the estimated frequency at which a threat is expected to transpire?, Temporal Probability (TP), Annualized Rate of Occurrence (ARO), Single Loss Expectancy (SLE), Exposure Factor (EF), A security officer wants to implement a vulnerability scanning program. The officer is uncertain of the state of vulnerability resiliency within the organization's large IT infrastructure. What would be the BEST approach to minimize scan data output while retaining a realistic view of system vulnerability?, Decrease the vulnerabilities within the scan tool settings, Scan a representative sample of systems, Filter the scan output so only pertinent data is analyzed, Perform the scans only during off-business hours, What should an organization do to ensure that they have a sound Business Continuity (BC) Plan?, Conduct a Disaster Recovery (DR) exercise every year to test the plan, Conduct periodic tabletop exercises to refine the BC plan, Test every three years to ensure that the BC plan is valid, Define the Recovery Point Objective (RPO), which of the following considerations are MOST important when creating a vulnerability management program?, Susceptibility to attack, expected duration of attack, and mitigation availability, Attack vectors, controls cost, and investigation staffing needs, Susceptibility to attack, mitigation response time, and cost, Vulnerability exploitation, attack recovery, and mean time to repair, When deploying an Intrusion Prevention System (IPS), the BEST way to get maximum protection from the system is to deploy it___________, In-line and turn on alert mode to stop malicious traffic., In promiscuous mode and block malicious traffic., In promiscuous mode and only detect malicious traffic., In-line and turn on blocking mode to stop malicious traffic in-line., Which of the following is a weakness of an asset or group of assets that can be exploited by one or more threats?, Vulnerability, Threat, Exploitation, Attack vector, How often should an environment be monitored for cyber threats, risks, and exposure?, Weekly, Daily, Monthly, Quarterly, Many times, a CISO may have to speak to the Board of Directors (BOD) about their cyber security posture. What would be the BEST choice of security metrics to present to the BOD?, All vulnerabilities found on servers and desktops, Only critical and high vulnerabilities servers, Only critical and high vulnerabilities on servers and desktops, All vulnerabilities that impact important production servers, Creating a secondary authentication process for network access would be an example of?, Defense in depth cost enumerated costs, Nonlinearities in physical security performance metrics, System hardening and patching requirements, Anti-virus for mobile devices, In MOST organizations which group periodically reviews network intrusion detection system logs for all systems as part of their daily tasks?, Internal Audit, Information Security, Compliance, Database Administration, Which of the following BEST describes an international standard framework that is based on the security model Information Technology-Code of Practice for Information Security Management?, National Institute of Standards and technology Special Publication SP 800-12, Request for Comment 2196, International Organization for Standardization 27001, National Institute of Standards and technology Special Publication SP 800-26, The BEST organization to provide a comprehensive, independent and certifiable perspective on established security controls in an environment is _______________, External Audit, Forensic experts, Internal Audit, Penetration testers, When a critical vulnerability has been discovered on production systems and needs to be fixed immediately, what is the BEST approach for a CISO to mitigate the vulnerability under tight budget constraints?, Schedule an emergency meeting and request the finding to fix the issue, Take the system off line until budget is available, Transfer financial resources from other critical programs, Deploy countermeasures and compensation controls until the budget is available, The executive board has requested that the CISO of an organization define and Key Performance Indicators (KPI) to measure the effectiveness of the security awareness program provided to call center employees. Which of the following can be used as a KPI?, Number of successful social engineering attempts on the call center, Number of callers who abandon the call before speaking with a representative, Number of callers who report a lack of customer service from the call center, Number of callers who report security issues., The effectiveness of social engineering penetration testing using phishing can be used as a Key Performance Indicator (KPI) for the effectiveness of an organization's, Risk Management Program, Anti-Spam controls, Identity and Access Management Program, Security Awareness Program, Which of the following is the MOST effective way to measure the effectiveness of security controls on a perimeter network?, Perform a vulnerability scan of the network, Internal Firewall ruleset reviews, Implement network intrusion prevention systems, External penetration testing by a qualified third party, The CIO of an organization has decided to assign the responsibility of internal IT audit to the IT team. This is considering a bad practice MAINLY because_______________, The IT team is not familiar in IT audit practices, This represents a bad implementation of the Least Privilege principle, The IT team is not certified to perform audits, This represents a conflict of interest, Which of the following activities is the MAIN purpose of the risk assessment process?, Creating an inventory of information assets, Calculating the risks to which assets are exposed in their current setting, Classifying and organizing information assets into