Question 11
A global health insurance company is concerned about protecting confidential information. Which of the following is of MOST concern to this organization?
Question 12
The regular review of a firewall ruleset is considered a _______________________.
Question 13
SCENARIO: A Chief Information Security Officer (CISO) recently had a third party conduct an audit of the security program. Internal policies and international standards were used as audit baselines. The audit report was presented to the CISO and a variety of high, medium and low rated gaps were identified.
The CISO has validated audit findings, determined if compensating controls exist, and started initial remediation planning. Which of the following is the MOST logical next step?
The CISO has validated audit findings, determined if compensating controls exist, and started initial remediation planning. Which of the following is the MOST logical next step?
Question 14
SCENARIO: Critical servers show signs of erratic behavior within your organization's intranet. Initial information indicates the systems are under attack from an outside entity. As the Chief Information Security Officer (CISO), you decide to deploy the Incident Response Team (IRT) to determine the details of this incident and take action according to the information available to the team.
In what phase of the response will the team extract information from the affected systems without altering original data?
In what phase of the response will the team extract information from the affected systems without altering original data?
Question 15
Which of the following functions implements and oversees the use of controls to reduce risk when creating an information security program?