meaningful groups, Assigning value to each information asset, You are the Chief Information Security Officer of a large, multinational bank and you suspect there is a flaw in a two-factor authentication token management process. Which of the following represents your BEST course of action?, Determine program ownership to implement compensating controls, Send a report to executive peers and business unit owners detailing your suspicions, Validate that security awareness program content includes information about potential vulnerability, Conduct a throughout risk assessment against the current implementation to determine system functions, Which of the following is considered to be an IT governance framework and a supporting toolset that allows for managers to bridge the gap between control requirements, technical issues, and business risks?, Information technology Infrastructure Library (ITIL), Committee of Sponsoring Organizations (COSO), Control Objective for Information Technology (COBIT), Payment Card Industry (PCI), Which is the BEST solution to monitor, measure, and report changes to critical data in a system?, SNMP traps, Syslog, File integrity monitoring, Application logs, Which of the following represents the BEST reason for an organization to use the Control Objectives for Information and Related Technology (COBIT) as an Information Technology (IT) framework?, Information Security (IS) procedures often require augmentation with other standards, Implementation of it eases an organization auditing and compliance burden, It provides for a consistent and repeatable staffing model for technology organizations, It allows executives to more effectively monitor IT implementation costs, The mean time to patch, number of virus outbreaks prevented, and number of vulnerabilities mitigated are examples of what type of performance metrics?, Risk metrics, Operational metrics, Compliance metrics, Management metrics, When should IT security project management be outsourced?, On projects not forecasted in the yearly budget, When organizational resources are limited, When the benefits of outsourcing outweigh the inherent risks of outsourcing, On new, enterprise-wide security initiatives, Assigning the role and responsibility of Information Assurance to a dedicated and independent security group is an example of:, Detective Controls, Proactive Controls, Organizational Controls, Preemptive Controls, An international organization is planning a project to implement encryption technologies to protect company confidential information. This organization has data centers on three continents. Which of the following would be considered a MAJOR constraint for the project?, Compliance to local hiring laws, Encryption import/export regulations, Local customer privacy laws, Time zone differences, A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be your first priority?, Review the recommendations and follow up to see if audit implemented the changes, Meet with audit team to determine a timeline for corrections, Have internal audit conduct another audit to see what has changed., Contract with an external audit company to conduct an unbiased audit, The risk found after a control has been fully implemented is called:, Total Risk, Transferred Risk, Residual Risk, Post Implementation Risk, Which of the following set of processes is considered to be one of the cornerstone cycles of the International Organization for Standardization (ISO) 27001 standard?, Plan-Check-Do-Act, Plan-Select-Implement-Evaluate, Plan-Do-Check-Act, SCORE (Security Consensus Operational Readiness Evaluation), A recent audit has identified a few control exceptions and is recommending the implementation of technology and processes to address the finding. Which of the following is the MOST likely reason for the organization to reject the implementation of the recommended technology and processes?, The organization has purchased cyber insurance, The risk tolerance of the organization permits this risk, The CIO of the organization disagrees with the finding, The auditors have not followed proper auditing processes, When you develop your audit remediation plan what is the MOST important criteria?, To validate the remediation process with the auditor., To validate that the cost of the remediation is less than risk of the finding., To remediate half of the findings before the next audit., To remediate all of the findings before the next audit., To have accurate and effective information security policies how often should the CISO review the organization policies?, Before an audit, At least once a year, Quarterly, Every 6 month, When a CISO considers delaying or not remediating system vulnerabilities which of the following are MOST important to take into account?, Threat Level, Risk of Compromise, and Consequences of Compromise, Risk Avoidance, Threat Level, and Consequences of Compromise, Reputational Impact, Financial impact, and Risk of Compromise, Risk transfer, reputational Impact, and Consequences of Compromise, When managing the critical path of an IT security project, which of the following is MOST important?, Knowing all the stakeholders., Knowing the milestones and timelines of deliverables., Knowing the people on the data center team., Knowing the threats to the organization, Creating good security metrics is essential for a CISO. What would be the BEST sources for creating security metrics for baseline defenses coverage?, Servers, routers, switches, modem, Firewall, anti-virus console, IDS, syslog, Firewall, exchange, web server, intrusion detection system (IDS), IDS, syslog, router, switches, A Chief Information Security Officer received a list of high, medium, and low impact audit findings. Which of the following represents the BEST course of action?, If the findings do not impact regulatory compliance, remediate only the high and medium risk findings., If the findings do not impact regulatory compliance, review current security controls., If the findings impact regulatory compliance, try to apply remediation that will address the most findings for the least cost., if the findings impact regulatory compliance, remediate the high findings as quickly as possible., At which point should the identity access management team be notified of the termination of an employee?, Immediately so the employee account(s) can be disabled, During the monthly review cycle, At the end of the day once the employee is off site, Before an audit, Providing oversight of a comprehensive information security program for the entire organization is the primary responsibility of which group under the InfoSec, governance framework?, Office of the Auditor, Senior Executives, All employees and users, Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology., ISO 27005, ISO 27004, ISO 27002, ISO 27001, With respect to the audit management process, management response serves what funtion?, revealing the root cause of the process failure and mitigating for all internal and external units, adding controls to ensure that proper oversight is achieved by management, determining whether or not resources will be allocated to remediate a finding, placing underperforming units on notice for failing to meet standards, The remediation of a specific audit finding is deemed too expensive and will not be implemented. Which of the following is a TRUE statement?, The audit findings is incorrect, The asset is more expensive than the remediation, The asset being protected is less valuable than the remediation costs, The remediation costs are irrelevant; it must be implemented regardless of cost, Which of the following organizations is typically in charge of validating the Implementation and effectiveness of security controls?, Security Operations, Internal/External Audit, Risk Management, Security Administrators, An information security department is required to remediate system vulnerabilities when they are discovered. Please select the three primary remediation methods that can be used on an affected system., Install software patch, configuration adjustment, software removal, Install software patch, operate system, maintain system, Discover software, remove affected software, apply software patch, Software removal, install software patch, maintain system, Which of the following best describes the purpose of the International Organization for Standardization (ISO) 27002 standard?, To provide effective security management practice and to provide confidence in interorganizational dealings, To established guidelines and general principles for initiating, implementing, maintaining and improving information security management within an organization, To give information security management recommendations to those who are responsible for initiating, implementing, or maintaining security in their organization., To provide a common basis for developing organizational security standards, Which represents PROPER separation of duties in the corporate environment?, Information Security and Network teams perform two distinct functions, Information Security and Identity Access Management teams perform two distinct functions, Finance has access to Human Resources data, Developers and Network teams both have admin rights on servers, When working in the Payment Card Industry (PCI), how often should security logs be review to comply with the standards?, Monthly, Hourly, Weekly, Daily, The MOST common method to get an unbiased measurement of the effectiveness of an Information Security Management System (ISMS) is to_________________________., Assign the responsibility to the information security team, assign the responsibility to the team responsible for the management of the controls, perform an independent audit of the security controls, create operational reports on the effectiveness of the controls., The ultimate goal of an IT security projects is:, Support business requirements, Implement information security policies, Increase stock value, Complete security, An organization has implemented a change management process for all changes to the IT production environment. This change management process follows best practices and is expected to help stabilize the availability and integrity of the organization's IT environment. Which of the following can be used to measure the effectiveness of this newly implemented process?, Number and length of planned outages, Number of change orders processed, Number of change orders rejected, Number of unplanned outages, You have implemented the new controls. What is the next step?, Perform a risk assessment, Monitor the effectiveness of the controls, Document the process for the stakeholders, Update the audit findings report, Step-by-step procedures to regain normalcy in the event of a major earthquake is PRIMARILY covered by which of the following plans?, Damage control plan, Disaster recovery plan, Business Continuity plan, Incident response plan, An employee successfully avoids becoming a victim of a sophisticated spear phishing attack due to knowledge gained through the corporate information security awareness program. What type of control has been effectively utilized?, Technical Control, Management Control, Operational Control, Training Control, A system was hardened at the Operating System level and placed into the production environment. Months later an audit was performed and it identified insecure configuration different from the original hardened state. Which of the following security issues is the MOST likely reason leading to the audit findings?, Lack of asset management processes, Lack of hardening standards, Lack of proper access controls, Lack of change management processes, When is an application security development project complete?, When the application turned over to production., After one year, When the application reaches the maintenance phase., When the application is retired., An audit was conducted and many critical applications were found to have no disaster recovery plans in place. You conduct a Business Impact Analysis (BIA) to determine impact to the company for each application. What should be the NEXT step?, Create technology recovery plans, Determine the annual loss expectancy (ALE), Build a secondary hot site, Create a crisis management plan, Which of the following activities must be completed BEFORE you can calculate risk?, Assigning a value to each information asset, Assessing the relative risk facing the organization's information assets, Determining the likelihood that vulnerable systems will be attacked by specific threats, Calculating the risks to which assets are exposed in their current setting, Which of the following are primary concerns for management with regard to assessing internal control objectives?, Confidentiality, Availability, Integrity, Compliance, Effectiveness, Efficiency, Communication, Reliability, Cost, Confidentiality, Compliance, Cost, The effectiveness of an audit is measured by?, The number of security controls the company has in use, How it exposes the risk tolerance of the company, The number of actionable items in the recommendations, How the recommendations directly support the goals of the company, Which of the following is the MOST important reason to measure the effectiveness of an Information Security Management System (ISMS)?, Better understand the threats and vulnerabilities affecting the environment, Better understand strengths and weakness of the program, Meet regulatory compliance requirements, Meet legal requirements, Control Objectives for Information and Related Technology (COBIT) is which of the following?, An audit guideline for certifying secure systems and controls, An information Security audit standard, A framework for Information Technology management and governance, A set of international regulations for Information Technology governance, Which of the following are not stakeholders of IT security projects?, Board of directors, Help Desk, Third party vendors, CISO, Which of the following illustrates an operational control process:, Classifying an information system as part of a risk assessment, Conducting an audit of the configuration management process, Installing an appropriate fire suppression system in the data center, Establishing procurement standards for cloud vendors, A person in your security team calls you at night and informs you that one of your web applications is potentially under attack from a cross-site scripting vulnerability. What do you do?, Tell him to shut down the server, Tell him to call the police, Tell him to invoke the incident response process, Tell him to analyze the problem, preserve the evidence and provide a full analysis and report., Which of the following are necessary to formulate responses to external audit findings?, Technical Staff, Budget Authority, Management, Technical Staff, Internal Audit, Budget Authority, Internal Audit, Budget Authority, Management, Internal Audit, management, and Technical Staff, Which of the following is the PRIMARY purpose of International Organization for Standardization (ISO) 27001?, Implementation of business-enabling information security, Use within an organization to ensure compliance with laws and regulations, To enable organizations that adopt it to obtain certifications, Use within an organization to formulate security requirements and objectives, A missing/ineffective security control is identified. Which of the following should be the NEXT step?, Perform an audit to measure the control formally, Escalate the issue to the IT organization, Perform a risk assessment to measure risk, Establish Key Risk Indicators, Acme Inc. has engaged a third party vendor to provide 99.999% up-time for their online web presence and had them contractually agree to this service level agreement. What type of risk tolerance is Acme exhibiting?, Medium-high risk-tolerance, low risk-tolerance, high risk-tolerance, moderate risk-tolerance, Your incident response plan should include which of the following?, Procedures for classification, Procedures for charge-back, Procedures for reclamation, Procedures for litigation, To get an Information Security project back on schedule, which of the following will provide the MOST help?, Upper management support, More frequent project milestone meetings, C. Stakeholder support, None, Extend work hours, You currently cannot provide for 24/7 coverage of your security monitoring and incident response duties and your company is resistant to the idea of adding more full-time employees to the payroll. Which combination of solutions would help to provide the coverage needed without the addition of more dedicated staff?, Employ an assumption of breach protocol and defend only essential information resources., Deploy a SEIM solution and have your staff review incidents first thing in the morning, Configure your syslog to send SMS messages to current staff when target events are triggered., Engage a managed security provider and have current staff on call for incident response, A department within your company has proposed a third party vendor solution to address an urgent, critical business need. As the CISO you have been asked to accelerate screening of their security control claims. Which of the following vendor provided documents is BEST to make your decision?, Vendor provided reference from an existing reputable client detailing their implementation, Vendor’s client list of reputable organizations currently using their solution, Vendor provided internal risk assessment and security control documentation, Vendor provided attestation of the detailed security controls from a reputable accounting firm, A severe security threat has been detected on your corporate network. As CISO you quickly assemble key members of the Information Technology team and business operations to determine a modification to security controls in response to the threat. This is an example of:, Change management, Thought leadership, Business continuity planning, Security Incident Response, Which of the following represents the best method of ensuring business unit alignment with security program requirements?, Create collaborative risk management approaches within the organization, Perform increased audits of security processes and procedures, Provide clear communication of security requirements throughout the organization, Demonstrate executive support with written mandates for security policy adherence, When operating under severe budget constraints a CISO will have to be creative to maintain a strong security organization. Which example below is the MOST creative way to maintain a strong security posture during these difficult times?, Download security tools from a trusted source and deploy to production network, Download open source security tools from a trusted site, test, and then deploy, Download trial versions of commercially available security tools and deploy on your production network, Download open source security tools and deploy them on your production network, How often should the SSAE16 report of your vendors be reviewed?, Quarterly, Semi-annually, Bi-annually, Annually, Which of the following will be MOST helpful for getting an Information Security project that is behind schedule back on schedule?, More frequent project milestone meetings, Involve internal audit, Upper management support, More training of staff members, The organization does not have the time to remediate the vulnerability; however it is critical to release the application. Which of the following needs to be further evaluated to help mitigate the risks?, Provide security testing tools, Provide developer security training, Deploy Intrusion Detection Systems, Implement Compensating Controls, Your company has a `no right to privacy` notice on all logon screens for your information systems and users sign an Acceptable Use Policy informing them of this condition. A peer group member and friend comes to you and requests access to one of her employee's email account., Deny the request citing national privacy laws, None, Grant her access, the employee has been adequately warned through the AUP ., Assist her with the request, but only after her supervisor signs off on the action., Reset the employee's password and give it to the supervisor., Which one of the following BEST describes which member of the management team is accountable for the day-to-day operation of the information security program?, Security managers, Security analysts, Security technicians, Security administrators, Which of the following is a major benefit of applying risk levels?, Resources are not wasted on risks that are already managed to an acceptable level, Risk appetite increase within the organization once the levels are understood, Risk budgets are more easily managed due to fewer due to fewer identified risks as a result of using a methodology, Risk management governance becomes easier since most risks remain low once mitigated, Which business stakeholder is accountable for the integrity of a new information system?, Compliance Officer, CISO, Project manager, Board of directors, A CISO decides to analyze the IT infrastructure to ensure security solutions adhere to the concepts of how hardware and software is implemented and managed within the organization. Which of the following principles does this best demonstrate?, Proper budget management, Effective use of existing technologies, Alignment with the business, Leveraging existing implementations, Which of the following functions evaluates risk present in IT initiatives and/or systems when implementing an information security program?, Risk Assessment, Risk Management, Vulnerability Assessment, System Testing, Which of the following information may be found in table top exercises for incident response?, Real-time to remediate, Process improvements, Security budget augmentation, Security control selection, When gathering security requirements for an automated business process improvement program, which of the following is MOST important?, Type of data contained in the process/system, Type of encryption required for the data once it is at rest, Type of computer the data is processed on, Type of connection/protocol used to transfer the data, You manage a newly created Security Operations Center (SOC), your team is being inundated with security alerts and don't know what to do. What is the BEST approach to handle this situation?, Tune the sensors to help reduce false positives so the team can react better, Request additional resources to handle the workload, Tell the team to do their best and respond to each alert, Tell the team to only respond to the critical and high alertsD. Tell the team to only respond to the critical and high alerts
0%
CCISO- Part2
Share
Share
by
Afifih816
Edit Content
Print
Embed
More
Assignments
Leaderboard
Show more
Show less
This leaderboard is currently private. Click
Share
to make it public.
This leaderboard has been disabled by the resource owner.
This leaderboard is disabled as your options are different to the resource owner.
Revert Options
Quiz
is an open-ended template. It does not generate scores for a leaderboard.
Log in required
Visual style
Fonts
Subscription required
Options
Switch template
Show all
Open results
Copy link
QR code
Delete
Continue editing:
?